

vPenTest
By Vonahi Security (A Kaseya Company)
Implementing vPenTest is designed to be a 'Deploy, Click, and Go' experience. For external penetration testing, the process is virtually instant: users simply log into the portal, enter their public IP addresses, and schedule the test. For internal penetration testing, the user must deploy a lightweight agent. This agent is typically provided as a pre-configured Ubuntu-based Virtual Machine (OVA/OVF) that can be imported into VMware, Hyper-V, or Nutanix environments in minutes. Once the VM is powered on, the user registers it to their portal account using a unique UUID. The agent then performs a 'call-home' to the vPenTest cloud over port 443 (HTTPS) to receive its instructions. There is no complex network reconfiguration required, other than ensuring the agent has access to the segments intended for testing. Assessments can be scheduled to run immediately or during off-peak hours. Reports are usually generated and ready for review within 48 hours after the testing phase concludes, often much faster.
vPenTest offers extensive customization, particularly for service providers. The platform is fully white-labelable, meaning MSPs can replace all Vonahi branding with their own logos, brand colors, and company information. This extends to both the management portal and the final PDF/Word reports provided to clients. Users can also customize the 'scope' of their assessments by selecting specific IP ranges, excluding sensitive devices (like medical equipment or old industrial controllers), and choosing between different testing 'intensities.' The reporting engine allows users to toggle specific sections on or off, such as the technical exploitation logs or the executive summary. Furthermore, the platform's API allows for deeper integration into existing custom dashboards or automated workflows, enabling organizations to trigger tests based on specific events in their IT environment.
The base subscription for vPenTest is typically inclusive of the core testing features and reporting. However, there are a few areas where additional costs may apply. Pricing is consumption-based, so if an organization needs to test more IP addresses than their current plan allows, they will need to purchase additional 'IP blocks.' Some advanced reporting features or deep-dive modules (like specialized cloud assessments) might be tiered under higher-level subscriptions. While basic support is included, some organizations may opt for 'Premium' support packages through Kaseya for faster response times or dedicated account management. Crucially, vPenTest eliminates the largest 'additional cost' found in traditional security: the five-figure daily fees of human consultants. There are no travel costs, no scheduling fees, and no per-hour surcharges for re-testing after remediation.
Vonahi Security provides a comprehensive training ecosystem to ensure users can maximize the value of the platform. This includes an extensive Knowledge Base (hosted by Kaseya) that covers everything from initial VM deployment to interpreting complex exploitation logs. For MSPs, they offer specialized sales training and 'marketing-in-a-box' kits to help them explain the value of automated pentesting to non-technical business owners. Regular webinars are held to cover new feature releases and emerging threat trends. Additionally, Kaseya University provides structured learning paths for vPenTest, where users can earn certifications. These training resources are designed to cater to both the 'one-man-shop' MSP and the large enterprise IT department with dedicated security staff.
Security is paramount for a platform that conducts offensive activities. vPenTest is SOC 2 Type II certified, ensuring that its own internal controls for data privacy, integrity, and availability meet rigorous industry standards. All communication between the on-premise agent and the vPenTest cloud is encrypted via TLS 1.2+ over port 443. The platform uses Amazon Web Services (AWS) for its cloud infrastructure, leveraging AWS's robust physical and logical security controls. vPenTest does not store sensitive client data (like full database contents) longer than necessary; it primarily captures evidence of exploitability (e.g., proof of file access or a system shell). To prevent the tool from being misused, the system includes blacklisting capabilities for malicious IP addresses and requires multi-factor authentication (MFA) for portal access. Furthermore, as a CREST-accredited service, the methodology itself is regularly audited for safety and ethics.
As a SaaS platform, vPenTest follows a continuous delivery model. The central testing engine is updated frequently—often weekly—with new exploit modules, vulnerability signatures, and improved lateral movement logic based on the latest threat intelligence. These updates happen in the cloud and do not require the user to manually update their on-premise agents in most cases, as the agent pulls down the latest testing scripts at the start of each assessment. Major platform updates, such as UI overhauls or new reporting modules, are announced via the Kaseya portal and company newsletters. The release cadence is highly responsive to the cybersecurity landscape; for example, when a major zero-day vulnerability like Log4j or PrintNightmare is discovered, vPenTest typically adds detection and exploitation capabilities for it within days.
Vonahi Security maintains a clear data ownership policy: the customer owns all data related to their assessments and findings. While vPenTest processes this data to generate reports and provide insights, it does not claim ownership of the underlying vulnerability information. Customers can export their data at any time in various formats, including PDF, Microsoft Word, and CSV. Reports can also be exported into structured formats for ingestion into other GRC (Governance, Risk, and Compliance) tools. Kaseya’s broader privacy policy governs how account-level information is handled, ensuring compliance with global regulations like GDPR. If a customer cancels their subscription, they are generally given a window to download their historical reports before they are purged from the system in accordance with data retention policies.
vPenTest is built to scale from a single office to global enterprises with thousands of endpoints. For MSPs, the platform's multi-tenant architecture is the key to scalability, allowing them to add hundreds of clients (organizations) and manage them through a single pane of glass. The 'IP Block' pricing model supports this growth, as IP addresses can be easily added as the client base expands. Technically, scaling is handled by deploying additional agents in different network segments or geographic locations. Since the agents are lightweight VMs, there is no significant infrastructure overhead to adding more testing capacity. The cloud backend is designed to handle thousands of concurrent assessments, ensuring that large-scale monthly testing cycles across an entire MSP portfolio do not suffer from performance bottlenecks.
vPenTest is typically sold as a monthly or annual subscription. Under Kaseya's ownership, contracts are often aligned with the broader 'IT Complete' suite, which may offer multi-year discounts. Subscriptions generally renew automatically unless notice is given within the specified window (typically 30-60 days before the term ends). Cancellation terms are standard for SaaS agreements, with access continuing until the end of the paid period. Service Level Agreements (SLAs) cover the availability of the management portal and the support response times. It is important for users to review their specific Kaseya Master Services Agreement (MSA) for detailed legal terms regarding liability and use of the offensive testing tools, as the customer is responsible for ensuring they have the legal right to test the target IPs.
vPenTest is specifically designed to help organizations meet the 'penetration testing' requirements of major compliance frameworks. Its reports are widely accepted by auditors for PCI DSS (Requirement 11.3), HIPAA (Risk Analysis requirement), and SOC 2 (Trust Services Criteria). The platform also helps organizations meet the stringent requirements of cyber insurance providers, who increasingly demand proof of regular penetration testing before issuing or renewing policies. In addition to being SOC 2 Type II certified itself, Vonahi Security is a member of CREST, an international accreditation body for the technical information security industry. This ensures that the platform's methodology aligns with the high-quality, professional standards expected by regulatory bodies around the world.