Partner accounts approved in 24–48h · No credit card required
For MSPs, SMBs and IT companies

Sell pentesting under your brand.
Keep up to 90% margin.

PentX runs the pentest. You deliver the white-label report in hours, under your own brand, at a margin you set. No pentester hire needed.

No credit card required. Account live within 24–48 hours.
70+ MSPs & IT companies onboard CREST-certified co-sign available ISO 27001 certified
PentX dashboard running a live pentest
70+
MSPs delivering with PentX
Hours
to a finished pentest, not weeks
12 mo
unlimited retesting on every package
90%
gross margin you keep
How it works

Client scope to branded report. Three steps.

Your team sells. PentX delivers. Your client never sees us.

~2 min

Scope it

Add the client's approved assets: external, web app, internal or cloud. Scope is locked at the network layer: the test can't go beyond what you authorize.

hours

PentX attacks it

Real reconnaissance, exploitation and validation. Every finding is proven with a working exploit, screenshots and evidence, not scanner guesses.

your brand

You deliver it

Export the report with your logo and colors. Need extra assurance? Add a CREST-certified engineer co-sign. Retest after fixes is included.

Why MSPs switch

Everything a pentest practice needs. Nothing you have to build.

🏷️

100% white-label

Your logo, your colors, your report. Your client buys from you. PentX stays invisible.

🎯

Exploit-proven findings

Not a scanner. Findings only ship with working exploit evidence, impact and fix steps.

✍️

CREST co-sign on demand

A named CREST-certified senior engineer reviews and signs when insurers or auditors require it.

🔒

Scope locked by design

Enforced at the network layer. Rate limits, kill switch, full audit log. It cannot test what you didn't approve.

🔁

Free retest included

Client fixes the issues, you rerun the test and deliver proof. Built-in reason for the next invoice.

🚀

Launch Kit included

Sales deck, proposal template, quote calculator, email sequences and objection battlecard, so you can sell from day one.

The honest part

"Sounds great, but…"

Every MSP founder asks the same five questions. Fair. Here are the answers.

"Isn't this just an AI scanner with a nice report?"
No. Scanners list maybes. PentX proves exploitability: exploit chain, payloads, screenshots, request/response captures. If it can't prove it, it doesn't go in the report.
"What if my client's auditor or insurer rejects it?"
PentX reports passed Big Four audits for 12 months with zero revisions. For regulated work, add a named CREST-certified engineer co-sign.
"What if the AI breaks something in production?"
Scope is enforced at the network layer, so it physically can't touch unapproved assets. Rate limiting, kill switches and audit logs are standard.
"My team has never sold pentesting."
The MSP Launch Kit gives you the deck, proposal, pricing calculator and objection answers, plus an onboarding session and a review of your first client quote.
"What if my client finds out it's not us doing it?"
The Partner plan is fully white-label: report, branding, positioning. You also review everything before it ships. It's your service, delivered your way.
"What if it's not as good as you say?"
Start with a pentest on your own environment. Judge the report quality yourself before you ever put your brand on it.
Already in production

MSPs are doing this right now.

125
pentests in 5 months

A US IT company serving financial clients went from 8–12 outsourced pentests a year to 125 in-house engagements, cutting cost per pentest by 70%. Payback inside month one.

US financial-sector IT company
95%
faster report turnaround

CTDefense cut report production from 25 hours of manual writing to 4 hours of senior review, freeing engineers for billable remediation and advisory work.

CTDefense
100%
Big Four auditor acceptance

Forward Defense submitted PentX-powered reports to Big Four auditors for 12 months. Every report accepted. Zero revisions requested.

Forward Defense
ISO 27001 ISO 9001 GDPR CREST PCI-DSS 4.0
Packages

Penetration Testing Packages

Two engagement models built around how your attack surface actually looks. Each one includes a full year of unlimited retesting and expert validation on demand, scoped and priced around your environment.

External & Web Application
10 targets
1 target = 1 web application or 1 IP
Prove exactly what an attacker could reach from the outside. Every internet-facing application and host is tested, exploited and re-validated for a full year.
  • 10 targets, each one web application or one IP
  • Unlimited retesting for 12 months
  • External infrastructure penetration testing
  • Web application testing, black-box and white-box
  • Internal network penetration test included
  • Cloud configuration review at no extra cost
  • White-label report, ready for clients and auditors
Contact Us
Internal Network Pentest
Up to 100 live IPs
Post-breach and insider threat simulation
Assume the perimeter has already failed. The PentX AI engine tests lateral movement, privilege escalation and domain compromise across your live estate.
  • Internal network testing across up to 100 live IPs
  • Unlimited retesting for 12 months
  • Cloud configuration review at no extra cost
  • White-label report, ready for clients and auditors
Contact Us
★ Optional add-on
Expert Technical Support
Monthly

Put senior security engineers behind either package, with hands-on delivery, quality assurance and direct technical guidance throughout your engagement.

Contact Us
Every engagement includes:
  • Kickoff and scoping meeting
  • Report review and walkthrough
  • Pentest quality assurance review
  • Manual verification of findings
  • Formal report delivery
  • Ongoing technical support
Recommended wherever findings must be independently verified and defensible to auditors, boards and clients.
Custom

White-label delivery across a client base, volume programmes or a continuous testing practice. The PentX AI engine scales to the scope and cadence you need, with partner terms, branding and commercial arrangements built around your business.

Contact Us
Every package includes unlimited retesting for 12 months, a cloud configuration review at no extra cost, and a white-label report ready for clients and auditors.
FAQ

What founders ask before the first engagement.

Is PentX just a vulnerability scanner?

No. Scanners list what might be vulnerable. PentX delivers a real pentest: every finding is proven with a working exploit, evidence, business impact and remediation steps, packaged in a client-ready report under your brand.

Will my client know PentX is involved?

No. On the Partner plan the entire experience is white-labeled: your logo, your colors, your report. You own the client relationship. PentX stays invisible.

Will auditors and insurers accept the report?

Yes. PentX reports have been accepted by Big Four auditors with zero revisions over 12 months. For regulated or insurer-facing work, add a named CREST-certified senior engineer co-sign.

Do we need a pentester on staff?

No. Your team defines the scope and reviews the output. PentX handles reconnaissance, exploitation, validation, evidence and reporting.

What if the AI tests something it shouldn't?

It can't. Scope is enforced at the network layer. PentX physically cannot touch assets outside what you authorize. Rate limits, kill switches and full audit logs are built in.

What does one pentest credit cover?

One approved scope for one client: an external, web app, internal or cloud pentest. Scope is confirmed before launch, so you know your cost before you quote. Every pentest includes one free retest.

How do we make money with this?

You set your own client price and keep the margin on every engagement you resell, plus remediation projects, retests, compliance support and vCISO work the report generates. Contact the partner team for package and partner terms.

How fast can we deliver the first one?

Most engagements finish in hours once scope is approved. New partners typically go from signup to first client-ready quote within days.

Get started

Run your first pentest on your own environment.
Then sell it to every client who asks.

Tell us about your MSP. We'll set up your account, white-label options and partner pricing within 24–48 hours.

No credit card required. Most MSPs hear back within 24–48 hours.
Explore the Platform