For MSPs, vCISOs and agencies
Attack surface management for MSPs and vCISOs, under your brand.
You already answer for your clients' security. The MSP plan puts continuous external attack surface monitoring behind your name: every client watched from one console, every report branded as yours, alerts landing where your team already works, and one flat price that leaves room for margin. Nothing to deploy at client sites.
25 domains across your clients, unlimited scans, daily checks, 25 seats. Two months free on annual billing. No per-asset metering.
What the MSP plan includes
Your brand on every report
Set your firm's name, logo and accent color once, and every report and compliance evidence pack carries them. Attack Surface Scan stays in the engine room; the report you bring to a quarterly review looks like it came from the people your client pays for security, because it did.
Every client in one console
File each client's domains under their own workspace: one view for your team, a dashboard grouped by client, and a clean handover when a client moves on. Twenty-five domains across your book, checked daily.
Alerts routed per client
Point a client's alerts at their own channel: an email list, Slack, Microsoft Teams, PagerDuty, Jira, or your PSA through a webhook. It only ever hears about that client. An expiring certificate becomes a ticket in the right queue, not an email nobody claims.
Unit economics that leave margin
$149/month flat across your whole book: under $6 per client domain, on one bill. No per-asset metering, so a client whose estate grows does not eat your margin. You set what monitoring is worth to your clients.
Honest scoping: the monitoring underneath is the same every Attack Surface Scan plan runs, covering each client's inventory, known vulnerabilities, exposed services, certificates, email security, domain registration, website privacy and reputation. PSA tools connect through a webhook rather than a dedicated integration; if your stack needs something more specific, tell us below and we'll give you a straight answer on timing.
What you can sell with it
Services your clients already understand and will pay for, built on monitoring you do not have to run by hand.
A monthly security report
A branded, dated report per client: a posture score, what changed, and what to fix first. The easiest recurring deliverable you will ever add to a contract.
Audit and insurance evidence
Clients facing SOC 2, ISO 27001 or a cyber-insurance renewal need proof of continuous external monitoring. The evidence pack is that proof, with your name on it.
Exploited-vulnerability watch
When a flaw starts being used in real attacks, you find out which clients run the affected software on the next check, and can call them before they call you.
An inventory they have never had
Most small clients cannot list everything they have on the internet. You can hand them that list, with where each system is hosted, and keep it current.
For the playbook (onboarding, monthly client reports, and pricing it with margin), read attack surface management for MSPs.
For vCISOs and fractional security teams
If your clients are SaaS companies working through SOC 2 or ISO 27001, the same plan is an evidence engine: continuous external monitoring for every client, written up for their auditor under your name.
SOC 2 evidence for every client program
Each client gets a branded evidence pack for their audit period: a daily scan log, coverage gaps disclosed, findings mapped to CC7.1, CC6.6 and CC6.7, and the domains in scope with their ownership proof. What the pack contains →
Walkthroughs answered by page reference
When the auditor asks how a client monitors its external systems, the answer is a section of a dated document rather than a screen share. One less meeting per client per audit.
Risk acceptance with an owner
Accepting a finding records who decided, why, and until when, and the exception register prints it for the auditor. Expired acceptances reopen on their own, so nothing is quietly accepted forever.
Every program from one console
Client workspaces keep each company's domains, alerts and reports apart, so a book of SOC 2 clients runs from one account with your name on everything they receive.
Questions before you commit?
Bigger book than 25 domains, a PSA integration you can't live without, or procurement that needs an authorization-to-scan agreement? A few sentences is plenty, and a person replies within a business day.
What to expect
A reply from a person, not a sequence. MSP customers talk directly to the people building the product, and feature asks from working MSPs decide what ships next. If Attack Surface Scan isn't the right engine for what you're describing, we'll say so plainly.
Partner questions
Can MSPs white-label Attack Surface Scan?
Yes. White-label is part of the MSP plan ($149/month, or $1,490/year with two months free): reports branded with your logo, name and accent color, client workspaces that group domains per end customer, alerts routed per client, 25 domains, 250 systems per domain, unlimited scans, daily scheduled checks, 25 team seats and the REST API. See pricing for the full comparison.
We're a vCISO or fractional security firm, not an MSP. Is this plan for us?
Yes. The plan is named for MSPs, but it fits anyone who runs security for several companies: client workspaces, white-label reports and per-client alerts work the same way. vCISOs mostly use it for the evidence pack, which gives each client's SOC 2 or ISO 27001 auditor a dated record of external monitoring across the audit period. See SOC 2 evidence for what it contains.
What does white-label mean here?
Your clients see your brand, not ours. Reports carry your logo and firm name, alerts reach your team through your own tools, and you remain the security provider your client deals with. Attack Surface Scan is the monitoring engine underneath: it finds each client's internet-facing systems, checks them on a schedule and tells you what changed.
How do we get permission to monitor a client's domains?
A domain is only checked after control of it is proven, for MSPs as for everyone. The fastest route is usually an emailed approval: send a request to your contact at the client (for example their IT lead), they click approve, and nothing needs changing on their side. If you already manage their domain or website, you can publish the proof yourself. Monitoring a client without their knowledge is deliberately not possible. Technical details are in getting started.
Do we have to install anything at client sites?
No. There are no agents, appliances or network access. Onboarding a client is adding their domain and getting it approved, and their first report is ready in minutes.
Does it plug into our PSA or ticketing?
Alerts can go to email, Slack, Microsoft Teams, PagerDuty and Jira, and to any PSA or ticketing system that accepts a webhook, scoped per client. The REST API (included on the MSP plan) lets you pull findings and inventory into your own reporting. Setup guides are in the documentation.
What if I manage more than 25 domains?
Talk to us. That is Enterprise territory, with unlimited domains, single sign-on and a countersigned authorization-to-scan agreement. The form below reaches a person who will give you a straight answer on price, usually within one business day.