Key takeaways
- White-label website security means a specialist does the detection, clean-up and hardening while your clients see your brand.
- It lets an agency offer security and malware removal without hiring a dedicated incident-response team.
- Whole-server coverage matters for agencies, because client sites often share servers and one infection spreads.
- Shareable reports turn invisible security work into something clients can see and value.
- PatientZero's Agency (white-label) plan starts from £299 a month, with unlimited malware removal and no contract.
What is white-label website security?
White-label website security is a service an agency resells under its own brand. A specialist provider monitors client sites and servers, removes malware, fixes the entry point and hardens the stack, while the agency keeps the client relationship and presents the work, and the reports, as its own. Clients get expert security; the agency gets a recurring service line.
For most agencies, security is already part of the job whether they sell it or not. When a client's site is hacked, the first call goes to whoever built it. Without a plan, that means unbilled late nights, uncertain clean-ups and awkward conversations. White-label security turns that reactive, unpaid work into a defined, priced service backed by specialist tooling and incident experience.
It is different from simple referral or reselling a plugin licence. With a true white-label service, the specialist does the hands-on work, from forensic scanning to clean-up and hardening, but the relationship, the branding and the pricing to the client all stay with you. Done well, clients never need to know a second company is involved.
Why do agencies use white-label malware removal?
Agencies use white-label malware removal because incident response is a specialist skill that is expensive to build in-house and hard to keep busy. Reselling a specialist service gives clients expert protection, gives the agency predictable margin and response capacity, and keeps developers on client projects rather than firefighting infections.
| Approach | What it looks like | Trade-off |
|---|---|---|
| Do nothing formal | Fix hacks ad hoc when clients call | Unbilled time, inconsistent clean-ups, risk to reputation |
| Plugins only | A security plugin on every client site | Useful, but blind to server-level backdoors; no one owns the clean-up |
| Build an in-house team | Hire and train incident responders | High fixed cost, hard to cover out of hours |
| Refer clients elsewhere | Pass clients to a third-party security firm | Client relationship and revenue move to someone else |
| White-label specialist | Specialist does the work under your brand | Relies on choosing a provider you trust |
If your agency already installs a security plugin everywhere, our comparison of security plugins and server-side scanning explains the gap a white-label service fills.
How does white-label website security work day to day?
Day to day, the provider connects to your client servers, runs continuous monitoring and scheduled scans, and alerts you when something changes. When an infection is found, they clean it, fix the entry point and harden the server. You receive reports you can share with clients under your brand, and you stay the client's point of contact.
- Onboard servers. Each client server is connected over SSH and the scan engine is deployed to
/opt/patient-zero/scan-engine. - Baseline scan. A Forensic scan (
dfir-fast) and Malware sweep (malware-intelligence) run across every site on each server, so you know what you are inheriting. - Clean and harden. Existing infections are removed, entry points fixed and Harden playbooks applied.
- Monitor. 24/7 monitoring watches for file changes, new admins, suspicious cron entries and warnings.
- Respond. If a client site is hit, it is cleaned under the plan, with priority response for agencies.
- Report. Shareable monthly reports show clients what was checked, found and fixed.
A monitoring alert on a client server might look like this in the Activity log, followed by the fix:
# shop-eu-02 · acme-shop.co.uk
[ALERT] New administrator created: wp_support_admin (not in approved list)
[ALERT] New PHP file in uploads: wp-content/uploads/2026/09/thumb.php
# Automated containment and analyst review
[FIX] Rogue administrator removed, sessions invalidated
[FIX] thumb.php quarantined (sha256 recorded in evidence vault)
[FIX] Entry point closed: outdated form plugin updated
[REPORT] Incident summary added to monthly client reportWhat do clients see with a white-label service?
With a white-label service, clients see your agency. They receive reports and updates in your name, contact you when they have concerns, and experience security as part of what you deliver. The specialist provider works in the background, and you decide how much technical detail each client receives.
Reports are where white-label security earns its keep. Most clients never see security working, only failing. A clear monthly report changes that: sites scanned, updates applied, threats blocked or removed, and remaining risks in plain English, with full technical findings available when a client, their insurer or their data protection lead needs them. PatientZero's Reports are built for this, with a plain-English executive summary alongside the technical timeline.
Tip: include security in your care plans rather than selling it as a separate line. Clients understand "your site is maintained and protected" more easily than a list of tools.
Security triage
Is your site showing any of this?
Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.
How should agencies package security for clients?
Most agencies package white-label security inside a monthly care or maintenance plan, alongside hosting, updates and support, rather than selling it as a standalone product. Tiering works well: a core tier with monitoring and clean-ups for every client, and a higher tier with more frequent reporting for shops and higher-risk sites.
| Care plan element | What the client hears | What happens behind it |
|---|---|---|
| Monitoring | "We watch your site around the clock." | 24/7 server and file monitoring with alerts |
| Malware removal | "If it is ever hacked, we fix it, included." | Unlimited clean-ups under the plan |
| Hardening | "We lock it down so it is harder to attack." | Harden playbooks: PHP blocked in uploads, SSH and firewall lockdown |
| Updates | "We keep everything up to date." | Updates across client sites |
| Reporting | "You get a monthly report." | Shareable white-label reports |
Two practical points make this easier to sell. First, talk about outcomes, not tools: clients buy "your site stays online and trusted", not "server-side scanning". Second, show the value regularly. A short monthly report reminds clients what they are paying for, and makes renewal a formality rather than a negotiation. For e-commerce clients, point to the specific risks, such as card skimmers, covered in our WooCommerce skimmer guide and the e-commerce security page.
Why does whole-server coverage matter for agencies?
Whole-server coverage matters because agencies usually host several client sites on the same VPS or reseller account. An infection in one site can spread to the others through shared users, file permissions or root access. Protecting sites one at a time leaves gaps; protecting the whole server closes them.
A typical agency pattern is a handful of servers, such as acme-prod-01 and shop-eu-02, each running a mix of brochure sites, shops and legacy projects nobody has touched in years. The legacy site with the outdated plugin is often the way in, and the shop next door pays the price. Whole-server monitoring means every site on the server is scanned, including the ones you had forgotten about. Our guide to why one hacked site infects the rest covers this in detail, and the WordPress hardening checklist gives you a baseline for every client site.
What should agencies look for in a white-label security provider?
Look for a provider that scans at server level, not just inside WordPress, includes unlimited clean-ups so repeat infections do not become surprise invoices, fixes root causes, provides shareable reports under your brand, and is clear about how it accesses and protects your clients' servers. Contract terms and response arrangements should be written down.
- Server-side detection of webshells, cron and systemd persistence, rogue users and reverse shells.
- Unlimited malware removal on the plan, with fair-use terms stated plainly.
- Root-cause fixes and hardening, not file deletion alone.
- White-label, shareable reports and an audit trail of every action.
- Least-privilege access, key-based SSH and a clear policy on what data leaves the server (see our security page).
- No lock-in: monthly terms you can cancel.
PatientZero's Agency (white-label) plan starts from £299 a month, covering whole-server protection for client sites, white-label shareable reports, updates across client sites and priority emergency response, with no contract. Read more on PatientZero for agencies, compare plans on the pricing page, or get protected to scope your servers.
Frequently asked questions
What is white-label malware removal?
White-label malware removal is a clean-up and protection service that an agency resells under its own brand. A specialist provider detects and removes malware, fixes the entry point and hardens the server, while the agency keeps the client relationship and shares the reports as its own.
How much does white-label website security cost?
PatientZero's Agency (white-label) plan starts from £299 a month and includes unlimited malware removal, whole-server protection for client sites, shareable client reports and priority emergency response. There is no long-term contract. The final price depends on the servers and sites covered.
Can I set my own prices for clients?
Yes. With a white-label service you decide how to package and price security for your clients, for example as part of a monthly care plan. Many agencies bundle it with hosting, updates and support rather than selling it separately, which makes the value easier to explain and renew.
Do my clients need to give PatientZero access directly?
We connect to the servers you manage over SSH using key-based access. Where you manage hosting for clients, you arrange access, so the relationship stays with your agency. Where a client manages their own hosting, they or you can grant access, and it can be revoked at any time by removing the key.
What happens if a client site is hacked while on the plan?
It is cleaned under the plan at no extra cost, because every PatientZero plan includes unlimited malware removal. Agencies get priority emergency response. You receive the findings and a report you can share with the client, explaining what happened, what was removed and how the entry point was closed.