Managed Service Providers

Multi-client external attack surface management. Brand the client portal as yours.

MSP workspace

One provider account. Many client organizations. Your team runs the book.

PortWarden for MSPs is a multi-tenant workspace for authorized, internet-facing assets across small-business clients. Your staff manages organizations, inventory, scheduled scans, findings, reports, and alerts in one place.

Clients can get a portal login if you want that. You pick what each organization may see and change. White-label options cover logo, theme colors, custom hostname, TLS materials, and whether the client footer shows PortWarden.

Recurring monitoring watches for exposure drift. On-demand jobs dig in when a client change needs a harder look.

Talk about MSP onboarding Portal demo

What you get

  • Portfolio dashboard across every client organization
  • Per-client IPs, domains, and subdomains
  • Scheduled jobs, run history, findings, and reports
  • Per-org portal permissions you control
  • AI-agent-ready API for your provider account and client orgs
  • White-label logo, colors, hostname, and attribution
MSP portfolio dashboard with organization counts, open findings, scan status, and action center panels
Provider dashboard: portfolio counts, open findings, coverage gaps, and recent scan activity across clients.
Provider operations

Staff, clients, assets, and findings stay inside your provider boundary

You administer the portfolio. Clients only get the access you turn on. Nobody else on the platform sees your orgs.

MSP organizations list for managing downstream client companies
Organizations list: every client company under your provider account.
MSP monitoring services catalog with recurring scan coverage cards
Monitoring services: recurring coverage cards for the endpoints you run.

Provider team

Logins, team users, roles, and profiles so more than one engineer can work the book without sharing one password.

Client organizations

Create and manage orgs: active or suspended, contacts, locale, plus counts for inventory, scans, findings, reports, and users.

Client user roles

Invite organization admins, members, and viewers. Keep client day-to-day access separate from provider admin.

Per-client permissions

Allow or deny endpoints, org users, alerts, reports, findings activity, and advisory AI guidance independently per organization.

Action center

Open and high-severity findings, assets without coverage, recent reports, failed runs, and upcoming scheduled scans across clients.

API keys

Provider admins mint API keys so your own AI agents can work the provider account and the client organizations you manage, inside the permissions you set. How the agent API fits.

MSP team management screen for provider staff users
Team: provider staff who operate the portfolio.
MSP API key management for provider administrators
API keys: credentials your agents use against the provider account and client orgs you already control.
AI-agent-ready API

Let your agents work the book, with the same boundaries your staff already have

MSPs already run their own AI agents for tickets, inventory, and client ops. PortWarden's API is built so those agents can manage your provider account and the client organizations under it, instead of a person clicking every org by hand.

Agents act through credentials you issue. They stay inside the provider boundary and the per-organization permissions you already set in the portal. They do not get a side door around client isolation.

  • Provider-account work: portfolio context, organizations, and the controls your admins already use
  • Client-organization work: the same orgs your staff manage, scoped to what that org is allowed to see and change
  • API keys minted by provider administrators, rotated and revoked from the same screen as the rest of the workspace
  • Fits internal automations and agent-assisted operations. It is not a public scrape surface

PortWarden still identifies and monitors internet-facing exposure. An agent using the API does not make autonomous security decisions for you, and it does not certify compliance or prevent a breach.

Talk about API access for your MSP Read the announcement

What this is for

Hook the agents you already operate so they can open the right client, pull current exposure context, and keep provider work in the same system of record your humans use.

Start from the MSP workspace, issue keys to trusted automations, and keep client logins and portal powers separate. Quoted with the rest of your MSP rollout. No public endpoint price list on this page.

White-label client portal

Set the logo and colors your clients see

The branding screen is where a provider makes the organization portal look like their company, not a shared default product page.

  • Company logo: upload an SVG for the client-facing portal, with a live preview
  • Theme preset: start from a named preset (for example Arctic light), then tune it
  • Color tokens: backgrounds, panels, primary/bright/deep/secondary accents, and text colors with hex pickers
  • Client portal preview: see how the organization portal renders with your logo and palette
  • Attribution control: optional switch to remove the “Powered by PortWarden” footer line
  • Custom hostname and TLS materials are configured on the portal host settings when you run your own portal name

MSP work is quoted for your volume and rollout shape. Contact us with client count, white-label needs, and whether clients will log in themselves.

MSP branding settings with company logo upload, theme preset selector, hex color pickers for surfaces accents and text, client portal preview, and Powered by PortWarden footer toggle
Branding: SVG logo upload, theme preset, hex color controls for surfaces/accents/text, live client portal preview, and optional removal of the PortWarden footer line.
Inside a client organization

Inventory, findings, and access controls per client

Drill into one organization for endpoints, scans, findings, and the portal powers that client may use.

Inventory and jobs

Know what each client exposes, on a schedule

Add IPs, domains, and subdomains per organization. Domain refresh can discover related subdomains and IPs. Monitoring status and service tier sit on each asset so coverage is something you can see, not guess.

  • Scan jobs on IP or subdomain targets, with enable/disable and optional schedules
  • Portal scan types include Nmap, OpenVAS, Basic, and Full
  • Run history with status, timing, linked findings and reports
  • Cleanup guards so assets with dependent scan history are not wiped by accident
Client organization endpoints inventory showing IPs domains and monitoring status
Endpoints: per-organization inventory and monitoring status.
Findings and reports

Triage once. Keep the trail.

Findings group under a shared key so the same issue is not twenty tickets. Filter by severity, state, source, target, and asset. Detail views show CVE IDs, CVSS when present, host/port/service evidence, references, and remediation steps built from stored evidence.

  • States: open, fixed, accepted, false positive
  • Risk acceptance needs a reason and acknowledgment; optional comment and expiration; logged
  • Advisory AI chat tied to findings, labeled incomplete when it is
  • Reports and notifications per org
Client organization findings list with severity and triage states
Findings: severity, state, and triage inside one client org.
Per-organization client portal access controls allowing or denying endpoint user alert report and findings permissions
Access: allow or deny what client users can do in their portal.
Single client organization overview with inventory scan finding and user counts
Organization overview: inventory, scans, findings, reports, and users at a glance.
MSP reports overview across the provider portfolio
Reports overview across the portfolio when you need evidence for a client conversation.
Where it fits day to day

Useful MSP work. Not a second SOC you have to staff.

New client intake

Stand up the org, seed inventory, get an external baseline, and catch unknown public exposure before it turns into a ticket storm.

Recurring external checks

Leave scheduled jobs running so deploys, firewall edits, and vendor changes show up as monitored drift instead of angry client mail.

Before and after a change

Run on-demand jobs around migrations and launches, then retest after the fix against the same client record and history.

Questionnaires

Pull monitoring history, reports, and finding state when someone asks what you watch and what you fixed. PortWarden helps identify and monitor internet-facing exposure. It does not certify compliance by itself.

Support in the workspace

Tickets and FAQs, without secrets in the body

Provider-scoped tickets: open, reply, close, reopen. Searchable FAQ and knowledge base in product. The UI warns operators not to paste passwords, API keys, or other secrets into tickets.

Honest limits

What this is not

  • Not a breach-prevention promise, and not a full stand-in for a professional penetration test
  • Not unlimited client self-service by default; you choose each org's portal powers
  • Not a free-for-all scanner; assets must be owned or explicitly authorized
  • Not automatic compliance certification; evidence helps questionnaires, your process still owns the framework
Next step

Tell us about the book of business

How many client environments? Do you need white-label branding and a custom portal hostname? Will clients log in, or do you keep it fully managed? We quote custom pricing from volume and how you want to run the book.

Questions

Common questions about this page

A multi-client provider portal for authorized external attack surface management: organizations, inventory, scheduled scans, findings triage, reports, alerts, optional client portal access, white-label branding, and an API your own AI agents can use against the provider account and client organizations you manage.

Yes. Set brand name and logo, pick or customize a theme, use a custom portal hostname, manage TLS materials, and control whether the Powered by PortWarden footer appears. MSP pricing is custom and quoted from volume during onboarding.

Yes. Access settings are per organization. You can allow or deny client actions such as managing endpoints, managing organization users, viewing alerts, reports, findings activity, and advisory AI remediation guidance.

Yes. Provider administrators issue API keys so the agents you already run can work with your provider account and the client organizations under it. Agents stay inside the provider boundary and the per-organization permissions you set. They do not bypass client isolation, and they do not certify compliance or prevent a breach.

Use the contact page. Mention that you want MSP API access for your own agents, plus approximate client count, whether you need white-label branding or a custom hostname, and whether clients will log in themselves or stay fully managed by your team.

No. Provider admins only work with organizations that belong to their provider. Client data stays inside that provider account.

Use the contact page. Include approximate client count, whether you need white-label branding or a custom hostname, and whether clients will log in themselves or stay fully managed by your team.

Want client external monitoring under your brand?

Contact us for MSP onboarding, white-label options, and multi-client rollout.