For MSP & MSSP founders · white-label AI pentesting

Your clients will buy a pentest this year. Make sure they buy it from you.

PentX runs real, exploit-proven pentests in hours. You deliver the report under your own brand, own the client relationship, and keep up to 90% of every engagement. No pentester to hire. No subcontractor taking your margin. Optional CREST-certified human co-sign when an auditor or insurer asks for it.

No credit card. No commitment. Account ready in 24–48 hours.
€250
your cost
€2,500
client price
90%
your margin
Trained on 10,000+ real pentests CREST engineer co-sign ISO 27001 70+ MSPs already delivering
pentx · live engagement
✓ Exploit validated · evidence captured
Report ready in hours · your logo on it
70+
MSPs & IT companies delivering with PentX
Hours
from approved scope to finished report
90%
gross margin you keep per pentest
100%
Big Four auditor acceptance, 12 months running
The window is open now

Pentesting demand is no longer optional. It’s mandated. Someone will collect that revenue from your clients.

Cyber insurance questionnaires, ISO 27001 and SOC 2 audits, PCI-DSS 4.0, NIS2, and vendor security reviews are all pushing your SMB clients toward annual pentesting. When they ask and you say “we don’t do that,” a security boutique gets the project, and a seat at the table with your client.

💰

The subcontractor trap

You sell the project, a boutique does the work, keeps most of the margin, and becomes visible to your client. You carry the risk; they earn the credibility.

The hiring dead end

A senior pentester costs six figures, takes months to find, and becomes a single point of failure for scoping, testing, reporting, and retests.

🔍

The scanner credibility gap

Scanners create tickets, not proof. Insurers, auditors, and boards want a defensible pentest report with validated exploitation, not a CSV of maybes.

📉

The lost-account risk

Every pentest you can’t deliver invites a security provider into your account. Today it’s the pentest. Next quarter it’s your managed services contract.

PentX closes all four gaps at once: you keep the engagement, the margin, the report, and the relationship, without hiring anyone.

How delivery works

From client scope to a white-label report in five steps. Your team never touches an exploit.

You stay the trusted advisor in front of the client. PentX is the delivery engine behind the curtain.

~2 min

Scope it

Add the approved assets: domains, web apps, IP ranges, internal targets, or cloud environments. Scope is enforced at the network layer, so the test physically cannot exceed what you authorize.

hours

PentX attacks

Reconnaissance, exploitation, validation, and evidence collection run autonomously across the approved attack surface. No babysitting required.

auto

Findings are proven

Every confirmed vulnerability ships with reproducible proof: exploit chain, payloads, request/response captures, screenshots, impact, and remediation steps.

your brand

You deliver

Export the report with your logo, your colors, your language. Optional: a CREST-certified senior engineer reviews and co-signs before it reaches the client.

included

Retest & renew

After remediation, run the included retest and hand over proof the issues are fixed. That’s your natural opening for next year’s engagement.

What you can sell with it
Run your own numbers

This is what pentesting does to your P&L.

Drag the sliders. The delivery cost is €250 per pentest on 10-pack pricing. Everything above that is yours.

Your pentesting service line

Most MSPs charge €1,500–€5,000 per engagement depending on scope and market.

Delivery cost assumes 10-pack rate (€250/pentest). Excludes your internal time and follow-on remediation revenue, which is usually 2–3× the pentest itself.

Annual pentest revenue€25,000
PentX delivery cost€2,500
Gross profit, year one€22,500
Gross margin90%
Start Free Trial · claim this margin
No credit card required. Validate report quality before you sell anything.
The deliverable

What lands in your client’s inbox, with your logo on the cover.

A pentest deliverable built for four audiences at once: the client’s technical team, their executives, their insurer, and their auditor.

Your brand on the cover. PentX stays invisible.
Executive summary
Business-level risk, impact, and priority actions an owner or board member actually understands.
Technical findings
Confirmed vulnerabilities with severity, affected assets, exploit evidence, and step-by-step reproduction.
Proof of exploitation
Screenshots, payloads, request/response captures, full exploit chain. Nothing theoretical.
Remediation plan
Practical fixes your team can execute or quote as follow-on projects.
Retest report
Evidence of what was fixed after remediation, included with every pentest credit.
CREST co-sign (optional)
A named CREST-certified senior engineer reviews and signs the report for insurer, auditor, or enterprise review.

Every finding in the report is exploit-proven. If it couldn’t be validated, it doesn’t go in. Your name is on the cover. That’s the standard.

Let’s address what you’re actually thinking

Your reputation goes on that report. Here’s why that’s safe.

Every MSP founder has the same six doubts before reselling pentesting. Here they are, answered straight.

This is what “exploit-proven” means: if it can’t be reproduced, it doesn’t reach your client.

Reputation“What if an AI report embarrasses me in front of a client?”
A finding only enters the report when it’s backed by reproducible exploit evidence: payload, request/response capture, screenshot, affected asset. No hallucinated CVEs, no scanner noise. If PentX couldn’t prove it, your client never sees it.
White-label“Will my client find out it’s a platform I’m reselling?”
On the Partner tier the experience is fully white-labeled: your logo, colors, report template, and positioning. PentX never appears in front of your client unless you choose it. You own the relationship and the renewal.
Acceptance“Will auditors and insurers actually accept this?”
PentX-powered reports were accepted by Big Four auditors with zero revisions over 12 months. For regulated or insurer-facing work, add a named CREST-certified senior engineer who reviews and co-signs before delivery.
Safety“What if the test breaks my client’s environment?”
Scope is enforced at the network layer, so the test cannot touch assets you didn’t authorize. Rate-limiting, kill switches, and full audit logs are part of every engagement, and exploitation uses production-safe techniques.
Expertise“We’re not a security shop. Can we even sell this?”
Yes. That’s exactly who PentX was built for. Your team scopes and reviews; PentX does the offensive work. The launch kit gives you the sales deck, proposal template, pricing calculator, and objection battlecard, plus a review of your first client quote so you don’t underprice it.
Commitment“What if I commit and it doesn’t sell?”
Start free with no credit card, test PentX on your own environment, and judge the report yourself before quoting a single client. Entry is one pentest, not an annual platform contract, and it’s covered by a first-report money-back guarantee. Qualified partners can even get pay-after-paid terms: you pay PentX after your client pays you.
See the report quality yourself, for free
Tip: run the first pentest on your own MSP. If the report wouldn’t convince you, don’t sell it.
Already in production

MSPs and security providers are replacing subcontractors with PentX, and keeping the margin.

125
pentests in 5 months · payback in month one

A US Northeast IT company serving financial-sector clients went from 8–12 outsourced pentests a year to 125 engagements in 5 months, cut cost per engagement by 70%, and turned PCI-DSS 4.0 and SOC 2 evidence into an on-demand service.

US financial-sector IT company
95%
faster report turnaround

CTDefense reduced report production from 25 hours of manual writing to 4 hours of senior review, freeing senior engineers for remediation and client-facing advisory without reducing report defensibility.

CTDefense
100%
Big Four auditor acceptance

Forward Defense submitted PentX-powered reports to Big Four auditors for 12 months with 100% acceptance and zero revisions. MSP-grade delivery, auditor-ready evidence.

Forward Defense
ISO 27001 ISO 9001 GDPR compliant CREST PCI-DSS 4.0
Your options, honestly compared

Five ways to answer a client’s pentest request. Only one keeps the margin and the relationship.

OptionWhat happensWhat it costs you
Say “we don’t do that”Client buys from a security boutiqueThe project, the margin, and a competitor inside your account
Hire a pentesterYou build internal capacitySix-figure fixed cost, months of hiring, one-person bottleneck, retention risk
Subcontract to a boutiqueSomeone else delivers your projectMost of the margin, slower delivery, your client meets your subcontractor
Resell a scannerYou get raw technical findingsYour team still validates, prioritizes, and writes the report. And clients can tell the difference
Deliver with PentXExploit-proven pentest under your brand, in hoursFrom €250 per engagement. You keep up to 90% and the client never leaves your orbit

PentX gives you the economics of software, the credibility of exploit-proven testing, and the commercial control of a white-label service.

Pricing

Start with one pentest. Scale into a branded security practice.

Every paid pentest includes one retest. Scope is confirmed before launch, so you always know your delivery cost before you quote a client.

Pilot
Validate report quality on your own environment first.
€500 / pentest / year
1 pentest + 1 retest
  • External, web, internal, or cloud scope
  • Exploit-proven findings with evidence
  • Client-ready, white-label report export
  • Optional CREST-certified co-sign
  • Money-back if the first report doesn’t meet your standard
Start Free Trial
Best for proving the report to yourself before you quote a client.
★ Most popular with MSPs
MSP 10-Pack
Add annual pentesting to 5–10 clients at €250 per pentest.
€2,500 / year
10 pentests + 10 retests · €250/pentest
  • 10 pentest credits, any engagement type
  • 10 retests of the same scopes
  • White-label report exports
  • Reusable client-facing report format
  • Optional CREST-certified co-sign
  • Margin model built for resale: sell one engagement and the pack pays for itself
Start Free Trial
Best if clients already ask you about pentests, insurance evidence, or compliance.
White-label Partner
Launch a fully branded pentesting service line.
€2,500 / year
+ €2,500 one-time MSP Launch Kit
  • Everything in MSP 10-Pack
  • Fully white-label client experience
  • Sales deck, proposal template, email sequence
  • Quote calculator & objection battlecard
  • Onboarding session + first-quote review
  • Priority partner support
  • Pay-after-paid terms for qualified partners
Talk to the partner team
Best if you want the positioning, assets, and support to start selling immediately.
Scale Partner
MSSPs and providers delivering 25+ pentests per year.
Custom
Volume pricing
  • 25, 50, 100+ pentest credit packages
  • Multi-client delivery workflow
  • Custom white-label setup
  • Partner success & co-selling support
  • CREST-certified review packages
  • Flexible commercial terms
Talk to the partner team
Best when pentesting becomes a strategic service line, not an occasional project.
🛡
First-report guarantee: if your first report doesn’t meet your standard, we refund the pentest. No forms, no friction. And you’re never selling alone: onboarding session, first-quote review, and a partner team on call for your first client deals. Qualified partners can pay PentX after their client pays them.
Every paid pentest includes one retest. PentX covers web applications, external networks, internal networks, and cloud environments.
White-label partner program

You don’t need to become a security company. You need the words, the price, and the deck.

MSPs rarely fail at pentesting for lack of demand. They fail for lack of an offer. The MSP Launch Kit closes that gap on day one.

The 20-second pitch your account managers will use
“We now offer annual penetration testing as part of our security services. You get an evidence-backed report showing exactly how your environment could be exploited, what to fix, and proof after remediation, accepted for cyber insurance, audits, and vendor reviews. When required, a named CREST-certified engineer signs off.”
The eight moments clients say yes
Cyber insurance renewal ISO 27001 / SOC 2 prep PCI-DSS 4.0 evidence request New portal, VPN, firewall, or cloud go-live Quarterly business review Scanner just found criticals Board or investor security review New managed-IT client onboarding
Your questions, answered

Everything an MSP founder asks before the first engagement.

Is PentX just a vulnerability scanner with a nicer report?

No. Scanners list what might be vulnerable. PentX delivers a pentest-style engagement: it exploits, validates, and documents what is actually vulnerable, with reproducible evidence, business impact, remediation guidance, and a client-ready report. Nothing reaches the report without proof.

Will my client ever know PentX is behind it?

Not unless you tell them. On the Partner tier the entire client experience is white-labeled: your logo, your colors, your report template, your positioning. You own the relationship, the pricing, and the delivery.

Can the test damage my client's environment?

The authorized scope is enforced at the network layer, so the test cannot touch assets you have not approved. Rate-limiting, kill switches, and full audit logs are built into the delivery model, and exploitation is performed with production-safe techniques.

Will auditors and insurers accept the report?

PentX-powered reports have been accepted by Big Four auditors with zero revisions over 12 months. For insurer, auditor, or enterprise review you can add a named CREST-certified senior engineer who reviews and co-signs the report before delivery.

We're not security experts. Can we still sell and support this?

Yes. Your team defines the client scope and reviews the output; PentX handles reconnaissance, exploitation, validation, evidence, and reporting. The Partner launch kit includes the sales deck, proposal template, pricing calculator, and objection battlecard, plus an onboarding session and a review of your first client quote.

What does one pentest credit include?

One credit covers one approved engagement scope (an external, web, internal, or cloud pentest for one client) plus one retest of the same scope after remediation. Scope is confirmed before launch, so you know your delivery cost before you quote. Large multi-environment scopes may need more credits, but you'll know before the engagement starts.

What if the pentest finds nothing serious?

A clean report is still the deliverable your client is paying for: defensible evidence for insurers, auditors, and boards that their environment was tested against real exploitation. In practice, most environments produce actionable findings, which become your remediation and managed-security pipeline.

How do MSPs make money with PentX?

With 10-pack pricing your delivery cost can be €250 per pentest. You set your own client price, typically €1,500–€5,000, and keep the margin. Then the findings drive follow-on revenue: remediation projects, retests, compliance support, managed security upgrades, and vCISO services.

Can we use PentX for cyber insurance and compliance evidence?

Yes. PentX reports support cyber insurance reviews, ISO 27001, SOC 2, PCI-DSS 4.0, and vendor security reviews. For higher-assurance situations, add the CREST-certified engineer co-sign.

How fast can we deliver the first engagement?

A typical external engagement completes in hours once scope is approved. New partners usually go from signup to their first client-ready quote within days, not months.

Where is engagement data stored and who can see it?

PentX operates under ISO 27001 and GDPR. Engagement data is scoped to your account, evidence is collected only from assets you authorized, and full audit logs document every action taken during the test.

What happens after the client fixes the issues?

Each pentest includes one retest of the same scope. Rerun the test after remediation, verify the fixes, and hand the client proof, which is also your opening for next year's engagement.

Get started

The next pentest your client buys is either your revenue or someone else’s foothold.

Open a free account, run the first pentest on your own environment, and judge the report yourself. If it wouldn’t convince you, don’t sell it. If it would, you just found your highest-margin service line.

No credit card required.  Account ready within 24–48 hours, backed by our first-report money-back guarantee, with onboarding and partner support included.
Start Free Trial · no card needed