CyberQP

CyberQP FAQ

CyberQP, formerly known as Quickpass, offers Panthera, an AI-native privileged access management platform designed for MSPs, MSSPs, and mid-market enterprises with in-house IT teams, covering all eight phases of privileged access—including discovery, remediation, zero-knowledge vault and credential rotation, MFA enforcement, just-in-time access, auditing, and endpoint privilege management—with SOC 2 Type II certification and a free trial that begins with discovery in the user's own environment.

FAQ

Panthera and CyberQP: frequently asked questions

General Questions

01

What is CyberQP?

FAQ Icon

CyberQP builds Panthera, an AI-native privileged access management platform for MSPs, MSSPs and mid-market enterprises with in-house IT teams. It covers all eight phases of privileged access in one platform: discovery, remediation, a zero-knowledge vault, zero-knowledge credential rotation, MFA enforcement, just-in-time access, auditing, and endpoint privilege management. CyberQP is SOC 2 Type II certified.

02

Did you previously go by Quickpass?

FAQ Icon

Yes, CyberQP was formerly known as Quickpass.

03

Who is Panthera built for?

FAQ Icon

MSPs and MSSPs securing privileged access across every client they manage, from one multi-tenant console. Mid-market enterprises use the same platform to give their in-house IT teams control of privileged access across their own environment.

04

Is there a free trial?

FAQ Icon

Yes. The free trial runs on your own environment, with our team helping you scope it and stand it up. Discovery runs first, so you see your real privileged-access position before deciding anything. Start one from the free trial page, or email [email protected]

Product Questions

01

What does Panthera cover?

FAQ Icon

The full privileged access lifecycle in one platform: Discover & Assess, Remediation of Privileged Access, Zero-Knowledge Credential Vault, Zero-Knowledge Credential Rotation, MFA & Secure Access Enforcement, Just-in-Time Access & Zero Standing Privilege, Auditing, Monitoring & Alerting, and Endpoint Privilege Management. CyberQP also offers QGuard for privileged access and QDesk for end-user access at the service desk.

02

Which identity platforms and operating systems does Panthera support?

FAQ Icon

Active Directory, Entra ID, Microsoft 365 and Google Workspace, plus local accounts on Windows servers and on Windows and macOS workstations.

03

What RMMs and MDMs do you integrate with?

FAQ Icon

CyberQP does not directly integrate with RMMs and MDMs but includes pre-built deployment scripts for the CyberQP agent for the most popular RMMs, including ConnectWise Automate, DattoRMM, NinjaOne, N-Able RMM and N-Able N-Central as well as Microsoft Intune MDM. PowerShell and Command Line scripts are also available to be used with Group Policy and any other RMM or MDM platform.

04

Does CyberQP integrate with third-party password managers?

FAQ Icon

Panthera stores privileged credentials, API keys and tokens in its own zero-knowledge vault. QGuard also integrates with the password vaults in IT Glue and Hudu.

05

Do you have a knowledge base for your integrations?

FAQ Icon

Our knowledge base includes detailed step-by-step guides for setting up and configuring 3rd party integrations here.

06

Which PSA platforms does CyberQP integrate with?

FAQ Icon

CyberQP currently integrates with ConnectWise PSA, Datto Autotask PSA, and Halo PSA.

07

What features are available in the QDesk PSA integrations?

FAQ Icon

Currently, end-user identity verification, sending a password reset link, manual password resets, unlocking accounts, and enabling/disabling an account are available for end-user accounts within the QDesk PSA integrations. More capabilities will be added in the future to add additional functionality.

08

Does CyberQP store my passwords?

FAQ Icon

Yes, in a zero-knowledge vault. CyberQP doesn't hold the encryption keys, so it can't read your credentials in plain text, including while Panthera rotates them. Your data is never sent to a third-party AI model provider.

09

How often can privileged account passwords be rotated?

FAQ Icon

On a schedule you set, from every day to once a year, or automatically after each use.

10

Can you rotate service account passwords?

FAQ Icon

Yes. When a Windows service account's password rotates, CyberQP finds the service, updates the password and restarts the service so the change takes effect. Scheduled tasks that use the account are updated too.

11

Which accounts can Panthera rotate?

FAQ Icon

Shared, break-glass and service-account credentials across local Windows accounts, Active Directory, Entra ID, Microsoft 365 and Google Workspace. The vault stays zero-knowledge through every rotation.

12

Is Panthera multi-tenant?

FAQ Icon

Yes. Manage every client environment from one console and switch tenants without re-authenticating, with role-based access and clean separation between them. Set a policy at the parent level and it cascades to the orgs beneath it.

13

Does endpoint privilege management elevate a process or the user?

FAQ Icon

Either. A technician can elevate a single process or an end user. Safe elevations can be approved automatically based on a risk score, so only the risky ones need a look.

14

Can endpoint privilege management find and remove local admins?

FAQ Icon

Yes. It detects every local administrator on an endpoint and its current UAC settings, removes local admin rights and enforces stricter UAC settings.

15

Which systems does QGuard passwordless technician login work on?

FAQ Icon

Windows endpoints, including Windows servers and workstations.

16

Does QGuard passwordless technician login include MFA?

FAQ Icon

Yes. It uses number-matching MFA registered with the QTech mobile app on iOS and Android.

17

Does just-in-time access work with passwordless technician login?

FAQ Icon

Yes. Passwordless technician login uses just-in-time accounts by default on Windows endpoints. For Microsoft 365 or Entra ID, you can use Temporary Access Passes, OTP, or Microsoft Authenticator passwordless sign-in.

18

Does just-in-time access use role-based policies?

FAQ Icon

Yes. A technician can only use a just-in-time account under a policy that sets the customer, the account type, the privileges allowed and the time frames permitted.

19

Are just-in-time account passwords rotated after every use?

FAQ Icon

Yes, after every use.

20

How can the service desk verify an end user's identity?

FAQ Icon

QDesk sends a 6-digit code by SMS or email, or a push notification through the CyberQP mobile app or Microsoft Authenticator.

21

What can end users do in the QDesk self-service password reset app?

FAQ Icon

Reset their password, unlock their account, and get notified before their password expires.

22

Does CyberQP map controls to compliance frameworks?

FAQ Icon

Yes, including CIS v8, CMMC 2.0, ISO 27001:2022, NIST 800-53, SOC 2 and HIPAA. Panthera generates the privileged-access evidence auditors and cyber insurers ask for, on demand.

Pricing Questions

01

How is Panthera licensed?

FAQ Icon

Two licenses. The technician license covers your operators and everything they administer, including servers, Active Directory, Entra ID and Google Workspace. The device license covers the workstations your end users work on. Buy either on its own, or both.

02

How do discounts work?

FAQ Icon

Your discount follows your total monthly spend, not the count of any one license type, so putting both licenses on one agreement works in your favor. The pricing page has the details.

03

Is there any preferred pricing for peer groups?

FAQ Icon

We have agreements with many industry peer groups. Check with your group or a member of the CyberQP team to see if an agreement is in place with your peer group.

04

What currencies do you accept?

FAQ Icon

Our prices are in USD and CAD.

05

What forms of payment do you accept?

FAQ Icon

We accept credit card for monthly billing. If you would like to pay annual up-front, we will accept bank transfer and can often provide a discount for doing so.

Platform Fundamentals

01

What is zero standing privilege?

FAQ Icon

No account carries admin rights around the clock. Access is granted when it's needed, scoped to the task, and removed when the task is done, so there's nothing standing for an attacker to steal or abuse.

02

What is standing privilege?

FAQ Icon

Admin accounts that stay enabled even when nobody is using them, giving persistent, always-on privileged access.

03

What are some examples of privileged accounts?

FAQ Icon

- Active Directory Domain Administrator Accounts

- Entra ID Global Administrator Accounts

- Windows Local Administrator Accounts

04

What is just-in-time (JIT) privileged access?

FAQ Icon

Admin rights granted only when a task needs them, and removed afterwards. Each grant should have:

- A reason for access

- A time frame for access

- The least privilege necessary to perform the task

05

What are the best practices for managing privileged accounts?

FAQ Icon

- Rotate passwords frequently

- Enforce Multi-Factor Authentication (MFA) with device registration

- Minimize the number of accounts with standing privilege

- Implement the principle of least privilege

- Use dedicated privileged accounts for each technician

- Avoid shared accounts where possible

- Maintain a process to grant/revoke privilege access

- Keep an inventory of all privileged accounts

06

What is endpoint privilege management?

FAQ Icon

It removes always-on local admin rights from workstations and replaces them with policy-controlled elevation. Users can still do legitimate work, while malware and ransomware lose the admin rights they rely on.

07

What is the principle of least privilege?

FAQ Icon

Every user and technician gets the minimum access needed to do the job, and no more.

08

What is a just-in-time account?

FAQ Icon

A dedicated privileged account for each technician that stays disabled by default, is enabled with the least privilege a task needs, then is disabled again.

09

How can an MSP manage privileged accounts across every client?

FAQ Icon

From one multi-tenant console that discovers privileged, admin and service accounts across every client, vaults and rotates their credentials, and grants technicians just-in-time access. Panthera's Prompt Terminal can run that work from a plain-language request.

10

What does privileged access management change for a technical team?

FAQ Icon

It removes standing privilege without slowing technicians down. Technicians get just-in-time access instead of standing admin rights or shared passwords, break-glass and shared accounts rotate automatically, and unused, misconfigured or over-privileged accounts are flagged for clean-up.

11

What is end-to-end help desk automation?

FAQ Icon

End to End Help Desk Automation helps MSPs and in-house IT teams eliminate their most costly help desk tickets and empowers technicians of all skill levels to resolve tickets quickly.

12

How can organizations monitor changes to critical accounts?

FAQ Icon

Panthera logs every privileged account change, including creation, disabling, deletion and password changes, and alerts on high-risk activity.

13

What is self-service password reset?

FAQ Icon

Self-Service Password Reset enables end users to quickly, easily, and securely reset their passwords, potentially eliminating up to 95% of password reset tickets.

14

What is a zero-knowledge vault?

FAQ Icon

A vault where the provider never holds the encryption keys, so it can't read what's stored. Panthera's vault stays zero-knowledge even while it rotates credentials, which is rare even in enterprise PAM.

Products

Pricing QGuard QDesk Integrations Product Tours Product Roadmap Release Notes

Products

Submit a Ticket Partner Portal Trust Center Knowledge Base

Company

Company Leadership Contact Careers

Resources

Resource Hub Blog White Papers eBooks Webinars Success Stories

CyberQP Monochrome LogoCCPA Compliant, SOC 2 Type 2 Certifies, GDPR Compliant Badges

© 2026 CyberQP Inc. All rights reserved.

Privacy Policy Terms & Conditions Cookie Policy Consent Preferences