Certified penetration testing without building a team.
Tarian Labs works with MSPs, cloud providers, and IT consultancies who want to offer certified penetration testing to their clients. Three models depending on how involved you want to be. We handle the delivery in every one of them.
Strategic Alliances
Who we work alongside.
We partner with organisations that share our standards. When your provider works with Tarian Labs, you get certified practitioners without the overhead of building an in-house team.
Critical Cloud
Managed Runtime Assurance
Critical Cloud delivers Managed Runtime Assurance for AI-era software. They operate, secure, and govern the cloud, observability, and AI runtime layer behind mission-critical products, powered by Datadog, so teams can ship fast while production stays reliable, secure, cost-controlled, and evidence-ready.
What we deliver together
Continuous Runtime Security Validation
A joint service that connects Critical Cloud's Managed Runtime Assurance model with the practitioner-led offensive security capability of Tarian Labs, shaped from government, defence, and critical national infrastructure experience.
Observe
Critical Cloud keeps the production runtime observable, monitored and operationally governed across cloud, observability and AI runtime environments.
Detect
Detection uses the best-fit tooling for the customer's environment. That may include Datadog Cloud Security, Cloud SIEM, CSPM or other Datadog security modules where already adopted or appropriate.
Validate
Tarian Labs independently challenges the runtime through practitioner-led offensive security testing. This can include cloud and infrastructure assessment, penetration testing, web application testing, API testing, attack-path validation and retesting.
The Assurance Loop
Every engagement follows a structured cycle from scoping through to evidence of closure.
Scope and authorise
Written authorisation with agreed scope and rules of engagement.
Establish runtime context
Critical Cloud aligns telemetry and cloud environment.
Validate like an attacker
Tarian Labs conducts practitioner-led offensive testing.
Prioritise findings
Actionable findings with severity ratings.
Remediate with operational support
Critical Cloud assists with operational improvements.
Retest independently
Tarian Labs confirms fixes work.
Evidence closure
Document what was tested, found, fixed, and verified.
Who it's for
Designed for teams where runtime evidence matters.
FinTech and financial services
For teams facing board, customer, investor, audit or regulatory scrutiny.
SaaS and technology platforms
For fast-moving teams where release velocity can outpace runtime assurance.
Healthcare and MedTech
For businesses where security, resilience and evidence matter to trust.
AI-native and AI-adopting companies
For teams putting AI features, agents or model-backed workflows into production.
Regulated and audit-sensitive SMBs
For companies that need enterprise-grade assurance without building an enterprise-sized team.
Outcomes
What customers get.
Independent evidence that runtime controls have been tested
A practical path from finding to remediation
Retesting that confirms whether fixes hold
Clear executive and technical reporting
Better alignment between security testing and operational improvement
Evidence that can support board, audit, regulator, investor or enterprise customer conversations
A route to ongoing assurance as the environment changes
Why Tarian
Credentials that answer the question.
When a client asks who is doing the testing, this is what you tell them.
Credentials your clients will recognise.
Every Tarian Labs practitioner holds CREST CRT as a baseline. Our Head of Technical Delivery holds CSTL-INF, PriCSP, OSCP, and OSEP. Every engagement is defensible under investor due diligence, ISO 27001 audit, and regulatory scrutiny. When your clients ask who is doing the testing, the answer holds up.
We test. We do not compete.
Tarian Labs is a delivery organisation. We do not manage infrastructure, sell licences, or consult on the same systems you do. Every engagement we deliver makes your relationship with that client stronger, not weaker.
Senior practitioners. Every time.
No account managers, no hand-offs to juniors. The practitioners you speak to are the ones delivering the work. Your clients get the same standard on every engagement, regardless of size.
How we work together
Three models. One standard of delivery.
Choose the structure that fits your business. We will confirm the right model on a call.
Referral Partner
A client asks you about security testing. You make the introduction. We take it from there: scoping, delivery, reporting. You receive a fee when the engagement closes. Nothing else is required from you.
What is included:
- Referral fee on every closed engagement
- We handle all scoping and delivery
- Joint calls available where useful
- No delivery responsibility on your side
Reseller Partner
You sell it. We deliver it. Certified penetration testing sits inside your portfolio under your brand. Your clients see a seamless service. You set the margin. We handle everything behind it.
What is included:
- White-label or co-branded delivery
- Agreed reseller margin on every engagement
- Full scoping and proposal support
- Reporting formatted to your requirements
Strategic Alliance
You have a platform or a customer base with a security angle. We have the delivery capability and the credentials. A strategic alliance puts both to work with shared pipeline, joint go-to-market, and a commercial arrangement built around the long term.
What is included:
- Joint go-to-market planning
- Co-marketing and co-promotion
- Shared pipeline development
- Formal written alliance agreement
Your relationship. Protected.
We work for you as much as for your client.
The concern every partner has is the same: will you go around me and work directly with my client? Here is exactly how we prevent that.
We never approach your clients directly.
Every client introduced through a partner is flagged in our records. We do not market to them, contact them independently, or accept inbound enquiries from them outside of the agreed arrangement.
Everything is agreed in writing first.
No engagement proceeds without a signed partner agreement in place. Your commercial terms, the scope of the relationship, and the rules around client introductions are documented before any work begins.
Strict NDA on every engagement.
The same confidentiality obligations we apply to clients apply to partners. No case studies, no references, no mentions without explicit written permission. What happens in an engagement stays there.
You stay in the loop.
For reseller arrangements, you receive copies of all client-facing communications and reports as standard. You are never in a position where your client knows more about an engagement than you do.
Who this is for.
If your clients are asking about security testing and you do not have a certified answer ready, that is the gap Tarian fills.
Managed Service Providers
Your clients trust you with their infrastructure. When they ask about penetration testing, that trust should stay with you. A reseller arrangement means you own the answer, not just the introduction.
Cloud Service Providers
You migrate clients to AWS, Azure, or GCP. The configuration work is done. But who is telling them whether it is actually secure? That gap is where we come in.
IT Consultancies
You get called in for a project. Security requirements surface. Right now you refer it out and hope the client comes back. A reseller arrangement means you stop sending that work to someone else.
Professional Services
Your clients are hitting regulatory requirements, investor scrutiny, or insurer demands around security. You are the trusted adviser in the room. A referral arrangement means you have a certified answer ready when they need one.
The process
From conversation to first engagement.
Initial conversation
We meet, understand your client base and service model, and agree which partnership structure fits. No long procurement process. Most arrangements are in place within a week of first contact.
Written agreement
Simple, clear terms covering fees or margins, the scope of the relationship, and client protection commitments. Everything documented and signed before any introduction is made.
First introduction
You introduce the client or pass the lead. We handle the scoping call and issue a fixed-price proposal directly or through you, depending on the model. No hidden costs on either side.
Delivery and payment
We deliver to the standard the client expects. You receive your agreed fee or margin on completion. Reports go to you and the client simultaneously on reseller arrangements.
Your clients are already asking the question.
Get in touch to discuss which model fits your business. Most partnership arrangements are in place within a week.