For MSPs and MSSPs

Turn NAC into a managed security service

Offer enterprise-grade network access control to your customers without building and maintaining the underlying NAC platform. Arbiter gives MSPs a multi-tenant cloud NAC platform with isolated customer environments, central management and predictable recurring revenue.

Built for MSP operations

Add a recurring security service, not an infrastructure project

Everything you need to deliver managed NAC across a portfolio of customers, with none of the platform to run yourself. For the longer argument, see why NAC has not fitted the MSP model.

One portal to manage every customer
Dedicated infrastructure per partner
Customer isolation by design
Predictable, capacity-based pricing
No NAC servers, PKI infrastructure or RADIUS clusters to maintain
Security isolation you can sell

Your customers do not share infrastructure with other MSPs

Most cloud platforms are multi-tenant, and MSPs are right to ask what that means if another provider's environment is ever compromised.

With Arbiter, each partner operates on dedicated infrastructure with isolated customer data, policies and certificates. Nothing your customers depend on is shared with another MSP, so you can give them a clean, defensible answer rather than a multi-tenant promise. The Trust Centre sets out how that data is stored, encrypted and accessed.

What an MSP partnership looks like

Every MSP receives a dedicated Arbiter environment that hosts their customers. Customer policies, certificates and authentication data stay isolated from other partners, giving you a clean security and compliance story to take to your customers.

Your own partner portal
Sign in at your-shortname.arbiter.ie with your team’s identity provider. See every customer tenant you manage in one list, drill into any tenant for full policy and authentication visibility, branded as Arbiter or co-branded by arrangement.
Dedicated database
Your customers’ policies, endpoints, authentication logs and per-tenant PKI live in a database that no other MSP touches. Per-block backups and per-block restore drills. A clean data story for any customer who asks where their information sits.
Two identical nodes, no single point of failure
Every block ships as two matching nodes, each running the complete stack. There is no load balancer in front of them to fail: each customer appliance is given both addresses and moves between them on its own. Either node can take over the database automatically, in seconds, with no manual promotion and no operator awake.
Predictable, isolated capacity
One block is validated for up to 10,000 authentications per minute across many customers concurrently, with comfortable failover headroom. Issues at another MSP’s block cannot affect yours. The blast radius for any operational event is bounded to one block.

How partner pricing works

An MSP partnership starts with a partner block that supports up to 50 customer environments, with more blocks added as your portfolio grows. You purchase total endpoint capacity and allocate it across customers at your discretion: one could carry several thousand endpoints, another a handful, with the ability to rebalance at any time as your portfolio evolves.

Every tier carries the same feature set. There is no feature gating at Arbiter, no advanced licence and no add-ons to bolt on later. Tier selection per tenant is purely a function of endpoint count, so you size each customer to fit their estate without losing any capability.

Tenant tiers within a block

  • Trial: short evaluation tenants, no production SLA.
  • Essential: up to 100 endpoints.
  • Professional: up to 500 endpoints.
  • Enterprise: up to 1,500 endpoints.

Same guest portal, same MDM integrations, same policy engine, same SIEM forwarding, same retention controls across all of them. The only thing that changes between tiers is how many endpoints the tenant can authenticate.

Channel partner pricing is discounted from the public per-tenant rates with volume terms for larger block commitments. Add a second block when you outgrow the first, with no tenant migration required for existing customers. Specifics are agreed during partner onboarding based on your expected portfolio shape.

The business case

What the service looks like commercially

NAC has been hard to package as a managed service because every customer needed its own platform build. The economics change when the platform is shared and the per-customer work is configuration rather than infrastructure.

Recurring revenue, not project revenue

Each customer becomes a monthly subscription rather than a one-off deployment. You buy block capacity at channel rates and allocate it across the portfolio, rebalancing as customers grow or leave. Adding a customer is a tenant, not a build.

No platform cost to carry

There are no NAC servers, RADIUS clusters, certificate authorities or high-availability pairs for you to license, host, patch or be woken up for. The two nodes in a block and the per-tenant PKI are operated for you, so the cost of serving one more customer is capacity rather than infrastructure.

The same product at every size

Every tier carries the full feature set, so the same guest portal, MDM integrations, policy engine and SIEM forwarding go to a 40-endpoint practice and a 1,400-endpoint manufacturer. Tier is a function of endpoint count alone, which keeps quoting simple and removes the conversation about which capabilities a smaller customer has to give up.

A low-friction way in

Not every customer is ready for enforcement on day one. Asset Discovery is a visibility-only tier that profiles and inventories devices without enforcing access, so you can land a small first engagement and hand over an audit-ready asset register. When the customer is ready it upgrades to an access-control tier without rebuilding the inventory or starting a separate project. See why traditional NAC has to change for SMEs.

Demand you are not creating from scratch

NIS2, cyber-insurance questionnaires and customer supply-chain assessments already push SMEs to evidence asset visibility, authentication and access control. That work lands on whoever runs their network. The regulatory overview sets out what is being asked for and where NAC fits.

Built to scale with your customer base

The detail behind the model: published capacity figures backed by public stress and soak testing. Every figure below maps to an Arbiter dev-log with methodology and test data available for review.

Per-block capacity

A standard partner block supports up to 50 customer environments, with additional blocks added as your managed NAC portfolio grows. A block is two identical nodes on dedicated infrastructure:

  • Two matching nodes, each running the complete stack
  • No load balancer in the path, so there is no shared component to fail
  • Automatic database failover between the two, in seconds
  • Per-tenant PKI and policy isolation

Neither node is the spare. Both serve authentication at the same time, and each customer appliance holds both addresses, so it moves between them by itself without waiting on anything in the middle. Adding a block adds capacity and redundancy together.

Customer tenantsTenant 1 (per-tenant PKI)Tenant 2 (per-tenant PKI)...up to 50 tenants...Tenant 50 (per-tenant PKI)RadSecRadSec (standby)Arbiter block (dedicated infra)Node ARadSec · RADIUS policy · API · databaseholds the databaseNode BRadSec · RADIUS policy · API · databaseready to take overautomatic failover+ next block(same shape)
Two identical nodes to a block, with no load balancer between customers and the platform. Add a block alongside for horizontal scale: same shape, no architecture change, and existing customers stay where they are.

Validated aggregate block capacity:

  • 10,000 RADIUS authentications per minute sustained across all tenants
  • 2,000 mixed EAP-TLS and MAB authentications per minute across real European WAN paths
  • Up to 10,000 authentications per minute for an individual tenant (validated independently, not concurrently across all fifty)
  • Approximately 420 EAP-TLS handshakes per minute per tenant on the crypto-heavy path

Validation included:

  • Single-tenant ceiling testing
  • Four-hour multi-tenant soak testing
  • Multi-region WAN authentication testing
  • 2.7 million total authentication events processed

Authentication performance

Under sustained peak load:

  • End-to-end p99 authentication latency remained below two seconds
  • Typical steady-state p99 latency measured between 1.1 and 1.4 seconds
  • Internal queue utilisation remained below 2% of configured ceilings
  • No authentication-path drops or queue overflow observed during soak testing

Approximately one second of reject latency comes from FreeRADIUS defensive delay behaviour applied to failed authentications industry-wide. Arbiter processing time itself measures in low milliseconds.

Tenant isolation and correctness

Across 2.7 million authentication events:

  • 100% policy-decision accuracy
  • No observed cross-tenant policy or certificate contamination
  • 99.997% EAP-TLS reject reliability

Each tenant operates with:

  • Dedicated FreeRADIUS virtual servers
  • Independent certificate trust chains
  • Isolated policy evaluation
  • Isolated audit logging

Real-world MSP sizing

Arbiter is designed for SME environments rather than large enterprise campus estates. Typical peak authentication rates observed in SME environments are substantially below tested platform ceilings:

EnvironmentApproximate peak auth rate
50-endpoint office~25 auth/min
250-endpoint SME~80 auth/min
500-endpoint SME~150 auth/min
2,000-endpoint estate~500 auth/min

A full partner block populated with typical SME customers operates with substantial headroom against the tested 10,000-authentication-per-minute ceiling. As your portfolio grows you scale horizontally by adding more blocks, with no tenant migration or architectural change required.

Per-tenant protection

Each tenant operates under independent rate limiting set relative to contracted endpoint count. A misconfigured supplicant, authentication loop or flapping NAS at one customer cannot consume shared listener capacity or impact co-tenants on the same block. Isolation is enforced technically rather than operationally.

Current validation roadmap

The following scenarios are currently undergoing validation testing:

  • Eight-hour sustained EAP-TLS endurance testing
  • Higher EAP-TLS concurrency scenarios
  • FreeRADIUS restart under load
  • Database failover testing
  • Edge-to-cloud network partition testing
  • Formal uptime SLA validation

Source dev-logs: round one, round two, round three. Figures update as new rounds publish.

Become an Arbiter partner

Partner onboarding is by introduction. Tell us about your portfolio, the customer sizes you serve and any regulatory requirements you need to meet.

Talk to us about a partner blockExplore the live demo