What is an MSP security platform?
An MSP security platform is offensive security tooling built to be operated by one organisation on behalf of many. The technical work is the same penetration testing you would run on your own estate. What changes is everything around it: hard isolation between clients, branding that is yours rather than the vendor's, management that works at fleet scale, and commercial terms that leave room for a margin.
Three things separate a genuine partner platform from a product with a reseller discount attached. Isolation has to be structural rather than a filter applied to a shared database. Branding has to reach the client-facing portal and the reports, not just a logo slot. And management has to scale, because logging into a separate console per client stops working somewhere around the fifth client.
PentestOps is built for that model: a dedicated Kubernetes namespace and PostgreSQL database per client, custom domains with SSL auto-managed via ACME, and a fleet orchestrator that reaches every deployed agent. It is a sales-led partner programme, scoped to your client base and your margin model.
| Question | Short answer |
|---|---|
| Who it is for | Managed service providers, resellers and consultancies serving a client base. |
| Client isolation | A dedicated Kubernetes namespace and PostgreSQL database per client. |
| Branding | Custom domain per client or practice, with SSL auto-managed via ACME. |
| Fleet management | One console, with force-update across every deployed client agent. |
| Commercials | Sales-led and asset-wise, on a 3-tier MSP plan catalogue. See the partner programme. |
Built to be resold, not just used
Most security platforms are built for one organisation to use on itself. Managed service providers and reseller partners need something different: a platform they can put their own name on, keep every client's data completely separate, and manage at fleet scale without logging into a dozen disconnected consoles.
The PentestOps MSP Security Platform is built for exactly that. It is the same full-stack penetration testing platform, external, internal, web, API, cloud and identity, wrapped in the isolation, branding and fleet management a partner business actually needs. It is a sales-led programme; see the Partner and MSP contact form to start a conversation.
Isolation, client by client
Every client you onboard gets its own Kubernetes namespace with a dedicated PostgreSQL database. There is no shared tenant data store, so one client's findings, credentials and reports are never visible to another, and a problem in one client's environment cannot spill into the next.
On top of that isolation, each client, or your practice as a whole, can run under a custom domain with SSL certificates auto-managed via ACME. Clients log into a portal that looks like yours, not a shared multi-tenant product with your logo pasted on top.
How MSP onboarding works
Because MSP and Partner pricing is sales-led, onboarding starts with a conversation, not a signup form.
- 1. Scope the programme. Book a partner call to talk through your client base, expected asset volume and margin model. Start at the partner programme or go straight to Partner and MSP contact.
- 2. Provision your environment. Your MSP account is set up with its own custom domain and auto-managed SSL.
- 3. Onboard each client. Every client gets an isolated namespace and dedicated database as they come on board.
- 4. Deploy client agents. Each client's on-premise agent deploys in about 5 minutes with 0 inbound firewall rules, and appears in your fleet console.
- 5. Run the full platform, per client. External, internal, web, API, cloud and Active Directory testing, safe exploitation and AI-guided remediation, all scoped to that client's own Rules of Engagement.
- 6. Report under your brand. Findings map to 8 compliance reporting frameworks plus CIS Benchmarks, exported as PDF, CSV or JSON/API.
Managing a fleet of client agents
Each client's on-premise agent connects outbound-only over TLS 443, so there are no inbound firewall rules to open on any client site, no VPN and no jump host. It ships as a Docker container, RPM or DEB package, and deploys in about 5 minutes.
Where a single deployed console is not enough, the fleet orchestrator gives you force-update across customer agents from one place, so a change window or a patch rolls out consistently instead of client by client by hand. Every agent stays tied to its own client's isolated environment and its own Rules of Engagement.
What every client gets
Clients on an MSP-managed tenant get the same platform capability as a direct Enterprise customer, run inside their own isolated environment:
- Full-stack coverage: external perimeter, internal network via the on-premise agent, web applications, APIs, cloud (AWS, Azure, GCP, M365) and identity.
- Active Directory testing, including password-policy auditing and safe, RoE-gated exploit chains. See Active Directory security testing.
- Self-hosted AI by default, so client scan data is not sent to third-party model providers unless a client opts in per tenant.
- Safe automated exploitation, gated by each client's own per-tenant Rules of Engagement, with a full evidence trail.
- Compliance-mapped reporting against 8 frameworks plus CIS Benchmarks, exported as PDF, CSV or JSON/API.
- 7-year data retention, the same term as a direct Enterprise account.
MSP capability at a glance
One partner account, isolated client by client, managed as a single fleet.
| MSP capability | What it means |
|---|---|
| Client isolation | Dedicated Kubernetes namespace and PostgreSQL database per client. No shared tenant data store. |
| Branding | Custom domain per client or practice, with SSL auto-managed via ACME. |
| Agent fleet | Fleet orchestrator manages every deployed agent, with force-update across your customer base. |
| Plan structure | 3-tier MSP plan catalogue, separate from the public plans API, matched to client size. |
| Retention | MSP tenants retain assessment data for 7 years. |
| Onboarding | Sales-led, not self-serve. Scoped to your client base and margin model. |
Why partner with PentestOps
White-labelling a platform means trusting it with your clients' data and your own reputation.
- Real isolation: dedicated namespace and database per client, never a shared tenant data store.
- Your brand: custom domain and auto-managed SSL per client or practice.
- Fleet management: one console, force-update across every client agent.
- The full platform per client: exploitation, AI, compliance mapping and continuous monitoring, not a cut-down reseller tier.
- Australian-built and operated. The platform is hosted in Australia on infrastructure operated by Extranet Systems, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.