Security for MSPs & vCISOs
Supply-chain risk, cyber insurer questionnaires, and customer audit resale-script governance beside your incumbent RMM.
Govern privileged automation with signing, separation of duties, and exportable audit-beside your RMM, verifiable in a trial tenant.
MSPs are supply-chain targets. When an assessor or insurer asks *who ran what on which customer machine*, RMM operational logs rarely answer with signing attribution and exportable evidence.
Trustholm sits beside NinjaOne, ConnectWise, and PDQ-not replacing them. You keep patch and AV breadth; Trustholm adds signed PowerShell policy, dual-custody approval, and security audit export your end-customers can attach to their own audits.
Resell evidence: Per-customer Sentinel routing lets you forward audit events to dedicated customer workspaces. Export JSON/CSV slices scoped by customer/group for vCISO deliverables.
Honest positioning: We do not hold SOC 2 Type II yet. Reproduce Shipped rows in trial during insurer or enterprise diligence calls.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
Key capabilities
- Schema-per-tenant isolation for your MSP organization
- Dual-custody (four-eyes) on by default for script publish
- Per-customer Event Hub routing for Sentinel resale
- 30-minute pilot: one agent, one signed script, one export
- Shipped/Gap tables for customer questionnaire pre-fill
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| Just-in-time privilege elevation | Settings → Security JIT policy + grant queue; audit PrivilegeElevation / jit.privilege.*; Assessor Package can include elevation lifecycle | Shipped | Default off; Phase 2 packages, settings/agent/user gates, eligible roles, justification and break-glass policies shipped |
| Privileged actions audit | Web Audit logs (/audit); GET /api/audit, export JSON/CSV | Shipped | - |
| Tenant isolation | Schema-per-tenant PostgreSQL; JWT tenant binding on API | Shipped | - |
| Dual-custody (four-eyes) | Settings → Security toggle; Script Management blocks submitter self-approve | Shipped | On by default; ERR_DUAL_CUSTODY_VIOLATION and script.dual_custody.denied in audit |
| Microsoft Sentinel / Event Hub audit sink | azure_eventhub / azure_dcr sink; DCR template download; per-customer routing | Shipped | Splunk/Datadog native sinks and in-product detection rules remain backlog |
Frequently asked questions
- Do we need a separate Trustholm tenant per end customer?
Typically one MSP tenant with customer/group scoping inside it. Assessors evaluating end-customer separation should review your group-to-client mapping and export slices-not assume separate tenants unless your commercial model requires it.
- Will this satisfy our cyber insurer?
Insurers ask for attributable script execution evidence. Export audit rows from trial and attach to your application-we supply technical artifacts, not insurance guarantees.