White-label under your own brand

Resell asset-wise penetration testing under your own brand. Clients see your name and your domain, not ours.

Per-client namespace and database isolation

Every client runs in its own Kubernetes namespace with a dedicated database. No shared tenant data store between clients.

Custom domains with auto-managed SSL

Give each client, or your whole practice, a custom domain with SSL certificates auto-managed via ACME. No manual renewals.

Fleet-wide agent management

Oversee every deployed client agent from one console, with a fleet orchestrator that can force-update agents across your customer base.

3-tier MSP plan catalogue

A dedicated MSP plan catalogue, separate from the public plans API, gives you 3 tiers to match client size.

Sales-led onboarding

MSP and Partner pricing is sales-led, not self-serve, so your programme is scoped to your client base and margin model.

What is an MSP security platform?

An MSP security platform is offensive security tooling built to be operated by one organisation on behalf of many. The technical work is the same penetration testing you would run on your own estate. What changes is everything around it: hard isolation between clients, branding that is yours rather than the vendor's, management that works at fleet scale, and commercial terms that leave room for a margin.

Three things separate a genuine partner platform from a product with a reseller discount attached. Isolation has to be structural rather than a filter applied to a shared database. Branding has to reach the client-facing portal and the reports, not just a logo slot. And management has to scale, because logging into a separate console per client stops working somewhere around the fifth client.

PentestOps is built for that model: a dedicated Kubernetes namespace and PostgreSQL database per client, custom domains with SSL auto-managed via ACME, and a fleet orchestrator that reaches every deployed agent. It is a sales-led partner programme, scoped to your client base and your margin model.

QuestionShort answer
Who it is forManaged service providers, resellers and consultancies serving a client base.
Client isolationA dedicated Kubernetes namespace and PostgreSQL database per client.
BrandingCustom domain per client or practice, with SSL auto-managed via ACME.
Fleet managementOne console, with force-update across every deployed client agent.
CommercialsSales-led and asset-wise, on a 3-tier MSP plan catalogue. See the partner programme.

Built to be resold, not just used

Most security platforms are built for one organisation to use on itself. Managed service providers and reseller partners need something different: a platform they can put their own name on, keep every client's data completely separate, and manage at fleet scale without logging into a dozen disconnected consoles.

The PentestOps MSP Security Platform is built for exactly that. It is the same full-stack penetration testing platform, external, internal, web, API, cloud and identity, wrapped in the isolation, branding and fleet management a partner business actually needs. It is a sales-led programme; see the Partner and MSP contact form to start a conversation.

Isolation, client by client

Every client you onboard gets its own Kubernetes namespace with a dedicated PostgreSQL database. There is no shared tenant data store, so one client's findings, credentials and reports are never visible to another, and a problem in one client's environment cannot spill into the next.

On top of that isolation, each client, or your practice as a whole, can run under a custom domain with SSL certificates auto-managed via ACME. Clients log into a portal that looks like yours, not a shared multi-tenant product with your logo pasted on top.

How MSP onboarding works

Because MSP and Partner pricing is sales-led, onboarding starts with a conversation, not a signup form.

  • 1. Scope the programme. Book a partner call to talk through your client base, expected asset volume and margin model. Start at the partner programme or go straight to Partner and MSP contact.
  • 2. Provision your environment. Your MSP account is set up with its own custom domain and auto-managed SSL.
  • 3. Onboard each client. Every client gets an isolated namespace and dedicated database as they come on board.
  • 4. Deploy client agents. Each client's on-premise agent deploys in about 5 minutes with 0 inbound firewall rules, and appears in your fleet console.
  • 5. Run the full platform, per client. External, internal, web, API, cloud and Active Directory testing, safe exploitation and AI-guided remediation, all scoped to that client's own Rules of Engagement.
  • 6. Report under your brand. Findings map to 8 compliance reporting frameworks plus CIS Benchmarks, exported as PDF, CSV or JSON/API.

Managing a fleet of client agents

Each client's on-premise agent connects outbound-only over TLS 443, so there are no inbound firewall rules to open on any client site, no VPN and no jump host. It ships as a Docker container, RPM or DEB package, and deploys in about 5 minutes.

Where a single deployed console is not enough, the fleet orchestrator gives you force-update across customer agents from one place, so a change window or a patch rolls out consistently instead of client by client by hand. Every agent stays tied to its own client's isolated environment and its own Rules of Engagement.

What every client gets

Clients on an MSP-managed tenant get the same platform capability as a direct Enterprise customer, run inside their own isolated environment:

  • Full-stack coverage: external perimeter, internal network via the on-premise agent, web applications, APIs, cloud (AWS, Azure, GCP, M365) and identity.
  • Active Directory testing, including password-policy auditing and safe, RoE-gated exploit chains. See Active Directory security testing.
  • Self-hosted AI by default, so client scan data is not sent to third-party model providers unless a client opts in per tenant.
  • Safe automated exploitation, gated by each client's own per-tenant Rules of Engagement, with a full evidence trail.
  • Compliance-mapped reporting against 8 frameworks plus CIS Benchmarks, exported as PDF, CSV or JSON/API.
  • 7-year data retention, the same term as a direct Enterprise account.

MSP capability at a glance

One partner account, isolated client by client, managed as a single fleet.

MSP capabilityWhat it means
Client isolationDedicated Kubernetes namespace and PostgreSQL database per client. No shared tenant data store.
BrandingCustom domain per client or practice, with SSL auto-managed via ACME.
Agent fleetFleet orchestrator manages every deployed agent, with force-update across your customer base.
Plan structure3-tier MSP plan catalogue, separate from the public plans API, matched to client size.
RetentionMSP tenants retain assessment data for 7 years.
OnboardingSales-led, not self-serve. Scoped to your client base and margin model.

Why partner with PentestOps

White-labelling a platform means trusting it with your clients' data and your own reputation.

  • Real isolation: dedicated namespace and database per client, never a shared tenant data store.
  • Your brand: custom domain and auto-managed SSL per client or practice.
  • Fleet management: one console, force-update across every client agent.
  • The full platform per client: exploitation, AI, compliance mapping and continuous monitoring, not a cut-down reseller tier.
  • Australian-built and operated. The platform is hosted in Australia on infrastructure operated by Extranet Systems, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.

Frequently Asked Questions

What is the PentestOps MSP Security Platform?

It is the same full-stack penetration testing platform, wrapped in per-client isolation, white-label branding and fleet-wide agent management, so managed service providers and reseller partners can run it across a client base under their own name.

Can I white-label the platform under my own brand?

Yes. You can run each client, or your practice as a whole, under a custom domain with SSL certificates auto-managed via ACME, so clients see your brand rather than PentestOps.

How are my clients isolated from each other?

Every client gets its own Kubernetes namespace with a dedicated PostgreSQL database. There is no shared tenant data store, so one client's findings and credentials are never visible to another.

Can I manage all my clients' agents from one place?

Yes. A fleet orchestrator lets you oversee every deployed client agent and force-update across your customer base from one console, instead of managing each client site by hand.

How is MSP and Partner pricing structured?

Pricing is asset-wise and organised into a 3-tier MSP plan catalogue, kept separate from the public plans API. MSP onboarding is sales-led, so pricing is scoped to your client base. Contact our Partner and MSP team to get a proposal.

Is MSP onboarding self-serve?

No. Unlike the Starter, Professional and Enterprise plans, MSP and Partner accounts are sales-led, not self-serve. Get in touch via Partner and MSP contact to scope a programme for your client base.

Do clients get the full platform, including Active Directory and cloud testing?

Yes. Clients on an MSP-managed tenant get the same capability as a direct Enterprise account inside their own isolated environment: external, internal, web, API, cloud and Active Directory testing, safe exploitation and AI-guided remediation.

How long is client data retained under an MSP account?

MSP tenants retain assessment data for 7 years, the same term as a direct Enterprise account, with 365-day audit-log retention across the platform.

Book a partner call

MSP and Partner pricing is sales-led and scoped to your client base. To talk white-label branding, per-client isolation and fleet-wide agent management, book a partner call.