Refer, Resell or Integrate.
Earn €399 Per Pentest.

Your clients, your audience, or your own product needs pentesting. SQUR delivers enterprise-grade reports in 24 hours at €1,995. Introduce them and earn 20%, bundle us into your own service at volume pricing, or build the integration with us.

€399
Per pentest (20%)
180d
Attribution window
0
Exclusivity or minimum

What You're Recommending

SQUR is autonomous pentesting that your clients can afford, understand, and act on. Here's why it converts.

€1,995
Flat fee per pentest
vs €15-30k traditional
24h
Report delivery
vs 4-6 week wait
Human parity
vs a top pentester
autonomous verification
EU
Brussels-hosted data
GDPR compliant
NIS2
Pentest evidence
for Art. 21 & §30 BSIG
0
False positives:
only verified findings

Three Ways to Partner

Start with the one that describes you. The commercial track comes next, and the two combine freely.

Resellers, MSPs & MSSPs

You already deliver security for other companies

Bundle SQUR into the packages you already sell. Buy at volume pricing, deliver a full pentest in 24 hours without hiring testers, and keep the client relationship end to end. MSPs and MSSPs are themselves in scope of Implementing Regulation (EU) 2024/2690, which requires documented, risk-based security testing: a SQUR pentest is the test and its documentation in one.

Volume pricing from €1,595 per pentest
Deliver in 24h with no bench of testers
White-label report option (in development)
Dedicated account manager
Apply as a reseller →
Referral & Affiliate

You advise, audit or teach, and pentesting keeps coming up

vCISOs, compliance consultants, auditors and security creators. Make the introduction, we deliver the engagement, you earn 20% of every pentest that lands in your 180-day window.

€399 per paid pentest (20%)
180-day attribution window
No exclusivity. No minimums.
Co-branded NIS2 security testing package
Apply as a referral partner →
Technology & Integration

You build the platform your customers already work in

Put proof of exploit next to the code, the ticket or the pipeline where the fix actually happens. The integration API is in development, so early partners shape what it exposes.

Integration API in development, early access open
Joint go-to-market with your customer base
Listed as a SQUR technology partner
Commercial terms agreed per integration
Talk to us about an integration →

Three Tracks. One Program.

Whichever of the three you are, this is how the commercial side works. Pick the track that fits how you want to work. Switch anytime.

01

Referral Partner

Introduce a client or contact to SQUR. When they order and pay for a pentest, you earn 20%. No delivery work, no account management, just introduce and earn.

€399 per paid pentest (20%)
180-day attribution window
No exclusivity. No minimums.
Monthly payouts via bank transfer
02

Active Ambassador

Actively promote SQUR to your network, audience, or clients. Get a co-branded NIS2 security testing package, dedicated partner collateral, and priority support.

20% commission + co-branded materials
NIS2 security testing package
Partner portal + tracking dashboard
Listed as SQUR Certified Partner
03

Reseller / White-Label

Bundle SQUR into your service packages. Buy credits at volume pricing, with white-label reporting for your own brand in development.

Volume pricing from €1,595/pentest
White-label report option (coming soon)
API access for automation (coming soon)
Dedicated account manager
20% commission 180-day attribution No exclusivity No minimums Monthly payouts GDPR compliant Brussels-hosted data

Common Questions

How does attribution work?
When someone clicks your referral link, a 180-day cookie tracks the attribution. If they order and pay for a pentest within that window (even after multiple visits), you earn €399. Repeat orders by the same client within 12 months of their first paid pentest earn the same commission. You can also manually attribute referrals by emailing us with the client's name.
When do I get paid?
We run monthly payouts via SEPA bank transfer on the 15th, for every client payment received in the previous month. Commission is earned when the client has paid, not when the test completes. You'll receive a self-billing credit note each month.
Is there a minimum number of referrals required?
No. You can refer one client a year or one hundred. The program is designed to be zero-friction: refer when it makes sense for your clients, earn when they pay.
Can I use SQUR under my own brand for my clients?
Not yet. White-label reporting is in development for the Reseller track (Track 3). Today Track 3 gives you volume pricing and 24-hour delivery, and you keep the client relationship end to end. Apply as a reseller and tell us white-label matters to you: that is what moves it up the roadmap.
We build a platform. Can we integrate SQUR into it?
That is the Technology & Integration path. The integration API is in development, so early partners help decide what it exposes and in what shape. Apply with "Technology / Integration Partner" and we'll walk through your use case; commercial terms are agreed per integration rather than fixed.
What does the NIS2 security testing package include?
A structured pentest report with documented scope, test methodology, findings, criticality and concrete remediation actions. It helps your clients document their security testing and the effectiveness of their cybersecurity measures under NIS2 Article 21(2)(e) and (f), and for German entities under Section 30 BSIG, which requires compliance to be documented. For entities covered by Implementing Regulation (EU) 2024/2690, such as managed service providers and cloud providers, the documentation supports the security testing requirements in Annex point 6.5. It does not certify NIS2 compliance and it is not a submission format: NIS2 does not define one. Available to Active Ambassadors (Track 2) and above.
Does NIS2 require a penetration test?
Not in those words. NIS2 requires organisations to handle vulnerabilities and to assess whether their cybersecurity measures are effective (Article 21(2)(e) and (f); Section 30(2) BSIG in Germany). For several regulated digital sectors, including MSPs, MSSPs and cloud providers, Implementing Regulation (EU) 2024/2690 goes further: it requires risk-based security testing with documented scope, timing, results and mitigation, and names penetration tests among the possible test types. A SQUR pentest supports all three duties. It finds and validates exploitable vulnerabilities, it tests whether existing controls actually stop attacks, and it records methodology, scope, findings, severity and remediation evidence.

Apply to the Partner Program

Takes 5 minutes. We'll reach out within 24 hours with your referral link and partner materials.

By applying you agree to our referral partner terms. We do not sell or share your data. GDPR compliant.