Kaseya VSA has been an MSP RMM standard for many years, with broad automation, scripting, patch management, and a deep partner ecosystem under the wider Kaseya umbrella (IT Complete bundle, Datto, RapidFire, etc.).
MSPs running Kaseya VSA still face a security-and-compliance procurement question: cross-platform compliance evidence, multi-tenant cloud breach detection with endpoint correlation, administrator elevation and execution prevention (no kernel driver), replacement prioritization, and curated SaaS / shadow-AI discovery. Check Kaseya's documentation for how much of that VSA covers.
Technicians get browser-based remote control, a background admin workspace, and a remote shell on Windows and Mac, scripting on Linux, and ad-hoc support for computers without the agent, with end-to-end encrypted sessions available. Lavawall can run on its own as your RMM, or be installed through Datto RMM, NinjaOne, ConnectWise, Kaseya, Intune or any tool that runs a script, while you move over.
Where Lavawall® wins for MSPs
Lavawall® puts security, compliance, and breach detection in the same agent and console as patching and remote support. For MSPs delivering CMMC 2.0, CPCSC, SOC 2, HIPAA, PCI DSS, or cyber-insurance readiness, the Lavawall® evidence base is what an assessor will sample.
M365 / Entra / Azure / Google Workspace identity threat detection and response (ITDR) with endpoint correlation is worth checking in Kaseya's documentation. Lavawall® treats it as a first-class capability.
For MSPs running Kaseya VSA plus separate Vanta / Drata-class GRC, ThreatLocker-class elevation control, M365 monitoring, helpdesk, and remote-support tools, Lavawall® brings the RMM and that stack into one platform.
Where Kaseya VSA wins
Kaseya VSA is a deep, well-established RMM with broad automation libraries and a large partner ecosystem.
For MSPs deeply invested in the Kaseya IT Complete bundle (Datto, BMS, etc.) where the operational integration matters more than consolidating onto one platform, Kaseya VSA stays the operational core. Lavawall® can be installed through Kaseya VSA and run side by side with it while you decide whether to move over.
Feature comparison
| Feature | Lavawall® | Kaseya VSA |
|---|---|---|
| Mature MSP RMM with deep automation | Standard scripting and APIs | Yes, mature platform with deep automation |
| Cross-platform agent (Windows, macOS, Linux) | Yes; remote control on Windows and macOS, scripts, patching, and monitoring on all three | Yes, varying depth |
| Public application patch catalogue | 7,400+ applications, published openly | OS + third-party (varies) |
| Compliance framework mapping (CMMC 2.0 / NIST / SOC 2 / HIPAA) | 70+ frameworks; continuous evidence with System Security Plan (SSP) and remediation plan (POA&M) | Reports; not framework-mapped GRC platform |
| M365 / Entra ID / Azure breach detection | Native multi-tenant identity threat detection and response (ITDR) | Limited |
| Google Workspace breach detection | Native | Limited |
| Administrator elevation and execution prevention (no kernel driver) | Native | No |
| Curated SaaS / shadow-AI discovery (1,277-app catalogue) | Native | No |
| Replacement prioritization (battery / TPM / SMART / RAM / age) | Multi-factor scoring | Lifecycle dates |
| Akira ransomware indicator hunter | Native | No |
| Built and used by an audit firm | ThreeShield (CISSP / CISA) | No |
| Kaseya high-watermark and lock-in billing | Absolutely not | Yes |
Who should pick which?
Pick Lavawall® if…
MSPs that want an RMM with security, GRC, breach detection, and analytics built in, installed through Kaseya VSA while they move over.
MSPs delivering compliance readiness across CMMC 2.0, CPCSC, NIST, SOC 2, ISO 27001, HIPAA, PCI DSS, or PIPEDA as a service.
Pick Kaseya VSA if…
MSPs whose RMM and PSA workflows are already deep in the Kaseya IT Complete bundle and whose security needs are handled separately.
Frequently asked
- Does Lavawall® replace Kaseya VSA?
- Yes. Lavawall® covers remote support, patching, and scripting itself, along with security, GRC, and analytics. It can be installed through Kaseya VSA, and both can run side by side while you move over.
- Can Lavawall® be deployed through Kaseya VSA?
- Yes. PowerShell and bash deployment scripts run through Kaseya VSA agent procedures.
- Will Lavawall® conflict with the Kaseya VSA agent?
- No. Lavawall® coexists with major RMM agents without conflicts.
Security and FIPS 140-3 by design
Lavawall® is built so the secrets it manages stay encrypted where you are. The secrets that matter (vault items, server credentials, and any key pushed to an endpoint) are encrypted where you are and stored by us only as ciphertext, so an administrator with full access to our database sees encrypted blobs and nothing to open them with. See security and privacy.
Lavawall®’s relay and Windows and Mac agents use a FIPS 140-3 validated cryptographic module, the Go Cryptographic Module, NIST CMVP certificate #5247, and sign-in can be restricted to a FIPS 140-3 validated security key, the YubiKey 5 FIPS Series, certificate #5291. In-browser encryption uses the FIPS 140-3 approved algorithms. Full detail is on FIPS 140-3 support.
That same secret-handling powers WireGuard deployment across the fleet. Each endpoint generates its own private key locally and only the public key comes back, so the tunnel’s private key is never in a script, a log, or our database. Weighing Kaseya VSA for a regulated environment? This is the line worth checking against your obligation.