OptiTech provides multiple options for building compliance services on the platform, whether you advise clients, manage their IT, or run your own product. Choose the approach that best matches your business.
Partner plan for MSPs and advisors
Best for: IT service providers, accounting firms, and advisors who manage compliance for many clients
Use this approach if you run compliance work for a portfolio of clients and want one console instead of one login per client. This includes everything in the standard plans, plus multi-tenant management built for service delivery.
Key features:
- Multi-tenant console with one view across every client
- Volume pricing that scales with your portfolio
- Client-level roles, so your staff see only their assigned clients
- Standardized playbooks you reuse across engagements
- Revenue share for referred subscriptions
- Dedicated partner support channel
Example use cases:
- MSPs whose SMB clients keep asking about NIS2
- Accounting and audit firms adding compliance services
- vCISO practices running client programs on one platform
- Law firms operationalizing their advice
Vendor network flow
Best for: Companies that want their suppliers compliant without forcing tools on them
Use this approach when you need to assess your supply chain, as NIS2 and DORA require, without requiring your vendors to buy anything first. Vendors receive your questionnaire, answer in a free OptiTech account, and can optionally upgrade to run their own program later. This is ideal for supply-chain-heavy businesses that need coverage fast.
Key features:
- Free vendor accounts, no purchase required to answer
- Answers stay current instead of dying in PDFs
- Vendors reuse their answers for the next customer who asks
- Risk classification lands in your register automatically
- Shareable compliance passes in both directions
Example use cases:
- NIS2-covered companies assessing their suppliers
- Financial institutions building their DORA ICT register
- Public sector suppliers forwarding requirements downstream
- Large enterprises standardizing vendor assessments
- Groups rolling out one assessment standard across subsidiaries
- Procurement teams replacing questionnaire email chains
Example implementations:
- A regional energy company assessed 40 suppliers in one quarter; each supplier answered once and reused the answers with other customers
- An IT operations provider received a customer questionnaire, answered in the free account, and upgraded to run its own NIS2 program
- A municipality's suppliers forward the same requirement set to their own subcontractors, extending coverage down the chain
White-label delivery
Best for: Partners who want to deliver compliance under their own brand
Use the white-label approach when you want OptiTech to power your service while your clients see your name. This is the program-per-client model where you run isolated client organizations under your own branding through the Partner plan.
Key features:
- Your logo and colors on the console and reports
- Complete data isolation per client
- Client-facing Trust Centers under their domains
- Configure plan limits per client
- Track engagement for your own billing
- Full API control over client resources
Example use cases:
- MSPs selling a branded compliance service
- Consultancies productizing their methodology
- Industry associations offering member services
- International firms packaging Nordic compliance for their clients
API integration
Best for: Tools and platforms that need to interact with existing OptiTech organizations
Use API integration when you're building a tool or service that connects to existing OptiTech accounts. Your application will interact with organizations and perform authorized actions like reading control status, creating tasks, and pulling reports on their behalf, without requiring direct access to user credentials.
Key features:
- Secure, user-authorized access to OptiTech organizations
- Access control through scoped API keys
- Customers maintain full ownership of their data
Example use cases:
- SOC and monitoring platforms pushing findings into the risk register
- Ticketing systems syncing remediation tasks
- CI/CD integrations that gate deploys on control status
- BI tools that visualize compliance posture
Example implementation:
- An MSP's monitoring stack pushes endpoint findings into client risk registers automatically, so drift shows up in OptiTech minutes after detection
Still not sure?
If you're uncertain which path is right for you, here's a quick decision tree:
-
Do you manage compliance for multiple clients?
→ Use the Partner plan -
Do you need your suppliers assessed without forcing tools on them?
→ Use the vendor network flow -
Do you want to deliver compliance under your own brand?
→ Use white-label delivery -
Are you building a tool that connects to existing OptiTech organizations?
→ Use API integration
Get help
We're here to support you through every step of your partnership.