For MSPs & vCISOs

Run vendor risk for every client from one console.

Your clients are being asked for a vendor-risk program and HIPAA BAAs they don't have. That's a service you can deliver — if the tooling doesn't bill you per vendor across dozens of tenants. Covenant is flat per client, multi-tenant, and white-label.

Built for the multi-client reality

One console, isolated tenants, flat pricing

Cross-client console

Every client's vendor portfolio, BAA inventory, and open findings in a single view — with strict tenant isolation so nothing leaks between clients.

Flat per-client pricing

$199 per managed client per month, no per-vendor fee, with volume discounts at 10+ and 25+ clients. Predictable margin on a service you resell.

White-label vendor portal

Send questionnaires and collect evidence under your own brand. Consolidated billing across all clients.

HIPAA BAA tracking per client

For healthcare clients, run the full §164.504(e) BAA lifecycle — the obligation OCR audits hardest — across every tenant.

External scanning at scale

Schedule TLS, header, email-auth, and breach checks per client and surface the riskiest vendors across your whole book.

Evidence that travels

Vendor evidence maps to NIST SR, HIPAA, SOC 2, and ISO and feeds the shared Dosanjh Labs evidence graph for sibling tools.

The resale math

A managed vendor-risk service you can price

Per-vendor incumbents make MSP economics impossible: 20 clients with 30 vendors each is 600 billable vendors. Covenant's flat per-client model means your cost is predictable and your markup is yours to set.

ModelCovenant MSPPer-vendor incumbents
Billing basisPer client, flatPer vendor, per client
20 clients × 30 vendorsPredictable per-client fee600 vendors metered
White-label portalIncludedRare / enterprise-only
HIPAA BAA trackingNativeNot offered
Self-serve onboardingYesSales-led

Add vendor risk to your service catalog.

Start free with one client, then scale to the multi-client console.

Start free →