PARTNERS

Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now

White Label

White-label SecEng capabilities as a product-level or platform-level partner offering.

White Label means deeper brand, packaging, distribution, and commercial control than private-label services, with stronger minimums, support obligations, audit rights, release coordination, and misuse controls.

CLI
Headless invocation for partners and automation
SARIF
Scanner-friendly output for partner ingestion
OEM
Commercial path for embedded AI security coverage
Private Label vs White Label

Make the distinction unmissable

Private label is service branding. White label is product-level or platform-level branding and commercial control.

Private Label

Service and report branding

Consultancy or assessment delivery, partner-facing client work, partner-branded reports, and contractual recognition that the underlying SecEng capability remains licensed and controlled.

White Label

Product-level brand control

Product naming and packaging, embedded or partner-branded outputs, deeper attribution control, distribution or sublicensing rights, stronger minimum commitments, support obligations, audit controls, and release coordination.

Decision rule

Choose by customer promise

Use private label when the partner sells a service. Use white label when the partner sells a product, platform, or branded capability that customers treat as the partner product.

Choose the licensing and control model before choosing the label.

Resale, private-label service delivery, white-label product experience, OEM embedding, and transferred implementation represent different levels of control, responsibility, dependency, support, and IP exposure.

LOWERHIGHERSecEng-brandedSecEng product identity andpresentation remain primary.Co-brandedSecEng and partner identitiesremain visible in one offer.White-labelPartner presentation leads whileSecEng capability remainscontractually defined.Private-labelThe partner owns more of thevisible product identity andcommercial packaging.Embedded capabilitySecEng operates as a module insidethe partner product and workflow.WHAT CHANGESSecEng brand visibilitydecreasesPartner presentation controlincreasesPartner product responsibilityincreasesSupport and roadmap boundariesbecome more specificMODEL-SELECTION BOUNDARYLater models are not automatically betterBrand, product, support, and IP boundariesrequire contract definition

The agreement must identify exactly what the partner may brand, operate, distribute, integrate, modify, sublicense, and support - and what remains a protected SecEng capability.

White label

Present licensed capability through your product and brand.

White label provides greater control over naming, packaging, presentation, and customer experience. It requires explicit rights for the selected capability, deployment, branding, support, updates, claims, and quality controls.

May include

What white label may include

Scoped in the license.

  • Partner-controlled product presentation
  • Licensed naming and packaging rights
  • Defined customer-facing output treatment
  • Approved redistribution scope
  • Agreed deployment model
  • Support and update entitlement
  • Claim and logo approval process
Retained

What remains SecEng IP

Not transferred by a white-label license.

  • Engines and source
  • Canonical contracts
  • Internal prompts
  • Scoring and detector logic
  • Methods and research
  • General improvements
  • Unrelated modules and tooling
Definitions

Five labels, five different rights

Resale, private-label, white-label, OEM, and transferred implementation are not interchangeable terms, and none of them automatically includes source-code ownership, assignment of SecEng IP, unrestricted modification, universal sublicensing, or unlimited redistribution.

Resale

Resale

The partner sells an approved SecEng offer with limited packaging rights.

Private-label service

Private-label service

The partner presents an approved service under its brand while delivery and technical controls remain explicitly governed.

White-label product experience

White-label product experience

The partner presents selected capability through its own customer-facing product or interface under negotiated operational and licensing terms.

OEM embedding

OEM embedding

A selected capability is invoked inside the partner product through a bounded technical contract.

Not included by default

Transferred or deeply modifiable implementation

Not included unless separately negotiated and explicitly documented. This is never a normal or default white-label right.

Define what changes and what remains controlled.

White-label presentation can change the product identity, interface, packaging, and customer workflow. It must not obscure technical provenance, version state, evidence integrity, authorization, support ownership, or the limitations of the licensed capability.

Shared responsibility
  • Partner controls
    • Brand and domain
    • Theme and presentation
    • Offer and pricing
    • Tenant operations
    • Front-line support
  • SecEng-governed foundations
    • Evidence and provenance
    • Validation and claim states
    • Security boundaries
    • Entitlement controls
    • Versioned updates

A clean customer experience depends on explicit control boundaries behind it. Branding cannot substitute for product truth, safe deployment, maintained compatibility, or accountable support.

Pathways

Two white-label pathways

White-label routes should map to the product or platform the partner is taking to market.

Pathway

Security Product White Label

SecEng scanner, APC, evidence, or related capabilities embedded behind another product identity with defined attribution, entitlement, support, audit, and update boundaries.

Pathway

Workforce Platform White Label

Role taxonomy, assessments, labs, readiness scoring, and workforce intelligence delivered inside a learning platform or cyber range.

Control

Release and misuse controls

White-label rights require stronger packaging controls, minimum commitments, security obligations, release coordination, and audit rights because customers experience the capability as the partner product.

Termination

What termination or expiry addresses

At termination or license expiry, the agreement defines: whether new use must stop; whether existing customer use may continue; removal of branding and claims; return or deletion of packages and documentation; support wind-down; and treatment of adapters and derivative integration work.

Validate the licensed experience before production distribution.

The pilot should prove the customer workflow, technical contract, deployment model, entitlement path, evidence behavior, support ownership, version coordination, and commercial assumptions.

Launch lifecycle
  1. 1
    Select licensing model
  2. 2
    Configure brand and theme
  3. 3
    Configure offer and catalog
  4. 4
    Provision tenant
  5. 5
    Acceptance test
  6. 6
    Partner launch
  7. 7
    Operate and support
  8. 8
    Versioned upgrade
Decision gate
  • Ready to launch
  • Conditional launch
  • Revise and retest
  • Hold launch

Production approval follows demonstrated fit and an executed license. A pilot does not itself grant production use, redistribution, sublicensing, exclusivity, source access, or indefinite support.

Define the rights, responsibilities, and protected boundary before productization

Bring the intended customer experience, deployment model, distribution path, and support expectations. We will identify the appropriate licensing model, protected IP boundary, pilot scope, and conditions required for production.