Help Centre

Frequently Asked Questions.

Straight answers to what security teams, MSPs, procurement and auditors actually ask — in plain English, no marketing fog. 46 questions, grouped so you can jump to what matters.

46Questions answered
9Topics
SOC 2 II+ Cyber Essentials Plus

Product & Positioning

7 questions
We already have an RMM — why do we need RoboShadow?

RoboShadow isn't here to replace your RMM (yet) — it sits alongside it and focuses purely on security outcomes rather than day-to-day device management. It picks up the things RMMs typically don't do well: logging vulnerabilities as tickets into your PSA/helpdesk, pulling risk in from Microsoft 365 and Intune, cleaning up app patching your RMM misses via our curated WinGet integration, CIS Level 1 and 2 benchmarking, triangulating Windows Defender data (even in passive mode behind an EDR), running internal LAN, IoT, external attack-surface and authenticated web scans, and reconciling results with Rapid7, Nessus, Qualys and Tenable so everything lines up. We integrate with NinjaOne and Datto today, and if you want us to link up with your RMM specifically, just ask — the dev team will work it out with you. Best of all, it shows exactly what security work was done each week or month, so MSPs can actually charge for managed security.

Am I paying twice with other products?

No. There'll always be some overlap with Microsoft tooling and with RMMs — patching is becoming ubiquitous, and soon almost every app and platform will offer it. The value isn't in doing patching for its own sake; it's in saving IT teams and service providers real time across the whole find-fix-report cycle while keeping you aware of your vulnerability landscape. We built our own remediation engine because we couldn't get that outcome cleanly from anything else — and with our big agentic automation push in 2026, we needed a solid engine of our own to harness AI properly. Think of us as the find, fix and report engine, not another patch tool bolted on top.

How hard is RoboShadow to use?

It's built to be low-touch — minimal false positives and a genuinely easy platform, so even non-IT people get on fine. There's an AI-driven Virtual CSO you can ask questions of and have remediate issues for you. And because security itself is complex, our support and customer success teams don't just train you on the product — they'll help you understand the underlying cyber principles too. There's also a YouTube channel that walks through the key concepts.

What's on the roadmap for 2026?

Full automation of cyber operations and giving IT teams their time back — if it ticks that box, it's where we're heading. We don't publish a formal roadmap for competitive reasons, but you can see what we're actively building and playing with under Experimental Features in your settings. If you've got specific roadmap questions, our CEO Terry Lewis (terry@roboshadow.com) is happy to answer them directly.

Is RoboShadow open source or proprietary?

A deliberate blend of both, brought into one clear viewpoint so you're not drowning in cyber noise across multiple tools. We use trusted open-source engines like Nmap and ZAP where they're the right tool, and our own proprietary tooling where open-source options don't hit the accuracy or reliability we need. That mix matters because results have to stand up to scrutiny — insurers and legal reviews want to compare apples with apples, so where the right tool doesn't exist, we build it ourselves.

Will it replace my anti-virus or firewall?

No — RoboShadow works alongside your existing antivirus, EDR, firewalls and RMMs, surfacing the vulnerabilities, gaps, misconfigurations and exposures those tools miss on their own. It'll also report on every type of antimalware so you can manage coverage and compliance centrally, and it lets you manage Windows Defender far more closely — including the free version centrally, which normally only the pricier Microsoft 365 plans allow.

Are you building this to sell the company?

No. RoboShadow is privately held, bootstrapped and built for the long game — product quality and our mission come first. We field acquisition approaches and investment offers most weeks and turn them down. The management team already run other successful tech businesses, so this was never about the money; we genuinely love the mission and we're having a lot of fun with it. We don't know exactly where it ends up, but selling out isn't the plan.

↑ Back to top

Pricing & Value

4 questions
I don't need fixing or patching — can't I just use the free version?

Largely, yes — but there's a soft limit, and here's the honest reason why. Almost all of our running cost sits in the continuous read-only agent, not in the fixing part; so the economics only really stack up on our commercial plans, and some tiers run close to cost. We keep a genuine free tier because we mean it: we give the full product away to hard-strapped charities, startups and NFPs like schools to find and fix their issues, and even to distressed end users caught in a security mess. What we can't do is hand unlimited commercial access to everyone for free, or we couldn't keep the lights on for the people who genuinely can't afford it.

Why is MSP pricing based on tiers?

Because MSPs told us that's what works. Most partners need a predictable monthly cost they can package into their own services without the accounting nightmare of per-seat licensing. Our tier structure gives you that certainty, and it means you can roll RoboShadow out widely—or even use it for prospecting—without worrying that your costs will spiral. Our Growth plan handles up to 500 devices, which suits smaller or early-stage providers building out their security offering. From there, most partners move to MSP Plan 1 (up to 1,500 devices), then scale through the tiers as you grow. You get the flexibility to shape RoboShadow into your services, not the complexity of wrestling with per-user pricing.

Is the price going to increase quickly?

No. We designed the pricing to stay affordable and stable because reducing the cost and complexity of cybersecurity actually means something to us. We're backed by the GCHQ and the NCSC for Startups programmes in the UK, and we got into those on a promise to make security cheaper and simpler—not to hike prices later. We're not going to break that promise.

Do you do pricing for charities and non-profits?

Yes, at massive discounts—and in some cases we give the full product away entirely. We joined the GCHQ accelerator programmes specifically because we wanted to make cybersecurity accessible, and that includes charities and not-for-profits. If you just want to run a one-off compliance check and clean everything up, we often do that for free. Get in touch with the team and we'll walk through what we can do for you.

↑ Back to top

For MSPs & Partners

4 questions
I'm an MSP — how do I sell this to clients and make money?

Most MSP clients fall into three camps, and RoboShadow gives you a way to sell to all of them. Those already hacked want reassurance it won't happen again. Those holding customer data need proof they're secure. And the biggest group — those who don't really think about security — change their tune the moment you show them their own risks and where they'd fail an audit. From there you package three chargeable services: a daily SecOps remediation service (a monthly fee to monitor and fix to an agreed standard), read-only visibility and reporting (a smaller fee for eyes-on without fixing), and compliance-framework alignment (keeping them mapped to a recognised baseline). Layering RoboShadow in also keeps clients sticky and harder to poach. There's a full walkthrough in our "How Top MSPs Build Recurring Revenue Through Cybersecurity" video.

Can the platform be white-labelled?

Yes — fully, with both MSP and customer branding. Use your own logo, or for service providers inject your client's, and on some reports show both together. The one exception is subdomain white-labelling, which we don't offer because of the security risks it carries (CORS and supply-chain attacks). If you ever spot a RoboShadow logo somewhere you'd rather it wasn't, tell us and we'll sort it.

How can I use RoboShadow for prospecting?

Brilliantly, and lots of our partners do. Nine times out of ten it goes like this: get one or two agents installed and fire off a LAN scan for a cross-section of device vulnerabilities, drop the prospect's IP addresses and domains into the External Scanner, and ask for Microsoft 365 Global Admin to pull their cloud risks (someone in the business usually has it). That gives you an internal scan, an external scan, a device cross-section and a 365 assessment. Add the AI Pentest and reporting on top and you can hand a prospect a fast, branded vulnerability assessment — without ever bothering their incumbent vendor.

Can I see combined client-level reporting across multiple accounts?

Not yet — there's currently no single dashboard that rolls up all your organisations (whether you're an MSP managing multiple clients or running a multi-organisation tenancy yourself). Right now you'll need to tab between them. That said, our AI features (vCSO) can amalgamate the data on demand if you ask it the right question. We're actively building proper tenant-level dashboards to give you one unified view across all your organisations, which will make the reporting genuinely useful instead of a browsing exercise.

↑ Back to top

Deployment & Setup

4 questions
How difficult is RoboShadow to deploy?

It's genuinely simple. You're up and running within minutes—most organisations have agents installed and scanning before lunch. Deploy lightweight agents via your RMM or group policy, sync with Intune for a one-click Microsoft 365 integration (and we'll keep devices in sync automatically), or use automation through NinjaOne, Datto or whatever RMM you've already got. It's that straightforward. Head to the downloads section for agent deployment docs, or click the Cloud tab to see how to wire up Microsoft 365 and Intune.

How do user permissions work?

Right now, you've got admin (can do anything) and read-only (can't change anything). The part that usually raises eyebrows is that read-only users can run LAN scans and external scans—but here's the honest reasoning: unless you're running specialist kit that genuinely can't handle port scans (like high-grade medical gear), these scans are perfectly safe. Your firewall gets hammered by random bots on the internet (Shodan, etc.) every single day, so our scanners won't break anything. That said, we're splitting permissions into finer-grained roles in 2026, so you'll have more control if you need it.

Will it impact the performance of the machines?

No. Users won't even know it's there. We collect small snapshots of data daily—no filter drivers, no file inspection like antivirus does. It's genuinely lightweight; we get zero complaints on resource usage. The agent plays nicely with everything else on the box and it's a straightforward .NET client.

Will RoboShadow trip EDR?

We run a lot of tools and scripts to do what we do, and the good news is that most mainstream EDR platforms already know us. Occasionally we'll trigger less common EDR, so it's sensible to allowlist RoboShadow if you can—ask your security team and they'll sort it in about five minutes.

↑ Back to top

Scanning & Detection

8 questions
Why isn't there PII scanning in RoboShadow?

Because the dedicated tools already do it brilliantly. Microsoft 365 DLP and specialist third-party platforms own that problem, and we're not going to duplicate their work just to bloat our own. Most PII scanners grafted into vulnerability management tools create a firehose of false positives that drown out the signal. We stay focused on vulnerability management and remediation — that's where we can add real value without adding more noise to your life.

Is vulnerability scanning dangerous?

Standard scanning is completely safe and non-destructive. Our authenticated web scanner can run active scans and generate test queries if you enable it, but it's fully configurable and documented so you control the risk — that's advanced and needs additional setup. The default quick and automated scanning in RoboShadow is safe on any technology that can handle port scans (which is most things). The one caveat: if you're using the LAN scanner on ancient, legacy or medical-grade equipment that's extremely sensitive, go carefully.

How good is the LAN scanner and what will it find?

It's solid at showing you what an attacker would see without authentication. One click runs an IoT scan of your network, then a port scan, then a vulnerability scan over the open ports — all non-invasive and accurate. What it doesn't do (yet) is use vendor-specific plugins to detect particular VMware versions or services, and it's not SNMP-enabled or authenticated to dig deeper into devices for more granular data. We're working on that in 2026. Here's the philosophy: if an attacker already has authentication on your network, you're in trouble — they don't need vulnerable devices, they've got the keys to the kingdom. So we mimic what an unauthenticated hacker actually sees, which is the realistic threat model.

How often does RoboShadow scan?

The agent scans on first boot and wake, then every 12 hours after that. If you're on a Professional licence or above, you can rescan any machine on demand via the portal. The agent is lightweight and takes minimal data — it won't drag your machines down, and it plays well with everything else.

Does RoboShadow benchmark properly against Qualys, Nessus or Rapid7?

Yes, very well — and we sometimes find things they don't. Minor differences in detection logic are normal across all vendors; that's just how scanners work. If you spot something we miss, send it to hello@roboshadow.com and help us tune our logic. The remaining gaps — mainly user profile data — are scheduled to be fully closed by early 2026. One important note: our LAN scanner does "see what the hackers see". We do device discovery to find IoT devices, then a port scan, then banner and header checks against open ports. That's what an unauthenticated attacker actually sees, which is the most common attack. We're not yet running all the vendor-specific plugin libraries for firmware, BIOS and other deep hardware issues — that's coming in 2026.

I'm seeing different data from Qualys, Nessus, Rapid7 or Defender. Why?

It's completely normal — even the big-name platforms show differences because everyone uses different tools and fuzzy logic to match vulnerabilities. Because we manually check every new header, banner and potential vulnerability we've never seen before, we often find things the major platforms miss. We use some AI, but it's primarily a painstaking manual process to keep accuracy high. Here's what drives the gaps:

  • User profiles: Sometimes vulnerabilities live inside user profiles that an attacker can't access unless they're logged in as that user. Admin access would already mean game over anyway — they wouldn't need vulnerabilities to cause damage. We can enable this for you, but we don't turn it on by default to keep noise down. We'll roll it out fully sometime in 2026.
  • Device binaries: Issues hidden in obscure binaries usually need admin access to exploit and create a lot of noise. We're integrating these into the rest of the product in 2026.
  • LAN scanner plugins: Our LAN scanner does IoT discovery, port scans and vulnerability checks over open ports — perfect for showing what an unauthenticated attacker sees. We don't yet have plugins to detect specific VMware versions or services, and we're not SNMP-enabled or authenticated to dig deeper. We're working on this in 2026. The logic is simple: if attackers have network authentication, you're already in trouble and they don't need to exploit vulnerable devices.
Does RoboShadow manage prioritisation with EPSS scores?

We track EPSS scores in the background and could surface exploitability scoring, but we've deliberately chosen simplicity instead. CVSS is the standard the world uses for prioritisation because it works — every major compliance framework builds strict patching regimes around it. You can get caught chasing hypotheticals about what can and can't be exploited, but no Chief Security Officer will bet their job that something marked vulnerable isn't actually exploitable, or that their EDR will catch it in time. Vendors keep improving and need their software updated. Yes, patching can cause problems, but trying to split hairs between ambiguous "maybe we should patch this" scenarios — even with exploit data — is risky. We stick with CVSS because it's the framework everyone relies on for good reason, and we won't add confusion with EPSS or exploitability layers on top.

What vulnerability databases do you use?

We triangulate data from all the global CVE databases, seven major vulnerability sources, and an internal research team that validates gaps and inaccuracies. We don't trust any single source because the landscape is littered with data errors and it changes every day. Our 25-person research team manually checks every application and service change we've never seen before, verifies it, and updates our records accordingly. We use some AI to help, but it's still fundamentally a manual, painstaking process to get accuracy right.

↑ Back to top

Patching, Remediation & AI

7 questions
Should I be worried about WinGet for patching?

No. WinGet is updated daily in line with Microsoft updates and is no less secure than other package managers like APT or YUM. Microsoft manages this repository closely — it's now their main package manager and core to their future compliance and update strategy. If it's good enough for Microsoft, it's good enough for us. That said, there's always a vanishingly small chance a threat actor could fool Microsoft, so we advise sticking to well-known, trusted vendors. If you're running obscure apps, only do it if you know the vendor well.

Can I run my own scripts using RoboShadow?

Not yet — we use scripts extensively in the background to power our fixing capability, but you can't run your own. That's changing in 2026: we're opening it up so you can run custom scripts and manage your environment via scripting. Historically we locked this down for security reasons, but we're moving past that. In the meantime, you can roll out your own apps using Cyber Heal.

Can I see what patches and remediation attempts have been made?

You can dig into logs in the Cyber Heal section to see what succeeded and failed, but they read like real logs — not always the most intuitive. In 2026 we're rolling out a proper remediation report to show you what failed after we've tried everything, and we're pulling in Windows event logs to tell you why (AV blocked it, permissions failed, whatever). That'll tell you the real story. If you want to test it early, get in touch.

This is just an AI pen test, not a real one — what does that mean?

RoboShadow doesn't replace a traditional, in-person, human-led penetration test. What we do is simulate a penetration test using large language models, which cuts the need for SMBs to spend £20,000 on full pen tests regularly. If you can afford a proper adversarial, human-team–driven test, we'd always advocate for that. Our LLMs are framed over vulnerability assessment data, which is the largest chunk of most full pen testing engagements (the bulk of that £10,000–£20,000 cost). Here's why we do this and not live exploitation: vulnerability assessment is a major part of most pen tests anyway, so our LLMs analyse that data and add commentary. We don't currently exploit vulnerabilities — RoboShadow is safe to run on sensitive platforms — and that's deliberate. If a vulnerability exists, it should be fixed regardless of whether it's exploitable or not. Leaving known vulnerabilities in place and hoping other controls catch them isn't good practice. We respect the pen testing community, but if the software vendor says it's vulnerable, you don't need someone spending a day or two exploiting it to prove it. You trust the vendor — they wouldn't damage their reputation lightly. Finding and fixing is our priority; exploitation may come later.

Do I just sit back and let the AI fix everything?

No. AI AutoFix automation can save 60%–90% of the workload and significantly help with bulk remediation, but some things still need manual work:

  • BIOS updates
  • Firmware
  • Open ports and firewall rules
  • Critical services you don't want automation for
  • Obscure third-party applications

RoboShadow automates where there's a clear path and keeps human oversight where it matters. We're expanding the toolset to handle more of the user communication and friction that plagues day-to-day patching, but not everything will be automatic.

Will the AI fix things automatically without permission?

No. We have a read-only mode that keeps everything locked down. Nothing gets fixed automatically unless you enable it — and even then, the AI checks with you before anything goes out to your machines.

Is the AI secure and how does it work?

AI runs using private models via secure providers. We predominantly use Bedrock via AWS, which is private — but you can choose a ChatGPT model for the AI Pen Test (we'll alert you that ChatGPT will see that data). No customer data trains public models unless you opt into ChatGPT. You can keep AI actions in read-only mode using the Virtual CSO, so nothing touches your machines automatically unless you give the AI write access and approve its suggestions.

↑ Back to top

Reporting & Compliance

3 questions
How do I get alerted to new high or critical vulnerabilities?

We give you three ways to stay on top of new threats. For your external attack surface, RoboGuard alerts you by email whenever a new port opens or a vulnerability hits an existing port — we chose email because it's fast and sits outside your helpdesk clutter where it matters most. For internal application vulnerabilities, our PSA integrations log tickets straight into your helpdesk or PSA, and you can set a CVSS threshold so you only see high-impact items. That way noise stays low but nothing critical slips through. We're always open to other alert methods if those don't fit your workflow — just get in touch and tell us what you need.

Does RoboShadow keep historical vulnerability data?

Yes, we store both current and past vulnerability data alongside scoring so you can track how your account is improving over time. We're projecting deeper trend analysis and reporting improvements for 2026, and if that's not yet live on your account, just get in touch and we can enable it for you.

What compliance frameworks does RoboShadow support?

We excel at building clean, digestible compliance reports that you can hand straight to investors, clients and assessors. You pick a framework, we export the evidence needed to prove you're compliant — we handle that side so your assessors can focus on their job. Currently we cover HIPAA, SOC2, NIST CSF 2.0, NIST 800-171, Essentials 8, Cyber Essentials and ISO 27001:2022. If your framework isn't listed, tell us and we'll add it to the product team's backlog. (We've never had a request for a Vanta-style GRC tool to manage evidence — the assessors usually own that part anyway.)

↑ Back to top

Integrations & API

6 questions
Can RoboShadow trigger tickets automatically, and how does it work?

Yes, we'll log tickets automatically for each application (not each CVE, to keep the noise down). You can filter to CVSS thresholds you care about, and tell us which obscure stuff like firewall rules or switch upgrades to ticket separately — we'll let the AI handle it. We don't yet ticket per device, but ask your customer success rep and we can work with you. We integrate with just about every helpdesk and PSA platform out there — ask if yours isn't listed.

Does RoboShadow support APIs?

Yes. The whole platform runs on AWS API Gateway, which keeps us secure and out of reach of most front-end vulnerabilities. We document the API in the portal, and if you want to pull data into your own tools, hit F12 in your browser, find what the portal uses, and reverse-engineer it from there — most people do that first. If you need something specific walked through, get in touch and we'll help.

Do you integrate with Google Workspace?

Not yet, but we're building it for 2026 — we've had enough customer requests that it's now a proper project. Let us know if it's something you need.

Do you integrate with any SIEMs or SOC products?

Not yet, but it's coming. Get in touch and tell us what you'd want — understanding how you'd use it is the first step.

What products does RoboShadow integrate with?

We integrate with the main anti-virus, PSA, and RMM platforms. Here's what we support:

  • Anti-virus: Avast, AVG, Avira, Bitdefender, Check Point, Comodo, Cortex, CrowdStrike, Cybereason, Cylance, Cynet, Datto, Defense.com, Deep Instinct, Defender, Elastic, Emsisoft, ESET, Fortinet, Heimdal, HP Wolf, Huntress, Kaspersky, Malwarebytes, McAfee, N-able, Norton, Panda, SentinelOne, Shadow, Spear, Sophos, Splashtop, Surfshark, Symantec, TotalAV, Trellix, Trend Micro, Vipre, WatchGuard, Webroot, WithSecure
  • PSA platforms: Atera, Autotask, Desk365, Freshdesk, Freshservice, Halo, Jira, Kaseya BMS, ManageEngine ServiceDesk Plus, N-able MSP Manager, Pulseway, ServiceNow, SuperOps, Syncro, Zendesk
  • RMM tools: ConnectWise, Datto, NinjaOne

If there's something else you need, get in touch and we'll see what we can do.

Why do you need write access on Microsoft 365?

You don't — permissions can be limited to read-only if that's what you need. We ask for write access to 365 and Intune because we can fix things for you and roll them out automatically, but if you'd rather we only read, just ask and we'll make that work.

↑ Back to top

Security, Trust & Data

3 questions
Do you have a SOC 2 certificate?

Yes. We hold a SOC 2 Type II report as of March 2026, built into the platform from day one. We're also Cyber Essentials Plus certified (UK), and we get a yearly Crest Certified penetration test to make sure what we claim actually holds up under fire.

How safe is your development and release process?

We treat release like we mean it. No single person can push code to production — every change needs multiple approvals and code review from other developers first. The APIs do the heavy lifting; the web GUI is just a front-end shell so you're not exposed to standard front-end bugs. AI tools continuously scan the codebase for backdoors. Core components (like the Agent) release only twice a year after intensive testing — we're talking military-grade conditions. We've never had a release issue in the 8 years we've been running this. That discipline came from the team's earlier life running mission-critical financial systems for global investment banks. We release agents very slowly by design: we will not rush production code just to ship fast.

Where is your data hosted?

Data is currently hosted in Ireland, chosen for its strong regulatory standing and global trust in its ethics and standards. Global expansion is planned for 2026, particularly to the Middle East and US, so you'll have more options as we grow.

↑ Back to top

If it is not here, our team will answer it straight — no scripts, no runaround.

Talk to us