Attack surface management for MSSPs and agencies
If you run security for other companies, the tooling problem is different. You are not managing one estate - you are managing several that must never mix, reporting on each separately, and absorbing the cost of every client you add.
The pricing problem nobody mentions until the renewal
Most tools in this category bill by asset. For a single company that is merely irritating. For a service provider it compounds: every client you take on adds their domains, their subdomains and their IP addresses to your bill, and the better the discovery works, the more you pay.
Twenty clients averaging thirty assets each is six hundred billable assets. On asset-based pricing, that is well past the published tiers and into a conversation with sales.
AYAsec charges a flat fee per organization. What sets the price is scan frequency, the size of your team and how many workspaces you need - not how many assets those workspaces contain. Enterprise is €450 per month with unlimited workspaces and unlimited members, whatever your clients expose.
That is the whole commercial argument, and it is checkable against our pricing page and against anyone else's.
Keeping clients apart
Each client gets a workspace. Assets, scans, alerts, schedules and integrations all belong to a workspace and do not leak between them. Workspaces have their own name, colour and icon, which matters more than it sounds when you switch between them forty times a day.
Access is controlled at two levels. Organization roles cover your own company; workspace roles - admin, analyst, viewer - cover who sees which client. An analyst assigned to one client cannot see another.
For your own oversight there is an All Workspaces view: every client's posture on one screen, with a per-workspace breakdown, so you can see which client needs attention this week without opening eight tabs.
Everything is recorded in an audit log - who scanned what, and when. When a client asks, the answer is in the system rather than in somebody's memory.
Reporting to clients
Every scan produces a report with a score and a grade from A+ to F, exportable as PDF in a brief form for the client's management and a full form for their technical people.
Reports can also be shared as a link that opens without an AYAsec account, and the link can be revoked. For a client who wants to see their own posture without you provisioning them a seat, that is usually the right answer.
Asset groups roll up to a worst-of grade, so "this client's production estate is at C" is a single number you can put in a monthly report. What makes that number hold up when a client's auditor asks is a separate question.
Automation
There is a public REST API with scoped tokens that can be bound to a single workspace, so an integration for one client cannot reach another. There is also an MCP server, which means an AI agent can list assets, trigger scans and read findings as tools - with the same scope limits and with every call logged.
If your reporting runs through your own systems, that is how the data gets there.
What to check before you commit
Three things are worth knowing in advance rather than discovering in month two.
Every client domain must be verified. Before AYAsec scans anything, the domain has to be proven - a DNS record, a file, or a meta tag. If you already manage your clients' DNS, this is a minute per domain. If you do not, it is a request to each client and a wait. Plan the rollout accordingly.
External only. AYAsec assesses what is reachable from the internet. Internal networks, endpoints and cloud configuration are outside its scope, and if your service covers those you will still need something else for them.
Check the plan limits against your client count. Workspaces are limited by plan: one on Free and Starter, five on Pro, unlimited on Enterprise. Five clients is the practical ceiling below the top tier.
Getting started
Start with one client, ideally one whose DNS you manage. Create their workspace, verify the domain, run Discovery, and see what comes back before you plan a rollout.
The free plan gives you one workspace and weekly scans, which is enough to evaluate the workflow but not to run a practice on.
Frequently asked questions
Can clients log in and see their own data?
Yes, with a workspace role scoped to their workspace. Or share a report link, which needs no account at all.
What happens when we take on a new client?
New workspace, verify their domains, scan. On Enterprise the price does not change.
Can we brand reports as our own?
Yes. Reports can carry your branding rather than ours, which matters when the report is the thing your client actually sees.
Do you charge per client?
No. Workspaces are limited by plan tier, but within your tier an extra client does not change the bill.
Can we automate reporting into our own systems?
Yes, through the REST API with workspace-scoped tokens.
Start with one client whose DNS you already manage, and see what a first scan returns before planning a rollout.