Who Uses HailBytes

HailBytes SAT and HailBytes ASM are built for three distinct customer profiles — in-house security teams, MSSPs, and offensive-security firms. The product makes different sense for each, and we want to be precise about who it’s for.

Customer Profiles

In-House Security Teams

Mid-market & Enterprise Security

Security teams at organizations from ~200 to 10,000+ employees who want phishing simulation and external attack-surface monitoring without per-seat or per-asset pricing scaling against headcount or asset count.

  • Cloud-first procurement (AWS EDP / Azure MACC drawdown preferred)
  • Strong data-residency or self-hosting requirements
  • Need to audit the platform itself under source-available license
  • Compliance evidence for SOC 2, HIPAA, PCI-DSS, ISO 27001, NIST CSF
MSSPs

Managed Security Providers

MSSPs and managed compliance providers who attach phishing simulation to client SOC 2, HIPAA, and cyber-insurance bundles, billing the client at retainer rates while running on a flat per-instance cost basis.

  • Per-tenant branding, OIDC, and audit-log isolation
  • One-instance-per-client architecture (clean SOC 2 boundary)
  • White-label margins that survive into the 500–5,000-seat range
  • Marketplace co-sell motions on AWS and Azure
MSSP Playbook
Pen-Test Firms

Offensive-Security Boutiques

Pen-test firms and red-team practices who run HailBytes ASM internally as a scoping accelerator and externally as a recurring continuous-monitoring deliverable resold to clients between point-in-time engagements.

  • Internal scoping: 24-hour SOWs instead of week-long recon
  • Reseller model: recurring monthly fee per client instance
  • Pre-engagement recon on every prospect, not just paying clients
  • Custom wordlists, scan logic, and AI-agent orchestration via MCP
Pen-Test Playbook

Deployment Patterns

How customers actually run the platform.

Single-Tenant on AWS or Azure

The most common deployment: one HailBytes SAT or ASM instance per organization, running on a 2 vCPU VM in the customer’s AWS or Azure account. Marketplace charges flow through the existing cloud bill and count toward EDP / MACC commits.

Profile: mid-market and enterprise security teams.

Multi-Tenant MSSP Fleet

One instance per client in a shared MSSP cloud account, with per-tenant branding, OIDC, and audit logging. Tenant data never crosses instance boundaries — the model SOC 2 auditors expect from MSSP-delivered services.

Profile: MSSPs running 5+ active clients on phishing simulation or ASM.

Pen-Test Firm Internal + Client Instances

One firm-internal ASM instance scanning every prospect and active engagement (scoping accelerator), plus per-client white-label instances billed monthly to clients who want continuous monitoring between point-in-time tests.

Profile: offensive-security firms with active recurring-revenue practices.

Government Cloud (GovCloud / Azure Gov)

HailBytes SAT and ASM both deploy in AWS GovCloud and Azure Government. Federal contractors and regulated industries run there for FedRAMP-aligned data residency requirements.

Profile: federal contractors, defense industrial base, and regulated state-level agencies.

Industries We Work With

HailBytes is designed to be vertical-agnostic, but compliance pressure makes some industries especially common.

Financial Services

SOC 2, PCI-DSS evidence pipelines and the cyber-insurance underwriting requirements that landed phishing-simulation programs as table stakes.

Healthcare & Life Sciences

HIPAA Security Rule §164.308(a)(5) explicitly mandates security-awareness training. SAT generates the documented evidence auditors expect.

SaaS & Technology

SOC 2 Type II is procurement table stakes for B2B SaaS. SAT campaigns and ASM scan logs feed the CC2.2 awareness and CC7.1 vulnerability-management controls.

Government & Defense

FedRAMP-aligned deployments via AWS GovCloud and Azure Government. NIST CSF PR.AT and SP 800-53 awareness requirements covered by SAT evidence.

Higher Education

Universities running multi-school phishing simulation programs with per-school branding and reporting, plus continuous external monitoring of large public attack surfaces.

Cyber Insurance & MSSPs

Carriers and MSSPs bundling SAT and ASM as policy-condition deliverables for insureds, with the audit evidence underwriters require.

Become a Reference Customer

We’re actively building out our public case-study program. Twelve months of free access to HailBytes SAT or ASM, plus our highest support tier, in exchange for feedback and a written or video case study at the end of the year. Open to all three customer profiles.

Apply to the Case-Study Program

Talk to Customers Like You

If you’d like an introduction to a current customer running a similar deployment pattern (in-house, MSSP, or pen-test firm), our team can arrange a peer reference call once you’re in active evaluation.

Request a Reference Call
{{ partial "newsletter-cta.html" . }}