Partner accounts approved in 24–48h · No credit card required
For MSPs, SMBs and IT companies

Sell pentesting under your brand.
Keep up to 90% margin.

PentX runs the pentest. You deliver the white-label report in hours. Your cost from €250, your client pays €2,500+. No pentester hire needed.

No credit card required. Account live within 24–48 hours.
70+ MSPs & IT companies onboard CREST-certified co-sign available ISO 27001 certified
PentX dashboard running a live pentest
70+
MSPs delivering with PentX
Hours
to a finished pentest, not weeks
€250
your cost per pentest
90%
gross margin you keep
How it works

Client scope to branded report. Three steps.

Your team sells. PentX delivers. Your client never sees us.

~2 min

Scope it

Add the client's approved assets: external, web app, internal or cloud. Scope is locked at the network layer: the test can't go beyond what you authorize.

hours

PentX attacks it

Real reconnaissance, exploitation and validation. Every finding is proven with a working exploit, screenshots and evidence, not scanner guesses.

your brand

You deliver it

Export the report with your logo and colors. Need extra assurance? Add a CREST-certified engineer co-sign. Retest after fixes is included.

The margin math

Your clients already ask for pentests. This is what saying "yes" is worth.

Cyber insurance, ISO 27001, SOC 2, PCI-DSS, vendor reviews: the demand walks in the door every year. Right now that money goes to a subcontractor or a boutique firm.

With PentX it stays in your P&L, and every report opens remediation, retest and vCISO revenue on top.

Explore the Platform
Your revenue€25,000
PentX delivery cost€2,500
Your gross profit€22,500
Gross margin90%

Based on 10-pack partner pricing (€250/pentest). Excludes your sales time. Remediation & follow-on revenue not included.

Why MSPs switch

Everything a pentest practice needs. Nothing you have to build.

🏷️

100% white-label

Your logo, your colors, your report. Your client buys from you. PentX stays invisible.

🎯

Exploit-proven findings

Not a scanner. Findings only ship with working exploit evidence, impact and fix steps.

✍️

CREST co-sign on demand

A named CREST-certified senior engineer reviews and signs when insurers or auditors require it.

🔒

Scope locked by design

Enforced at the network layer. Rate limits, kill switch, full audit log. It cannot test what you didn't approve.

🔁

Free retest included

Client fixes the issues, you rerun the test and deliver proof. Built-in reason for the next invoice.

🚀

Launch Kit included

Sales deck, proposal template, quote calculator, email sequences and objection battlecard, so you can sell from day one.

The honest part

"Sounds great, but…"

Every MSP founder asks the same five questions. Fair. Here are the answers.

"Isn't this just an AI scanner with a nice report?"
No. Scanners list maybes. PentX proves exploitability: exploit chain, payloads, screenshots, request/response captures. If it can't prove it, it doesn't go in the report.
"What if my client's auditor or insurer rejects it?"
PentX reports passed Big Four audits for 12 months with zero revisions. For regulated work, add a named CREST-certified engineer co-sign.
"What if the AI breaks something in production?"
Scope is enforced at the network layer, so it physically can't touch unapproved assets. Rate limiting, kill switches and audit logs are standard.
"My team has never sold pentesting."
The MSP Launch Kit gives you the deck, proposal, pricing calculator and objection answers, plus an onboarding session and a review of your first client quote.
"What if my client finds out it's not us doing it?"
The Partner plan is fully white-label: report, branding, positioning. You also review everything before it ships. It's your service, delivered your way.
"What if it's not as good as you say?"
Start with a €500 Pilot on your own environment. Judge the report quality yourself before you ever put your brand on it.
Already in production

MSPs are doing this right now.

125
pentests in 5 months

A US IT company serving financial clients went from 8–12 outsourced pentests a year to 125 in-house engagements, cutting cost per pentest by 70%. Payback inside month one.

US financial-sector IT company
95%
faster report turnaround

CTDefense cut report production from 25 hours of manual writing to 4 hours of senior review, freeing engineers for billable remediation and advisory work.

CTDefense
100%
Big Four auditor acceptance

Forward Defense submitted PentX-powered reports to Big Four auditors for 12 months. Every report accepted. Zero revisions requested.

Forward Defense
ISO 27001 ISO 9001 GDPR CREST PCI-DSS 4.0
Pricing

Start small. Scale when the invoices do.

Every pentest includes one free retest. External, web app, internal and cloud scopes.

Pilot
Test the report quality on your own environment first.
€500 / pentest
1 pentest + 1 retest
  • Any scope: external, web, internal, cloud
  • Exploit-proven findings
  • White-label report export
  • CREST co-sign available
Start with a Pilot
Zero-risk way to validate before putting your brand on it.
★ Most MSPs choose this
White-label Partner
Launch your branded pentesting service line.
€2,500 / year
10 pentests + 10 retests · €250 per pentest
  • Fully white-label client experience
  • MSP Launch Kit: deck, proposal, quote calculator, email sequences, battlecard
  • Partner onboarding + first quote review
  • Priority partner support
  • Pay-after-paid terms for qualified partners
Contact us
Resell at €2,500 each and the pack pays for itself with the first client.
Scale
MSSPs & providers delivering 25+ pentests a year.
Custom
25 / 50 / 100+ credit packs
  • Volume pricing
  • Multi-client delivery workflow
  • Custom white-label setup
  • Co-selling & partner success support
Talk to the partner team
For teams making pentesting a strategic service line.
🛡️

Know your cost before you quote. Every scope is confirmed before launch: no surprise credit usage, no margin leakage. One credit = one client engagement, and you'll know if a complex scope needs more before it starts.

FAQ

What founders ask before the first engagement.

Is PentX just a vulnerability scanner?

No. Scanners list what might be vulnerable. PentX delivers a real pentest: every finding is proven with a working exploit, evidence, business impact and remediation steps, packaged in a client-ready report under your brand.

Will my client know PentX is involved?

No. On the Partner plan the entire experience is white-labeled: your logo, your colors, your report. You own the client relationship. PentX stays invisible.

Will auditors and insurers accept the report?

Yes. PentX reports have been accepted by Big Four auditors with zero revisions over 12 months. For regulated or insurer-facing work, add a named CREST-certified senior engineer co-sign.

Do we need a pentester on staff?

No. Your team defines the scope and reviews the output. PentX handles reconnaissance, exploitation, validation, evidence and reporting.

What if the AI tests something it shouldn't?

It can't. Scope is enforced at the network layer. PentX physically cannot touch assets outside what you authorize. Rate limits, kill switches and full audit logs are built in.

What does one pentest credit cover?

One approved scope for one client: an external, web app, internal or cloud pentest. Scope is confirmed before launch, so you know your cost before you quote. Every pentest includes one free retest.

How do we make money with this?

Your delivery cost is from €250 per pentest. MSPs typically charge clients €1,500–€4,000. You keep the difference, plus remediation projects, retests, compliance support and vCISO work the report generates.

How fast can we deliver the first one?

Most engagements finish in hours once scope is approved. New partners typically go from signup to first client-ready quote within days.

Get started

Run your first pentest on your own environment.
Then sell it to every client who asks.

Tell us about your MSP. We'll set up your account, white-label options and partner pricing within 24–48 hours.

No credit card required. Most MSPs hear back within 24–48 hours.
Explore the Platform