Simple, Transparent Pricing
No hidden fees. No per-scan charges. Just predictable pricing that scales with your needs.
Starter
Solo founder
- 100 credits/month + 25 bonus Bonus credits roll over every month
- 3 targets (domain/app)
- Weekly scheduled attack runs
- Manual runs (rate-limited)
- GitHub annotations
- Retest on demand
- Basic evidence pack export
Pro
Serious builder with staging + prod
- 400 credits/month + 100 bonus Bonus credits roll over every month
- 10 targets (domain/app)
- Daily scheduled attack runs
- Exploitability verification mode
- GitHub checks (fail PR on criticals)
- Baseline diffing
- Surface monitoring (new endpoints)
Team
Small, sharp team with governance
- 1,500 credits/month + 375 bonus Bonus credits roll over every month
- 30 targets (domain/app)
- RBAC + audit log
- Policy controls (severity thresholds)
- Branch protections
- Slack/Discord notifications
- Shared workspace triage
Agency
Multi-project management at scale
- 4,500 credits/month + 1,125 bonus Bonus credits roll over every month
- 100 targets (domain/app)
- Client portals
- White-label export option
- Priority queue + faster retests
- Authorization artifact tracking
- Priority support
What counts as a target? A target is a domain or a distinct API base URL you want tested and tracked independently. I.E. api.example.com and www.example.com are two separate targets. Subdomains count as separate targets.
Our Promise
We do not guarantee "no vulns." We guarantee evidence, reproducibility, and a remediation path. We only test owner-approved systems. We never expose your data or store your code beyond the duration of the test.
Enterprise
For procurement-bound buyers who need custom contracts and dedicated support.
- SSO/SAML + SCIM
- Dedicated tenant isolation
- Custom SLAs
- Advanced audit + retention
- Custom onboarding
- Security review support
What Could a Breach Cost You?
Get a personalized risk estimate in 30 seconds.
What Could a Breach Cost You?
Get a personalized risk estimate in 30 seconds.
What stage is your company?
Add-ons
Capture additional value without bloating your tier. Available on any paid plan.
Offensive Sprint
5 business days. One target. Deeper manual validation on your highest-risk flows.
- Exploit chain analysis
- Fix-order plan
- Closure verification
Evidence Pack
For customers, investors, or compliance. Executive-ready security summary.
- Curated evidence summary
- Reproductions + mitigations
- "What changed" diff
Authenticated Flows
Additional authenticated profiles for deeper authz/authn path testing.
- Multi-role testing
- Session management testing
- Privilege escalation checks
Frequently Asked Questions
Everything you need to know before running Your First Attack Free.
Still have questions?
Get in touch