Who Uses HailBytes

HailBytes SAT and HailBytes ASM are built for three distinct customer profiles: in-house security teams, MSSPs, and offensive-security firms. The product makes different sense for each, and we want to be precise about who it’s for.

Customer Profiles

In-House Security Teams

Mid-market & Enterprise Security

Security teams at organizations from ~200 to 10,000+ employees who want phishing simulation and external attack-surface monitoring without per-seat or per-asset pricing scaling against headcount or asset count.

  • Cloud-first procurement (AWS EDP / Azure MACC drawdown preferred)
  • Strong data-residency or self-hosting requirements
  • Need to audit the platform itself under source-available license
  • Compliance evidence for SOC 2, HIPAA, PCI-DSS, ISO 27001, NIST CSF
MSSPs

Managed Security Providers

MSSPs and managed compliance providers who attach phishing simulation to client SOC 2, HIPAA, and cyber-insurance bundles, billing the client at retainer rates while running on a flat per-instance cost basis.

  • Per-tenant branding, OIDC, and audit-log isolation
  • One-instance-per-client architecture (clean SOC 2 boundary)
  • White-label margins that survive into the 500–5,000-seat range
  • Marketplace co-sell motions on AWS and Azure
MSSP Playbook
Pen-Test Firms

Offensive-Security Boutiques

Pen-test firms and red-team practices who run HailBytes ASM internally as a scoping accelerator and externally as a recurring continuous-monitoring deliverable resold to clients between point-in-time engagements.

  • Internal scoping: 24-hour SOWs instead of week-long recon
  • Reseller model: recurring monthly fee per client instance
  • Pre-engagement recon on every prospect, not just paying clients
  • Custom wordlists, scan logic, and AI-agent orchestration via MCP
Pen-Test Playbook

Deployment Patterns

How customers actually run the platform.

Single-Tenant on AWS or Azure

The most common deployment: one HailBytes SAT or ASM instance per organization, running on a 2 vCPU VM in the customer’s AWS or Azure account. Marketplace charges flow through the existing cloud bill and count toward EDP / MACC commits.

Profile: mid-market and enterprise security teams.

Multi-Tenant MSSP Fleet

One instance per client in a shared MSSP cloud account, with per-tenant branding, OIDC, and audit logging. Tenant data never crosses instance boundaries, which is the model SOC 2 auditors expect from MSSP-delivered services.

Profile: MSSPs running 5+ active clients on phishing simulation or ASM.

Pen-Test Firm Internal + Client Instances

One firm-internal ASM instance scanning every prospect and active engagement (scoping accelerator), plus per-client white-label instances billed monthly to clients who want continuous monitoring between point-in-time tests.

Profile: offensive-security firms with active recurring-revenue practices.

Government Cloud (GovCloud / Azure Gov)

HailBytes SAT and ASM both deploy in AWS GovCloud and Azure Government. Federal contractors and regulated industries run there for FedRAMP-aligned data residency requirements.

Profile: federal contractors, defense industrial base, and regulated state-level agencies.

Industries We Work With

HailBytes is designed to be vertical-agnostic, but compliance pressure makes some industries especially common.

Financial Services

SOC 2, PCI-DSS evidence pipelines and the cyber-insurance underwriting requirements that landed phishing-simulation programs as table stakes.

Healthcare & Life Sciences

HIPAA Security Rule §164.308(a)(5) explicitly mandates security-awareness training. SAT generates the documented evidence auditors expect.

SaaS & Technology

SOC 2 Type II is procurement table stakes for B2B SaaS. SAT campaigns and ASM scan logs feed the CC2.2 awareness and CC7.1 vulnerability-management controls.

Government & Defense

FedRAMP-aligned deployments via AWS GovCloud and Azure Government. NIST CSF PR.AT and SP 800-53 awareness requirements covered by SAT evidence.

Higher Education

Universities running multi-school phishing simulation programs with per-school branding and reporting, plus continuous external monitoring of large public attack surfaces.

Cyber Insurance & MSSPs

Carriers and MSSPs bundling SAT and ASM as policy-condition deliverables for insureds, with the audit evidence underwriters require.

Become a Reference Customer

We’re actively building out our public case-study program. Twelve months of free access to HailBytes SAT or ASM, plus our highest support tier, in exchange for feedback and a written or video case study at the end of the year. Open to all three customer profiles.

Apply to the Case-Study Program

Talk to Customers Like You

If you’d like an introduction to a current customer running a similar deployment pattern (in-house, MSSP, or pen-test firm), our team can arrange a peer reference call once you’re in active evaluation.

Request a Reference Call

Stay Ahead of the Threat Landscape

Get monthly security insights, deployment guides, and exclusive early access to new features for HailBytes SAT and HailBytes ASM.

No spam. Unsubscribe anytime.