The Dual-Product Channel: How Labrador and Penzzer Fit Together for a Security VAR

Security VARs and consultancies often build their practice around a single security category - endpoint, SIEM, maybe a GRC platform. Adding application security to the mix feels like a category jump. The reality is that two complementary products, Labrador and Penzzer, can anchor a coherent AppSec and product-security service line without forcing you to become a different kind of firm.

This article explains how the two products address adjacent buyer problems, where they share accounts, and how a VAR can structure the motion.


What Each Product Actually Does

Labrador covers static analysis, software composition analysis, and supply-chain / SBOM work. It is built for AppSec teams - developers, security engineers, and the consultancies that serve them - who care about signal quality more than scan volume. The value proposition centers on finding real issues in code and dependencies, not generating a waterfall of findings that gets ignored.

Penzzer does dynamic fuzzing. Its targets are IoT firmware, embedded systems, and CAN bus - the kind of software that runs on a device rather than a server. If your customers build connected products, medical devices, or automotive components, Penzzer reaches the attack surface that static analysis cannot.

These are distinct tools solving distinct problems. They are not redundant. That is exactly what makes them worth carrying together.


The Buyer Overlap Is Real

At first glance the buyers seem different: Labrador lands with AppSec leads and DevSecOps teams inside software companies; Penzzer lands with product security engineers inside device manufacturers. In practice, there is significant overlap.

Consider a mid-size industrial IoT company. Their software team writes the cloud backend and mobile app - Labrador territory. Their firmware team writes the embedded stack that runs on the device - Penzzer territory. Both teams often report to the same VP of Engineering or CISO. A VAR with both products in the bag can open a single enterprise conversation and address both halves of the attack surface.

The same logic applies in automotive suppliers, medical device OEMs, and defense contractors. These are not niche segments; they are the core of the US manufacturing and product-company market.


Why a Single-Product Motion Leaves Money on the Table

If you carry only Labrador, you win the AppSec conversation and then watch the product security team go somewhere else for firmware testing. If you carry only Penzzer, you win the embedded side and leave the application code unprotected.

The real cost is competitive exposure. A competitor who carries both products - or a generalist platform that covers both poorly - can displace you at renewal by offering consolidation. A VAR who brings both to the first conversation removes that lever.

There is also a service-line argument. Labrador and Penzzer both support a managed or augmented model: you can wrap either with assessment services, triage services, or ongoing monitoring. Two products running in the same account double the billable surface without doubling customer acquisition cost.


How the Apona Channel Program Structures This

Apona's partner program is built for service-led firms. A few mechanics are worth understanding:

Deal registration protects your work. Registered deals carry margin uplift even if the customer self-sources mid-cycle. That matters when you are working a long enterprise sale across multiple stakeholders.

First POCs are co-delivered. For the first deals on each product, Apona's SE team co-delivers the proof-of-concept with your team. The intent is to get your engineers to independence, not to create a dependency on Apona resources. This lowers the ramp cost for adding a second product line.

Training and demo environments are included. You get direct SE access, demo environments, and the technical enablement you need to run a credible conversation before you have closed a deal. For a VAR building a new practice, this reduces the upfront investment required.

The program is designed around MSSPs, AppSec consultancies, and VARs - firms that want to build recurring service lines, not just transact licenses.


Building the Practice

The cleanest go-to-market structure for a VAR entering this space looks like this:

  1. Start with the customer's attack surface. Is it primarily application code, embedded/firmware, or both? That tells you which product anchors the first conversation.
  1. Use the other product as an expansion motion. Once you have proven value on one side, the second product is a natural expansion conversation - not a new sale, but a gap-filling one.
  1. Wrap both with services. Labrador assessments, SBOM reviews, triage and remediation guidance on the static side; firmware security assessments and fuzz campaign design on the dynamic side. The products generate findings; your team generates value from those findings.
  1. Register deals early. The registration protects margin and signals commitment to Apona's channel team, which affects the level of SE support you get on complex deals.

The Honest Qualifier

Not every VAR needs both products on day one. If your current customer base is pure SaaS companies with no hardware play, Penzzer may not fit yet. If your customers are pure device manufacturers with minimal application code, Labrador may be the stretch. The dual-product pitch makes sense when you have - or are targeting - accounts that straddle both worlds.

The point is that the two products are designed to coexist in a channel motion. The economics work, the buyer overlap is real, and the technical ramp is supported. Adding the second product later is easier than building two separate vendor relationships from scratch.


If you want to see how the channel economics work in detail, the partner program overview is at apona.ai/partners. Labrador product details are at apona.ai/labrador; Penzzer's canonical home is penzzer.com.