MSPs
Recurring exposure management across every client you manage.
One view of every client, ranked. What they didn’t know arrives in the service desk your technicians already use.
For MSPs and MSSPs
A recurring exposure management service you can sell to every client you manage, under your brand, with the work arriving in the PSA your team already uses. Outerwall is sold only through MSPs and MSSPs and priced per client per month, so you set the price and keep the margin.
Who it’s for
MSPs
One view of every client, ranked. What they didn’t know arrives in the service desk your technicians already use.
MSSPs
Deterministic rules, evidence with every finding, attack paths traced from each confirmed flaw, and coverage that shows its own gaps.
Your clients
Mortgage brokers, tax preparers, investment advisers and medical practices, typically 20 to 200 staff.
What you get
A new client’s public picture is ready within an hour or two, before any scan touches its systems.
ConnectWise, Autotask and HaloPSA. Ranked by blast radius, with the evidence and a plain-language note for your client.
Every client ranked in one place, with the suppliers they share across your book.
Sold only through MSPs and MSSPs. Reports and the client portal carry your name.
Mapped to the FTC Safeguards Rule, SEC Regulation S-P and NYDFS Part 500.
Run Outerwall on your own domain, after proving control of it, and see exactly what your clients would see.
Pricing
Per client, per month, sold only through MSPs and MSSPs. You set your own price to your clients and keep the margin. Design partners get pricing details during the pilot.
Small firms buy security from the MSP that already runs their IT. Canalys expected about 95% of cybersecurity products and services to be sold through partners in 2025.
Source: Canalys, reported by MSSP Alert.
Compliance
Many of your clients must show regular vulnerability testing and oversight of their service providers. Outerwall supplies evidence for both.
| Rule | Who it covers | What it asks for | How Outerwall helps |
|---|---|---|---|
| FTC Safeguards Rule16 CFR 314 | Non-bank financial firms such as mortgage brokers, tax preparers and finance companies | Continuous monitoring, or an annual penetration test and vulnerability assessments every six months. Oversight of service providers. | External scan evidence and supplier monitoring |
| SEC Regulation S-P2024 amendments | Broker-dealers, investment advisers, investment companies and transfer agents | Oversight of service providers through due diligence and monitoring, and breach notice from them within 72 hours. | Supplier inventory and monitoring evidence |
| NYDFS Part 50023 NYCRR 500 | Financial services firms regulated in New York | An annual penetration test, risk-based automated scans, an asset inventory and a third-party service provider policy. | External scans, an inventory of internet-facing assets and supplier monitoring |
| PCI DSS v4.0.1Requirement 11.3.2 | Anyone that handles card data | External vulnerability scans every three months by an Approved Scanning Vendor. | Adds to those scans; Outerwall is not an Approved Scanning Vendor |
| HIPAA Security RuleProposed update | Healthcare providers, health plans and their business associates | Proposed: vulnerability scans every six months, a yearly penetration test and an asset inventory. | The same evidence, if the rule is finalized |
Outerwall’s output supports a client’s compliance evidence. It does not, by itself, make a client compliant.
We’re working with a small group of US MSPs and MSSPs ahead of the first partner release.