One price. Any web app or API.
A full pentest for €1,995: results in 24 hours, free retest on every finding. No retainers, no hidden fees, no scoping calls.
Free Trial
- check_circleCreate pentest setup
- check_circleExplore key flows
- check_circleDemo pentest with sample report
Compliance Pentest
- check_circleLive automated pentest (24h)
- check_circleWeb + API coverage
- check_circleISO 27001, SOC 2, CRA reports
- check_circleActionable remediation
- check_circleFree retest included
Testing 10+ apps? Bulk credits: €1,495 per pentest, valid 12 months.
Get a PentestProfessional
- check_circleOne full pentest every month, per app
- check_circleRun it when you're ready, or set a monthly schedule
- check_circleRe-tests your open findings: Fixed, Regressed, New
- check_circleLiving certificate, refreshes each clean run
- check_circleAlerts on new or regressed findings
One full pentest every month, per app. Run it when you're ready, or schedule it. Cancel anytime.
Start continuous testingEnterprise
- check_circleVolume pricing & bulk credits
- check_circleHuman pentester deep-dive
- check_circleGitHub & CI/CD integration (enterprise)
- check_circleCustom SLAs & white-label reports
- check_circleSSO / SAML
- check_circlePriority queue & dedicated CSM
- check_circleNDA & DPA on request
All prices excl. VAT.
What one pentest covers
- check_circleOne target: your web app or API, including authenticated areas (your credentials, multiple user roles)
- check_circleYou set the scope: which URLs are in and out of bounds, and what may be actively exploited
- check_circleVerified findings only: every issue proven with a working exploit, no scan noise
- check_circleCompliance-ready report in 24 hours (ISO 27001, SOC 2, CRA)
- check_circleFree retest to confirm your fixes
No complexity tiers and no sizing call: if it is a web app or an API, it is one pentest. You define the scope; the agents enforce it before every action.
Frequently asked questions
Not ready to decide?
Start with step zero: a free 60-second scan shows what is publicly visible on your domain. The scan is separate from the pentest and finds no vulnerabilities on its own. A pentest is the next, paid step: it shows what of that surface is actually exploitable.
Run the free 60-second scanNeed pricing on paper for your purchase process? Get a written quote within one business day.