EspañolEnglish
White-label pentesting for your clients.
You own the client relationship and you invoice them every month. We have the offensive team. You sell the pentest under your brand, we execute it, the report carries your logo, and the client stays yours.
Who this is for.
- MSPs and managed IT providers You run the firewall, the Active Directory or the Microsoft 365 tenant for your clients.
- Consultancies and integrators You sell infrastructure, cloud or development projects, and the security questions that come back get referred out.
- Kit Digital agentes digitalizadores You have a book of clients on the Ciberseguridad, Comunicaciones seguras or Puesto de trabajo seguro solutions.
- Kit Consulting advisors You deliver the Servicio de Asesoramiento en Ciberseguridad.
The argument is not the commission. It is that if someone is going to find a Critical on your client, better that it is you and not a third party.
How it works.
- 01
You bring us the opportunity
You spot the need and tell us about it. Thirty minutes with the three of us, or with you alone if you would rather we stayed out of sight for now, to settle the scope.
- 02
Proposal at partner price
We send you the quote at the partner rate. You present it to your client with your price and your brand. We do not discuss price with your client.
- 03
Testing authorization
The end client signs the authorization. It names REDOPS Security Ltd. as the technical executor, even though the report and the commercial relationship are yours. This part is not optional. Nothing is fired at a third party without written authorization naming whoever runs it.
- 04
Execution
Same-day notice of any critical finding, and a direct channel to the operator for the whole engagement, not a ticket queue.
- 05
Delivery
Report under your brand, and a technical walkthrough session. You run it, or we run it introduced as your offensive security team. Free retest of High and Critical findings within thirty days, same as on any other job of ours.
Mutual NDA before any technical detail. Non-circumvention in both directions: we do not approach your client to sell them anything, and you do not subcontract the same work to someone else off the back of our report. We also reserve the right to turn down scopes we cannot execute well. We would rather tell you no before you promise it to the client.
What you can sell.
The catalog is the one already published on the site, with no cut-down partner edition. Only the starting rate is listed here.
| Service | Published rate |
|---|---|
| Attack Surface Review | €1,900 |
| Web Application Pentest | from €5,900 |
| External Network Pentest | from €5,900 |
| Internal Network Pentest | after scoping |
| Active Directory Assessment | from €8,900 |
| Mobile Application Pentest | after scoping |
| Red Team Operations | after scoping |
| Cloud Security Assessment | after scoping |
Partner price is 20% off that published rate. What you charge your client is yours to decide, and we do not ask. Scope, days and deliverables for each service are broken down in services and pricing.
To open the security conversation with a client who has never had a pentest, start with the Attack Surface Review: 2 days on their external perimeter, validation only, ending in a prioritized list of what is exposed. It is cheap to sell and it is usually what uncovers the larger project.
If you sell monthly maintenance, Watch and Watch + Verify, at €790 and €1,490 a month, fold into your fee without you having to build anything. The monitoring and the monthly report are on us.
If you are a Kit Digital agente digitalizador.
The obvious part first: applications for Kit Digital closed on 31 October 2025, with the last two calls that were still open. From here the program is only about executing and justifying grants already awarded.
The second part: pentesting has never been a fundable solution under the program. We do not sell it as though it were, and we will not help you present it that way.
The opportunity is your book of clients, not the grant. The clients you installed antivirus, EDR, firewall or secure communications for are left with one unanswered question, which is whether any of it works. An Attack Surface Review or an external pentest under your brand is the answer. Unsubsidized service, at market price, sold to a client who already trusts you.
A clear filter, so the call is not wasted: this makes sense with clients of fifty employees and up and an ongoing maintenance relationship. If your book is micro-businesses with a website and a CRM, say so on the call and we will tell you whether it is worth it.
If you are a Kit Consulting advisor.
The state of the program first. Kit Consulting ran a single call, closed on 31 March 2025, and the final deadline to submit service agreements expired on 31 May 2026. It takes no new applications. As with Kit Digital, what is left is execution and justification.
The grant targeted companies of 10 to 249 employees, at 12,000, 18,000 and 24,000 euros depending on the bracket, and one of its categories is the Servicio de Asesoramiento en Ciberseguridad, in three levels: basic, advanced, and certification readiness.
Plenty of advisors deliver that service as a desk exercise: questionnaires, policies and a three-year action plan. A real external pentest inside the deliverable turns the advisory into something the client can show their board and their auditors. We run the technical part white-label and you fold it into your advisory report. Your client sees a single supplier, which is you.
The company profile these grants aimed at, mid-sized, with its own infrastructure, Active Directory and internet-facing services, is exactly the one that gets the most out of a pentest. That book of clients is still there once the grant is justified, and the work sells anyway, at market price.
Common questions.
Does the report carry my brand or yours?
Yours. Our name appears only on the testing authorization the client signs, and in the contract between you and REDOPS.
Can you talk to my client?
Only in the technical sessions you set up, and introduced as your team. Never to sell.
Who invoices whom?
REDOPS invoices you, at partner price. You invoice your client whatever you decide. We never see that figure.
What if the client wants to hire you directly afterwards?
We send them back to you. It is written into the partner contract and it runs both ways.
Do you carry liability cover for work delivered under my brand?
The testing authorization and the partner contract set out who answers for what, and that gets reviewed on the call with both contracts in front of us, before anything is signed.
What if the scope my sales team sold is not realistic?
We tell you before signing, not halfway through the job. And we work out together what can be done for that budget.
First partner engagement
Start with a real client of yours.
An Attack Surface Review on the perimeter of one of your clients, at the partner 20% off the published €1,900. You see the report under your brand, you show it to the client, and you decide afterwards whether this becomes a channel. No volume minimum and no exclusivity to sign up front.
Book 30 minutes