Skip to content

For managed service providers, IT firms and software agencies

Penetration testing for your clients, under your name or ours.

A 3-person, OffSec-certified team in British Columbia that tests what your clients run, delivers a graded report their developers and auditors can work from, and stays out of your client relationship.

Engagements from $5,000 CAD. Partner pricing on the rate sheet.

  • OSCP
  • OSEP
  • OSWE
  • OSMR
  • BSCP
  • CRTO
  • OWASP Top 10
  • OWASP ASVS
  • OWASP Testing Guide
  • NIST SP 800-115
  • OSSTMM
  • WASC

How it works with you

You keep the client. We do the testing.

Your relationship, your invoice
You scope with us or hand the client over for scoping. Either way you own the account, and you can bill the engagement through your own catalogue or have us invoice directly.
White-label or co-branded report
Your name on the cover, ours, or both. The content is the same graded report either way, with every finding carrying a CVSS vector, a CWE classification and reproduction steps.
A turnaround fixed at scoping
Dates are agreed in writing before work starts, so you can pass them to your client as a commitment rather than an estimate.
Retest included
One retest round of the reported findings, within 60 days of the report, at no extra charge. Your team or theirs remediates; we confirm closure.
No unsolicited contact with your clients
We do not sell to your clients, and we do not contact them without your approval. Where direct contact helps, such as a scoping call or a findings walkthrough, it happens with you in the loop.

Why your clients are asking

The questions have already started.

Cyber-insurance renewals
Renewal questionnaires increasingly ask whether a penetration test was performed in the last year, and some carriers want the report rather than a yes. Requirements vary by carrier and policy.
SOC 2 and ISO 27001
Auditors generally look for independent testing inside the audit period. A test scheduled after the period closes does not help.
PCI DSS 4.0.1
Requirement 11.4 calls for internal and external penetration testing at least every twelve months and after significant change.
Enterprise procurement
Security questionnaires arrive before the contract does. A current report covers the technical testing questions; the rest is policy, and that is where you come in.

What you get

For you, and for your client.

What a partner receives

An anonymised sample report, a plain-language explainer you can hand to a client, a scoping checklist for each service, and one person to call: the tester who will run the work, not an account manager.

What a client receives

An executive summary, an overall A-to-F risk grade for the tested scope, every finding with its CVSS vector, CWE classification and reproduction steps, proof-of-concept evidence, remediation written against their stack, and a retest summary once fixed.

Getting started

Four steps to the first engagement.

  1. A 20-minute call What your clients run, what they are being asked for, and how you want to bill it.
  2. Partner rate sheet Pricing per service with room for your margin, and the partner agreement.
  3. First scope Targets, roles and exclusions agreed in writing, with dates you can pass on.
  4. Report and retest Delivered under your name or ours. One retest round of the reported findings within 60 days.

Request the partner rate sheet

Tell us what your clients run and how you would want to bill it. We reply within one business day with the rate sheet and the partner agreement.

Form not working? Email info@unit91.com directly and we will pick it up the same way.