The number that should keep you up at night
CyberSmart’s 2026 MSP cybersecurity report found that 75% of MSPs suffered at least one breach in the past year. 54% had two or more. 32% had three or more. Read that again, owner to owner. Being breached is no longer the exception in this trade. It is closer to the base rate.
And here is the part that changes the maths. Business of Tech coverage of the trend notes that clients no longer respond to an MSP compromise by asking you to tighten up. They respond by planning to leave. A breach is not a remediation conversation anymore. It is a churn event.
Your PSA is a master key
When your PSA is a multi-tenant SaaS, stop and picture what actually sits inside it. Every client org. Every ticket, with the notes and credentials your techs pasted in during a 2am incident. Every contract, every MSA, every month-end billing run. Your entire book of business, in one place.
Now picture that same book sitting in a vendor’s shared database alongside hundreds of other MSPs. That shared tenant is a single, high value target. Attackers do not need to breach you. They need to breach the landlord once. Supply chain compromises against MSP tooling work exactly this way: one master key, many downstream victims.
You can harden your own network all you like. You cannot audit or control a database you do not own.
Self-hosted and single-tenant is the answer
This is the whole reason Opentra is built the way it is. Self-hosted, single-tenant means your PSA data lives on infrastructure you control and secure. Your own box, your own network segment, your own backups, your own patch cadence. There is no shared tenant, because there is no landlord.
MS Graph email-to-ticket runs against your instance. Xero billing pushes from your instance. Nothing about your client book passes through a pooled cloud database that hundreds of other shops also depend on. If a competitor’s SaaS gets popped next quarter, your name is not on the victim list, because you were never in the pool.
We do not do RMM, and that is the point. Your monitoring stays yours. Opentra does one job completely: the PSA your work runs on, from first email to paid invoice, on hardware you answer for.
Ownership is a security posture
Ask yourself the question your next client will ask you: where does our data actually live? If the honest answer is “a vendor’s shared tenant,” that is a gap you can close.
Run the flat-fee options on the pricing page: Community is free to self-host, Pro is $149 a month, Opentra Cloud is $249 a month, all with no per-seat tax. Want the auditor-facing detail first? Start with security.