📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Answers

Lavawall® FAQ

Answers to the questions teams and MSPs ask us most about security, privacy, pricing, compliance, and every module. Jump to a section or search the page.

Security & privacy

Where is Lavawall made and hosted?
Lavawall is built in Canada by ThreeShield Information Security Corporation. Your data can be hosted in Canada, the United States, Europe, or Australia, and there is a US-only path. Telemetry, reports, and evidence are stored against your own tenant and are not comingled with other customers' data.
Is our data encrypted?
Yes. Data is encrypted in transit (TLS) and at rest. Where Lavawall stores sensitive client credentials on your behalf, it uses zero-knowledge encryption so the secrets are not readable by us.
Is Lavawall FIPS 140-3 validated?
Lavawall uses FIPS 140-3 validated cryptographic modules in specific components: the Go Cryptographic Module (CMVP certificate #5247) in the relay and the Windows and Mac agents, and YubiKey 5 FIPS (certificate #5291) for hardware technician authentication. The product as a whole is not a cryptographic module and has no certificate of its own. See our FIPS 140-3 support page.
Do you meet the CJIS FIPS 140-3 encryption requirement?
Not for your whole environment, but Lavawall's remote sessions use validated modules. CJIS control SC-13 requires criminal justice information in transit to be protected by FIPS 140-3 validated cryptographic modules, and much of the infrastructure carrying that data is outside Lavawall. Remote sessions are protected by FIPS 140-3 validated cryptography in the relay and the Windows and Mac agents (Go Cryptographic Module, CMVP certificate #5247), with end-to-end encryption in which the relay holds no session key. Technicians can also sign in with YubiKey 5 FIPS (CMVP #5291), and the console can require validated login keys.
How are passwords stored?
User account passwords are salted and hashed, never stored in plain text. For the client secrets Lavawall manages for you, we use zero-knowledge encryption keyed so that only your tenant can unlock them.
Do you sell or share our data?
No. We do not sell your data or share it with advertisers. Data is used only to provide the service to you and your tenants. Outbound reputation lookups (for phishing and threat analysis) can be disabled per tenant if your policy requires it.
How long is data retained, and can we have it deleted?
Reports and evidence are retained for as long as your Lavawall® tenant is active. You can request deletion of specific records, of all records for a user (for example to satisfy a GDPR/PIPEDA right-to-erasure request), or of your tenant, through the console or by contacting support.
Are you GDPR and PIPEDA compliant?
Yes. Lavawall is built by a CISSP/CISA firm and operated with Canadian (PIPEDA) and EU (GDPR) privacy obligations in mind. Security-related processing (such as reputation lookups) relies on the GDPR Article 6(1)(f) legitimate-interest basis for network and information security, and can be turned off per tenant.
Can Lavawall help us pass a SOC 2, ISO 27001, or PCI audit?
Lavawall's GRC engine maps your live posture to those frameworks and collects timestamped evidence continuously, and ThreeShield's CISSP/CISA team can run the assessment with you. A SOC 2 report itself is issued only by a licensed CPA firm; Lavawall gets you audit-ready and works alongside your auditor.
How do we report a security vulnerability (bug bounty / responsible disclosure)?
We welcome responsible disclosure. Email the security team via the contact page with details and steps to reproduce, and we will acknowledge and work the issue. Please do not publicly disclose before we have had a chance to remediate.

Getting started & general

Is Lavawall an RMM?
Yes. Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams. One agent and one console cover monitoring, patching for more than 7,400 applications, scripting, browser-based remote support, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance evidence.
Is Lavawall a Datto RMM component?
No. Lavawall is its own RMM, made by ThreeShield Information Security Corporation in Canada. It has a ready-made Datto RMM component that installs the Lavawall agent on the computers Datto RMM already manages, and it installs through NinjaOne, ConnectWise, Kaseya VSA, Intune, or any tool that runs a script. Many teams start that way, use the Lavawall features they need first, and move remote support, patching, and scripts over when they are ready.
Can Lavawall replace Datto RMM or NinjaOne?
Yes, for most MSPs and IT teams. Lavawall covers remote support, patching, scripting, and monitoring itself, on the same agent as its security monitoring, breach detection, and compliance. You don't have to switch overnight: both agents can run side by side while you move over, and every module you add replaces a tool, saves your team time, and makes your clients more secure.
Does Lavawall support Linux?
Yes, for patching, monitoring, and scripts. Lavawall patches, monitors, and runs scripts on Linux. Remote control and the interactive remote shell cover Windows and Mac.
Does Lavawall have a free tier?
Yes. Two domains can be scanned free, forever, via Scout (the included external attack-surface scanner). Lavawall also offers a 14-day free trial of the full platform with no credit card required.
Can I buy just one module?
Yes. That's the intended way to start. Most teams land with the module that solves this month's problem (phishing reporting, SharePoint monitoring, M365 breach detection) and expand later. Pricing is month-to-month, with no high-water-mark billing and no minimum for single modules.
What happens when I need a human expert?
Every Lavawall customer can escalate to ThreeShield, the CISSP/CISA-certified audit and incident-response team that builds Lavawall. Tier 3 help without hiring a security department.
Is this really one agent and one console?
Yes. Remote support, patching, scripting, detection, configuration backup, file integrity monitoring, compliance evidence, administrator elevation, and helpdesk all run through a single Lavawall agent and a single multi-tenant console, so there is no stitching together five vendors.
Do I have to buy everything at once?
No. Modules are available a-la-carte as Individual Services or bundled in a plan. Start with what hurts most today and add the rest when you're ready. See the pricing page for the current breakdown.
Who is it built for?
MSPs and lean internal IT teams. Lavawall was built by an MSP for its own use and hardened by ThreeShield, a CISSP/CISA audit firm, so the multi-tenant, white-label, and margin realities of an MSP are designed in, and a single internal IT team gets the same power without the overhead.

Pricing & licensing

Is Lavawall really month-to-month?
Yes. No long-term contracts, no minimum term, and no high-water-mark billing: you're never charged for a peak device count from three months ago. Costs go down when you shrink as well as up when you grow.
Do I have to buy a plan, or can I buy just one module?
Either. Pick a tier (Grow, Professional, Complete) for a bundled platform, or buy any single module as an Individual Service with no plan and no platform commitment. Internal IT teams often start with one module; MSPs usually pick a tier per client.
What's the difference for internal IT vs an MSP?
The platform is identical. MSPs get multi-tenant management, white-label options, and per-client billing; internal IT teams just manage one organization. Both pay the same transparent per-unit rates.
CAD or USD?
Both. Toggle the currency at the top of the page. Prices are billed in your selected currency. Canadian customers can pay in Canadian dollars by Interac, Canadian pre-authorized debit, or Canadian credit card.

Compliance & GRC

Which frameworks are supported?
70+, including CIS Controls v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta/BC health & privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight.
Can Lavawall issue our SOC 2 report?
No. Only a licensed CPA firm can, and Lavawall/ThreeShield is not one. Lavawall gets you audit-ready fast (control mapping, policies, continuous evidence) and works alongside your CPA auditor.
Do you include PCI ASV scanning?
Yes. Integrated Clone Systems PCI ASV scanning is included, with missed-scan notifications and inclusion in reports.
Which frameworks does Lavawall cover?
70+, including CIS Controls v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta and BC health/privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight. One control you turn on usually satisfies requirements across several at once.
Can Lavawall issue our SOC 2 report?
No. A SOC 2 report can only be issued by a licensed CPA firm, and Lavawall (and ThreeShield) is not a CPA firm. What we do is get you audit-ready fast: map and operationalize the controls, collect the evidence continuously, and prepare you so the CPA firm's examination is quick and predictable.
How fast is 'fast'?
Days to a few weeks, for most teams. Because Lavawall maps the controls you already have and generates the policies and evidence automatically, most teams move from 'the auditor is asking' to a defensible, documented posture in that time, instead of the quarters a from-scratch, consultant-led project usually takes.

Breach & threat detection

What exactly does Lavawall watch in Microsoft 365?
Risky and impossible-travel sign-ins, newly consented OAuth apps, MFA method changes, mailbox and inbox-rule creation, licence and mailbox health, and tenant-level configuration changes (policy edits, role assignments, app registrations, and conditional-access changes), each logged with who/what/when.
Does it cover Google Workspace too?
Yes. The same tenant-level monitoring covers Google Workspace alongside Microsoft 365, so mixed environments are watched from one console.
How is this different from Microsoft's own alerts?
Microsoft surfaces raw signals in several portals. Lavawall correlates them across identity, mailbox, and configuration, prioritizes what matters, and escalates to ThreeShield's CISSP/CISA team when something needs a human.
What does Lavawall monitor in Google Workspace?
Risky sign-ins, OAuth app grants, sharing and permission changes, admin and directory edits, and mailbox/licence health: the same tenant-level depth it gives Microsoft 365.
Can I watch both Google and Microsoft from one place?
Yes. Mixed environments are monitored side by side in one console, with unified alerting.
Does it back up Google Workspace too?
Yes. Separate Google Workspace backup (Gmail, Drive, Shared Drives, Calendar) and configuration backup are available as modules.
Does Lavawall replace Sophos or Huntress?
No. It unifies them. Lavawall sits above your MDR tools, pulls their signals together with its own Microsoft 365, endpoint, and network detections, and gives you one prioritized feed across every tenant. Keep the MDR you like; stop living in five consoles.
How does it catch what slips between consoles?
The dangerous incidents are the ones that look minor in each tool alone: a Defender low-severity alert plus a risky M365 sign-in plus a new admin. Lavawall correlates across sources and tenants, so a pattern that no single console flags becomes one clear alert.
We're an MSP with dozens of tenants. Does this scale?
Yes. That's exactly who it's built for. Lavawall was built inside an MSP practice: every tenant in one multi-tenant console, unified alerting, and white-label options for what your clients see.
How is this different from our antivirus or EDR?
Antivirus, EDR, and breach-detection tools mostly check for known executables and behaviour while ransomware is actively running. The Ransomware Hunter does an in-depth look for the pre-warning signs they skip (ransom notes, exfiltration tools, remote-access tools, and living-off-the-land activity), so you catch a dormant or missed instance before it detonates again.
How long does a scan take?
Typically 5–15 minutes per computer to run and update the summary. It also runs automatically as part of Lavawall's monthly health scans.
What does it look for?
Ransom notes (originally focused on Akira, now covering the most common variants), data-exfiltration tools used in hybrid attacks, installed remote-access tools, and suspicious living-off-the-land processes. Unfamiliar tool? Click the question mark in the listing header for a plain explanation, or chat with a Level 3 expert.
Which operating systems are covered?
Windows, macOS, and Linux, including many Linux distribution families. Mac has almost as many security-relevant configurations as Windows, and Lavawall assesses all three from one console.
What is configuration drift and why does it matter?
Configuration drift is when a machine's settings quietly move away from a secure baseline: a hardening toggle flipped, a service re-enabled, or encryption turned off. It rarely triggers an alert on its own, which is exactly why attackers rely on it. Lavawall notifies you automatically whenever a configuration gets less secure.
Do I have to check every machine manually?
No. You get a per-computer deep dive plus a fleet-wide summary, and automatic notifications when something regresses, so you act on the change instead of hunting for it.

Data, files & identity monitoring

How is configuration backup different from mailbox or file backup?
Mailbox and file backup (Dropsuite, SkyKick, Veeam) capture user data. Configuration backup captures tenant settings (Conditional Access policies, role assignments, app registrations, OAuth grants, Intune profiles, transport rules, NSG rules, and Key Vault access), so changes can be detected, logged, and reverted. Different layer, different threat model.
Why isn't Microsoft's own audit log enough?
Because Microsoft's audit log records that a change happened but not the previous value, and how long it keeps entries depends on your plan (check Microsoft's documentation for yours). Lavawall snapshots the actual object state, computes a diff against the previous snapshot, and provides rollback. Every change is correlated with who made it, when, and from where.
Is rollback safe to run against production?
It is built to be. Rollback is a write against a live tenant, so it's deliberately not a one-click button an operator can fire by accident. It's a plan → approve → execute workflow with a dry-run mode that previews every API call before anything changes.
What file activity does Lavawall track?
Opens, edits, downloads, shares (including external), permission changes, and deletions across SharePoint and OneDrive, attributed to the user, with timestamps.
Can it catch an employee taking files before they leave?
Yes. Mass downloads and external shares over the last 60 days are visible, so you can preserve evidence before an account is disabled.
Does it cover on-prem file servers and Google Drive too?
Yes. On-premises file-change monitoring and Google Drive monitoring are available alongside SharePoint.
What does on-prem file monitoring watch?
File create, change, access, and delete events on monitored Windows servers and shares, attributed and timestamped, so both insider access and ransomware-style mass encryption are visible.
How is it licensed?
Per on-premises server. File access tracking across monitored servers and tenants is included in higher tiers or available a la carte.
Does it help detect ransomware?
Yes. The rapid, wide file-change pattern that ransomware creates on a share is exactly the kind of anomaly this surfaces, alongside the Akira Ransomware Hunter.
What does an access review actually produce?
A structured, timestamped record of who has access to what across SharePoint, Teams, and Entra; the decisions your approvers made (keep, remove, escalate); and the evidence to prove the review happened. That is exactly what a SOC 2, HIPAA, or NIST auditor asks for.
Does it catch orphaned and over-privileged accounts?
Yes. Reviews surface dormant accounts, accounts that outlived a role change, and entitlements that drifted beyond least privilege, so the recertification is a real cleanup with an audit trail instead of a rubber stamp.
Is it gated by subscription?
Yes. Access Review is enabled per company in billing. When it isn't turned on for a tenant, the figures may be empty or stale until it's added to that company's subscription, so what you see always reflects what you're actually paying for.
How does Lavawall discover SaaS use without an agent on every browser?
It reviews email metadata against a carefully curated list of 1,277 known SaaS applications. That approach limits false positives and tells you exactly who uses a service as well as how many, without scraping browsing history.
Why is my firewall's app list not enough?
A firewall shows thousands of different applications your users might be touching, with no sense of which ones hold company data or who actually signed up. That noise makes real governance impossible. Lavawall turns it into a named, prioritized picture.
Does this help with rogue AI and shadow IT?
Yes. Unsanctioned AI tools and shadow SaaS are exactly what the discovery surfaces: which services are in use, and by whom, so you can sanction, block, or bring them under governance.
How does Lavawall find shadow IT without an agent on every SaaS app?
It doesn't need one. Lavawall reads Microsoft 365 email and sign-up metadata and other signals (the welcome emails, OAuth grants, and login patterns that every new SaaS tool leaves behind) to surface what people are actually using, including tools no agent could see.
Does it catch shadow AI specifically?
Yes. The same discovery flags AI and LLM tools your staff have signed up for, so you can decide what's sanctioned before sensitive data walks into an unvetted model.
What can I do once I can see it?
Mark tools as official or unsanctioned, see who signed up for what, and get notified when someone adopts a new tool behind your back, so shadow IT becomes a managed list instead of a blind spot.
Does Lavawall include administrator elevation?
Yes, for Windows. Administrator elevation gives just-in-time admin rights with certificate-based rules and ringfencing, so people run what they need without a standing local-admin account. Execution prevention blocks named high-risk tools, and it is rolled out in audit mode first.
Do you install a kernel driver?
No. Lavawall installs no kernel driver. The agent works with Windows' own security controls instead of re-implementing them in kernel space. That means fewer crashes, faster boot and install, and a clean uninstall.
What happens when the endpoint is offline?
The computer keeps applying the signed rule set it already has, and decisions are logged and reach your console when the connection comes back. When a request needs a person and the computer is offline, a technician can approve it with a one-time code.
How is this different from ThreatLocker or AutoElevate?
It is administrator elevation built into the Lavawall agent, with no kernel driver and no separate enrolment code. You remove local admin rights, approve specific programs by certificate, thumbprint, hash, or path, ringfence what they can do, and add execution prevention for high-risk tools, rolled out in audit mode first. For how ThreatLocker and AutoElevate work, check their documentation.

Email, phishing & DMARC

Do users need a separate login or OAuth consent?
No. The add-in identifies the user automatically from the Outlook mailbox it runs in, the same identity Microsoft 365 has already authenticated. There are no extra sign-in screens, no consent dialogs asking for mailbox access, and no third-party OAuth grants.
Which Outlook clients are supported?
Classic Outlook, new Outlook, Outlook on the web, Outlook for Mac, and Outlook for iOS and Android. On mobile, some message headers aren't exposed to add-ins, so instead of pretending the SPF/DKIM/DMARC checks ran, the Reporter shows an honest 'headers unavailable on this device' notice and points to Outlook on the web or desktop, while sender, link, attachment, impersonation, and simulation checks still run.
What makes this valuable to my customers, not just my analysts?
When a legitimate sender fails DMARC alignment, the taskpane flags it and explains what's wrong with that sender's setup and gives the exact DNS records to fix it (Mailchimp, SendGrid, Amazon SES, HubSpot, and more), with a one-click link to Lavawall's free DMARC tool to confirm the fix. The expert advice appears right inside the add-in your customer already trusts, from your MSP.
Our KnowBe4 (or other) phishing simulations flood the help desk with reported emails. Does Lavawall handle that?
Yes. This is the core of it. Lavawall recognizes simulated-phishing traffic and credits the user for reporting it without ever creating a help-desk ticket. Your simulation program keeps running and users still get the 'good catch' reinforcement, but your techs stop triaging hundreds of fake emails a month.
How does a user find out if a reported email was dangerous?
Instantly. When someone reports an email with the Outlook or webmail plugin, Lavawall analyzes it (unwrapping links your gateway rewrote and deep-scanning PDFs and attachments) and tells the user right away whether it was safe, suspicious, or malicious. Most reports resolve themselves without a tech ever touching them.
What still reaches my team?
Only what should: genuinely suspicious or malicious mail, auto-triaged and prioritized, with the analysis already done. And you get visibility into who is actively engaged with email security and who needs a nudge.
Will this overwrite my existing DMARC record?
No. Lavawall reads your live DNS and does a non-destructive merge: it preserves existing third-party report addresses (Cloudflare and others) while adding its own rua receiver, then generates the exact _dmarc TXT record with a copy-to-clipboard hostname and value.
How do I move to enforcement safely?
One-click graduation from p=none to quarantine to reject, with safe percentage stepping. Live-DNS drift detection tells you if a record changes out from under you, and a per-source analyst workflow (authorized, phishing, suspicious, ignore) keeps an audit trail of every decision.
Does it find my sending domains for me?
Yes. It automatically discovers sending domains from connected Microsoft 365, Google Workspace, and Scout, and shows per-domain SPF and DMARC pass-rates from live DNS lookups. It's multi-tenant, built for MSPs managing many domains at once.
Why is our email going to junk when nothing changed on our end?
Usually because SPF, DKIM, or DMARC drifted: a new sending service was added, a record hit its lookup limit, or DMARC is set to 'none' so mailbox providers don't trust you. Gmail and Yahoo tightened their rules, so 'it used to work' isn't enough anymore. Lavawall shows you exactly which records are failing and why.
Isn't DMARC risky? I've heard it can block our own mail.
It can, if you jump to enforcement blind. Lavawall monitors your real mail streams first, shows you every legitimate sender, and helps you fix SPF/DKIM for each before you move the policy to quarantine or reject. You reach enforcement without blocking your own invoices.
Will this show spoofing of our domain?
Yes. DMARC reporting reveals who is sending email as your domain, including attackers spoofing you to phish your clients, so you can shut it down and protect your brand.

Endpoints, patching & network

How does Lavawall know a computer is slow before the user complains?
Lavawall reads each machine's real health signals continuously and scores them: CPU and memory pressure, runaway processes, disk space and disk health, thermals, and system event errors. When a device trends toward trouble it surfaces on your replacement-priority list before it turns into a ticket.
Does this replace my RMM?
Yes, for most teams. The same agent that reports health also patches more than 7,400 applications, runs remote support and scripts, and feeds compliance, so many teams retire a separate RMM. Both can run side by side while you move over, and it is month-to-month, with no minimum for single modules.
How is the replacement priority calculated?
Lavawall combines performance headroom, battery and disk wear, age, and error frequency into a ranked list, so budget goes to the machines that will fail or frustrate first, not whoever complains loudest.
What can Lavawall see on the network?
Lavawall discovers and watches what's on your LAN and reaches across the WAN to remote and home-based devices. It watches for new or unknown devices and risky exposure, and tracks the everyday health of printers, NAS, and endpoints. Breaches and breakdowns both surface in one place.
Does it cover people working from home?
Yes. Coverage follows the device, not the office network, so a compromised laptop on a home Wi-Fi is watched the same as one at HQ, and you're alerted whether it's a security event or just a failing drive.
Is this only for security, or day-to-day IT too?
Both. The same visibility that catches a quiet breach also catches the low-toner printer, the offline NAS, and the device nobody told you about, so you fix small frustrations before they become tickets.
Is it really free, and do I need an account?
Yes. It's genuinely free. Enter your email on the download page and we'll send you the download link for the Windows utility. You need no Lavawall account, no credit card, and no trial to cancel.
What does it actually do?
It's a small Windows tool that alerts you the moment a program or browser tab activates the camera, microphone, or speakers, so a background tab that's quietly listening, or malware using the webcam, has nowhere to hide.
Why does this matter?
Forgotten meeting tabs, sketchy extensions, and malware can silently hold the mic or camera. For clinics, law firms, and anyone handling sensitive conversations, knowing what has access is a real privacy and compliance safeguard.

Remote support & helpdesk

How is this different from the remote control in my RMM?
Lavawall is itself an RMM, and it puts a full workspace on one screen: the session, live health (CPU, RAM, disk, temperature, patch status), an Admin Workspace that works without interrupting the user, 50 Windows admin tools each one click away with administrator rights, direct script execution, elevated CMD/PowerShell, file transfer, and ticket and time entry, so a tech rarely needs to leave the window.
Is it safe? We've been burned by remote tools before.
Yes. It is built security-first: remote support is built into Lavawall, so there is no separate remote tool such as ScreenConnect, Splashtop, or TeamViewer to patch and secure; endpoints are never broadcast or directly exposed; IP and country restrictions (country limits on by default); certificate verification for server and clients; authentication-strength rules; and session logging, where every connection and every command sent is logged, and screen captures can be attached to the ticket when the technician wants a record.
Can Lavawall support a computer that doesn't have the agent installed?
Yes. Ad-hoc support lets a technician help someone on a computer that doesn't have the Lavawall agent installed, such as a new client's machine or a one-off request.
Can a technician fix a computer without interrupting the user?
Yes. The Admin Workspace is a private workspace where the technician works with administrator rights while the user keeps working undisturbed. On Windows it has 19 tools plus PowerShell as system, PowerShell as the logged-in user, and Command Prompt as system, and the technician can upload files of up to 2 GB each. On Mac, it gives the technician a root zsh shell.
Can Lavawall run commands as the logged-in user?
Yes, on Windows. PowerShell as the logged-in user runs in their own profile and environment, without appearing on their screen. PowerShell and Command Prompt with system rights are there too, and Mac gets a root zsh shell.
Does Lavawall work from a phone?
Yes. Remote control runs in any modern browser, including phones and tablets, with an on-screen keyboard, Ctrl, Alt, Tab, and Esc keys, Bluetooth keyboard support, and fast full-colour PowerShell. Push notifications reach the technician's phone for requests that need a decision.
How hard is it to set up?
It's a drop-in embed. In the console, open Embed & Branding in the left menu, scroll to Chat Widget Settings, brand it, and paste the snippet onto your site. The same widget powers chat on Lavawall's own pages.
What does the knowledge base do?
As you or a website visitor types, relevant knowledge-base articles surface instantly, so common questions get answered before they ever become a ticket, and your techs aren't retyping the same reply.
Is it really free?
Yes. Smart Web Chat is included with Lavawall. It's a simple, brandable chat with emoji support and built-in KB suggestions, and it needs no separate live-chat subscription.

For MSPs & partners

Why should I trust a tool built by another MSP?
Because it was built to solve our own problems first. After a missing Plex Media Server patch played a part in the LastPass breach, we built monitoring for it into Lavawall instead of waiting for someone else to. We've committed not to become the vendors MSPs resent: no surprise lock-in, no games.
How does Lavawall help me grow, not just monitor?
Three ways: acquire clients (white-label scanner, branded reports, a public MSP directory that sends interested companies to you), retain and grow them (deeper coverage and compliance evidence that make you stickier), and lower your marginal cost to serve so each new client is more profitable than the last.
Is it multi-tenant and white-label?
Yes. Multi-tenant remote support, per-tenant user management, and a white-label domain scanner and reports are core, so your brand stays front and centre across every client.
Is this a full CRM or a light add-on?
It's a working CRM and help desk: contacts, a deal pipeline with stages and close dates, prospect-vs-client classification, company scoring, industry classification, duplicate detection and merge, and activity tracking, built into the same console as your security and monitoring data.
How do leads get in?
Scanner prospects flow straight in: run a white-label domain scan at an event or on your site, and the company lands in the CRM as a scored prospect you can work. You can also add contacts manually and enrich or classify them in bulk.
Why keep CRM and security in one tool?
Because your best sales signal is the security posture you can already see. When the scan shows a prospect's exposed configuration, the CRM is right there to turn that finding into a conversation and a deal, with no export and no second login.
How does Lavawall deal registration work?
Register an opportunity through your partner contact and it's protected: we won't quote, sell, or negotiate with that client directly, and any inbound interest from them routes back to you. Registration is confirmed in writing so there's never ambiguity about whose deal it is.
Can I white-label Lavawall?
Yes. MSP partners can embed a white-label version of the Lavawall scanner on their own site, present findings under their own brand, and manage all client tenants from one multi-tenant console. Your clients see you, not us.
Does Lavawall compete with its partners for end clients?
No. Lavawall grew out of an MSP practice that watched vendors poach clients firsthand, so the rule is written down: we never go around a partner to their client, we sell direct only where no partner is engaged, and we pay referral fees when a direct lead belongs in a partner's territory.
How do I embed the scanner on my site?
In the console, open Embed Scanner under the You menu at the bottom of the left sidebar. Fill in your white-label details (phone number, URLs), then copy the head snippet into your page's <head> and the body snippet into the <body>. Clicking each red code block auto-selects it for copy-paste.
Whose brand shows on the results?
Yours. The white-label information you enter (your phone number and URLs) appears on the results page, so the scan looks and feels like your own tool, not a third party's.
What is it actually for?
Proving value and capturing leads. You're at a networking event, or a prospect is on your site: run a scan, show them real findings about their own domain, and collect their contact information right away.

Still have a question? Talk to a real security person same or next business day.

Datto and Datto RMM are trademarks of Kaseya. NinjaOne is a trademark of NinjaOne, LLC. Lavawall is not affiliated with either.