Answers
Lavawall® FAQ
Security, privacy, pricing, compliance, and every module, the questions teams and MSPs ask us most. Jump to a section or search the page.
Security & privacy
Where is our data stored, and in what country?
Your Lavawall® console and its data are hosted in Canada. Telemetry, reports, and evidence are stored against your own tenant and are not comingled with other customers' data.
Is our data encrypted?
Yes. Data is encrypted in transit (TLS) and at rest. Where Lavawall stores sensitive client credentials on your behalf, it uses zero-knowledge encryption so the secrets are not readable by us.
How are passwords stored?
User account passwords are salted and hashed, never stored in plain text. For the client secrets Lavawall manages for you, we use zero-knowledge encryption keyed so that only your tenant can unlock them.
Do you sell or share our data?
No. We do not sell your data or share it with advertisers. Data is used only to provide the service to you and your tenants. Outbound reputation lookups (for phishing and threat analysis) can be disabled per tenant if your policy requires it.
How long is data retained, and can we have it deleted?
Reports and evidence are retained for as long as your Lavawall® tenant is active. You can request deletion of specific records, of all records for a user (for example to satisfy a GDPR/PIPEDA right-to-erasure request), or of your tenant, through the console or by contacting support.
Are you GDPR and PIPEDA compliant?
Yes. Lavawall is built by a CISSP/CISA firm and operated with Canadian (PIPEDA) and EU (GDPR) privacy obligations in mind. Security-related processing (such as reputation lookups) relies on the GDPR Article 6(1)(f) legitimate-interest basis for network and information security, and can be turned off per tenant.
Can Lavawall help us pass a SOC 2, ISO 27001, or PCI audit?
Lavawall's GRC engine maps your live posture to those frameworks and collects timestamped evidence continuously, and ThreeShield's CISSP/CISA team can run the assessment with you. A SOC 2 report itself is issued only by a licensed CPA firm; Lavawall gets you audit-ready and works alongside your auditor.
How do we report a security vulnerability (bug bounty / responsible disclosure)?
We welcome responsible disclosure. Email the security team via the contact page with details and steps to reproduce, and we will acknowledge and work the issue. Please do not publicly disclose before we have had a chance to remediate.
Getting started & general
Does Lavawall replace my RMM?
Yes, and most teams are surprised by how much better it is. Lavawall's own RMM patches more third-party applications than the mainstream tools, and its remote support is a real step up: full backstage access to fix a machine without interrupting the user, plus interactive screen sharing, both showing far more live detail and one-click automated actions than a typical RMM's bolt-on remote control. You don't have to switch overnight; start with one module alongside NinjaOne, Datto, Atera, ConnectWise Automate, N-able, Kaseya or Syncro and migrate gradually. Every module you add replaces a tool, saves your team time, and makes your clients more secure, because Lavawall also adds the security, GRC, breach-detection, and analytics layer legacy RMMs were never designed for.
Does Lavawall have a free tier?
Yes. Two domains can be scanned free, forever, via Scout (the included external attack-surface scanner). Lavawall also offers a 14-day free trial of the full platform with no credit card required.
Can I buy just one module?
Yes, that's the intended way to start. Most teams land with the module that solves this month's problem (phishing reporting, SharePoint monitoring, M365 breach detection) and expand later. Pricing is month-to-month with no minimums and no high-water-mark billing.
What happens when I need a human expert?
Every Lavawall customer can escalate to ThreeShield, the CISSP/CISA-certified audit and incident-response team that builds Lavawall. Tier 3 help without hiring a security department.
Is this really one agent and one console?
Yes. Patching, detection, configuration backup, file integrity monitoring, compliance evidence, application control, helpdesk, and remote support all run through a single Lavawall agent and a single multi-tenant console, no stitching together five vendors.
Do I have to buy everything at once?
No. Modules are available a-la-carte as Individual Services or bundled in a plan. Start with what hurts most today and add the rest when you're ready, see the pricing page for the current breakdown.
Who is it built for?
MSPs and lean internal IT teams. Lavawall was built by an MSP for its own use and hardened by ThreeShield, a CISSP/CISA audit firm, so the multi-tenant, white-label, and margin realities of an MSP are designed in, and a single internal IT team gets the same power without the overhead.
Pricing & licensing
Is Lavawall really month-to-month?
Yes. No long-term contracts, no minimums, and no high-water-mark billing, you're never charged for a peak device count from three months ago. Costs go down as you shrink, not just up as you grow.
Do I have to buy a plan, or can I buy just one module?
Either. Pick a tier (Grow, Professional, Complete) for a bundled platform, or buy any single module as an Individual Service with no plan and no platform commitment. Internal IT teams often start with one module; MSPs usually pick a tier per client.
What's the difference for internal IT vs an MSP?
The platform is identical. MSPs get multi-tenant management, white-label options, and per-client billing; internal IT teams just manage one organization. Both pay the same transparent per-unit rates.
CAD or USD?
Both. Toggle the currency at the top of the page. Prices are billed in your selected currency.
Compliance & GRC
Which frameworks are supported?
54, including CIS Controls v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta/BC health & privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight.
Can Lavawall issue our SOC 2 report?
No, only a licensed CPA firm can, and Lavawall/ThreeShield is not one. Lavawall gets you audit-ready fast (control mapping, policies, continuous evidence) and works alongside your CPA auditor.
Do you include PCI ASV scanning?
Yes, integrated Clone Systems PCI ASV scanning with missed-scan notifications and inclusion in reports.
Which frameworks does Lavawall cover?
50+, including CIS Controls v8.1, NIST CSF 2.0, NIST 800-171, SOC 2, HIPAA, PCI DSS (all SAQs), ISO 27001:2022, CMMC 2.0, Canada's CPCSC, PIPEDA, Alberta and BC health/privacy acts, Quebec Law 25, CPA Canada, OSFI, IIROC/CIRO, EU GDPR/NIS2/DORA, UK Cyber Essentials, and Australia's Essential Eight. One control you turn on usually satisfies requirements across several at once.
Can Lavawall issue our SOC 2 report?
No, a SOC 2 report can only be issued by a licensed CPA firm, and Lavawall (and ThreeShield) is not a CPA firm. What we do is get you audit-ready fast: map and operationalize the controls, collect the evidence continuously, and prepare you so the CPA firm's examination is quick and predictable.
How fast is 'fast'?
Because Lavawall maps the controls you already have and generates the policies and evidence automatically, most teams move from 'the auditor is asking' to a defensible, documented posture in days to a few weeks, not the quarters a from-scratch, consultant-led project usually takes.
Breach & threat detection
What exactly does Lavawall watch in Microsoft 365?
Risky and impossible-travel sign-ins, newly consented OAuth apps, MFA method changes, mailbox and inbox-rule creation, license and mailbox health, and tenant-level configuration changes, policy edits, role assignments, app registrations, and conditional-access changes, each logged with who/what/when.
Does it cover Google Workspace too?
Yes, the same tenant-level monitoring covers Google Workspace alongside Microsoft 365, so mixed environments are watched from one console.
How is this different from Microsoft's own alerts?
Microsoft surfaces raw signals in several portals. Lavawall correlates them across identity, mailbox, and configuration, prioritizes what matters, and escalates to ThreeShield's CISSP/CISA team when something needs a human.
What does Lavawall monitor in Google Workspace?
Risky sign-ins, OAuth app grants, sharing and permission changes, admin and directory edits, and mailbox/license health, the same tenant-level depth it gives Microsoft 365.
Can I watch both Google and Microsoft from one place?
Yes. Mixed environments are monitored side by side in one console, with unified alerting.
Does it back up Google Workspace too?
Yes, separate Google Workspace backup (Gmail, Drive, Shared Drives, Calendar) and configuration backup are available as modules.
Does Lavawall replace Sophos or Huntress?
No, it unifies them. Lavawall sits above your MDR tools, pulls their signals together with its own Microsoft 365, endpoint, and network detections, and gives you one prioritized feed across every tenant. Keep the MDR you like; stop living in five consoles.
How does it catch what slips between consoles?
The dangerous incidents are the ones that look minor in each tool alone, a Defender low-severity alert plus a risky M365 sign-in plus a new admin. Lavawall correlates across sources and tenants, so a pattern that no single console flags becomes one clear alert.
We're an MSP with dozens of tenants. Does this scale?
That's exactly who it's built for. Lavawall was built inside an MSP practice, every tenant, one multi-tenant console, unified alerting, and white-label options for what your clients see.
How is this different from our antivirus or EDR?
Antivirus, EDR, and breach-detection tools mostly check for known executables and behaviour while ransomware is actively running. The Ransomware Hunter does an in-depth look for the pre-warning signs they skip, ransom notes, exfiltration tools, remote-access tools, and living-off-the-land activity, so you catch a dormant or missed instance before it detonates again.
How long does a scan take?
Typically 5–15 minutes per computer to run and update the summary. It also runs automatically as part of Lavawall's monthly health scans.
What does it look for?
Ransom notes (originally focused on Akira, now covering the most common variants), data-exfiltration tools used in hybrid attacks, installed remote-access tools, and suspicious living-off-the-land processes. Unfamiliar tool? Click the question mark in the listing header for a plain explanation, or chat with a Level 3 expert.
Which operating systems are covered?
Windows, macOS, and Linux, including many Linux distribution families. Mac has almost as many security-relevant configurations as Windows, and Lavawall assesses all three from one console.
What is configuration drift and why does it matter?
Drift is when a machine's settings quietly move away from a secure baseline, a hardening toggle flipped, a service re-enabled, encryption turned off. It rarely triggers an alert on its own, which is exactly why attackers rely on it. Lavawall notifies you automatically whenever a configuration gets less secure.
Do I have to check every machine manually?
No. You get a per-computer deep dive plus a fleet-wide summary, and automatic notifications when something regresses, so you act on the change instead of hunting for it.
Data, files & identity monitoring
How is configuration backup different from mailbox or file backup?
Mailbox and file backup (Dropsuite, SkyKick, Veeam) capture user data. Configuration backup captures tenant settings, Conditional Access policies, role assignments, app registrations, OAuth grants, Intune profiles, transport rules, NSG rules, Key Vault access, so changes can be detected, logged, and reverted. Different layer, different threat model.
Why isn't Microsoft's own audit log enough?
Microsoft audit retention is 30 days at most on default plans, and it records that a change happened, not the previous value, and with no one-click undo. Lavawall snapshots the actual object state, computes a diff against the previous snapshot, and provides rollback, correlating every change with who made it, when, and from where.
Is rollback safe to run against production?
Rollback is a write against a live tenant, so it's deliberately not a one-click button an operator can fire by accident. It's a plan → approve → execute workflow with a dry-run mode that previews every API call before anything changes.
What file activity does Lavawall track?
Opens, edits, downloads, shares (including external), permission changes, and deletions across SharePoint and OneDrive, attributed to the user, with timestamps.
Can it catch an employee taking files before they leave?
Yes. Mass downloads and external shares over the last 60 days are visible, so you can preserve evidence before an account is disabled.
Does it cover on-prem file servers and Google Drive too?
Yes, on-premises file-change monitoring and Google Drive monitoring are available alongside SharePoint.
What does on-prem file monitoring watch?
File create, change, access, and delete events on monitored Windows servers and shares, attributed and timestamped, so both insider access and ransomware-style mass encryption are visible.
How is it licensed?
Per on-premises server. File access tracking across monitored servers and tenants is included in higher tiers or available a la carte.
Does it help detect ransomware?
Yes, the rapid, wide file-change pattern that ransomware creates on a share is exactly the kind of anomaly this surfaces, alongside the Akira Ransomware Hunter.
What does an access review actually produce?
A structured, timestamped record of who has access to what across SharePoint, Teams, and Entra, the decisions your approvers made (keep, remove, escalate), and the evidence to prove the review happened, exactly what a SOC 2, HIPAA, or NIST auditor asks for.
Does it catch orphaned and over-privileged accounts?
Yes. Reviews surface dormant accounts, accounts that outlived a role change, and entitlements that drifted beyond least privilege, so the recertification isn't a rubber stamp, it's a real cleanup with an audit trail.
Is it gated by subscription?
Access Review is enabled per company in billing. When it isn't turned on for a tenant, the figures may be empty or stale until it's added to that company's subscription, so what you see always reflects what you're actually paying for.
How does Lavawall discover SaaS use without an agent on every browser?
It reviews email metadata against a carefully curated list of over 1,130 known SaaS applications. That approach limits false positives and tells you not just how many people use a service, but exactly who, without scraping browsing history.
Why is my firewall's app list not enough?
A firewall shows thousands of different applications your users might be touching, with no sense of which ones hold company data or who actually signed up. That noise makes real governance impossible. Lavawall turns it into a named, prioritized picture.
Does this help with rogue AI and shadow IT?
Yes. Unsanctioned AI tools and shadow SaaS are exactly what the discovery surfaces, which services are in use, by whom, so you can sanction, block, or bring them under governance.
How does Lavawall find shadow IT without an agent on every SaaS app?
It doesn't need one. Lavawall reads Microsoft 365 email and sign-up metadata and other signals, the welcome emails, OAuth grants, and login patterns that every new SaaS tool leaves behind, to surface what people are actually using, including tools no agent could see.
Does it catch shadow AI specifically?
Yes. The same discovery flags AI and LLM tools your staff have signed up for, so you can decide what's sanctioned before sensitive data walks into an unvetted model.
What can I do once I can see it?
Mark tools as official or unsanctioned, see who signed up for what, and get notified when someone adopts a new tool behind your back, so shadow IT becomes a managed list instead of a blind spot.
Do you install a kernel driver?
No, never. The agent runs as LocalSystem and layers on top of Windows security primitives rather than re-implementing them in kernel space. That means fewer crashes, fewer signed-driver incidents, faster boot and install, and a clean uninstall.
What happens when the endpoint is offline?
Cached signed rule bundles keep making decisions for up to 24 hours by default (configurable). Decisions log locally and replay to your console when the connection comes back.
How is this different from ThreatLocker or AutoElevate?
Elevation, allowlisting, and ringfencing work together as one agent with no kernel driver. You remove local admin rights, approve specific binaries by signer/hash/path, and stop an elevated process from spawning child processes, all with sub-50ms cached decisions and a monitor-then-enforce rollout.
Email, phishing & DMARC
Do users need a separate login or OAuth consent?
No. The add-in identifies the user automatically from the Outlook mailbox it runs in, the same identity Microsoft 365 has already authenticated. No extra sign-in screens, no consent dialogs asking for mailbox access, no third-party OAuth grants.
Which Outlook clients are supported?
Classic Outlook, new Outlook, Outlook on the web, Outlook for Mac, and Outlook for iOS and Android. On mobile, some message headers aren't exposed to add-ins, so instead of pretending the SPF/DKIM/DMARC checks ran, the Reporter shows an honest 'headers unavailable on this device' notice and points to Outlook on the web or desktop, while sender, link, attachment, impersonation, and simulation checks still run.
What makes this valuable to my customers, not just my analysts?
When a legitimate sender fails DMARC alignment, the taskpane doesn't just flag it, it explains what's wrong with that sender's setup and gives the exact DNS records to fix it (Mailchimp, SendGrid, Amazon SES, HubSpot, and more), with a one-click link to Lavawall's free DMARC tool to confirm the fix. The expert advice appears right inside the add-in your customer already trusts, from your MSP.
Our KnowBe4 (or other) phishing simulations flood the help desk with reported emails. Does Lavawall handle that?
Yes, this is the core of it. Lavawall recognizes simulated-phishing traffic and credits the user for reporting it without ever creating a help-desk ticket. Your simulation program keeps running and users still get the 'good catch' reinforcement, but your techs stop triaging hundreds of fake emails a month.
How does a user find out if a reported email was dangerous?
Instantly. When someone reports an email with the Outlook or webmail plugin, Lavawall analyzes it, unwrapping links your gateway rewrote, deep-scanning PDFs and attachments, and tells the user right away whether it was safe, suspicious, or malicious. Most reports resolve themselves without a tech ever touching them.
What still reaches my team?
Only what should: genuinely suspicious or malicious mail, auto-triaged and prioritized, with the analysis already done. And you get visibility into who is actively engaged with email security and who needs a nudge.
Will this overwrite my existing DMARC record?
No. Lavawall reads your live DNS and does a non-destructive merge, it preserves existing third-party report addresses (Cloudflare and others) while adding its own rua receiver, then generates the exact _dmarc TXT record with a copy-to-clipboard hostname and value.
How do I move to enforcement safely?
One-click graduation from p=none to quarantine to reject, with safe percentage stepping. Live-DNS drift detection tells you if a record changes out from under you, and a per-source analyst workflow (authorized, phishing, suspicious, ignore) keeps an audit trail of every decision.
Does it find my sending domains for me?
Yes, it automatically discovers sending domains from connected Microsoft 365, Google Workspace, and Scout, and shows per-domain SPF and DMARC pass-rates from live DNS lookups. It's multi-tenant, built for MSPs managing many domains at once.
Why is our email going to junk when nothing changed on our end?
Usually SPF, DKIM, or DMARC drifted, a new sending service was added, a record hit its lookup limit, or DMARC is set to 'none' so mailbox providers don't trust you. Gmail and Yahoo tightened their rules, so 'it used to work' isn't enough anymore. Lavawall shows you exactly which records are failing and why.
Isn't DMARC risky? I've heard it can block our own mail.
It can, if you jump to enforcement blind. Lavawall monitors your real mail streams first, shows you every legitimate sender, and helps you fix SPF/DKIM for each before you move the policy to quarantine or reject. You reach enforcement without blocking your own invoices.
Will this show spoofing of our domain?
Yes. DMARC reporting reveals who is sending email as your domain, including attackers spoofing you to phish your clients, so you can shut it down and protect your brand.
Endpoints, patching & network
How does Lavawall know a computer is slow before the user complains?
Lavawall continuously reads each machine's real health signals, CPU and memory pressure, runaway processes, disk space and disk health, thermals, and system event errors, and scores them. When a device trends toward trouble it surfaces on your replacement-priority list before it turns into a ticket.
Does this replace my RMM?
It can. The same agent that reports health also patches 7,300+ applications, runs remote support, and feeds compliance, so many teams retire a separate RMM. Or run it alongside what you have; it is month-to-month with no minimums.
How is the replacement priority calculated?
Lavawall combines performance headroom, battery and disk wear, age, and error frequency into a ranked list, so budget goes to the machines that will fail or frustrate first, not whoever complains loudest.
What can Lavawall see on the network?
Lavawall discovers and watches what's on your LAN and reaches across the WAN to remote and home-based devices, new or unknown devices, risky exposure, and the everyday health of printers, NAS, and endpoints. Breaches and breakdowns both surface in one place.
Does it cover people working from home?
Yes. Coverage follows the device, not the office network, so a compromised laptop on a home Wi-Fi is watched the same as one at HQ, and you're alerted whether it's a security event or just a failing drive.
Is this only for security, or day-to-day IT too?
Both. The same visibility that catches a quiet breach also catches the low-toner printer, the offline NAS, and the device nobody told you about, so you fix small frustrations before they become tickets.
Is it really free, and do I need an account?
Yes, it's genuinely free. Enter your email on the download page and we'll send you the download link for the Windows utility, no Lavawall account, no credit card, no trial to cancel.
What does it actually do?
It's a small Windows tool that alerts you the moment a program or browser tab activates the camera, microphone, or speakers, so a background tab that's quietly listening, or malware using the webcam, has nowhere to hide.
Why does this matter?
Forgotten meeting tabs, sketchy extensions, and malware can silently hold the mic or camera. For clinics, law firms, and anyone handling sensitive conversations, knowing what has access is a real privacy and compliance safeguard.
Remote support & helpdesk
How is this different from the remote control in my RMM?
Most RMMs bolt on a basic screen-share. Lavawall puts a full cockpit on one screen: the session, live health (CPU, RAM, disk, temperature, patch status), a Backstage that works without interrupting the user, an admin-permissioned launcher for 30+ Windows tools, direct script execution, elevated CMD/PowerShell, file transfer, and ticket + time entry, so a tech rarely needs to leave the window.
Is it safe? We've been burned by remote tools before.
Security-first by design: no reliance on frequently-breached tools like ScreenConnect, SplashTop, or TeamViewer; endpoints are never broadcast or directly exposed; IP and country restrictions (country limits on by default); certificate verification for server and clients; authentication-strength rules; and comprehensive logging of GUI sessions, shell sessions, and every shell command.
Can techs really work from a phone?
Yes, the interface is mobile-friendly, including fast full-colour PowerShell, multi-monitor thumbnails, special keys, and Control+Alt+Delete. A tech can resolve an issue from their phone as if they were at the desk.
How hard is it to set up?
It's a drop-in embed. In the console, open Embed & Branding in the left menu, scroll to Chat Widget Settings, brand it, and paste the snippet onto your site. The same widget powers chat on Lavawall's own pages.
What does the knowledge base do?
As you or a website visitor types, relevant knowledge-base articles surface instantly, so common questions get answered before they ever become a ticket, and your techs aren't retyping the same reply.
Is it really free?
Smart Web Chat is included with Lavawall. It's a simple, brandable chat with emoji support and built-in KB suggestions, no separate live-chat subscription required.
For MSPs & partners
Why should I trust a tool built by another MSP?
Because it was built to solve our own problems first. Two years after a missing Plex Media Server led to the LastPass breach, the big RMMs still didn't monitor for it, so we built the coverage the industry left out. We've committed not to become the vendors MSPs resent: no surprise lock-in, no games.
How does Lavawall help me grow, not just monitor?
Three ways: acquire clients (white-label scanner, branded reports, a public MSP directory that sends interested companies to you), retain and grow them (deeper coverage and compliance evidence that make you stickier), and lower your marginal cost to serve so each new client is more profitable than the last.
Is it multi-tenant and white-label?
Yes. Multi-tenant remote support, per-tenant user management, and a white-label domain scanner and reports are core, so your brand stays front and centre across every client.
Is this a full CRM or a light add-on?
It's a working CRM and help desk: contacts, a deal pipeline with stages and close dates, prospect-vs-client classification, company scoring, industry classification, duplicate detection and merge, and activity tracking, built into the same console as your security and monitoring data.
How do leads get in?
Scanner prospects flow straight in, run a white-label domain scan at an event or on your site, and the company lands in the CRM as a scored prospect you can work. You can also add contacts manually and enrich or classify them in bulk.
Why keep CRM and security in one tool?
Because your best sales signal is the security posture you can already see. When the scan shows a prospect's exposed configuration, the CRM is right there to turn that finding into a conversation and a deal, no export, no second login.
How does Lavawall deal registration work?
Register an opportunity through your partner contact and it's protected: we won't quote, sell, or negotiate with that client directly, and any inbound interest from them routes back to you. Registration is confirmed in writing so there's never ambiguity about whose deal it is.
Can I white-label Lavawall?
Yes. MSP partners can embed a white-label version of the Lavawall scanner on their own site, present findings under their own brand, and manage all client tenants from one multi-tenant console. Your clients see you, not us.
Does Lavawall compete with its partners for end clients?
No. Lavawall grew out of an MSP practice that watched vendors poach clients firsthand, so the rule is written down: we never go around a partner to their client, we sell direct only where no partner is engaged, and we pay referral fees when a direct lead belongs in a partner's territory.
How do I embed the scanner on my site?
In the console, open Embed Scanner under the You menu at the bottom of the left sidebar. Fill in your white-label details (phone number, URLs), then copy the head snippet into your page's and the body snippet into the . Clicking each red code block auto-selects it for copy-paste.
Whose brand shows on the results?
Yours. The white-label information you enter, your phone number and URLs, appears on the results page, so the scan looks and feels like your own tool, not a third party's.
What is it actually for?
Proving value and capturing leads. You're at a networking event, or a prospect is on your site, run a scan, show them real findings about their own domain, and collect their contact information right away.
Still have a question? Talk to a real security person same or next business day.