OEM / White-label
OEM deals let a partner resell TapPass under their own brand to their own customers. We stay the engine; they stay the face.
Pricing shape
Section titled “Pricing shape”- Base license: €X / year
- Per end-customer royalty: €Y / active customer / month
- Minimum commitment: Z end-customers / year
- Support: partner handles tier-1; we handle tier-2/3
Specific numbers in Pricing.
What they get
Section titled “What they get”| Dimension | OEM can customise |
|---|---|
| UI branding | Logo, colours, product name, email templates |
| Vault backend | HashiCorp, AWS Secrets, Azure Key Vault, GCP Secret Manager, Conjur |
| Detection backend | Llama Guard, LLM Guard, NeMo, Azure Content Safety |
| Policy presets | Per-customer Rego rules |
| Multi-tenant boundary | Each of their customers is a separate TapPass tenant |
See sub-pages:
What they don’t get
Section titled “What they don’t get”- Source code access — binaries / containers only
- Database schema modifications
- Changes to audit trail internals — the compliance story is a joint one
- Redistribution to parties outside the contracted scope
Legal surface
Section titled “Legal surface”OEM contract has extra terms for:
- Trademark use — they can’t use “TapPass” in marketing without approval
- Support escalation — named path from their L1 to our on-call
- Breach notification — flows through partner to end-customer; timing clauses matter for GDPR/DORA
Loop in Jens + legal for every OEM contract; templates in working-assets/ repo.