Partner
Send us the work you do not do.
If your clients keep asking for penetration tests, CMMC scoping or a security program you do not deliver, we would rather be the firm you hand that to than the firm that takes the relationship.
Think of it as a bug bounty, but for sales. You bring in the work, we handle the engagement, and you get paid a percentage of it.
The terms
- What you earn
- A percentage of the tokens the client buys for their first statement of work, including any additional tokens they buy to finish that same statement of work. Tokens are how work is bought here, so the commission tracks what the client actually pays rather than an estimate.
- The rate is negotiated rather than published, and it lands in your agreement. What makes sense for a consultancy sending us work every quarter is not what makes sense for an attorney who refers twice a year, and one published number would be wrong for one of them.
- When it pays
- Twice a month, for everything the client has paid us for since the last run. We do not pay on signature, because a signature is not money, and a program that pays before the client does eventually stops paying anyone.
- If we ever refund a token purchase, the commission on the refunded part comes back with it. That is rare. Our services agreement makes tokens non-refundable apart from a few named cases, and your referral agreement says how the adjustment works.
- Whether renewals count
- It depends on who owns the relationship afterwards, and that is a real distinction rather than a way to pay less.
- If you keep the client, which is the usual shape for an MSP or a consultancy handing us the work they do not do, every later token purchase that client makes counts, for as long as you are still the firm they go through. Your agreement says what that means in practice and how either of us can end it.
- If you make the introduction and step back, and we take the relationship from there, the first contract pays and renewals do not. Finding a customer once is worth paying for. It is not the same contribution as keeping one.
- What has to be signed
- A short agreement, signed by both of us, before a referral completes. It exists to protect both sides and it is deliberately simple: who introduced whom, which of the two arrangements above applies, and the rate. Where this page and your signed agreement differ, the agreement is the one that counts.
If your own profession has rules about accepting a fee like this, and accountants and attorneys usually do, check them before you sign. We will not ask you to certify something we cannot see.
Who this tends to suit
MSPs and IT consultancies
Your client asked for a pentest
You run their infrastructure. An auditor or a customer now wants independent testing, which you cannot credibly do on a system you manage.
Accountants and auditors
A client needs a security program
SOC 2 readiness, cyber insurance questionnaires, or a CMMC obligation landing on a client who has nobody to hand it to.
Attorneys
Diligence or an incident
Technical assessment during diligence, or a client who needs a practitioner rather than a platform after something has gone wrong.
Other security firms
Outside your scope
Defensive shops that get asked for offensive work, and offensive shops that get asked for compliance advisory.
What we commit to
- If you keep the client, we do not sell around you. We will not use a referral as a way in to work you already do
- Where the client agrees, you hear where the engagement stands in scope terms and nothing more. Findings belong to the client, and we do not pass them on without their say-so
- If we are not the right fit for a referral, we say so rather than taking it
- You will not be asked to become a reseller or carry a quota
Register interest
Tell us what you do and what your clients keep asking for. We will come back to you with terms.
