Skip to main content

For investors · MspCoreX

Europe is bringing its IT infrastructure home. American vendors can't come with it.

MspCoreX is an RMM + PSA platform with a fully in-house stack, built by a company incorporated in Romania with 100% Romanian capital — in a software category where every dominant vendor is non-EU, just as three European regulations begin to demand the opposite.

01 · The moment

Three regulations pushing demand the same way, with dates on the calendar

The thesis doesn't rest on a market prediction. It rests on legislation already adopted or in procedure, with known deadlines — and every deadline raises the cost of running on an American stack and the value of a European alternative.

Oct 2024
NIS2 in force. Essential and important sectors answer for the security of their IT supply chain. Only 16% consider themselves compliant — that gap is the service MSPs sell, with our tooling.
11 Sep 2026
Cyber Resilience Act — reporting obligations. Makers of software installed on customer machines report actively exploited vulnerabilities within 24 hours. MspCoreX already has the disclosure channel, a four-ecosystem vulnerability gate and documented triage.
11 Dec 2027
CRA — full application. CE marking becomes mandatory for software placed on the EU market. It turns into an entry barrier — including for small competitors — and compliance capital becomes a moat.
late 2027 (target)
Cloud & AI Development Act — adoption. A four-level sovereignty framework for public procurement and critical sectors: level 2 requires independence from third countries, level 3 requires EU ownership and control.
2028 →
CADA in application. "Union added value" enters procurement as an award criterion; NIS2 clients start asking their IT providers for proof of level. The question reaches every MSP: what stack do you run on?

02 · The moat

The position can't be bought: an American vendor cannot become European

The RMM/PSA market is dominated by ConnectWise, Kaseya/Datto, NinjaOne, N-able — all American, all under the CLOUD Act. CADA level 3 requires EU ownership and control: for them that is not a roadmap item, it is a structural impossibility. For us it is the starting point.

Criterion MspCoreX Dominant vendor (non-EU)
EU ownership and control Yes — incorporated in Romania, 100% Romanian capital No — structurally, regardless of investment
Exposure to the CLOUD Act / third-country jurisdictions None Yes — through the parent entity
CADA level 2–3 eligibility By construction Closed at level 3; level 2 only via costly separations
Technology stack Own — agents, remote desktop, backup, PSA, one product Aggregated — partially integrated acquisitions
Data and infrastructure Yes — own servers in Romania and Frankfurt; most AI inference on our own infrastructure; backup storage in the EU region American cloud, or EU subsidiaries with a non-EU parent

CADA is a proposal in the legislative procedure (published 3 June 2026, adoption targeted for late 2027) — we compare architectures and ownership structures; we claim no certification that does not yet exist. Independent analyses estimate that ~70% of public contracts will fall under level 1, where EU subsidiaries of American vendors compete normally; our thesis rests on the upper levels and, above all, on MSPs' private NIS2 clients.

03 · The product

One product where the competition sells a portfolio of acquisitions

Everything an MSP sells — monitoring, remote control, backup, tickets, contracts, invoicing — in one platform, written by one team, not assembled from acquired companies.

RMM — our own agents on 3 operating systems

  • Windows, macOS and Linux, developed entirely in-house
  • full monitoring: hardware, services, temperatures, software inventory with baselines
  • patch management, a script library with remote execution and review
  • per-client alert policies, with auto-remediation
  • vulnerability (CVE) and compliance scanning on every device
  • signed auto-update, shipped in waves, with delta and automatic rollback

Remote desktop — our own engine

  • own low-latency video engine — we license no one else's technology
  • viewer in the browser plus native apps for Windows / macOS / Linux
  • unattended access, policy-enforced view-only mode, privacy mode
  • remote terminal, clipboard, reboot and system actions from within the session
  • optional system audio — enabled only by policy, off by default
  • encrypted session recording, with policy-driven duration limits

Full PSA

  • tickets via email and portal, with business-hours SLAs, escalations and automatic routing
  • per-ticket time tracking and client activity reports, ready to send
  • contracts with document and annex generation, straight from the platform
  • integrated invoicing, with online payment collection and dunning
  • client portal: tickets, equipment, reports — communication in the client's language

Operational AI, not a demo

  • a voice agent that answers incoming calls
  • alert triage and drafted ticket replies
  • AI-generated runbooks for repeatable interventions
  • a problem's history, analysed and put in context for the technician
  • European models: Mistral or Ollama, self-hosted — most inference stays in the EU

Integrated security

  • Bitdefender GravityZone integration
  • ransomware protection complementing Microsoft Defender where Bitdefender is absent
  • AI that analyses security logs and raises alerts
  • backup with image restore
  • an immutable audit trail on every mutation

European providers on the sensitive layers

  • datacenter: MyServer — Bucharest, Romania
  • connectivity: iNES — Romanian provider
  • payments: Netopia — Romanian processor
  • AI: Mistral + Ollama, self-hosted for most features; the finance copilot and alert-assist validation run on a US provider

04 · Verifiable

What due diligence finds already done

Not slide promises — artefacts that exist and can be inspected.

A public vulnerability disclosure channelsecurity.txt (RFC 9116) plus a dedicated address, a requirement the CRA will impose on the whole market.

A four-ecosystem vulnerability gate — npm, Rust, .NET, C++ — run on every commit, with documented, dated triage of every accepted advisory.

A signed delivery chain — signed and notarised binaries, a hash ledger, updates with automatic rollback. Precisely the surface the market fell on in the Kaseya and SolarWinds incidents.

Licence hygiene enforced by the build — no x264/x265 (GPL); the macOS engine is FFmpeg-free, verified by a script on every build. Zero surprises in an IP audit.

Multi-tenant from day zero — tenant isolation in every query, centralised ACL, automated 12-step tenant onboarding.

05 · Traction

Operational numbers, measured by the platform

No marketing figures: extracted straight from the production database on 1 September 2026 — measured, not estimated.

7
active MSPs on the platform
1,580+
devices under management
1.3M
management commands executed automatically / month
6,600+
alerts triaged / month
670+
remote sessions served / month
38,000+
tickets processed in the platform

06 · The team

A complete core: product, clients, infrastructure, finance

Every critical function has an owner — who builds the product, who keeps the clients, who keeps the platform standing and who keeps the numbers.

MI

Mihai Iancu

Founder · Product & Architecture

Leads the product vision and the platform's technical architecture — the direction of every layer, from the endpoint agents and the remote desktop engine to the cloud.

CR

Cătălin Răducanu

Engineering · Client Relations

Technical development and MSP account management — keeps the loop short between what clients ask for and what the product delivers.

BC

Bogdan Coșa

Infrastructure · Reliability

Systems administration expert; owns the production infrastructure and the platform's availability.

CB

Cristina Bratan

Finance · Operations

Leads the financial and operational side — the execution discipline behind the growth.

07 · The conversation

We are looking for partners for the European scale-up phase

The conversation starts with a live demo of the platform and up-to-date operational numbers — directly with the founding team, no intermediaries.

Book a conversation

Figure sources: EU spend on American IT — the European Commission's Open Source Strategy / Tech Sovereignty Package (2026); European managed-services market $67.5bn (2026) → $128.7bn (2031), 13.78% CAGR — Mordor Intelligence; 16% NIS2 compliance — study reported by Technology Reseller (2026). Market figures come from commercial reports with differing methodologies. Operational numbers are extracted from the production database as of 1 September 2026; infrastructure location — the RIPE registry (Bucharest, RO allocation); self-hosted AI usage and the backup storage region — measured the same day, on the same production data. Presentation material; not an offer of securities.