For MSPs

MSP white-label file transferyour clients recognise

Sell a branded share, file-request, and workspace portal under your service line. Files stay in the cloud tenancy you designate. Audit is ready for the client security questionnaire.

Give each client a portal that looks like your MSP. You keep the brand. They keep object storage and identity where you design the tenancy. Trustholm orchestrates invites, expiry, quarantine, and hash-chained audit.

White-label hostname · Multi-tenant · SIEM export for the QBR pack

Why MSPs still lose the handoff

You already run the tenant. Then a lawyer, insurer, or customer CISO asks for a board pack, an incident export, or a contract set that must not travel as an email attachment. Technicians reach for OneDrive links, a personal Dropbox, or whatever GoAnywhere HTTPS form another vendor left behind.

The client notices. Your brand disappears at the moment trust is being tested. The next questionnaire asks who downloaded the file, when, and whether the file lived on a third-party MFT estate that made the news in 2023.

MSP white-label file transfer is the service-line answer: same motion you already sell (secure exchange for clients), presented as you.

Night view of connected regions representing multi-tenant MSP fleet operations

How the service line should look

Stand up Bridge as a named offer beside your vCISO or compliance retainers. Scope one client motion first: quarterly board packs, incident evidence, or onboarding KYC files.

Brand the hostname and theme. Connect the storage account you want for that client (their Blob, or a storage account you operate on their behalf).

Federate their Entra or Google tenant for staff. Invite guests with Microsoft or Google work login, a one-time email code, or passkey / TOTP when you require MFA.

Walk a sample diligence workflow in week one: invite, upload, download, revoke, export audit to Sentinel or CSV. Put that walkthrough in the QBR. Expand to more clients only after security and delivery agree the runbook holds.

Govern still owns signed script evidence. Bridge owns the file handoff clients see.

What you can defend in a vendor review

File bytes sit in designated object storage, not in Trustholm's database. Workforce identity stays in the IdP you already bill hours against. Audit streams to the SIEM you already watch, or to CSV if the client is smaller.

Walk invite, upload, download, revoke, and export. That walkthrough is the QBR evidence. You keep the relationship because the portal looks like you and the custody diagram is yours to draw.

Pilot shape we expect

Request access with Bridge selected and MSP in the notes. Name one client and one motion. Bring logo, desired hostname, storage subscription, and IdP tenant.

Stand up one branded motion. Prove audit. Then expand to more clients once security and delivery agree the runbook holds.

MSP outcomes

One product story your vCISO, service desk, and account managers can repeat.

Your brand on the portal

Clients land on your hostname and theme. Useful when you already white-label PSA, security, or backup.

Per-client tenancy pattern

Multi-tenant control plane with SCIM where you need joiner-mover-leaver. Storage and IdP stay in the design you choose per client.

Evidence for the QBR

Who accessed what, when, with export into Sentinel, Splunk, webhook, or CSV.

What you take to the QBR

In the product

  • White-label hostname and theme for the MSP service line
  • Share, file-request, and workspaces with guest MFA
  • BYOS to Azure Blob, GCS, or S3 you designate per client
  • Entra, Google Workspace, or SAML for staff
  • SIEM and CSV audit for questionnaires

What you can show

  • A portal that presents as your MSP
  • Storage and IdP design you choose per client
  • Who accessed what, when, ready for the QBR pack
  • Guest MFA on every invite you send
  • One motion you can repeat across the book

Ready to put your brand on the handoff?

Request MSP Bridge access with one client motion named. We will scope brand, storage, identity, and the audit export your QBR already promises.

Frequently asked questions

Can we white-label Bridge completely?

Hostname, theme, and email identity are part of the offer. The control plane remains Trustholm. File bytes remain in the storage you connect.

Do we need one Bridge tenant per client?

Multi-tenant is shipped. How you slice storage accounts and IdP apps per client is a design choice we scope in onboarding.

Will this replace the client Dropbox?

For governed handoffs, yes. Clients land on your hostname. Files stay in the storage you designate. Everyday team sync stays in Microsoft 365 or whatever collab they already pay for.

Is there an Outlook add-in we can white-label?

Staff send and receive from the branded portal today. Outlook and Teams Send via Bridge is available as Preview for allowlisted tenants. Ask on the access form.

Can technicians invite guests without a tenant admin?

Sharer self-service ACLs are part of the product vision: owners manage recipients without waiting on a global admin for every invite.

How does this sit next to Govern?

Govern proves signed PowerShell beside the RMM. Bridge is the client-facing file portal. Same company trust hub, different product app.

How do we start?

Request Bridge access, name one client motion, and bring brand plus storage plus IdP details. Product app: bridge.trustholm.com.