// PCI REMEDIATION

IMPORT THE SCAN.
NEVER EDIT THE RAW.

The problem is not “a pretty vuln dashboard.” The problem is Nessus PCI exports that must stay auditable. PCRM keeps a raw layer (pcrm_scan_findings) with every imported row unmodified — info and dupes included — and an analytical layer (pcrm_findings, pcrm_servers, pcrm_vulnerabilities) deduped on Hostname + PluginID + Port, environment-classified, status-tracked. Screens and metrics use the clean layer; filtering never rewrites the source. Import CSV/TSV/XLSX/TXT with progress, stall heartbeat, SHA-256 duplicate guard (force override). Findings, servers, enrichment (LAN/AD CSV), vulns, bulk assign, SLA due dates on import (crit 7 / high 30 / med 90 / low 180 / none 365 — never overwrite existing due dates), owner rules, email composer, ServiceNow composer + optional AI fields, reports (environment, executive, technical, aging, audit, scan compare). Weekly digest cron Monday 08:00 ubuntu crontab — Telegram summary in docs is best-effort; tokens are retired, Herald is the live bus. RLS on 13 tables. Login for /app. This landing will not use deleted private screenshots as fake product photos.

Premier Two-layer SoT Nessus import 13 tables RLS
Dashboard Scans How it works
2
Truth layers
13
RLS tables
7d
Crit SLA
Mon 08:00
Digest cron
// HOW IT WORKS

Five steps from Nessus file to a tracked finding

View Scan is the raw file. Working the ticket happens on the deduped finding. Scan Comparison diffs fingerprints, not vibes.

01
Import
CSV/TSV/XLSX/TXT. Progress + stall detection. SHA-256 dupes unless force.
02
Keep the raw
pcrm_scan_findings immutable. Download raw CSV. Delete a batch only as an operator act.
03
Work the clean layer
Filters: env/risk/status/team/host/date. Status, assign, notes, evidence, risk-exception.
04
SLA + owners
Import applies first_seen+N if due_date empty. Owner rules by env/prefix/FQDN.
05
Report or ticket
Six report flavors. Email/SNOW composers. Digest cron. MCP read tools.
Open PCRM
// LAYERS

Raw vs analytical — CSS mock

Not Tenable.io chrome. Left: immutable rows. Right: Hostname+PluginID+Port.

meltuc.tech/pcrm/app/scans — CSS mock, not a product screenshot
Rawevery row kept
Cleandeduped working set
Comparefingerprint diff
// SLA

Due dates from severity, once

Existing dates never overwritten. Crit 7 days from first_seen.

meltuc.tech/pcrm/app/findings — CSS mock, not a product screenshot
critical7d
high30d
medium90d
low180d
// DASHBOARD

Auth-gated grids, not stock photos

Private screenshots were removed from static. This mock is honest CSS.

meltuc.tech/pcrm/app — CSS mock, not a product screenshot
Scans/app/scans
Findings/app/findings
Servers/app/servers
Reports/app/reports/*
// CRON

Monday digest is ubuntu crontab

Not meltuc-pipeline, not Kronos. GET /api/cron/digest localhost. Telegram line in README is stale relative to Herald.

// WHAT IT REFUSES

No silent rewrite of raw rows

Will not “clean” the import table. Will not overwrite a human due_date. Will not publish scan rows on /pcrm/.

// WHO THIS IS FOR

PCI operators with Nessus exports

People who must show an auditor the original file and the working queue as different objects.

// FEATURES

Import, isolate, remediate, report

Cards match README screens. No invented Tenable API sync.

📥
Scan import
Four formats, SHA-256 guard, progress.
🧊
Raw layer
Immutable pcrm_scan_findings.
🧹
Clean layer
Dedup Hostname+PluginID+Port.
🖥
Servers
Severity grid + LAN/AD enrich.
📅
SLA
Import-time due dates, no clobber.
👤
Owner rules
Priority-ordered auto map.
✉️
Email/SNOW
Composers; optional AI fields.
📑
Reports
Six named reports + compare.
🔌
MCP reads
Six agent tools.
// GET STARTED

Import a scan. Leave the raw alone.

Login for /pcrm/app. This page is not your finding queue.

Open PCRM

Requires a MelTuc account. Create one free.

// SAID SLOWLY

What stays true over time

Ingest Nessus PCI scan files, track vulnerabilities, manage remediation. Health stays cheap. If this page disagrees with the signed-in app, trust the app — the product contract and tests enforce that rule.