Pricing

Priced on what you test, never on how many people look

Scanning starts at 9 dollars a month. Hacker-led pentests are scoped per engagement in a day. Retests are never billed.

Scan

$9

per month

For a team that wants the scanner running before the next merge.

App Scanner, 12,400 active checks

One application, unlimited scans

CI check that blocks on criticals

Authenticated crawling behind SSO

Evidence exports for SOC 2 and ISO

Email support, same business day

Platform

Most popular

$349

per month

All four modules, correlated, for the whole engineering org.

Everything in Scan

API Surface and Cloud Posture

Unlimited applications and cloud accounts

Correlated attack paths across surfaces

Trust Center for your buyers

Slack Connect with a named engineer

Managed Pentest

Scoped

per engagement

Hacker-led testing that runs on your release cadence.

Everything in Platform

Hacker-led testing, scoped in a day

Unlimited retests, same engineer

A Slack thread per finding

Threat models from your real routes

Quarterly review with your tester

What is in each plan

Scan

Platform

Managed Pentest

Active checks

12,400

12,400

12,400 plus manual

Applications

1

Unlimited

Unlimited

Cloud accounts

—

Unlimited

Unlimited

API discovery

—

Yes

Yes

Correlated attack paths

—

Yes

Yes

CI merge gate

Yes

Yes

Yes

Hacker-led testing

—

—

Yes

Retests

—

—

Unlimited

Trust Center

—

Yes

Yes

Support

Email

Slack Connect

Named engineer

Questions about billing and scope

Is there a free trial?

The first App Scanner run is free and needs no card. After that Scan is 9 dollars a month, and you can cancel from the dashboard in two clicks.

Do you charge per seat?

No. Invite the whole engineering organisation on any plan. We price on the surface you test, not on how many people look at the results.

What counts as one application?

One deployed web application or API, including its staging copies. A monorepo that ships three separate products counts as three.

How is Managed Pentest priced?

Per engagement, based on the scope agreed in the first call. There is no per-seat component, and retests are never billed separately.

Can we start with scanning and add pentesting later?

That is the usual path. About two thirds of Managed Pentest customers ran the scanner for a quarter before booking their first engagement.

What happens to our data if we cancel?

Findings and evidence exports stay available for 90 days so you can hand them to an auditor or another vendor. Nothing is deleted the day you leave.

Not sure which one you need?

Tell us what you run and we will tell you the cheapest plan that covers it, even if that is the 9 dollar one.

Not sure which one you need?

Tell us what you run and we will tell you the cheapest plan that covers it, even if that is the 9 dollar one.

Create a free website with Framer, the website builder loved by startups, designers and agencies.