Pricing
Priced on what you test, never on how many people look
Scanning starts at 9 dollars a month. Hacker-led pentests are scoped per engagement in a day. Retests are never billed.
Scan
$9
per month
For a team that wants the scanner running before the next merge.
App Scanner, 12,400 active checks
One application, unlimited scans
Authenticated crawling behind SSO
Evidence exports for SOC 2 and ISO
Email support, same business day
Platform
Most popular
$349
per month
All four modules, correlated, for the whole engineering org.
Everything in Scan
API Surface and Cloud Posture
Unlimited applications and cloud accounts
Correlated attack paths across surfaces
Trust Center for your buyers
Slack Connect with a named engineer
Managed Pentest
Scoped
per engagement
Hacker-led testing that runs on your release cadence.
Everything in Platform
Hacker-led testing, scoped in a day
Unlimited retests, same engineer
A Slack thread per finding
Threat models from your real routes
Quarterly review with your tester
What is in each plan
Scan
Platform
Managed Pentest
Active checks
12,400
12,400
12,400 plus manual
Applications
1
Unlimited
Unlimited
Cloud accounts
—
Unlimited
Unlimited
API discovery
—
Yes
Yes
Correlated attack paths
—
Yes
Yes
CI merge gate
Yes
Yes
Yes
Hacker-led testing
—
—
Yes
Retests
—
—
Unlimited
Trust Center
—
Yes
Yes
Support
Slack Connect
Named engineer
Questions about billing and scope
Is there a free trial?
The first App Scanner run is free and needs no card. After that Scan is 9 dollars a month, and you can cancel from the dashboard in two clicks.
Do you charge per seat?
No. Invite the whole engineering organisation on any plan. We price on the surface you test, not on how many people look at the results.
What counts as one application?
One deployed web application or API, including its staging copies. A monorepo that ships three separate products counts as three.
How is Managed Pentest priced?
Per engagement, based on the scope agreed in the first call. There is no per-seat component, and retests are never billed separately.
Can we start with scanning and add pentesting later?
That is the usual path. About two thirds of Managed Pentest customers ran the scanner for a quarter before booking their first engagement.
What happens to our data if we cancel?
Findings and evidence exports stay available for 90 days so you can hand them to an auditor or another vendor. Nothing is deleted the day you leave.