The problem is not “a pretty vuln dashboard.” The problem is Nessus PCI exports that must
stay auditable. PCRM keeps a raw layer (pcrm_scan_findings) with every
imported row unmodified — info and dupes included — and an analytical layer
(pcrm_findings, pcrm_servers, pcrm_vulnerabilities) deduped on
Hostname + PluginID + Port, environment-classified, status-tracked. Screens and metrics use the
clean layer; filtering never rewrites the source. Import CSV/TSV/XLSX/TXT with progress, stall
heartbeat, SHA-256 duplicate guard (force override). Findings, servers, enrichment (LAN/AD CSV),
vulns, bulk assign, SLA due dates on import (crit 7 / high 30 / med 90 / low 180 / none 365 — never
overwrite existing due dates), owner rules, email composer, ServiceNow composer + optional AI
fields, reports (environment, executive, technical, aging, audit, scan compare). Weekly digest
cron Monday 08:00 ubuntu crontab — Telegram summary in docs is best-effort; tokens are retired,
Herald is the live bus. RLS on 13 tables. Login for /app. This landing will not use deleted
private screenshots as fake product photos.
View Scan is the raw file. Working the ticket happens on the deduped finding. Scan Comparison diffs fingerprints, not vibes.
Not Tenable.io chrome. Left: immutable rows. Right: Hostname+PluginID+Port.
Existing dates never overwritten. Crit 7 days from first_seen.
Private screenshots were removed from static. This mock is honest CSS.
Not meltuc-pipeline, not Kronos. GET /api/cron/digest localhost. Telegram line in README is stale relative to Herald.
Will not “clean” the import table. Will not overwrite a human due_date. Will not publish scan rows on /pcrm/.
People who must show an auditor the original file and the working queue as different objects.
Cards match README screens. No invented Tenable API sync.
Login for /pcrm/app. This page is not your finding queue.
Open PCRMRequires a MelTuc account. Create one free.
Ingest Nessus PCI scan files, track vulnerabilities, manage remediation. Health stays cheap. If this page disagrees with the signed-in app, trust the app — the product contract and tests enforce that rule.