A network test and the step before it
Kaseya's vPenTest documentation describes a full-scale network penetration-testing platform for scheduled internal and external tests. Published capabilities include simulated attacks, exploitation, privilege escalation, password cracking, lateral movement, reports, and compliance-oriented evidence. Internal testing uses an agent on a physical or virtual host.
SCOUTz does not attempt exploit validation. It starts with supported public evidence and asks what that evidence justifies saying. If the customer approves a Microsoft 365 review, the MSP can add read-only configuration and metadata. Deeper network testing remains a separate, explicitly authorized step.
The tools answer different questions. SCOUTz asks whether there is a responsible reason to continue and what access is justified next. vPenTest asks what an attacker could do within the agreed test scope.
Who vPenTest is right for
vPenTest is a fit for an MSP that can obtain authorization for internal or external network penetration testing and wants a repeatable platform for running that work. Kaseya's help system describes organizations, agents, scheduled assessments, reports, and internal and external test options.
The current Vonahi product page says internal work uses a deployed agent or VM and produces a report after the assessment. It also describes white labeling, multi-tenant use, flexible IP-block pricing, and on-demand or recurring tests.
An MSP evaluating vPenTest should review authorization, target scope, safe-testing controls, agent placement, excluded systems, scheduling, report validation, retest handling, and how findings enter the PSA.
Who SCOUTz is right for
SCOUTz is a fit when the MSP has not yet earned permission to test the network. A public account review can prepare the seller and buyer without deploying an internal agent or exercising a target. The output names what was observed and what the public source cannot answer.
The product can then support the trust progression. A prospect may agree to a read-only Microsoft 365 review before agreeing to an internal network test. That intermediate step can replace some assumptions with supported identity, application-consent, configuration, and activity metadata.
If the evidence supports a penetration test, SCOUTz can help define the business reason, owner, desired outcome, and verification expectation. The test itself belongs to vPenTest or another qualified provider.
Access changes the claim
vPenTest documentation says an internal agent acts as the platform's connection to the environment. Current installation guidance calls for an Ubuntu host with specified compute, storage, network, and outbound-connectivity requirements. The test container is used during the assessment and removed afterward according to Kaseya's VM update documentation.
That authorized position can support conclusions about exploitable paths, privilege movement, password behavior, and control effectiveness within the test scope. SCOUTz public evidence cannot support those claims and does not use that language for its public findings.
SCOUTz can still make the later test better. It can record the original condition, the question it created, the reason deeper testing was approved, and the result that should be verified after remediation.
Where each sits in the relationship
SCOUTz operates at prospect selection, preparation, discovery, and the first approved cloud review. Its access ladder is designed for the stage where the buyer is still deciding how much trust to grant and whether the MSP understands the problem.
vPenTest operates when the buyer has agreed to a test scope and authorized targets. It can support proposal validation, compliance work, recurring testing, and technical proof after the relationship is sufficiently developed.
The timing is important even when vPenTest is used for prospecting. A prospecting test still requires agreed targets and the permissions needed for the selected internal or external method. The sales label does not remove the authorization requirement.
Pricing and buying terms
Vonahi's public MSP page describes flexible pricing based on IP blocks but does not publish a complete current price table. Buyers should request current pricing and confirm the included IP blocks, internal and external tests, organizations, agents, reports, retests, integrations, and contract terms.
SCOUTz publishes a $279 monthly list price. Open Beta includes 30 days at $0 and clear conversion terms. An agreed beta rate is protected for three years. Annual billing receives a 10 percent discount that stacks with the agreed beta rate.
The correct cost comparison includes labor and risk. Include agent deployment, scope development, authorization, test windows, report review, remediation, retesting, and the sales value of the evidence before access exists.
Running both and considering alternatives
A practical sequence starts with SCOUTz preparing the account and the first conversation. The MSP identifies a supported public condition, documents the limit, and explains why an authorized network test may be useful. The customer approves the scope because the ask is now tied to a specific question.
vPenTest can then run the authorized internal or external test and provide deeper technical evidence. Findings move into the MSP's remediation workflow. SCOUTz can preserve the account story and verify supported observable changes, while vPenTest handles retesting within its own scope.
Sprocket Security is another option to evaluate when an MSP wants continuous penetration testing with a mix of automation and human expertise. It belongs in the later, authorized-testing stage as well. Compare method, tester involvement, scope, retesting, reporting, and partner delivery before selecting either platform.
vPenTest by Vonahi