The RMM built by an audit firm
RMM, remote support, and security in one console your auditor trusts.
Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams, with patching, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance built into the same agent and console. Technicians get browser-based remote control, a background admin workspace, and a remote shell on Windows and Mac, scripting on Linux, and ad-hoc support for computers without the agent, with end-to-end encrypted sessions available. Lavawall can run on its own as your RMM, or be installed through Datto RMM, NinjaOne, ConnectWise, Kaseya, Intune, or any tool that runs a script, while you move over. Built and run by ThreeShield, a CISSP/CISA audit firm.
- Live in minutes, not months
- Month-to-month, cancel anytime
- Add modules as you grow
- Replace 5+ point tools when ready
Start my free trial, no credit card
14-day full trial · two domains scanned free forever · cancel any month
Built by ThreeShield, the CISSP/CISA cybersecurity auditors trusted since 2006 by Calgary MSPs, startups, and European manufacturers. Scripts ThreeShield licensed to UTC ran on systems at NASA, JPL, and Rocketdyne, and later became part of Lavawall®.
When things go wrong
Start with the problem in front of you
Someone clicked a phishing link
The first-hour checklist, then one-click reporting that tells the person instantly whether it was safe, and follows up with training so it doesn't happen twice.
A Microsoft 365 account was compromised
Revoke access, investigate, and recover, then let Lavawall correlate risky sign-ins, OAuth grants, and mailbox rules automatically.
An employee is leaving with your files
Preserve evidence before the account dies, and see every mass download and external share from the last 60 days.
Need your Google Workspace data out, on a deadline?
A client leaving, a legal hold, or a tenant about to close. Lavawall Backup pulls every mailbox, Drive, and shared drive to a disk you own at full speed, read-only, and resumes if the connection drops. No 48 to 72 hour export queue.
Cyber insurance renewal is due
Scan yourself before the insurer does, answer the questionnaire truthfully. Clients have reported premiums 12% lower after doing this.
A client sent a security questionnaire
Stop guessing on answers that become contractual. Map questions to controls you already have, or can turn on today.
Worried about ransomware right now
The warning signs, what to do in the first hour, and active Akira IOC hunting across your fleet.
Your RMM renewal quote just arrived
High-water-mark billing again? Get better insights, more patching, faster remote access, and automatic endpoint log reviews, month-to-month.
Drowning in user phishing reports?
Lavawall gives every reporter instant risk-based feedback, feeds your training and simulation system, and cuts ticket noise. It also tracks who is actively engaged with their email security.
Phished through a PDF or a link your filter obscured?
You taught people to hover over links; your gateway killed that. Lavawall®’s Outlook and webmail plugin inspects PDFs and phishing relays in depth and shows users the real destination your filter hid.
Hit with a compliance fire-drill?
Lavawall®’s GRC engine auto-maps your controls to 70+ Canadian, US, European, UK, Australian, and international frameworks, and generates the policies and documentation to get you compliant fast.
Lost visitor insight when Google Analytics changed?
Lavawall®’s web chat and logging show how visitors actually use your site, connect to popular ad platforms, and don’t restrict your data the way Google Analytics does.
Email landing in junk, or not getting through?
The Lavawall® DMARC tool tunes and monitors your SPF, DKIM, and DMARC so your email reaches the inbox instead of the spam folder.
Concerned about shadow IT and AI use?
Lavawall®’s SaaS Discovery uses Microsoft 365 metadata and other signals to track 1,277 SaaS and shadow-IT tools, mark your official apps, and see who is signing up behind your back.
Users complaining about slow, unreliable computers?
Lavawall shows techs exactly what is slowing a machine (processes, system events, temperature, and disk space) and produces an instant replacement-priority list so you re-equip people before they complain.
Training that ignores your industry and its rules?
Lavawall® has 503 courses tailored to specific industries, provinces, states, countries, and job roles, so employees get the PCI, health, privacy, and role-specific training that applies, and skip the fluff.
Another sale slipping through the cracks?
Lavawall®’s integrated CRM is built for MSPs, so a follow-up, quote, or renewal never gets lost again.
Digging through Sophos or Huntress to find one threat?
Lavawall keeps track of every tenant and generates unified alerts for the incidents that slip between MDR consoles.
Employee compromised at home, or endless toner complaints?
Lavawall keeps an eye on the entire LAN and WAN, so neither a quiet breach nor a noisy frustration slips past you.
Blindsided by BC, Saskatchewan, Ontario, or Quebec PST/HST/QST?
Lavawall helps you quickly identify which SaaS licenses and support contracts carry which provincial tax requirements.
A PCI DSS deadline or ASV scan bearing down?
Lavawall® maps every PCI DSS v4.0.1 SAQ (A, A-EP, B, B-IP, C, C-VT, and D), monitors your Approved Scanning Vendor (ASV) scan results, and lets you run your own scans to clear findings before the official ASV scan. Experienced PCI professionals are on chat, phone, or email to walk you through the requirements whenever you need them.
Running Google Workspace with no real security visibility?
Lavawall® brings breach and vulnerability detection to Google Workspace: risky sign-ins, OAuth grants, over-shared files, and misconfigurations, surfaced the same way it watches Microsoft 365, Entra, and Azure.
RMM makes your techs hunt for what's actually wrong?
A technician shouldn't have to dig for the cause. Lavawall® tells them the moment they connect: high temperature, missing patches, a pending reboot, failed system integrity, disk trouble, and the processes hogging CPU, memory, or disk. Issues get fixed on first contact instead of the third callback.
Security modules: use one, or use them all.
Every module runs on the same Lavawall® RMM agent and console. Start with the one you need most and add the rest when you are ready.
Patching, 7,400+ apps
Windows, macOS, and Linux OS, firmware, and application patching, risk-ranked and automated, plus software deployment.
M365 / Entra / Azure breach detection
Breach detection that correlates cloud sign-ins and changes with what happens on the endpoint.
File & share monitoring
SharePoint, OneDrive, Google Drive, and on-prem file activity with actor attribution and external-share visibility.
Phishing Reporter & training
One-click reporting for every employee, automatic campaign analysis, and awareness training that sticks.
GRC & compliance automation
CMMC 2.0, NIST CSF, CIS, SOC 2, HIPAA, PCI DSS v4.0.1, ISO 27001, CPCSC, and Canadian privacy frameworks, evidence collected continuously.
Remote support & smart helpdesk
Secure remote support without carrying your laptop, plus smart ticketing and a free web chat widget.
External attack-surface & domain scanning
Continuous external scanning with scheduled re-scans, remediation tracking, and DMARC, DNS, and exposure findings. Two domains free forever with Scout, unlimited as a module.
When you're ready
Replace the stack. Keep one bill.
The same platform that lands as one module can replace your RMM, GRC platform, patch tool, cloud monitoring, shadow-IT discovery, admin elevation, remote support, and helpdesk. That means one console, one vendor, and one line on the budget.
One console means one clear bill: month to month, no minimum for single modules, and never a charge based on a "high water mark" from a busier month gone by. Teams that consolidate typically retire four to seven overlapping subscriptions, and the licensing math, integration glue, and finger-pointing that came with them.
Because every module writes to the same GRC core, everything it sees (patch state, breach signals, configuration changes, and access) becomes timestamped compliance evidence automatically. Compliance reporting turns into a by-product of running the platform, and breaches and vulnerabilities surface faster because the signals sit in one place.
Full coverage across Windows, macOS, Linux, Microsoft 365, Entra / Azure, Google Workspace, and Active Directory, so nothing gets dropped when you consolidate.
Software plus real experts
Talk to a real security expert, by chat, phone, or email.
Lavawall® is built by ThreeShield, the CISSP/CISA cybersecurity auditors trusted since 2006 by Calgary MSPs, startups, and European manufacturers. Scripts ThreeShield licensed to UTC ran on systems at NASA, JPL, and Rocketdyne, and later became part of Lavawall®. When something needs a human, you escalate to the people who wrote the detection.
Every plan includes real access to experienced senior security professionals by chat, phone, or email whenever you need them, not a first-line triage analyst reading from a script.
Pricing that respects how you actually buy
Start with one module
Land with the module that solves today's problem. No platform commitment, no bundle you don't need.
Month-to-month, start with one module
No long-term contracts. Costs decrease as you grow, and we'll never bill you on a bogus "high water mark" from months ago.
Annual saves two months, and spikes don't stick
Pay annually and two months are free. Go over what you prepaid in a busy month and you're billed the difference for that month only, and it drops back when your usage does. You're never locked to a past peak.
Free to try, free to scan
14-day full trial without a credit card, and two domains scanned free forever with Scout.
Plain dealing, and good for the community
Published prices, honest advice, and your data is yours to export and leave with. Registered not-for-profits get 50% off. See Community Good.
Running an MSP?
Lavawall® was built inside an MSP practice. White-label the domain scanner to differentiate your stack, and grow with written rules of engagement: registered deals are protected, and we never go around partners.
Internal IT team?
Same platform, no MSP required. Run one organization from one console, buy only the modules you need as Individual Services, and escalate to ThreeShield’s CISSP/CISA team when something needs a human.
What you're actually buying
Never be surprised by your own environment again
Know before your boss, your auditor, or the attacker does. Lavawall® hands you the findings that make you look good: "we found 17 risky mailbox rules", "here's the software nobody was patching", and "here's exactly who accessed Finance."
Quiet mornings
Alerts arrive triaged and prioritized, not as a wall of noise. You open the dashboard, see what actually matters, and get on with your day.
Audit-day calm
When the auditor or insurer asks, the evidence is already collected. No weekend scramble, no guessing which box is safe to tick.
Someone behind you
When something's genuinely weird at 4pm on a Friday, you're not alone: a CISSP who's seen it before picks up.
Common questions
- Does Lavawall replace my RMM?
- Yes. Lavawall is a multi-tenant RMM and remote support platform. Patching for more than 7,400 applications, scripting, monitoring, and browser-based remote support run on the same agent and console as security monitoring, breach detection, and compliance. The Admin Workspace lets a technician fix a computer with administrator rights while the user keeps working undisturbed. You don't have to switch overnight: Lavawall can be installed through NinjaOne, Datto RMM, Atera, ConnectWise Automate, N-able, Kaseya, Syncro, or any tool that runs a script, and both can run side by side while you move over. Every module you add replaces a tool, saves time, and makes clients more secure. See the comparisons.
- Does Lavawall have a free tier?
- Yes. Two domains can be scanned free, forever, with Scout. The full domain-scanner module adds unlimited domains, scheduled re-scans, and remediation tracking, and the platform has a 14-day trial with no credit card.
- Can I buy just one module?
- Yes, that's the intended way to start. Land with the module that solves this month's problem and expand later. Month-to-month, no high-water-mark billing, no minimum for single modules.
- What happens when I need a human expert?
- You escalate to ThreeShield, the CISSP/CISA team that builds Lavawall. Every customer can, so you get Tier 3 expertise without hiring a security department.
Datto and Datto RMM are trademarks of Kaseya. NinjaOne is a trademark of NinjaOne, LLC. Lavawall is not affiliated with either.