📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Lavawall® vs. NinjaOne

Lavawall® vs. NinjaOne: remote support, RMM, and security compared

Lavawall® and NinjaOne are both RMMs. Lavawall® also includes Microsoft 365 and Google Workspace breach detection, compliance evidence, Windows administrator elevation, and a password vault on the same agent, and offers end-to-end encrypted remote sessions in which the relay holds no key.

Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams, with patching, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance built into the same agent and console. Lavawall® is made in Canada by ThreeShield Information Security Corporation.

Install Lavawall® through NinjaOne with a script, run both agents side by side, and move companies over when your team is ready.

Start a 14-day free trialSee the comparison

14-day trial of the full platform, no credit card. Then month-to-month, with no long-term contract and no high-water-mark billing.

Side by side

The short version: NinjaOne documents full remote control for Windows and macOS, Linux through remote command execution, IP allowlists, session playback, and Quick Connect for devices without its agent. Lavawall® covers the same platforms, restricts technicians by country by default as well as by IP address, and also includes compliance evidence collected from the RMM, Windows administrator elevation, and a built-in password vault on the same agent. Every NinjaOne fact below links to NinjaOne's own documentation.

Lavawall compared with Datto RMM and NinjaOne, by capability
CapabilityLavawall®Datto RMMNinjaOne
Is it an RMM?YesYesYes
Browser-based remote controlYes, including from a phoneYes, HTML5 Web Remote (Datto help)Yes (NinjaOne FAQ)
Computers that can be remotely controlledWindows and Mac“Only Windows and macOS devices with a Managed Agent installed” (Datto help)Windows and macOS (NinjaOne FAQ)
Linux computersScripts, patching, and monitoring; no remote desktopSee Datto documentationRemote command execution (NinjaOne FAQ)
Support a computer that has no agent installedYes, ad-hoc sessions from the same consoleControls only devices with a Managed Agent installed (Datto help)Quick Connect, for devices without the NinjaOne agent (NinjaOne docs)
File upload size per fileUp to 2 GB“Limited to 1GB per file upload” (Datto help)Not stated in NinjaOne documentation
Technicians in one sessionSeveral, with control hand-off“Up to four” (Datto help)Multiple administrators (NinjaOne FAQ)
Session recordSession logging: every connection and command, with optional screen captures on the ticketSee Datto documentationSession playback (NinjaOne FAQ)
Restrict where technicians connect fromBy country (on by default) and by IP addressSee Datto documentationIP allowlist (NinjaOne FAQ)
Third-party and OS patching7,400+ applications on Windows, Mac, and Linux, kept up to date daily; waits for the program to close, warns the user, or updates at reboot; ARM supportedBroader catalogue through the Advanced Software Management add-on: Windows only, not supported on ARM-based devices, some programs “forcibly close without warning,” and up to 10 business days for Tier 3 applications (Datto help)See NinjaOne documentation
Password vaultIncluded; the server never sees stored passwordsSeparate product: IT Glue, integrated with Web Remote (Datto help)See NinjaOne documentation
Secrets for servers and scriptsServer secret manager: each server pulls only the secrets it needs, encrypted so only that server can open themInput variables set as environment variables at run time; types are selection, string, date, and Boolean (Datto help)Secure custom fields, hidden by default, that scripts can be permitted to read (NinjaOne docs)
FIPS 140-3 validated cryptography for remote sessionsRelay and Windows and Mac agents (Go Cryptographic Module, CMVP #5247); YubiKey 5 FIPS (#5291) for technician sign-inSee Datto documentationSee NinjaOne documentation

Competitor information is taken from each vendor's public documentation as of September 2026 and linked above. Tell us if something has changed and we will correct it.

Also on the Lavawall® agent

Neither vendor's linked documentation describes these in a way we can compare line by line, so check with them for their current offering.

Other Lavawall capabilities
CapabilityLavawall®
Installs through your current RMMDatto RMM component, or a script for NinjaOne, ConnectWise, Kaseya, Intune, or any tool that runs one
Admin tools without disturbing the userAdmin Workspace: 19 Windows tools and 3 shells; root zsh on Mac
Admin tools one click away with administrator rights, without elevating the user50 Windows tools
Shell as the logged-in user, in their environment, without disturbing themPowerShell (Windows)
End-to-end encrypted sessions, relay holds no keyAvailable
Hardware security key required before a sessionAvailable
Built-in administrator elevation (just-in-time admin)Included, Windows
Microsoft 365 and Google Workspace breach detectionIncluded
Compliance evidence collected automatically from the RMM70+ frameworks; GRC and RMM can also be used separately
Daily security checklists with live evidenceIncluded
Event logs and per-process history ready when you open a deviceIncluded
File download sizeNo fixed limit

Try it on one company through NinjaOneTalk to a human

Security questionnaires become a lookup, not a fire drill

GRC (compliance management) and RMM are tightly integrated in Lavawall®, and each can be used on its own. When a client questionnaire, a cyber-insurance renewal, or a SOC 2 or CMMC assessment asks for patch status, disk encryption, endpoint protection, and administrator rights on every computer, the RMM has been collecting that all along. The GRC module turns it into dated evidence for that company, so you look up the answer instead of gathering screenshots from several tools and rebuilding a spreadsheet.

Need compliance first? Start with GRC and turn on the RMM when you are ready.

Evidence collected from the RMM includes:

  • managed device inventory;
  • patch state by device;
  • disk encryption state;
  • endpoint protection coverage;
  • administrator rights, and administrator elevation rules and decisions;
  • compliance console access, access reviews, and control attestations;
  • password vault collections and sharing;
  • security training completion and phishing simulation results;
  • published policies and their attestations.

Each file records what was collected, the filter used, when it ran (UTC), and for which company, so it still makes sense to an auditor a year later. The evidence maps to 70+ compliance frameworks, including CMMC 2.0, HIPAA, SOC 2, and ISO 27001. Lavawall® is built by ThreeShield, a CISSP and CISA cybersecurity audit firm.

Remote support in detail

For the technician

  • Remote control from any modern browser, with nothing to install on the technician's side, including from a phone or tablet with an on-screen keyboard, Ctrl, Alt, Tab, and Esc keys, and Bluetooth keyboard support.
  • Full-screen mode with its toolbar, choice of monitor on multi-monitor computers, clipboard sending and fetching, and the remote computer's real cursor shape.
  • File transfer in both directions: uploads of up to 2 GB per file, and downloads with no fixed size limit.
  • Chat with the person at the computer, inside the session.
  • Several technicians in the same session, with hand-off of control.
  • Ad-hoc support: connect to a computer that does not have the Lavawall® agent installed, for a one-off session.
  • Scripts on Windows, Mac, and Linux, including imported Datto RMM scripts. A company can also be limited to the signed script library built into the agent, so a stolen console session cannot push an arbitrary script.
  • Push notifications to the technician's phone for requests that need a decision.

For the customer and the security team

  • The person at the computer can be asked for consent before a session, set per company, and can end sharing at any time.
  • Per-technician access scope: which companies each technician may reach at all.
  • Technician access limited by IP address and by country. Country restriction is on by default.
  • Sign-in with passkeys or hardware security keys, and technicians can be required to use a hardware key before a session starts.
  • End-to-end encrypted sessions are available. The relay carries encrypted traffic and holds no key for it. Each computer has its own key, held in the TPM on Windows and the Secure Enclave on Mac, and it cannot be exported.
  • Session logging: every connection and every command sent is logged, and screen captures can be attached to the ticket when the technician wants a record.
  • Every session and administrative action is written to a tamper-evident activity log.
  • Data residency in Canada, the United States, Europe, or Australia, and a US-only path for tenants that need one.

What NinjaOne documents

NinjaOne announced its native remote access on 8 December 2025. Its remote access FAQ says NinjaOne delivers full remote control for Windows and macOS devices, with Linux supported “through secure remote command execution,” and that NinjaOne Remote provides IP allowlist configuration. The FAQ also describes session playback, file transfer, and role-based access. For computers without the NinjaOne agent, NinjaOne documents Quick Connect, which connects through an invitation link or code.

NinjaOne's pages do not state a file size limit, so we do not compare ours with theirs. Lavawall® uploads files of up to 2 GB each and downloads files with no fixed size limit.

Where NinjaOne may fit better

NinjaOne may fit better if you rely on it for mobile device management of phones and tablets, or if video playback of every session matters more to you than a log; NinjaOne's FAQ describes session playback, while Lavawall® logs every connection and command and attaches screen captures when the technician wants a record.

If your team is already trained on NinjaOne's automation and policies, that switching cost is real. The side-by-side start exists for this: technicians keep NinjaOne for what they know and learn Lavawall® on one company first.

Remote sessions protected by FIPS 140-3 validated cryptography

Remote sessions are protected by FIPS 140-3 validated cryptography in the relay and the Windows and Mac agents (Go Cryptographic Module, NIST CMVP certificate #5247), and end-to-end encrypted sessions are available: in an end-to-end encrypted session, the relay holds no session key and cannot read the session. Technicians can be required to sign in with a YubiKey 5 FIPS hardware key (CMVP certificate #5291) before a session starts.

A useful question for any remote support vendor: who, at your company or in your cloud, can see my customer's screen? With an end-to-end encrypted Lavawall® session, the relay in the middle carries encrypted traffic and has no key for it. See FIPS 140-3 support for exactly what each validated module covers.

50 Windows admin tools, each one click away with administrator rights

In any Windows remote session, from a desktop or a phone, the technician opens an admin tool with one click and it runs with administrator rights. The user's account is never elevated, there is no UAC prompt, and there is no local administrator password to look up.

  • Command Prompt
  • PowerShell
  • File Explorer
  • Task Manager
  • Services
  • Registry Editor
  • Event Viewer
  • Device Manager
  • Disk Management
  • Computer Management
  • Hyper-V Manager
  • Task Scheduler
  • Local Users & Groups
  • Group Policy
  • Local Security Policy
  • Performance Monitor
  • Resource Monitor
  • Windows Defender Firewall with Advanced Security
  • Control Panel
  • Programs & Features
  • Shared Folders
  • Certificates (computer)
  • Print Management
  • System Properties
  • System Information
  • System Configuration
  • User Accounts
  • Component Services
  • WMI Control
  • Resultant Set of Policy
  • TPM Management
  • ODBC Data Sources
  • Driver Verifier
  • Memory Diagnostic
  • Windows Features
  • Disk Cleanup
  • Optimize Drives
  • Network Connections
  • Windows Defender Firewall (Control Panel)
  • Power Options
  • Sound
  • Internet Options
  • Security & Maintenance
  • Date & Time
  • Remote Settings
  • Remote Desktop Connection
  • DirectX Diagnostic
  • Character Map
  • About Windows
  • Camera, microphone and speaker use check

Some tools appear only where Windows provides them, for example Hyper-V Manager on Windows Server and Resultant Set of Policy on domain-joined computers.

Administrator elevation, built in

Lavawall® includes just-in-time administrator rights for Windows users on the same agent. When a standard user hits an administrator prompt, Lavawall checks the request against the company's rules and approves it, denies it, or sends it to a technician, who can approve it from a phone notification. Nobody needs standing administrator rights.

  • Rules can match a publisher's code-signing certificate, a thumbprint, a file hash or a path. Certificate rules are preferred and survive routine certificate renewals.
  • An MSI installer can be approved for one specific package, not all of msiexec.
  • Ringfencing: an elevated program can be blocked from starting other programs, reading files, or using the network.
  • Execution prevention: a curated block list of the tools ransomware commonly uses, such as the ones that delete shadow copies or clear logs, rolled out in audit mode first. Enforcement is allowed only after the audit shows what would have been blocked.
  • Offline approval with a one-time code when the computer has no connection.
  • The rule set each computer follows is signed, and the computer verifies the signature before applying it.
  • It installs automatically through the Lavawall® agent, with no separate enrolment code.

Administrator elevation is available for Windows. See administrator elevation for the details.

The Admin Workspace: fix it without disturbing the user

The Admin Workspace gives the technician a private workspace on the remote computer with administrator rights, while the person at the computer keeps working and sees nothing on their screen.

  • PowerShell (system)
  • PowerShell (logged-in user)
  • Command Prompt (system)
  • Task Manager
  • Performance Monitor
  • Windows Defender Firewall with Advanced Security
  • About Windows
  • Startup apps
  • Registry Editor
  • File Explorer
  • Services
  • Programs & Features
  • Event Viewer
  • Task Scheduler
  • Device Manager
  • Windows Features
  • Local Users & Groups
  • Disk Management
  • Memory Diagnostic
  • Reliability History
  • Active Connections
  • Disk Cleanup

Files move both ways from the same place: upload files of up to 2 GB each to the computer, and download files with no fixed size limit (large files stream straight to disk in Chrome and Edge).

On a Mac, the Admin Workspace gives a zsh shell with root access, without disturbing the user. macOS asks the user to allow screen and audio access; our Mac setup guide shows what to click.

Shells at system level or as the logged-in user

On Windows, a technician can open PowerShell with system rights, PowerShell as the logged-in user, or Command Prompt with system rights. The user-level PowerShell runs inside that person's own session, profile, and environment, so per-user installs (for example with winget), mapped drives and user settings work, and nothing appears on their screen.

On a Mac, a zsh shell with root access runs in the Admin Workspace. Each shell opens in seconds as a live terminal in the browser, including from a phone, with Ctrl, Alt, and the other special keys. Linux computers run scripts.

Morning security checklists

Daily, weekly and monthly checklists, on a morning, evening or any other schedule, for each company. Live panels bring the evidence to each check, such as monitored services and service-provider status, so the technician confirms rather than goes looking. Answering "same as last time" or "the rest are good" is one click, and each check rests until it is due again.

Event logs and process history, ready before you ask

Lavawall® collects and sorts Windows event logs and per-process resource use in the background. When a technician opens a device, the important events are already sorted and each running process has a chart of its CPU and memory use over time. There is no waiting for Event Viewer or Task Manager to load on a slow computer, and it works when the computer is too busy to use comfortably.

Secrets for servers and scripts

Scripts often need a password, an API key, or a service account. Lavawall® keeps those out of script bodies in two ways.

  • The server secret manager. Secrets that servers and automation depend on live in the Lavawall® vault. A Windows or Linux server pulls exactly the secret it needs, encrypted so only that server can open it, with nobody at the keyboard; Lavawall®'s servers store only encrypted data they cannot open.
  • A signed script library. Scripts can be your own, including imported Datto RMM scripts. A company can also be limited to the signed script library built into the agent, with typed parameters, so a stolen console session cannot push an arbitrary script to its computers.

See remote support and security and privacy for how the server secret manager works.

Making the case to your team

One line for your partners or manager: We can try Lavawall® on one client in minutes through NinjaOne with a script, without changing anything in NinjaOne. There is no credit card to start, it is month-to-month after that, and if it does not earn its place we uninstall it.

Before you compare prices, list what you pay for today beside NinjaOne: a remote support tool for computers without the agent, a password manager, administrator elevation, compliance evidence, security awareness training, and Microsoft 365 configuration backup. Compare that total with Lavawall® pricing.

Email this page to a colleague

How to switch, or run both during the move

Your first step is small. Lavawall® deploys in minutes through the RMM you already run, on one company or on all of them, and works alongside it while your staff build comfort with it, starting with the features you need most. Moving is quick when you are ready: the install script for NinjaOne takes minutes. Most organizations that start this way end up running their RMM work in Lavawall®, one company at a time, once they have used the two side by side. If it does not earn its place, uninstall it: Lavawall® installs no kernel driver, so the agent comes off cleanly.

Start by installing Lavawall® through NinjaOne with a script (see installing Lavawall through your current RMM). Both agents run side by side, so you can move remote support, patching, monitoring, and scripts over one company at a time, then retire the NinjaOne agent when you are ready.

Start a 14-day free trialTalk to a human

14-day trial of the full platform, no credit card. Then month-to-month, with no long-term contract and no high-water-mark billing.

Frequently asked questions

Is Lavawall an RMM?
Yes. Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams. It includes monitoring, patching for more than 7,400 applications, scripting, and browser-based remote support, along with security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance evidence on the same agent.
Can Lavawall replace NinjaOne?
Yes, for most MSPs and IT teams that manage Windows and Mac computers, with Linux covered by scripts, patching, and monitoring. You do not have to do it all at once: install Lavawall through NinjaOne with a script, use the features you need first, and move over one company at a time.
Does Lavawall need NinjaOne to run?
No. Lavawall® is its own RMM, made by ThreeShield Information Security Corporation in Canada. It installs through NinjaOne with a script, so you can try it on one company without changing anything in NinjaOne, then move remote support, patching, and scripts over when you are ready.
Can Lavawall and NinjaOne run on the same computers?
Yes. Both agents run side by side while you move over, so there is no cut-over weekend. Lavawall installs no kernel driver, so the agent uninstalls cleanly if you decide not to keep it.
What happens to our NinjaOne scripts?
They keep running in NinjaOne while both agents run side by side. You add your own scripts to Lavawall® as each company moves, and the signed script library built into the agent covers common tasks. Automatic import with variable detection is built for Datto RMM scripts.
Do we pay for both while we move?
You pay for Lavawall only for what you add to it, month-to-month, with no long-term contract and no high-water-mark billing, so your Lavawall bill grows as companies move over. Modules can be bought individually if you want to start with one. Paid tiers have a starting size; the pricing page lists current rates in Canadian and US dollars.
How much will our technicians need to learn?
Less than you might expect. The console runs in a browser, including on a phone, and the Admin Workspace opens the Windows tools technicians already use, such as Task Manager, Services, the Registry Editor, and Event Viewer. Starting with one company lets them learn on real tickets while your current RMM keeps running.
What if we decide Lavawall is not for us?
There is no long-term contract and no minimum term, your data is yours to export, and the agent uninstalls cleanly because Lavawall installs no kernel driver.
How does Lavawall remote support compare with NinjaOne's remote access?
Both run in the browser. Lavawall's remote support includes end-to-end encrypted sessions in which the relay holds no key, an Admin Workspace with 19 Windows tools and three shells, 50 Windows admin tools one click away with administrator rights, and technician access limited by country by default. NinjaOne's FAQ says its remote control covers Windows and macOS, with Linux handled through secure remote command execution, and that it offers IP allowlists and session playback.
Can Lavawall be used for compliance without replacing our RMM?
Yes. GRC and RMM are tightly integrated but can be used separately. Many teams start with the RMM, and when an assessment or a client security questionnaire comes up, the evidence the RMM has been collecting is ready to use. Others start with GRC and turn on the RMM later.
Is Lavawall FIPS 140-3 validated?
Lavawall uses FIPS 140-3 validated cryptographic modules in specific components: the Go Cryptographic Module (CMVP certificate #5247) in the relay and the Windows and Mac agents, and YubiKey 5 FIPS (certificate #5291) for hardware technician authentication. The product as a whole is not a cryptographic module and has no certificate of its own.
Who makes Lavawall, and where is it hosted?
Lavawall is built in Canada by ThreeShield Information Security Corporation, a CISSP and CISA cybersecurity audit firm founded in 2006. Data can be hosted in Canada, the United States, Europe, or Australia.

NinjaOne is a trademark of NinjaOne, LLC. Datto and Datto RMM are trademarks of Kaseya. Lavawall is not affiliated with either.