Cairnpoint Beta

Risk assessments your MSP can run, brand, and deliver.

Security assessments win MSP business — but running one usually means a pile of scripts, a spreadsheet, and a weekend of report writing. Cairnpoint packages the whole engagement: scan, discover, score, and deliver a report your prospect's leadership will actually read.

Now in beta — a 14-day free trial, no charge until it ends.

How it works

From first call to signed roadmap

Every assessment moves through five stages in the console — the pipeline view tracks each prospect from first link to delivered report.

1 stages 1–2

Send the link

Generate a private questionnaire link for the prospect. They answer plain-language discovery questions on their own time — no account, no software to install.

2 stage 3

Run the scans

Kick off a passive external attack-surface scan and a read-only Microsoft 365 posture review from the console. Safe to run against a prospect — nothing intrusive, nothing to deploy.

3 stages 4–5

Deliver the report

Cairnpoint scores everything against recognized frameworks and produces an executive-ready, white-label report — with a prioritized roadmap that becomes your statement of work.

Product tour

A look inside

Beta

The assessment console — every prospect in one pipeline view, from first link to delivered report.
Assessment detail — external scan grade, Microsoft 365 posture, and a 30/60/90 roadmap built from the findings.
The prospect's view — a plain-language questionnaire completed from a private link, no account required.

Make every report yours

Cairnpoint reports are white-label to the core. Set your identity and cover logo, choose the report graphics, and map your security stack — all self-service, per tenant, from the Settings console.

Report graphics — pick the posture gauge and remediation-timeframe styles, with a live preview of how each client's report prints.
Report brand — the company identity printed on every report you deliver; leave a field blank and it falls back to a generic default.
Your security stack — map your tools per capability and choose, per capability, whether the client report names them or stays generic.

What's inside

The full assessment, one platform

External scan

External attack-surface scan

Email authentication (SPF, DKIM, DMARC), TLS and certificate health, exposed services, breach exposure, and web security headers — gathered passively, so it is safe to run before you have any access at all.

M365

Microsoft 365 posture review

A read-only look at the tenant identity and security configuration most small businesses run on, surfacing the gaps that matter before they become incidents.

Discovery

Guided discovery questionnaire

Structured, plain-language questions mapped to CIS Controls v8.1 IG1 — built to work in a sales call or an onsite walkthrough, answered by people who are not IT professionals.

Frameworks

Framework-mapped findings

Findings score against CIS Controls v8.1 and NIST CSF, with compliance overlays for HIPAA, the FTC Safeguards Rule, Cyber Essentials, and CMMC — plus cyber-insurance readiness and critical-infrastructure reporting checks where they apply.

Reports

White-label reports, yours to shape

Polished DOCX and PDF under your brand: an executive summary with visuals for the decision-maker, and per-finding detail with plain-language and technical remediation for your engineers. Set your company identity, upload a cover logo, and edit the report copy and section headings yourself — no ticket to us.

Graphics

Report graphics, your way

Choose how the security-posture gauge and the remediation-timeframe banner print — three styles each — with a live preview that shows how a real client’s report will look. Each report reflects that client’s own CIS coverage and risk mix.

Your stack

Your stack, named in the report

Map your tools to each security capability. The client-facing report names your products where you want it to — or keeps them generic — and anything you don’t offer yet reads as a recommendation, never a gap. Your internal technical report always names names.

Roadmap

Effort-vs-impact roadmap

Findings rank into a prioritized plan — quick wins first, projects after — so the report ends with a path forward instead of a wall of red.

Tenancy

Multi-tenant by design

Every MSP signs in with its own Microsoft Entra tenant. Your prospects, assessments, and reports are scoped to you — never pooled with anyone else’s.

Access

No standing vendor access

Third West Labs holds no persistent access to your data. Support access exists only when you mint a short-lived code from your own console — time-boxed, permission-scoped by you, and audited.

Founding partners

Built with MSPs, for MSPs

Cairnpoint grew out of assessments run for real clients, and it's live in beta alongside a founding cohort of MSP partners who shape the roadmap. Start a 14-day free trial and run your own assessments today — or get in touch if you'd like a say in where it goes next.

Named for the stone cairns that mark a route through open country: a good assessment should tell a client exactly where they stand — and which way to go next.