Every pentest vendor's channel terms tell you the same thing its sales deck won't: whether your client is a referral or a lead. Most penetration testing vendors describe themselves as "channel-friendly." The partner agreement is where you find out what that word costs. MSP Pentesting is channel-only, and our own terms are on the table at the end of this post, so read the clauses below as the checklist we'd expect a serious MSSP, vCISO or GRC firm to run on us before signing anything.
This is one step in a larger evaluation. The full scorecard, from tester credentials to auditor fit to retest policy, is in how to vet penetration testing providers. This post goes deep on the contract.
Start with the pipeline, not the paperwork
A clause only matters if the vendor's business model doesn't fight it. So before you read a word of the agreement, ask one question: do you sell to end clients?
The structural problem is simple. For a generalist vendor, the pentest is the entry product. The retention move is everything adjacent to it: managed detection, vCISO hours, GRC tooling, compliance advisory. A single SOC 2 pentest is a small engagement. The lifetime value of that client across adjacent services is not. Of course they want a direct conversation with your client. Their incentives say so, and incentives outlast handshakes.
We've watched the pattern play out: an MSP introduces a 50-person accounting firm to a well-known pentest shop for a SOC 2 test, the client and the vendor spend hours together on findings, and eight months later the account has moved to the vendor's parent company. Nobody broke a rule. There was no rule to break.
If the vendor has a direct enterprise or SMB pipeline, assume your referrals will eventually flow into it regardless of what the contract says, and weigh every clause below against that assumption.
The eight clauses to read before you sign
1. Non-solicitation: scope, duration, survival
"We don't poach" is a sentence, not a clause. The clause needs three parts. Scope: it covers both the testing engagement and the broader client relationship, so the vendor can't sell the client anything, not just "another pentest." Duration: a stated period. Twelve months is the floor; 24 is reasonable. Survival: it stays in force after your partner agreement ends, because the moment you stop reselling is exactly when a vendor with a direct motion gets interested in your old accounts.
Ask what the remedy is. A non-solicit with no consequences is a preference.
2. No-contact and no-marketing
Separate from non-solicit. This clause says your client's contacts never enter the vendor's CRM as marketable records. No newsletter, no webinar invite, no "your annual test is due" reminder that arrives from a company your client has never heard of. All communication runs through you, or through the vendor under your rules and your title for them. If the vendor's answer is "our marketing team uses a suppression list," ask how the list is maintained and who audits it.
3. Relationship ownership in the deliverables
The report is where ownership becomes visible. Read the sample, not the brochure. Your brand on the cover, your contact details on the front page, your firm named as the engagement coordinator throughout. Check the document properties for the vendor's name. Check tool screenshots for another company's watermark. If you're using an attested third-party structure, the independent assessor is named on purpose; if you're white-labeling, it isn't. Either is fine. A vendor logo as a "tested by" footnote on a report you sold as your own is not.
The letter of attestation follows the same logic. Ask who signs it, whose letterhead it's on, and whether the wording can be adjusted for your client's auditor.
4. Pricing terms and price protection
You need a partner price list you can quote from without a call. Look for: fixed partner pricing by scope type, how long a price is protected once quoted, whether volume tiers exist and what triggers them, whether the retest is included or a separate line, and whether rush fees exist at all. Then compare against the vendor's public retail price, if it has one. If the partner price is close to retail, the vendor is treating you as a referral source, not a reseller.
5. Deal registration and conflict resolution
What happens when your client calls the vendor directly? What happens when two partners bring the same client? A channel-only vendor has an answer written down: the registered partner owns the account, the vendor routes the client back to the partner, and there's a process for disputes. A channel-friendly vendor's answer is usually "we'd handle that case by case," which means the vendor decides.
6. Confidentiality and data handling
Client data, findings and evidence belong to the client and pass through you. The clause should state where evidence lives during the engagement, when it's destroyed, and that the vendor can't name your client as a reference, use its logo, or cite the engagement in marketing without written consent from both of you. This is also where your own MSA with the client has to line up; if you promised the client 30-day evidence destruction, the vendor's 12-month retention is your problem.
7. Termination and what survives it
Read the termination section as if you're leaving. In-flight engagements complete under the existing terms. Reports already delivered stay yours. Non-solicit, no-contact and confidentiality survive for their stated periods. If any of those evaporate at termination, the agreement is telling you the vendor expects to keep your clients as consolation.
8. Liability, insurance and authorization flow-down
The vendor's certificate of insurance (professional liability and cyber) should be attached or available on request, with limits that make sense against what your MSA promises. Check the liability cap, the indemnification for the tester's negligence, and the authorization language: the client signs rules of engagement, the vendor holds signed authorization for every target, and third-party hosted assets are handled explicitly. We cover this in more depth in the provider vetting guide linked above, so this is a checkpoint, not the full treatment.
Channel-friendly versus channel-only, clause by clause
Use the table to score the agreement in front of you.
| Clause | Channel-friendly | Channel-only | Red flag |
|---|---|---|---|
| Non-solicit | Verbal assurance, or a clause limited to "another pentest" | Written, covers engagement and relationship, stated duration, survives termination | No clause, or no duration |
| No-contact | "We use a suppression list" | Client contacts never become marketable records; all comms through you | Client receives vendor marketing after the test |
| Deliverables | Your logo, vendor's name in the footer and metadata | Your brand throughout; assessor named only in the attested option | "Tested by [vendor]" on a report you sold as yours |
| Pricing | Retail minus a referral fee, quoted per deal | Fixed partner price list, protected quote window, retest included | Pricing only on a call |
| Deal registration | "Case by case" | Registered partner owns the account; documented routing and dispute process | Vendor decides |
| Confidentiality | Standard NDA | Evidence retention and destruction stated; no reference or logo use without consent | Vendor cites your client in marketing |
| Termination | Restrictive covenants end with the agreement | Non-solicit, no-contact and confidentiality survive; in-flight work completes | Clients become the vendor's on exit |
| Liability | "We can get the COI later" | COI available; indemnification and authorization flow-down present | Cap and indemnity undefined |
How to test the terms before you rely on them
- Ask for the partner agreement draft before the first deal, not after. A vendor that won't send it until you've committed a client is negotiating from your client's position, not yours.
- Ask for a sample report and read the footer, the metadata and the attestation wording. That's the deliverable your client's auditor sees.
- Ask what happens when your client emails the vendor directly. The right answer is a specific process that ends with the client back in your hands.
- Ask whether scoping calls can run under your brand. If the vendor's pre-sale support is a PDF and a calendar link, you'll be doing the scoping yourself.
- Run one engagement. Pick a client you know well and judge the whole cycle: scoping, communication during the test, report quality, retest. One real engagement tells you more about the terms than the terms do.
Our terms, since you'll ask
We sell only through MSPs, MSSPs, vCISOs, GRC firms and audit shops, and we have no direct sales motion to end clients. Every reseller agreement we sign carries a non-solicitation clause covering both the testing engagement and the client relationship for 24 months after engagement close. The same operators also run tests through a separate direct-to-client SMB brand, and the two commercial models are deliberately kept apart: no shared pipeline, no overlapping account list. A buyer who finds the direct brand through a search ad never enters the channel program's customer base.
White-labeled reports ship under your branding, scoping calls run under your name when you want them to, and we send sample reports, reseller pricing and a partner agreement draft on request through the partner program. Read the draft against the eight clauses above. That's what it's for.
Frequently asked questions
Is a non-solicitation clause actually enforceable?
Enforceability depends on jurisdiction and drafting, and your counsel should read it. Treat the clause as evidence of structure more than as a guarantee: a vendor whose business model doesn't need your client will sign it without friction, and one that hesitates has told you why.
Does a vendor with a separate direct brand still count as channel-only?
It can, if the separation is structural: different brand, no shared sales pipeline, no overlapping account list, and a written commitment that channel clients never enter the direct funnel. Ask the vendor to describe the wall in operational terms. If it's a policy rather than a structure, it's a promise.
Should the vendor ever talk to my client?
Yes, on your terms. Findings walkthroughs are better with the tester in the room. The clause you want says the vendor joins those calls as your security team, under a title you choose, and that no follow-up leaves the vendor's side without going through you.
Do channel terms matter for attested third-party reports?
More, not less. When the report names the vendor as the independent assessor, your client knows exactly who did the work. The non-solicit and no-contact clauses are what keep that knowledge from turning into a relationship.
Next step
Score the agreement in front of you against the table above, then put the vendor through the full penetration testing provider scorecard. If you want our draft to compare against, request reseller pricing and a quote for one engagement and read the terms before you resell a thing.



.avif)
.png)
.png)
.png)

