White label security reporting means a security platform generates client-facing reports carrying the reseller's own branding rather than the vendor's. This article covers what a report needs to contain, how the branding actually works in a platform, how to check what you are getting, and where ShieldMarc's own reporting sits today, including what it does not do.
Contents
- What white label security reporting is
- How white label reporting actually works in a platform
- Why white label reporting matters for MSPs
- How to check what a reporting platform actually gives you
- What good white label reporting looks like
- Common misunderstandings about white label reporting
- Where ShieldMarc fits
- Start today
- Frequently asked questions
What white label security reporting is
White label security reporting means a security platform's output carries the reseller's identity, logo, colours, sender name, rather than the vendor's, so the report presents the assessment as the MSP's own. An MSP may want reports to reflect its own client relationship rather than the name of an underlying tool.
There is a real distinction between a plain export and true white labelling. A branded PDF export can still name the vendor in a footer or a portal login screen. Genuine white labelling typically means a custom domain, no vendor mentions at any touchpoint, and a UI that matches the reseller's own design system, per Toucan Toco's guide to white-label reporting.
An MSP could use branded security reports as part of a recurring client service. The report becomes evidence of ongoing work, not just a one-off scan.
This article is not about hosted BIMI, PSA integrations or a reseller programme. ShieldMarc offers none of those today, and that limit matters before you promise a client anything built on them.
How white label reporting actually works in a platform
It helps to distinguish branding a report from white labelling the wider client portal. Template-level branding inserts a logo, colours and a cover page into a generated document; full portal white labelling goes further, with a custom domain and no vendor UI shown at any point a client might see it.
With ShieldMarc, you can choose Export sections and a lookback window, print an Export from your browser, or schedule an HTML email. ConnectSecure's white-label reports page describes dual branding, watermarks, custom headers and footers, and styled spreadsheet exports.
ShieldMarc's Exports feature, by comparison, gives you a report name, free-text "Prepared for" and "Prepared by" fields, a 7 to 180-day lookback, and section toggles for DMARC, SSL, uptime and DNS change status. There is no logo upload, no colour options, and every report ends "Powered by ShieldMarc". That makes it a labelled export, not a white-labelled document, and worth knowing before you quote a client on the strength of it.
Ask about the logo
Does the report carry your logo and colours, or only free-text fields
Ask about the sender
Does the email come from your domain or the vendor's no-reply mailbox
Ask about the footer
Does the document mention the vendor anywhere, including the footer
Ask about the portal
Do clients log into a branded portal, or do you forward files manually
Ask about the PDF
Is the PDF vendor-rendered, or generated through a browser print dialog
Why white label reporting matters for MSPs
A branded report reinforces that the MSP, not a third-party tool, is the source of the assessment and the expertise behind it, which can help justify a retainer rather than a one-off fee. The Websentry guide argues that adding security reports to care plans can improve retention by showing clients what they are paying for.
The limit is straightforward: a report is only as credible as the checks behind it. A polished PDF wrapped around a shallow scan does not change what was actually tested, whoever's logo sits on the cover.
There is also an audit angle. A dated report with named sections gives a client something to show an insurer or an auditor, separate from formal certification. ShieldMarc itself holds no SOC 2 report, ISO 27001 certificate or Cyber Essentials certificate, and its trust page names these as a future goal rather than a current claim.
How to check what a reporting platform actually gives you
Ask a vendor directly whether the report carries your logo, your colour palette and your sending domain, or only free-text fields. Free-text "Prepared for" and "Prepared by" fields, which is all ShieldMarc's Exports offer, are not the same as uploaded branding.
Check whether the client ever sees the vendor's name, in a footer, a portal URL or email headers. ShieldMarc's scheduled emails come from its own no-reply mailbox with a "Sent by ShieldMarc" footer; Exports end "Powered by ShieldMarc".
Find out whether reports are rendered as real PDFs by the vendor or produced through the browser's print dialog. ShieldMarc uses the browser's print dialog for Exports; its public /scan page can email a one-off grade PDF, the only PDF ShieldMarc renders itself.
Confirm what data actually feeds the report. ShieldMarc's Exports draw on DMARC volume and alignment, SSL certificate status, uptime percentages and DNS change status, and exclude the Security Grade, MTA-STS, TLS-RPT, DNSSEC, CAA, domain expiry and lookalikes.
Finally, ask whether client organisations get their own login to a branded portal, or whether the MSP downloads and forwards reports manually. ShieldMarc offers no client-side logins today.
Pro Tip: Before promising a client a white-labelled report, open the vendor's actual export and check the footer text and the PDF source, since marketing pages describe the ambition, not always the shipped feature.
What good white label reporting looks like
Good reporting starts with a one-page executive summary in plain English: a single overall grade, the top risks in priority order, and one clear recommendation, per the structure the Websentry guide recommends. The Websentry guide treats the executive summary as the page non-technical stakeholders will read.
Beneath the summary, a thorough report covers certificate validity and expiry, DNS and email authentication status, and any security header issues, each explained in business terms rather than protocol jargon. This is where the technical detail earns its place without losing the reader.
A genuinely white-labelled platform removes vendor branding at every touchpoint, including the URL, emails and error pages, and matches your design system, per Toucan Toco's guide.
The honest middle ground is what ShieldMarc actually offers. Exports cover DMARC, SSL, uptime and DNS change status, with "Prepared for" and "Prepared by" fields, but no logo, no custom domain and a visible ShieldMarc footer.
Labelled export
- Free-text 'prepared for' fields
- Vendor name in the footer
- Browser print-to-PDF output
- No custom domain or portal
True white label
- Logo and colour palette applied
- No vendor mention at any touchpoint
- Vendor-rendered branded PDF
- Custom domain and client portal logins
Common misunderstandings about white label reporting
A customisable settings panel is not the same as white labelling. A logo swap in a menu does not remove vendor branding from every touchpoint, a distinction Toucan Toco's guide makes explicitly.
A branded report does not imply a branded portal. ShieldMarc's MSP plan groups domains under one dashboard for your own team, but gives client organisations no separate login of their own.
- White labelling does not change what is measured, the underlying checks such as SPF, DMARC record validity and certificate expiry are identical whoever's logo sits on the cover page.
- A "Powered by" line is not a defect to hide, it is a fact worth knowing before you promise a client an unbranded document.
- PSA integration and white labelling are separate capabilities, often bundled in buyer expectations but not the same thing; ShieldMarc has neither a PSA integration nor a reseller programme.
Where ShieldMarc fits
ShieldMarc's reporting suits an MSP or IT team that wants dated DMARC, SSL and uptime evidence to show a client, with light labelling through the free-text fields, on the Professional or MSP plans. It does not suit anyone who needs a fully white-labelled client portal, custom domain, logo-branded PDFs or a reseller programme with PSA integrations, none of which exist today.
ConnectSecure's white-label reports page describes dual branding and customisable report templates; ShieldMarc offers neither. ShieldMarc is DMARC-first monitoring with reporting attached, not a reporting platform first. Read why ShieldMarc for the wider platform, or read our vendor comparisons, which cover pricing, coverage and hosting rather than reporting.
I would not sell white labelling as a feature ShieldMarc does not have. If a client asks for a fully branded portal, say so plainly and point them elsewhere; the Exports feature is honest about what it is, and that honesty is worth more than a claim that will not survive a client actually opening the PDF.
Start today
Run a free Security Grade scan on a client domain to see its letter grade and check results before deciding what a report needs to contain. It costs nothing and needs no account.
Start the 30-day trial, no card required, to generate an actual Export and judge the "Prepared for" and "Prepared by" fields and section coverage yourself, rather than from a marketing page.
Before committing a whole client base to any reporting workflow, read the MSP rollout guide for DMARC and weigh a branded PDF, a portal login and simple proof of monitoring against what your clients need.
Frequently asked questions
Is white label security reporting the same as a white-labelled platform?
No. White label reporting can mean just the output document carries different branding, while the underlying platform, login screen and support channel still show the vendor's name. A fully white-labelled platform removes vendor branding at every touchpoint, including a custom domain and matching UI, per the SaaS white labelling distinction. Ask a vendor specifically which one they offer before assuming a branded PDF means a branded portal.
Does ShieldMarc offer white label reports?
ShieldMarc's Exports feature lets you set a report name and free-text "Prepared for" and "Prepared by" fields, choose a 7 to 180-day lookback, and pick sections covering DMARC, SSL, uptime and DNS change status. There is no logo upload, no colour customisation, and every report carries a "Powered by ShieldMarc" line, so it is labelled rather than white-labelled. PDF output uses the browser's print dialog rather than a vendor-rendered PDF, available on Professional, MSP and the 30-day trial, not the free Starter plan.
What should a good security report to a client include?
A one-page executive summary in plain English with a single overall grade, the top risks in priority order and one clear recommendation. Detail sections should cover certificate validity and expiry, DNS and email authentication status, and any security header issues, explained in business terms. A dated report shows when it was produced; in ShieldMarc's Exports, the lookback window applies only to DMARC data.
Can I resell ShieldMarc under my own brand?
ShieldMarc has no partner or reseller programme and no PSA integrations such as ConnectWise, Autotask or HaloPSA today. The MSP plan includes 100 domain slots, with more in buckets of 50 for £40 a month, managed from one dashboard by your own team, but client organisations get no separate login or white-labelled portal. If you need a reseller programme or full white labelling, ShieldMarc offers neither today, so raise it before you commit rather than after.
Sources
- White Label Reporting for SaaS: The Practical Guide
- Professional White-Label Security Reports | ConnectSecure
- White Label Security Reports for Web Agencies: A Guide
