How the partnership works. 

The terms, the economics,
and the fine print.

The structure, terms, and operational details of the X Security partner program. Everything you'd want to know before, during, and after signing -- including what we charge, what you make, and what protects your margin from getting squeezed mid-deal.

At a Glance

The program in nine lines.

Service

A 24/7 SOC run by experienced analysts, operating entirely under your brand. Triage, investigation, and escalation across your clients' full stack -- not an alert-forwarding service.

Pricing model

Simple: Per-tenant pricing across four size tiers + an enterprise tier. No platform fees or surprise SIEM licensing fees.

Wholesale rate

Tenant Based Pricing:
Micro (1 - 25 Endpoints): $245 per month (Microsoft Only)
Standard (26 - 100 Endpoints): $595 per month
Enhanced (101 - 250 Endpoints): $1,195 per month
Advanced (251 - 500 Endpoints): $2,295 per month
Enterprise (501+ Endpoints): Contact us

Suggested retail

Micro (1 - 25 Endpoints): $490 per month
Standard (26 - 100 Endpoints): $1,190 per month
Enhanced (101 - 250 Endpoints): $2,390 per month
Advanced (251 - 500 Endpoints): $4,590 per month
Enterprise (501+ Endpoints): Contact us

Partner gross margin

50% at suggested retail. Both numbers are published above.

Onboarding fee

A one-time fee per tenant -- $1,500 to $2,500 depending on size -- covering log source onboarding, detection tuning, and escalation path configuration. Quoted before work begins. Never revised after.

Tier structure

Five published sizes, priced flat per tenant. Tenants move tiers at renewal, not mid-term, so your invoice doesn't drift with headcount.

renewal escalator

Capped at 4% or CPI, whichever is lower. This is written into the agreement. Your renewal conversation with your client never gets ambushed by ours with you.

Channel exclusivity

100% channel exclusivity. This is written in the contract, not just the marketing. We sell through partners only -- no direct clients.

wholesale rate

What you pay us. 
What's included.

A single per-tenant rate covers 24/7 cross-source monitoring across the client's entire stack. No per-integration fees, no log-volume surprises, no surprise mid-cycle escalators. The rate is the rate.

Starting at
$245
per Tenant / month

$1,500 - $2,500 one-time onboarding fee per client engagement. After that, the per-tenant rate is the entire monthly cost. No add-on fees for additional integrations, log volume, "investigations", or detection coverage breadth.

At a Glance

What the rate buys. 

What it doesn't.

Most channel programs nickel-and-dime partners with surprise line items. We don't. Here's exactly what's in the per-tenant rate and what gets quoted separately.

Included in the Rate
Priced separately

24/7/365 monitoring across endpoint, identity, network, SaaS, and RMM.

One-time onboarding per client engagement -- $1,500 to $2,500 depending on stack complexity.

All standard integrations -- 150+ supported, no per-integration fees.

Custom integration development for sources outside the standard catalog. (found here)

Cross-source correlation as the unit of detection, not single-source alerting.

EDR or platform licensing -- you bring the stack you already sell.

Triage and investigation with structured escalation to your team.

Incident response beyond triage -- partner-routed 
to your IR provider or our channel-aware IR partner.

Whitelabel reporting under your brand.

Bespoke compliance reporting packages (SOC 2 evidence, HIPAA, PCI -- contact us if needed).

What You Make

The markup math. 

Worked out in advance.

Most partner programs publish "competitive margin" without showing the math. Here's the math: suggested retail is $18–$22 per user per month, depending on your client tier and how the deal is structured.

Suggested Retail
$490-$4,590

Per tenant per month, retail to your end client.

Your Gross Margin
50%

Flat across every tier.

Per-User Profit
$245-$2,295

Gross profit per tenant per month, kept by you.

A typical partner book 

at four tenants averaging 

250 users

Total USERS on X Security
1, 000
users
wholesale cost to you
$7,450
month
Retail revenue to you
$14,900
month
Annual gross profit
$89,400
Where You Stack

Against the alternatives your
client is already comparing.

Your end client is being quoted by other vendors -- some direct, some channel. Here's how a $20/user retail line stacks against what they'd pay elsewhere, and what they'd actually get for it.

X Security (125 Users)

$4.78 - $11.83
endpoint / month

Consistent monthly tenant price of $1,195. Between 101 - 250 endpoints

Arctic Wolf (125 Users)

$12 - $14
endpoint / month

$1,500 - $1,750 per month. Fluctuates with increased headcount.
Direct-to-end-client. Your client's relationship moves to Arctic Wolf at signature.

Huntress + Blackpoint Cyber (125 Users)

$11 - $14
endpoint / month

$1,375 - $1,750 per month. Fluctuates with increased headcount.
Direct-to-end-client. Your client's relationship moves to Huntress and Blackpoint.

sophos mdr (125 Users)

$15 - $17
endpoint / month

$1,875 - $2,125 per month. Fluctuates with increased headcount.
Direct-to-end-client.

Margin Protection

How the margin 
holds up over time.

The most common channel program failure is wholesale rates that creep up faster than partners can pass them through. That's structurally engineered out of this program.

[ 01. Wholesale rate locked for the full term of your end-client contract ]

Once a tenant is signed at a rate, that rate holds for the term even if X Security's published rate card moves during the year. Your margin doesn't get squeezed in month seven of a twelve-month deal.

[ 02. Annual escalator capped at 4% or CPI,
whichever is lower ]

Renewal-cycle price increases have a hard ceiling. You can model
your end-client renewals against ours without a margin gap.

[ 03. priced by tenant size, not per seat ]

No per-user metering, no bill that moves every time a client hires. Tenant sizes are reviewed quarterly and a tenant that outgrows its band by >10% moves tiers at the next quarter -- with notice to you first, never retroactively.

[ 04. TIER MOVES ARE NEVER A SURPRISE ]

You see a tier change before it lands, in time to reprice your own client if you choose to. The band thresholds are published, so you can predict the move before we tell you.

[ 05. Onboarding fee is one-time, per engagement -- not per renewal ]

The setup cost happens once when the engagement starts.
Renewals don't trigger another onboarding charge.

Channel Program Discipline

Things we've

learned not to do.

Your end client is being quoted by other vendors -- some direct, some channel.

[   01   ]

We don't run partner tiers.

Every partner buys from the same published rate card whether they bring us two tenants or two hundred. Partner tiers exist to make small partners subsidize the discounts large partners negotiate, and to keep everyone guessing about what the partner next door is paying. We'd rather publish one set of numbers and let the program compete on what it delivers.

[   02   ]

We don't quote rates that aren't on the rate card.

"Special pricing" for strategic accounts is how programs degrade. Once one partner has a sweetheart rate, the next one negotiates against it. The published wholesale rate is the rate. There's no back-channel deal you'd be cut out of.

[   03   ]

We don't sell direct, 

ever -- even when
the end client asks.

Vendors that go direct usually start by saying they won't. Then a large account asks... the enterprise team makes an exception and the exception becomes a habit. Channel-only is in the contract, not just the marketing. If your client approaches us directly, we route the conversation back to you.

[   04   ]

We don't change wholesale rates mid-cycle.

Most channel agreements reserve the right to adjust pricing at the vendor's discretion. We contract it out. Your wholesale rate is locked for the full term of your end-client contract. Renewal escalators are capped at 4% or CPI, whichever is lower.

[   05   ]

We don't bundle in services we can't deliver.

"Threat hunting included" or "compliance reporting available" without a defined operational scope is how programs over-promise and partners get blamed. If we say it's included on the rate card, it's already running in production. If it isn't, it's quoted separately and named explicitly.

[   06   ]

We don't show up in your client conversations.

Whitelabel that's only skin-deep—a logo on the report, our name in the email signature, our URL in the portal—breaks the moment a client clicks the wrong link. We're invisible to your end client end-to-end. Reports, portals, escalations, alerts—all of it carries your brand, not ours.

Roles & Responsibilities

What you don't do.
What you still own.

A successful partnership starts with clear responsibilities. Here's exactly what we manage behind the scenes, and what remains firmly under your ownership.

What you don't have to build
What stays yours

SOC build-out — no analyst hiring, no shift schedules.

The client relationship — every report, alert, and escalation goes out under your brand.

SIEM tuning — the platform is already running.

Incident response — when something escalates beyond triage, your IR provider stays in front of your client.

Integration maintenance — 150+ integrations, all maintained.

The trusted-advisor seat — we route to your incident commander, never around them.

EDR or platform licensing — you bring the stack you already sell.

The pricing relationship — you set retail; we hold wholesale.

Channel conflict — there's no path for us to go around you.

The renewal conversation — it stays your call, on your timeline.

The Other Side of the Table

What we ask from partners.

Most channel programs hide their expectations until conflict surfaces. We'd rather name them up front — so partners can self-qualify and so the relationship is clearly bilateral from day one.

[ 01. Co-investment in onboarding. ]

The first 30 days of every engagement require partner attention — your AM on calls, your engineer on the technical handoff, your leadership signed off on the playbook. We don't make this work alone. The clients we onboard well are the ones where the partner shows up.

[ 02. Honest feedback in the first 90 days. ]

If something isn't working — the playbook doesn't fit your environment, the escalation rhythm is wrong, the reporting cadence isn't useful — we want to hear it inside the first quarter. Issues raised early get fixed. Issues that fester for a year become churn risk.

[ 03. Channel hygiene during the engagement. ]

The whitelabel only works if it's executed end-to-end. Don't bring us into client conversations directly, don't forward our internal escalation emails to your client, don't reference X Security by name on calls. If the client needs to talk to a SOC analyst, the analyst joins the call as a member of your team.

[ 04. Reasonable lead time on requests. ]

Active incidents need fast routing — we're built for that. Vendor selection conversations, custom proposal asks, and special reporting requests should come with at least a few business days. Same-day turnarounds during a sales cycle aren't realistic and rushing them compromises the work.

[ 05. Participation in program improvements. ]

We run a partner advisory cadence quarterly — partners tell us what's working, what isn't, and what they need next. Engaged partners get input on the roadmap. Passive partners get the program as it stands. Both are fine; the choice is yours.

[ 06. Standard care on client introductions. ]

When you introduce a new client into the program, we expect the basics — accurate stack inventory, named technical contact, signed engagement scope. Onboarding speed depends on the quality of the handoff. We can move fast, but we can't move on incomplete information.

For Your Client Conversation

The two-sentence pitch 
you can give your end client. 
Say it word for word.

"We run a 24/7 SOC across your endpoint, identity, network, SaaS, and RMM environments — backed by a team of US-led incident responders with two decades of breach experience.
If anything escalates beyond triage, we're on the bridge with your IR provider — we're not handing your incident off to a vendor you've never heard of."
Case Studies

The 4D Framework at Work

Every deal is different, but the stakes are always high. These case studies show how we apply our sponsor-aligned 4D framework to uncover material risks, provide clarity, and protect value across the transaction lifecycle.

From fast-moving carve-outs to sector-specific rollups, each example highlights real findings, strategic insight, and tangible outcomes — delivered at the speed and precision M&A demands.

case study

01

Phase:

Diligence

Sponsor Type:

Middle Market Private Equity

Sector:

Industrial Manufacturing

Deal Size:

$75M - $100M

The Challenge

The sponsor was scaling through a roll-up strategy: multiple back-to-back acquisitions that would all be under a shared operating model. But that efficiency came with a tradeoff. Minimal time for deep diligence. Cybersecurity reviews, in particular, threatened to slow execution and introduce friction. With competing bids always a possibility, the firm needed a way to assess cyber risk that aligned with how they buy: fast, focused, and repeatable.

X Security Involvement

We conducted our cyber screening in 5-days, focused on finding and quantifying material risk instead of cataloging every cybersecurity finding. We created an investor-focused report mapping findings to financial exposure, deal terms, and recommended actions.

Key Finding

The assessment found vulnerabilities in manufacturing systems that were exposed to the internet. These findings were material to the deal due to the historic use of the vulnerabilities in ransomware attacks. If exploited, all production would be stopped. That translated into a projected $3.7M exposure, representing 19% of adjusted EBITDA.

The Outcome

Cyber diligence needs to deliver risk-relevant answers on a timeline that matches how the firm moves. In this case, a structured screening approach provided the sponsor with decision-ready data without turning over every stone.

Takeaway

Cyber diligence needs to deliver risk-relevant answers on a timeline that matches how the firm moves. In this case, a structured screening approach provided the sponsor with decision-ready data without turning over every stone.

Portfolio Value Impact

The sponsor now uses this screening approach to benchmark each new target against the platform’s broader security maturity and quantified risk exposure. It enables more informed decisions: flagging when risks are acceptable, when they’re outliers, and when they require action pre-close. More than a speed play, it’s a framework for applying consistent risk tolerance across a high-velocity investment strategy.

Become a partner. Or evaluate the fit.

A thirty-minute conversation, not a sales pitch. We walk through your client portfolio, the engagements that fit, and whether the economics work for your business specifically. Channel-only means we only win when partners win.

Start a partner Conversation