White-label portals
Partners get a portal that feels like theirs, not a generic tool. Per-tenant theming, logo, icon, and favicon, and custom domains proven by DNS — certificates are issued and renewed automatically, and every domain is probed from the outside so a badge only says live when the host really serves.
A generic partner portal undercuts your brand
Off-the-shelf PRM tools slap their own logo on the partner experience. Your partners land on something that looks nothing like your program, and there's no way to give a strategic partner their own branded space.
The flow, end to end
Brand
Set a partner org's theme and upload its logo and favicon.
Map
Point a custom domain at the portal; the host resolver ties it to the tenant.
Verify
A DNS TXT record proves the partner owns the domain — unverified hosts are rejected.
Serve
A certificate is issued automatically and the branded portal loads on its own domain, probed from then on.
What's in the box
Per-tenant theming
Each partner org carries its own branding — colors, logo, favicon — applied to its portal.
Branding uploads
Upload a logo, a square icon, and a favicon, plus support, billing, terms, and privacy links.
Custom domains
Point a partner portal at a custom domain, proven with a DNS TXT record and resolved to the tenant by verified host.
Automatic TLS
Certificates are issued on demand for verified hosts only, and renewed without anyone touching them.
Outside-in probing
Every domain is checked for DNS, TLS, and HTTP every few minutes — status reflects what a visitor sees, not a claim.
Portal or product host
A domain serves the partner portal or the vendor's product, never both — so DNS always points the right way.
Verified-host security
Only verified domains resolve — and CORS grants match the same host, so nothing widens access.
Branding that never becomes a security hole
Custom domains resolve to a tenant only when verified, and the API's CORS layer grants the same verified host — so a branded portal on a partner's domain gets exactly its own data and nothing more.
- ✓Verified-domain host resolution → req.tenant
- ✓CORS origin allowlist matches verified white-label hosts
- ✓Per-tenant assets, never shared across partners
A green badge means a visitor would actually get the page
Ownership proof says a partner controls a name; it says nothing about whether the host serves anything. So every verified domain is probed from outside — DNS, then TLS, then a real request — and badges and readiness checks read that verdict alone. Certificate expiry is tracked too, so a renewal that quietly stops is visible before it takes a host down.
- ✓Probe states: live, HTTP error, no certificate, no DNS, unreachable
- ✓Recheck on demand while DNS propagates
- ✓Certificate expiry surfaced before it bites
Theming deep enough that partners forget it's a platform
Each partner org carries its own colors, logo, and favicon, applied everywhere its portal renders. Point it at a custom domain and — once verified — that domain becomes the partner's own front door, with PartnersWatch invisible behind it and access scoped to exactly that host.
- ✓Per-tenant colors, logo, and favicon served from storage
- ✓A verified custom domain becomes the partner's front door
- ✓Zero PartnersWatch branding on the partner experience
Security & multi-tenancy
Role-based access, strict tenant isolation, and encrypted BYO credentials — by construction.
Learn moreContent & legal OS
One library for sales content and contracts — templates, e-signature, renewals, and PDF, HTML, or PPTX export.
Learn moreAPI & integrations
A generated OpenAPI, scoped machine keys, signed webhooks, and an event-ingest rail.
Learn moreReady to run your partner program in one place?
Book a walkthrough and see recruitment, PRM, automation, payouts, CX, and dashboards working together — on one platform.