White-Label SAT Margin Economics
Concrete tier math, sample 200-seat P&L, and the renewal mechanics that make HailBytes SAT a high-margin add-on for client compliance bundles.
Published Apr 2026
Read More →Phishing simulation, training, and audit-ready reports — plus continuous attack-surface monitoring across your client portfolio — all under your brand. Built for managed security providers attaching SAT and ASM to client compliance bundles.
A first-time evaluator assembles the full picture across a few pages. Here’s the order that answers the questions in sequence — from “why HailBytes” through pricing, a proof-of-concept, resale terms, and support SLAs:
Not ready to stand up a VM? See it before you deploy — the two product walkthroughs and the console screenshots further down show the white-label branding and PDF-report settings, real scan findings, and the client-facing deliverables (a generated ASM report, SAT campaign results, and the audit log with its exports), plus a note on the artifacts we have deliberately not put there.
Every MSSP client buying SOC 2 Type II, NIST CSF, HIPAA, PCI-DSS, or cyber-insurance compliance support (and ISO 27001 for international clients) is required to demonstrate periodic security awareness training and phishing simulation. The auditor demands it, the cyber-insurance carrier demands it, and increasingly the client’s board demands it. That means the SAT line item is one of the highest-attach, highest-renewal SKUs an MSSP can carry, provided the platform underneath it has the right cost structure.
Per-seat SaaS platforms like KnowBe4 and Proofpoint Security Awareness price for direct enterprise sales, not for white-label resale. By the time you mark up their per-seat license enough to cover your program-management cost, the client’s netting numbers that don’t justify the program. HailBytes SAT prices per vCPU, not per seat: one AWS or Azure marketplace instance handles unlimited users, and one instance hosts many client organizations. The cost basis is the instance, divided across the book — so adding seats to an existing client costs you nothing, and your gross margin on a 500-seat client looks completely different than it does on a per-seat reseller agreement.
The platform deploys to your AWS or Azure account (or the client’s, depending on your service model) in minutes via the marketplace listing. In the single-instance and HA per-client topologies, each client gets a clean VM and database boundary — no shared infrastructure, no risk of campaign data crossing client lines — and the instance tears down cleanly when a client churns. One instance carries multiple client organizations when you operate the platform — row-level data isolation, per-client sending identities, and per-client hostnames, with clients receiving scheduled reports and certificates rather than logins — and that shape is materially cheaper per client. Isolation there is row-level and enforced in the application rather than by separate VMs and databases, and a client that requires its own branding, its own identity provider, or self-service administration needs a dedicated instance; review your client MSA requirements before choosing that shape (details in the topology comparison below). The reporting is CSV-exportable and feeds into whatever client-facing report template you already use.
4 minutes - explore HailBytes SAT →
For the team that delivers the service, not just the team that buys it. Out of the box, SAT ships:
Be deliberate in an RFP: this is a curated, fully-customizable library, not a multi-thousand-template catalog. The edge for an MSSP is editability — every lure and landing page is yours to rewrite per client — not raw template count. Browse the current set on the SAT product page.
White-label here means your brand replaces ours on the product and on every client-facing artifact. It does not mean a different brand per client. Be precise about the difference in an RFP:
Not supported on a shared instance: a different brand per client, a separate identity provider per client, or client self-service administration. Branding and SSO configuration are instance-wide — one identity-provider configuration per provider, per instance. A client that needs its own brand, its own IdP, or its own admins gets a dedicated instance. Do not promise a client-branded portal on a consolidated deployment.
Attack surface management is the other half of the managed-service book: continuous external recon that surfaces a client’s exposed subdomains, ports, services, and vulnerabilities between point-in-time pen tests. For MSSPs it carries the same economics as SAT — priced per vCPU, not per asset or per seat, so one instance covers a client’s entire attack surface no matter how many domains they run.
ASM is a one-instance-per-client product today, and we would rather say so here than on your first PoC. Work is organized into Projects, each with a hard ProjectQuota (targets, concurrent scans, scans-per-day, monthly compute budget) and its own findings, exposure graphs, scheduled reports, and per-Project SIEM destinations. But recurring scheduled scans running across multiple client Projects on a single instance are not supported today, operator roles are instance-wide rather than Project-scoped, and the /billing/projects/ rollup is not access-gated per client. So for managed multi-client delivery, deploy one ASM instance per client — which is also the clean VM-and-database boundary most client MSAs ask for. Your own branding carries over from the SAT side, on the same instance-wide basis. Consolidating a book onto one shared instance is the SAT shape, not the ASM shape.
The resell economics mirror SAT: a flat per-instance software fee — plus your own cloud bill, which the marketplace meter does not cover — with your managed-service fee on top, and AWS CPPO / Azure MPO margin on the platform itself. Adding ASM to a compliance bundle alongside SAT turns a single client engagement into two high-attach, high-renewal SKUs on the same deployment substrate. Model both on the portfolio calculators below, and see the ASM Solution Brief for per-client architecture and operations detail.
You’re carrying uptime and response commitments to your own clients, so the vendor-side SLA you build on belongs in your business case — not a footnote. The same tier structure covers both SAT and ASM:
| Tier | Response SLA | Coverage |
|---|---|---|
| Community (free) | Best-effort (no SLA) | Docs, email & Discord |
| Professional | 72-hour | Business hours (Mon–Fri, 9am–5pm ET) |
| Enterprise | 24-hour + Critical-severity escalation | 24/7 including weekends |
Full tiers, pricing, and the escalation path are on the support pricing page. For organizations that need custom SLAs or multi-year terms, contact sales.
Most MSSPs evaluating HailBytes SAT need answers to two specific questions before they’ll commit to standing up the first client instance. We wrote articles on both:
If you’d rather scope white-label terms on a call than read about it, the HailBytes SAT product page has a 15-minute demo slot. We’ll walk through your client portfolio and build a tier-mix recommendation on the call.
MSSPs land on one of four shapes depending on the client portfolio and what the client MSAs require. All of them deploy from the official Terraform modules at github.com/HailBytes/hailbytes-terraform-modules (MPL-2.0) — consolidation is a matter of how many organizations you create on the instance, not a different module:
sat-aws-single / sat-azure-single. The isolation shape: a clean VM and database boundary per client, in either your AWS/Azure account or theirs, tearing down on churn via terraform destroy. A dedicated 8 vCPU instance is $16,800/year in software fees whether it serves one client or several, so reserve it for clients whose MSA requires physical separation, whose contract comfortably clears ~$1,680/month on its own, or who need their own branding, their own identity provider, or self-service administration — those three are only deliverable on a dedicated instance. It is also the shape we deploy for ASM.sat-aws-ha / sat-azure-ha. For clients with formal uptime SLAs in their MSA (regulated industries, healthcare, financial services). Adds an ALB / Standard LB, Multi-AZ RDS / Zone-Redundant Postgres Flex, and shared Redis. Pre/post-patch SSM verifiers ship with the module so your rolling-update cadence is documented and auditable.sat-aws-autoscale / sat-azure-autoscale. Consolidation with elasticity, for regional MSSPs whose aggregate send volume outgrows a single node. Read replicas, rolling instance refresh with auto-rollback on 5xx, ElastiCache shared session store. Same row-level isolation posture as the consolidated shape above. Common for MSSPs running 100+ campaigns/month.The rate is identical across all four shapes ($0.24/vCPU-hour); what changes is how many vCPU you run and the cloud infrastructure underneath them. The marketplace meter is a software fee only — deployments are Bring-Your-Own-Cloud, so the VM, database, storage and networking land on your own AWS or Azure bill, at roughly $35/vCPU/month for the whole stack. Cross-cloud parity is intentional: AWS HA and Azure HA land within ~6% of each other at procurement-grade sizing. Full topology comparison and customer-shape examples →
| Shape | Topology | Monthly software fee | Est. cloud infrastructure |
|---|---|---|---|
| Consolidated, 8 vCPU (SAT) | sat-aws-single / sat-azure-single | $1,400/mo | ~$280/mo |
| Consolidated, 32 vCPU (SAT) | sat-aws-single / sat-azure-single | $5,610/mo | ~$1,120/mo |
| Single instance per client (8 vCPU) | sat-aws-single / sat-azure-single | $1,400/mo per client | ~$280/mo per client |
| HA hot-hot per client (2 × 8 vCPU) | sat-aws-ha / sat-azure-ha | $2,800/mo per client | ~$560/mo + LB and Multi-AZ premium |
| Auto-scaling (two-node baseline, 8 vCPU each) | sat-aws-autoscale / sat-azure-autoscale | from $2,800/mo (16 metered) | from ~$560/mo + read replicas |
Software fees are the published marketplace list rate at $1.92/hour for 8 vCPU; annual commitments take 30% (1-year, paid upfront), 35% (2-year), or 40% (3-year) off list via private offer. Cloud infrastructure is your own bill, estimated at ~$35/vCPU/month for the whole stack (VM, PostgreSQL, Redis, storage) and varying by region and reserved-instance pricing. Sizing on this ladder is throughput, not a client-organization cap: we do not publish a maximum number of client organizations per instance, because we have not measured one. Size to your aggregate send volume and target count. The ladder above is the SAT ladder; ASM is deployed one instance per client at 8 vCPU, and an ASM instance larger than 8 vCPU does not scan faster without a configuration change to the scan worker’s CPU and memory limits.
A single MSSP book can hold a HIPAA-covered US client, a GDPR-subject EU client, and a NYDFS-regulated financial client at the same time — and each will ask “where is our data stored?” on the first procurement call. Because HailBytes is a Bring-Your-Own-Cloud marketplace image, you can answer all three cleanly:
sa-east-1 or brazilsouth.This mirrors the data-sovereignty model on the enterprise page (“Your Cloud Account. Your Data.”); GDPR DPA terms for client data you process are in the HailBytes DPA.
The marketplace path most MSSPs miss until late in evaluation is the channel-partner private-offer flow on both clouds. It is what lets you mark up the platform itself, capture the resale margin, and have the customer’s purchase still count toward their EDP or MACC commit — without the customer having to onboard HailBytes as a new vendor:
What that looks like in unit economics: a 32 vCPU consolidated instance carries $67,300/year in HailBytes software fees at list, or $47,110 on a 1-year commitment. Resale margin is up to 20%, taken off the post-discount net the customer actually pays — so ~$9,400/year on the committed net, or ~$13,400 if the customer buys at list. That is layered on top of your managed-service ARR with zero incremental service-delivery cost. Margin scales with what the customer spends, so a book of dedicated per-client instances carries proportionally more of it — and costs the customer proportionally more. Customer sees one cloud invoice; their CFO sees committed-spend drawdown; you keep the platform margin as well as the service margin. Note that CPPO/MPO margin is earned on the HailBytes software fee only; the cloud infrastructure underneath is the customer’s own spend and is not resellable through the private offer.
Register on the partner program page with your AWS account ID or Azure tenant ID and we’ll issue resale authorization. First private offer usually ready within one business day. Full mechanics, worked examples, and procurement-language scripts are in the SAT Partner Brief (PPTX, download) and the ASM Partner Brief (PPTX, download).
Both Partner Briefs cover CPPO/MPO mechanics, worked resale examples, and procurement-language scripts — download whichever matches the product you’re scoping:
Looking for one-pagers, customer presentations, solution briefs, and account-brief templates too? The full partner library is on the partner program page.
The single-instance example above is the entry case for the CPPO/MPO motion. The full operational deep-dive — the annual commitment discount tiers (30% 1-year prepaid / 35% 2-year / 40% 3-year), how the wholesale baseline steps down as your client count grows, the four-step CPPO and MPO setup on each cloud, and what the branding and quota substrate actually does — lives on the dedicated partner resell page. If you are modeling a rollout across a book of clients or evaluating white-label, that page is what you should be reading next.
If you are pre-selling to a client on a PoC window, the PoC process page documents the 14-day and 30-day scoping options, deliverables, and the four-stage rollout decision gates (PoC → pilot → production rollout → negotiated custom band).
Registering your AWS account or Azure tenant gets you resale authorization, but it isn’t the contract. Before resale authorization is issued, MSSP and reseller partners sign a HailBytes Partner Agreement covering the CPPO/MPO resale grant, white-label and branding rights, and acceptable use — provided on request when you register so your legal and procurement teams can start the review early.
Bring this to your procurement team in parallel with PoC scoping so the legal track doesn’t stall a multi-client rollout.
Plug in your own numbers. HailBytes prices per vCPU on a shared instance, not per seat, so the cost basis is the instance divided across your book while a per-seat platform scales with every client’s headcount. All math runs in your browser — nothing is sent anywhere.
| Shape | Platform cost / client / mo (all-in) | Your resale / client / mo | Gross margin / client / yr |
|---|---|---|---|
| Consolidated, thin (upper end of the per-client range) | ~$345 | $1,500 | ~$13,860 (77%) |
| Consolidated, dense (lower end of the per-client range) | ~$115 | $1,500 | ~$16,620 (92%) |
| Dedicated 8 vCPU instance per client (required for own brand, own IdP, own admins, or VM-level separation) | ~$1,680 | $1,500 | −$2,160 (loss) |
Estimates only, for internal modeling — not a quote. The per-client software default of $280/mo is the upper (most expensive) end of the published consolidated range, $1,100–$3,400 per client per year; the cloud default of $56/mo is the ~20% your own AWS or Azure bill adds at $35/vCPU/month. Your actual cost depends on topology, how many client organizations you put on an instance, and whether you take an annual commitment (30/35/40% off list). The per-seat default of $3/seat/mo ($36/seat/year) sits at the $35/seat blended rate in the indicative competitor range published on our pricing page — no vendor in that comparison publishes list per-seat pricing, so treat it as an assumption and replace it with your own quote. Resale margin is calculated on the HailBytes software fee only — a partner cannot earn CPPO/MPO margin on the customer’s own cloud spend.
Like the numbers? Book a scoping call to pressure-test them against your portfolio, or see the partner resell page for the annual commitment discount tiers and CPPO/MPO mechanics.
Margin is the supply side of the story; the demand side is the answer to the question you get at every QBR: “What did this give us?” Each automated ASM scan replaces roughly two analyst-hours of manual recon — subdomain enumeration, port sweeps, screenshot review, and vulnerability triage. That heuristic is the same 2h/scan default ASM uses internally to compute usage ROI, and it is operator-tunable, so adjust it to your team’s reality. Pair it with cost-per-finding and you have a defensible answer that beats per-seat or per-engagement framing.
Estimates only, for internal modeling — not a quote. The 2h/scan default mirrors ASM’s internal MANUAL_HOURS_PER_SCAN heuristic. The $75/hr blended analyst rate is an editable placeholder, not a rate HailBytes publishes or stands behind — put your own loaded cost in. ASM’s billing dashboard also reports per-project attributed cost and cost-per-finding, on the operator-only screen described below.
Margin only survives if a runaway scan doesn’t quietly consume compute you already priced into a fixed fee. ASM ships a per-Project budget control built for exactly this: set a monthly budget ceiling per Project and the billing engine tracks its attributed cost (allocated by scan-time share) against it.
This is an operational cost control, distinct from the ROI value metrics above. The full portfolio mechanics live in the ASM Solution Brief.
HailBytes is one of the only vendors that ships both an attack-surface-management platform and a security-awareness-training platform. For an MSSP selling compliance bundles, that means you can hand a single client’s auditor one evidence package that covers both the human layer and the technical layer — from one vendor, with consistent audit-log formats, under your white-label branding. Same per-vCPU marketplace meter, same CPPO/MPO resale path, one renewal conversation.
| Control Area | Product | Evidence Generated |
|---|---|---|
| Security awareness training (SOC 2 CC1.4, HIPAA §164.308(a)(5)) | SAT | Campaign completion logs, branded PDF certificates, audit-trail CSVs |
| Security awareness measurement (NIST CSF PR.AT) | SAT | Click-rate trends, repeat-offender reports, training-completion rates |
| Attack-surface monitoring (SOC 2 CC7.1, CC7.2) | ASM | Scan history, asset-change summaries, vulnerability findings |
| Vulnerability management (PCI-DSS 11.3, NIST CSF ID.RA) | ASM | Nuclei findings, SARIF exports, per-framework compliance reports |
| Ongoing risk assessment (ISO 27001 A.8.8, NIST CSF ID.RA-1) | ASM + SAT | Combined: human-layer risk (SAT metrics) + technical-layer risk (ASM findings) |
When you run both products for a client, the combined branded PDF reports and structured audit logs go straight to the auditor — no reformatting, no second vendor to onboard. Read the full SOC 2 + PCI-DSS evidence walkthrough →
Concrete tier math, sample 200-seat P&L, and the renewal mechanics that make HailBytes SAT a high-margin add-on for client compliance bundles.
Published Apr 2026
Read More →Multi-client deployment architecture, template management, per-client reporting, and pricing tiers that work for 20-client MSSP portfolios.
Published Jan 2026
Read More →Honest feature-by-feature comparison covering pricing, deployment, customization, and reporting for MSSP white-label resale.
Published Dec 2025
Read More →Month-by-month blueprint for a phishing program that progresses from baseline through advanced scenarios with audit-ready reporting milestones.
Published Jan 2026
Read More →Move beyond click rates: time-to-click, repeat offenders, and longitudinal trends that drive measurable security outcomes for clients.
Published Feb 2026
Read More →How to use HailBytes SAT and HailBytes ASM together to satisfy SOC 2 Type II, PCI-DSS, and ISO 27001 with auditor-ready evidence.
Published Nov 2025
Read More →How to run ASM across a book of clients: one instance per client, a severity-coded alert ribbon in your console showing each Project’s highest unresolved finding and the change-delta since the last scan, scan-time cost attribution, and a monthly report delivered to each client — with the same per-vCPU economics and CPPO/MPO resale path as SAT.
Watch: the ASM operator console — Projects, cost attribution, and scheduled reports. Recorded with several client Projects on one instance; we deploy ASM one instance per client today.
The two products invert the tenancy model. Use this to pick the right shape per client engagement:
| Dimension | SAT | ASM |
|---|---|---|
| Tenancy model | One instance, many clients as Organizations — or one instance per client where the MSA requires it | One instance per client; Projects scope work inside it. Recurring scheduled scans across multiple client Projects on one instance are not supported today |
| Isolation boundary | Per-Organization, row-level on a shared instance; a separate VM and database only in the dedicated shape | Per-Project for data, enforced at the API and middleware layers — but operator roles are instance-wide, so the VM boundary is the client boundary |
| Quota & limits | Per-org seat caps | Per-Project ProjectQuota (targets, scan-rate, budget) |
| Cost attribution | Flat instance cost, divided across the organizations on it | The client’s own instance, with per-Project scan-time attribution at /billing/projects/ (operator-only screen) |
| Teardown on churn | Delete the organization, or destroy the instance in the dedicated shape (terraform destroy) | Delete the Project, or destroy that client’s instance (terraform destroy) |
Organizations on one SAT instance share that instance’s console, and /api/tenants rolls them up. Across instances there is no shared console, so an MSSP running dedicated per-client instances alongside a consolidated one has to assemble the portfolio view itself. Each SAT instance carries its own REST API (/api/docs) and a webhook system with per-event-type filtering, so the cross-instance pattern is aggregation, not a built-in roll-up: poll each instance’s API on a schedule, or have every instance push campaign and training events to a central webhook collector you own, then render the combined view in your own dashboard. This is one more reason consolidation is the cheaper operating model as well as the cheaper commercial one.
ASM does not take the shared-instance shape. Projects scope data — each carries its own scan targets, findings, scheduled reports, and quota, and Project-scoped queries are enforced at the API and middleware layers — but three things stop a shared ASM instance from being an honest multi-client boundary today: recurring scheduled scans across multiple client Projects on one instance are not supported, the three operator roles (Sys Admin, Penetration Tester, Auditor) are instance-wide rather than Project-scoped, and /billing/projects/ is not access-gated per client. So each client gets its own ASM instance, and the VM and database boundary is what you represent in the client MSA — a stronger statement than row-level scoping anyway. Projects are still useful inside a client: business units, subsidiaries, acquisition targets, separate scan scopes.
The two products provision differently, so script to each one’s real surface. SAT exposes a full REST API (documented at /api/docs) — create organizations and members, bulk-import targets (/api/import/group, email, site, azure-ad), set per-client sending profiles, and roll up partner tenants via /api/tenants — so a new client organization can be stood up entirely from code. Branding is not part of that loop: it is one instance-wide configuration carrying your brand, set once. ASM provisions through purpose-built endpoints rather than a REST resource tree: create a client Project with POST /api/action/create/project, provision and scope analyst accounts via SCIM 2.0 (/api/v1/scim/v2/), and stream scan and vulnerability events out through the per-Project webhook + SIEM dispatch. Per-Project quotas are set in the console, not over the API.
The /billing/projects/ dashboard attributes an instance’s monthly spend across its Projects in proportion to scan-time-seconds consumed, and ProjectQuota sets scan-rate and asset ceilings plus a monthly budget cap and alert threshold per Project — so you get notified before a runaway scan exhausts a budget. Two caveats worth stating plainly, because they change how you use it: it is an operator-only screen (not access-gated per client, so anyone who can reach it sees every Project’s name and spend), and in the one-instance-per-client shape the per-client number is simply that client’s own instance plus its cloud bill. Use the rollup to catch a misconfigured recurring scan inside a client, not to divide one instance across a book.
| Scan scope (Project) | Scans | Scan-time | Vulns (C/H) | Cost share | Attributed | Budget status |
|---|---|---|---|---|---|---|
| Primary domains | 128 | 41h 12m | 2 / 9 | 34% | $571 | ✓ OK |
| Acquired subsidiary | 95 | 33h 05m | 1 / 4 | 27% | $454 | ⚠ Over threshold (86%) |
| Dev & staging | 142 | 28h 47m | 0 / 2 | 24% | $403 | No budget set |
| Brand / typosquat monitoring | 61 | 18h 20m | 3 / 7 | 15% | $252 | ✓ OK |
| 4 active projects | 426 | 121h 24m | 6 / 22 | 100% | $1,680/mo | 1 over threshold |
ASM bills on the same $0.24/vCPU/hour marketplace meter as SAT — no per-asset and no per-scan fees. Because each client runs its own instance, the per-client cost is a whole instance: 8 vCPU at $1,400/month in software fees plus roughly $280/month of your own cloud infrastructure, about $1,680/month all-in — $16,800/year in software fees at list, $11,760 on a 1-year commitment. That is a real floor, and it means a small ASM client has to clear roughly $1,680/month of value before you make anything on the platform line. Eight vCPU is ASM’s own recommended production size and handles 10–50 scheduled scans/day. Going bigger is not a throughput lever out of the box: ASM’s scan worker ships with fixed CPU and memory limits and nothing in it reads the host CPU count, so a larger ASM instance scans no faster than 8 vCPU until those limits are raised — talk to us before quoting a client above the entry size. Inside the instance, ProjectQuota keeps one scan scope from monopolizing the rest, and the monthly /billing/projects/ rollup reconciles what each scope actually consumed.
ASM has its own resale-authorization path, separate from SAT. On AWS, HailBytes adds your account to the resale-authorized list for the ASM listing (prodview-66d5bswmbtfhs); on Azure, the equivalent for the ASM offer (hardened_ubuntu_with_rengine). You issue the customer a private offer at your resale price, Marketplace splits proceeds (wholesale to HailBytes, margin to you), and the purchase decrements the customer’s AWS EDP or Azure MACC commit — exactly as with SAT. Full mechanics and the annual commitment discount tiers (30% 1-year prepaid / 35% 2-year / 40% 3-year) are on the partner resell page.
ASM produces scheduled recurring reports deliverable by email: vulnerability findings by severity, newly discovered assets, resolved findings, and per-framework compliance evidence (SOC 2 CC7.x, NIST CSF 2.0, HIPAA, PCI-DSS 11.3, and 7 more). Everything is also exportable via SARIF and the REST API, so it drops straight into whatever client report template you already run — under your white-label branding.
ASM has three operator roles — Sys Admin, Penetration Tester, and Auditor — and they are instance-wide, not Project-scoped, so there is no client-facing read-only account that sees only one Project’s findings. The intended client touchpoint is the scheduled white-label PDF report delivered by email, plus per-Project SARIF and REST API exports that drop into your own client portal. Give clients deliverables, not a login — it keeps the tenant boundary clean and means a client never lands in the shared console.
ASM (and SAT) findings don’t stop at CSV. Per-Project dispatchers forward events to the SIEM, ticketing, and risk tools your SOC already runs — Splunk HEC, Microsoft Sentinel, syslog/CEF, CrowdStrike Falcon LogScale, and Palo Alto Cortex XSIAM for SIEM; Jira, ServiceNow, GitHub and GitLab Issues for ticketing; Wiz Issues for the risk register; plus an HMAC-signed generic webhook for anything else. A per-integration severity floor lets you gate which findings reach each client’s SIEM, and event categories (vulnerability, scan, audit, change, brand-risk) toggle independently. There’s no native ConnectWise, Autotask, or Halo PSA connector — route findings into your PSA through the HMAC-signed generic webhook, posting to its inbound API directly or via a middleware layer (Zapier, Make, n8n). See all integrations →
Redesigned for MSSP operators: triage banner with diff-from-last-scan summary, status-filtered findings at a glance, real-time scan progress bars, and attack-path visualization with MITRE ATT&CK badges — giving analysts a client-ready narrative beyond a CVE list.
ProjectQuota enforces target and scan ceilings per Project, so one scan scope cannot exhaust a client’s instance. Automatic 90-day scan history retention with durable ScanSnapshot aggregates keeps client SLA reporting intact even after data purges.
For enterprise and government procurement: SOC 2 CC7.x, NIST CSF 2.0, HIPAA, PCI DSS v4.0, FedRAMP, NYDFS 500, and CIS Controls v8 IG1+IG2 (North American), LGPD (Latin American), ISO 27001:2022, GDPR Art. 32, and IEC 62443 (global), and Australian Government ISM / Essential Eight (Asia-Pacific) — all generating exportable evidence reports your clients can hand to auditors.
One. ASM scales across a book by adding instances, not by adding clients to an instance: recurring scheduled scans across multiple client Projects on a single instance are not supported today, operator roles are instance-wide, and the billing rollup is not client-gated. Each client is an 8 vCPU deployment in your cloud account or theirs, torn down with terraform destroy on churn. Consolidation is the SAT story, and we do not publish an organizations-per-instance figure there either — there is no measured basis for one. For commitment tiers and wholesale-baseline mechanics across a book, see the partner resell page.
A marketplace deployment is the trial, not the evaluation. If you’re still answering “does this do what our service needs?”, the two walkthroughs on this page and the console screenshots below answer it without a cloud account, an IAM ticket, or an SSH key.
Both product walkthroughs are embedded higher up this page. The 4-minute SAT walkthrough runs the campaign lifecycle end to end — templates, sending profiles, the campaign wizard, post-click training, certificates, RBAC, SSO, white-label, and the audit log. The 11-minute ASM walkthrough covers running recon as a managed service: Projects, scoping, cost attribution, and scheduled reporting. It was recorded with several clients as Projects on one instance; read it alongside the tenancy note above, because we deploy ASM one instance per client today. Both are click-to-play — nothing loads until you start them.
Unmodified screenshots of the shipping UI, at the places an MSSP evaluator usually wants proof rather than prose. Open any of them full-size in a new tab.


The claims further up this page — branded PDF reports, audit-trail CSVs, SARIF and REST exports — are configuration screens and export buttons in the product, so here they are:




The report above is real output against a public test target, not a mock-up — but it carries our branding and a test domain, not a client’s. There is also no /billing/projects/ screenshot with client names on it. To produce either we’d have to invent the customer, the logo, and the numbers, and a fabricated artifact presented as a real client deliverable is worse than no artifact at all in an RFP — you’d find out on the first PoC. What you get instead: the real exports above, a clearly labeled representative cost-attribution rollup with anonymized project names earlier on this page, and a 14-day PoC that generates branded reports against your own tenant and your own clients. Need a branded sample sooner for a client conversation? Raise it on the scoping call.
A structured path from first call to a go/no-go decision — no open-ended trial.
Walk through your client portfolio, get a tier-mix recommendation, and confirm topology fit.
One live client tenant with Terraform modules, deployment support, and a structured test plan. Deliverable: a working campaign or scan report you can show your client.
Proceed to your first production instance, or cancel with no commitment.
Full mechanics are documented on the PoC process page. When a client campaign or scan needs help at 11 PM, MSSP support tiers and response-time SLAs spell out the escalation path and dedicated-contact options — review them before you commit so the answer is in hand for your stakeholders.
Onboarding is measured in hours, not a quarter — there’s no vendor-side provisioning queue because you deploy into your own cloud account.
sat-aws-single / sat-azure-single Terraform module into your (or the client’s) account — live in minutes either way.ProjectQuota (target, scan-rate, and monthly budget ceilings).Deployment specifics — module variables, region selection, and HA / autoscale shapes — live in the Terraform modules and the ASM Solution Brief.
“What happens to our data if we leave?” is a first-call procurement question. Because HailBytes is Bring-Your-Own-Cloud, the answer is clean and verifiable.
terraform destroy (or by deleting the marketplace instance), leaving nothing on a shared plane. Where a client MSA requires the second guarantee in writing, deploy them dedicated.terraform destroy (or by deleting the marketplace instance). Deleting an individual Project purges that scan scope inside a live instance; the 90-day scan-history retention and durable ScanSnapshot aggregates age out on their own.What you need for managed-service delivery at scale — each links to the authoritative reference.
Packaging, margin math, and CPPO/MPO resale mechanics for turning SAT/ASM into a recurring-revenue service line. Instant access.
Spin up a 30-day free trial through the AWS or Azure marketplace, or book 15 minutes to walk through tier mix and white-label arrangements for your client portfolio.
Running client SLAs? See MSSP support tiers and response-time SLAs for production-incident escalation paths.
15 minutes to walk through your client portfolio, tier mix, white-label setup, and CPPO/MPO resale mechanics — with a solutions engineer, not a generic intro call.