NinjaOne is a popular MSP RMM with strong patching and remote access. With Lavawall®, technicians get browser-based remote control, a background admin workspace, and a remote shell on Windows and Mac, scripting on Linux, and ad-hoc support for computers without the agent, with end-to-end encrypted sessions available. Lavawall can run on its own as your RMM, or be installed through Datto RMM, NinjaOne, ConnectWise, Kaseya, Intune or any tool that runs a script, while you move over.
Where Lavawall® wins for MSPs
Built by an MSP and audit firm (ThreeShield, CISSP and CISA staff). Every feature exists because we needed it on our own clients.
GRC compliance automation across 70+ frameworks (CMMC 2.0, NIST CSF 2.0, NIST SP 800-171, CIS Controls v8, SOC 2, ISO 27001, PCI DSS, HIPAA, PIPEDA, BC E-Health Act, Alberta HIA, NERC CIP, CIRO, CPA Canada, Australian Essential Eight, Canadian privacy bundle).
Microsoft 365 / Azure / Entra ID and Google Workspace breach detection with endpoint correlation, from the same agent that patches the device.
Administrator elevation and execution prevention without a kernel driver: no BSOD risk, works on Remote Desktop Session Hosts, no cloud callback required.
Cross-platform patching: 7,400+ application catalogue plus OS and firmware updates on Windows, macOS, and Linux from one agent and one console.
Replacement prioritization based on battery cycles and capacity, drive SMART data, TPM version, available RAM, and processor age, rather than lifecycle dates alone.
SaaS / shadow-AI discovery against a curated 1,277-app catalogue using email metadata.
Multi-tenant remote support that runs in a phone browser with no operator agent, plus backstage shell access.
Per-named-agent helpdesk pricing (US$59/agent/month) with unlimited tickets, instead of per-seat pricing.
Free white-label domain scanner ("Scout") to use as a sales tool with prospect-facing reports.
No high-water-mark billing, month-to-month, no minimum for single modules, free Canadian and US currency choice.
Where NinjaOne wins
Mature, polished RMM UX with broad feature coverage in scripting, monitoring, and remote control.
Large integration ecosystem and well-known brand recognition in the MSP channel.
Strong native remote access stack and integrated software-deployment workflows.
Marketplace of third-party integrations and a large community of existing technicians.
Feature comparison
| Feature | Lavawall® | NinjaOne |
|---|---|---|
| Cross-platform agent (Windows, macOS, Linux) | Yes, single agent on all three | Yes |
| Application patch catalogue (third-party apps) | 7,400+ applications | See NinjaOne documentation |
| GRC compliance framework mapping | CMMC 2.0, NIST CSF, CIS, SOC 2, ISO 27001, HIPAA, PCI DSS, PIPEDA, BC E-Health Act, Alberta HIA, NERC CIP, CIRO, CPA Canada, Essential Eight (70+ total) | See NinjaOne documentation |
| Microsoft 365 / Azure / Entra ID breach detection | Built-in identity threat detection and response (ITDR) with endpoint correlation | See NinjaOne documentation |
| Google Workspace breach detection | Built-in | See NinjaOne documentation |
| Administrator elevation and execution prevention (no kernel driver) | Yes, no BSOD risk, works on RDS hosts | See NinjaOne documentation |
| Replacement prioritization (battery, drive, TPM, RAM, age) | Yes, built-in scoring across multiple signals | See NinjaOne documentation |
| SaaS / shadow-AI discovery | Built-in (1,277 SaaS catalogue) | See NinjaOne documentation |
| Multi-tenant remote support without operator agent | Yes, runs in mobile/desktop browser | Native remote control included |
| Backstage shell (terminal without GUI session) | Yes | Yes |
| Pricing model | Month-to-month, no high-water mark, no minimum for single modules | See NinjaOne documentation |
| Free domain attack-surface scanner / sales tool | Scout (white-label, embeddable) | See NinjaOne documentation |
| Help desk pricing model | Per named agent (unlimited tickets) | See NinjaOne documentation |
| Native CAD billing for Canadian MSPs | Yes, native CAD with GST/HST/PST/QST | See NinjaOne documentation |
Who should pick which?
Pick Lavawall® if…
You want one platform that covers cybersecurity, GRC, patching, M365 and Google Workspace breach detection, helpdesk, remote support, and reliability monitoring, instead of five to seven separate tools.
Your clients ask whether you meet CMMC 2.0, NIST CSF, CIS, SOC 2, HIPAA, PIPEDA, NERC CIP, or other frameworks and you want continuous evidence collection instead of yearly fire drills.
You support a mix of Windows, macOS, and Linux endpoints and want one agent and one console for all three, with remote control on Windows and macOS and scripts, patching, and monitoring on Linux.
You are an audit firm, MSSP, or vCIO who needs proof-of-control evidence and co-branded reports for executive QBRs.
You operate in Canada and want native CAD billing, Canadian privacy framework coverage, and Canadian-resident data hosting.
Pick NinjaOne if…
You only need a traditional RMM with deep, mature scripting and monitoring features and you already have separate tools for security, GRC, M365 monitoring, and helpdesk.
Your team is already deeply trained on the NinjaOne workflow and the switching cost outweighs the benefit of consolidation.
You need a specific NinjaOne-only integration that has no equivalent in Lavawall®.
Frequently asked
- Is Lavawall® a NinjaOne replacement?
- Yes. Lavawall® covers remote support, patching, and scripting itself, along with cybersecurity, GRC, M365 breach detection, and replacement prioritization. It can be installed through NinjaOne, and both can run side by side while MSPs move over.
- Does Lavawall® patch the same applications as NinjaOne?
- You can check for yourself: Lavawall® maintains a public catalogue of 7,400+ applications across Windows, macOS, and Linux. The catalogue is published openly so MSPs can verify coverage against any application before adopting.
- How does Lavawall® pricing compare?
- Lavawall® is month-to-month, with no high-water-mark billing, 14-day free trials, and no minimum for single modules. The pricing page lists current rates in USD and CAD. See NinjaOne for its current pricing terms.
- Can Lavawall® consolidate other tools beyond an RMM?
- Yes. A typical 50-device, 3-technician MSP runs five to seven separate tools. Lavawall® can replace the RMM/patch tool, the GRC starter (Vanta/Drata-class), elevation control (ThreatLocker-class), the M365 monitoring add-on, helpdesk (Zendesk-class), and remote support (Bomgar/BeyondTrust-class) with one platform.
Security and FIPS 140-3 by design
Lavawall® is built so the secrets it manages stay encrypted where you are. The secrets that matter (vault items, server credentials, and any key pushed to an endpoint) are encrypted where you are and stored by us only as ciphertext, so an administrator with full access to our database sees encrypted blobs and nothing to open them with. See security and privacy.
Lavawall®’s relay and Windows and Mac agents use a FIPS 140-3 validated cryptographic module, the Go Cryptographic Module, NIST CMVP certificate #5247, and sign-in can be restricted to a FIPS 140-3 validated security key, the YubiKey 5 FIPS Series, certificate #5291. In-browser encryption uses the FIPS 140-3 approved algorithms. Full detail is on FIPS 140-3 support.
That same secret-handling powers WireGuard deployment across the fleet. Each endpoint generates its own private key locally and only the public key comes back, so the tunnel’s private key is never in a script, a log, or our database. Weighing NinjaOne for a regulated environment? This is the line worth checking against your obligation.
Related Lavawall® pages
Datto and Datto RMM are trademarks of Kaseya. NinjaOne is a trademark of NinjaOne, LLC. Lavawall is not affiliated with either.