Managed Service Providers
- Home
- MSP
Multi-client external attack surface management. Brand the client portal as yours.
One provider account. Many client organizations. Your team runs the book.
PortWarden for MSPs is a multi-tenant workspace for authorized, internet-facing assets across small-business clients. Your staff manages organizations, inventory, scheduled scans, findings, reports, and alerts in one place.
Clients can get a portal login if you want that. You pick what each organization may see and change. White-label options cover logo, theme colors, custom hostname, TLS materials, and whether the client footer shows PortWarden.
Recurring monitoring watches for exposure drift. On-demand jobs dig in when a client change needs a harder look.
Talk about MSP onboarding Portal demoWhat you get
- Portfolio dashboard across every client organization
- Per-client IPs, domains, and subdomains
- Scheduled jobs, run history, findings, and reports
- Per-org portal permissions you control
- AI-agent-ready API for your provider account and client orgs
- White-label logo, colors, hostname, and attribution
Staff, clients, assets, and findings stay inside your provider boundary
You administer the portfolio. Clients only get the access you turn on. Nobody else on the platform sees your orgs.
Provider team
Logins, team users, roles, and profiles so more than one engineer can work the book without sharing one password.
Client organizations
Create and manage orgs: active or suspended, contacts, locale, plus counts for inventory, scans, findings, reports, and users.
Client user roles
Invite organization admins, members, and viewers. Keep client day-to-day access separate from provider admin.
Per-client permissions
Allow or deny endpoints, org users, alerts, reports, findings activity, and advisory AI guidance independently per organization.
Action center
Open and high-severity findings, assets without coverage, recent reports, failed runs, and upcoming scheduled scans across clients.
API keys
Provider admins mint API keys so your own AI agents can work the provider account and the client organizations you manage, inside the permissions you set. How the agent API fits.
Let your agents work the book, with the same boundaries your staff already have
MSPs already run their own AI agents for tickets, inventory, and client ops. PortWarden's API is built so those agents can manage your provider account and the client organizations under it, instead of a person clicking every org by hand.
Agents act through credentials you issue. They stay inside the provider boundary and the per-organization permissions you already set in the portal. They do not get a side door around client isolation.
- Provider-account work: portfolio context, organizations, and the controls your admins already use
- Client-organization work: the same orgs your staff manage, scoped to what that org is allowed to see and change
- API keys minted by provider administrators, rotated and revoked from the same screen as the rest of the workspace
- Fits internal automations and agent-assisted operations. It is not a public scrape surface
PortWarden still identifies and monitors internet-facing exposure. An agent using the API does not make autonomous security decisions for you, and it does not certify compliance or prevent a breach.
Talk about API access for your MSP Read the announcementWhat this is for
Hook the agents you already operate so they can open the right client, pull current exposure context, and keep provider work in the same system of record your humans use.
Start from the MSP workspace, issue keys to trusted automations, and keep client logins and portal powers separate. Quoted with the rest of your MSP rollout. No public endpoint price list on this page.
Set the logo and colors your clients see
The branding screen is where a provider makes the organization portal look like their company, not a shared default product page.
- Company logo: upload an SVG for the client-facing portal, with a live preview
- Theme preset: start from a named preset (for example Arctic light), then tune it
- Color tokens: backgrounds, panels, primary/bright/deep/secondary accents, and text colors with hex pickers
- Client portal preview: see how the organization portal renders with your logo and palette
- Attribution control: optional switch to remove the “Powered by PortWarden” footer line
- Custom hostname and TLS materials are configured on the portal host settings when you run your own portal name
MSP work is quoted for your volume and rollout shape. Contact us with client count, white-label needs, and whether clients will log in themselves.
Inventory, findings, and access controls per client
Drill into one organization for endpoints, scans, findings, and the portal powers that client may use.
Know what each client exposes, on a schedule
Add IPs, domains, and subdomains per organization. Domain refresh can discover related subdomains and IPs. Monitoring status and service tier sit on each asset so coverage is something you can see, not guess.
- Scan jobs on IP or subdomain targets, with enable/disable and optional schedules
- Portal scan types include Nmap, OpenVAS, Basic, and Full
- Run history with status, timing, linked findings and reports
- Cleanup guards so assets with dependent scan history are not wiped by accident
Triage once. Keep the trail.
Findings group under a shared key so the same issue is not twenty tickets. Filter by severity, state, source, target, and asset. Detail views show CVE IDs, CVSS when present, host/port/service evidence, references, and remediation steps built from stored evidence.
- States: open, fixed, accepted, false positive
- Risk acceptance needs a reason and acknowledgment; optional comment and expiration; logged
- Advisory AI chat tied to findings, labeled incomplete when it is
- Reports and notifications per org
Useful MSP work. Not a second SOC you have to staff.
New client intake
Stand up the org, seed inventory, get an external baseline, and catch unknown public exposure before it turns into a ticket storm.
Recurring external checks
Leave scheduled jobs running so deploys, firewall edits, and vendor changes show up as monitored drift instead of angry client mail.
Before and after a change
Run on-demand jobs around migrations and launches, then retest after the fix against the same client record and history.
Questionnaires
Pull monitoring history, reports, and finding state when someone asks what you watch and what you fixed. PortWarden helps identify and monitor internet-facing exposure. It does not certify compliance by itself.
Tickets and FAQs, without secrets in the body
Provider-scoped tickets: open, reply, close, reopen. Searchable FAQ and knowledge base in product. The UI warns operators not to paste passwords, API keys, or other secrets into tickets.
What this is not
- Not a breach-prevention promise, and not a full stand-in for a professional penetration test
- Not unlimited client self-service by default; you choose each org's portal powers
- Not a free-for-all scanner; assets must be owned or explicitly authorized
- Not automatic compliance certification; evidence helps questionnaires, your process still owns the framework
Tell us about the book of business
How many client environments? Do you need white-label branding and a custom portal hostname? Will clients log in, or do you keep it fully managed? We quote custom pricing from volume and how you want to run the book.
Common questions about this page
Want client external monitoring under your brand?
Contact us for MSP onboarding, white-label options, and multi-client rollout.