Skip to content

Partner program

White-label and partner penetration testing

Sell penetration testing under your own brand. Our senior in-house team does the testing. Every client gets a fixed price, a fixed scope and a free retest, and the report goes out with your name on it.

Reports in your brandIn-house testers, no subcontractorsOnboarding within 24 hoursFree retest on every pentest

Who it is for

Firms whose clients ask for a penetration test

You already have the client relationship. We add the testing, so the request stays with you.

MSPs and IT providers

Your clients ask for a penetration test for insurance, SOC 2 or a customer questionnaire. Resell ours under your brand instead of turning the request away.

MSSPs

Add manual penetration testing and red teaming to your managed security catalog without hiring a testing team.

vCISOs and consultants

Put an independent test into the security programs you run for clients, delivered in your name.

Auditors, GRC firms and brokers

If your role requires you to stay independent of the testing, refer instead of resell. The client contracts with us directly and the report carries our name.

How white-label works

Five steps, your brand on the result

  1. 01

    Scope

    Send us the client’s scope through the scoping form or a short call. We return one fixed quote in writing.

  2. 02

    Authorize

    The end client signs the authorization for its own systems and agrees the rules of engagement. No testing starts before that.

  3. 03

    Test

    Our senior in-house testers do the work, manual-first. Critical findings go to you the moment we confirm them.

  4. 04

    Report in your brand

    Executive summary, technical report and attestation letter, delivered in your branding for you to hand to your client.

  5. 05

    Retest

    Your client fixes the findings, we retest them at no extra cost, and the report is updated to show them closed.

Independence

Why a resold test is still an independent test

Auditors, insurers and customers question a penetration test run by the provider that administers the network. That provider is grading its own work.

When you resell our testing, that is not what happens. Our team tests, and we do not build or run your clients’ systems. The tester has no stake in the result.

If an auditor, insurer or PCI assessor asks who performed the test, tell them. We will confirm in writing that an independent firm did the work.

How we document independence

Published prices

The full catalog, priced in public

These are the starting prices a client pays us directly. Partner pricing is on request.
Every quote is fixed in writing before work starts.

ServicePublished starting price
Web App PentestFrom $5,200
API PentestFrom $4,000
Mobile PentestFrom $6,000
External Network PentestFrom $4,200
Internal Network PentestFrom $6,000
Active Directory AssessmentFrom $6,000
Microsoft 365 AssessmentConfiguration review from $4,200, attack simulation from $6,800
Cloud PentestFrom $6,800
Wireless PentestFrom $3,800 for one office
Physical PentestFrom $6,800 for one NYC-metro site
Thick-Client PentestFrom $6,000
Salesforce PentestOrg test from $6,800, AppExchange review prep $5,200
Secure Code ReviewFrom $4,800
AI & LLM PentestFrom $4,500
Hardware & IoT PentestFrom $5,200
Phishing TestingFrom $3,600
Red TeamingFrom $12,500
Vulnerability ScanningFrom $1,500 per scan

Every penetration test includes the report, the attestation letter and a free retest. Every tier on the pricing page →

What your client receives

Deliverables in your brand

The sample report shows the structure. The white-label version carries your brand.

Executive summary

One readable summary for your client’s leadership, insurer or customer.

Technical report

Every finding verified by hand, rated by severity, with reproduction steps and a fix.

Attestation letter

What was tested, when, against which standards, and the status of the findings after the retest.

Control mapping

Findings mapped to SOC 2, ISO 27001, PCI DSS or HIPAA, as separate files that upload cleanly into Vanta, Drata or Secureframe.

No overlap

What we do not sell

We test. We do not sell the services our partners run, so there is nothing to cross-sell to your clients.

  • Managed IT or help desk services
  • Managed detection and response, or 24/7 monitoring
  • Incident response and digital forensics
  • vCISO retainers
  • SOC 2 audits

FAQ

Partnering, answered

What MSPs, MSSPs and consultants ask before the first resold test.

Still have questions? 
01What does white-label mean here?

The report and every deliverable carry your brand, not ours. You sell the test to your client, you stay their point of contact, and our team does the testing behind you.

02Who performs the testing?

Invadel’s senior in-house testers. They are employees, not subcontractors, and we do not offshore the work. The same standards apply whether the report carries your brand or ours.

03Who signs the authorization to test?

The end client, for its own systems. A partner cannot authorize testing of systems it does not own. The client also agrees the rules of engagement: dates, source addresses, off-limits systems and an emergency contact.

04Does reselling a test break independence?

No. Independence depends on who tests, not whose brand is on the report. Our team does the testing and runs none of your clients’ systems. If an auditor asks, we confirm in writing who did the work.

05How is partner pricing set?

Partner pricing is on request. Our published prices are what a client would pay us directly, and every quote is fixed in writing before work starts.

06How fast can a test start?

Onboarding starts within 24 hours of a signed proposal, and testing usually starts within a week. A single application or perimeter test typically completes in one to two weeks.

07Is the retest really included?

Yes, on every penetration test, at no extra cost to you or your client. Phishing campaigns measure behavior, so they have no retest.

08Can auditors refer clients without reselling?

Yes. Where independence matters to your role, introduce the client and we contract with them directly. The report and attestation letter carry Invadel’s name.

Bring us your first client.

Tell us about your firm and the test your client needs. We reply within one business day with partner pricing.

Scoping a specific client? Use the full questionnaire 

Become a partner

Tell us about your firm and your clients. We reply within one business day.