Skip to main content
Pricing

What one scan covers, and what counts as one

Pentest pricing here turns on a single unit, so it is worth stating plainly before you pay for one: a scan is one application, or one target. The entry price is $500, and five of the eleven coverage classes take a card. What follows is everything inside that unit, and the point at which a second application becomes a second scan.

Inside the unit

One scan, item by item

Every scan runs the same six phases — discovery, planning, scanning, exploitation, reporting, and the QA gate on the finished report — and the five rows below apply to each of the coverage classes you can buy on the card.

In one scanWhat that means in the run
All six phases Discovery, planning, scanning, exploitation, reporting, and the QA gate that runs on the finished report. The sixth is a gate the report can be sent back through, not a review of the work behind it.
The generated test set The set is generated for your target from the mindmap drawn of it, and the run works through all of it — so the checks belong to this application rather than to a list written in advance for any application.
Proven findings A candidate that cannot be exploited never reaches you: it is dropped during exploitation rather than kept as an observation. What is written up is what held against the live target.
The exploit artefact Request, response and steps to reproduce, on every finding the scan produces — with a CVSS v4.0 vector and the CWE beside it. All of it sits inside the unit.
The report Written, taken through the QA gate, and delivered with the same findings in the dashboard with their evidence attached — so the engineer fixing one reads the proof rather than a summary of it.

All six phases

What that means in the run
Discovery, planning, scanning, exploitation, reporting, and the QA gate that runs on the finished report. The sixth is a gate the report can be sent back through, not a review of the work behind it.

The generated test set

What that means in the run
The set is generated for your target from the mindmap drawn of it, and the run works through all of it — so the checks belong to this application rather than to a list written in advance for any application.

Proven findings

What that means in the run
A candidate that cannot be exploited never reaches you: it is dropped during exploitation rather than kept as an observation. What is written up is what held against the live target.

The exploit artefact

What that means in the run
Request, response and steps to reproduce, on every finding the scan produces — with a CVSS v4.0 vector and the CWE beside it. All of it sits inside the unit.

The report

What that means in the run
Written, taken through the QA gate, and delivered with the same findings in the dashboard with their evidence attached — so the engineer fixing one reads the proof rather than a summary of it.

Three actions wait for your written approval before B-52 takes them, and a scan that reaches one stops there until you answer. They are identical in every coverage class and in all three delivery models. The autonomy boundary names all three.

Where the unit ends

A second application is a second scan

It is the one boundary worth knowing before the card goes in. Where the work is larger than a single application or target, three things get settled on a scoping call, and they are the three that move the price.

Beyond one scan

What a scoping call settles

Number of targets or applications
How many, and which ones. The unit does not stretch: two applications is two scans, and each is worked to the end of its own target.
Test frequency or cadence
Whether a target is tested once, or on a cadence agreed with you and run against the same scope each time.
Delivery model
Fully autonomous, autonomous with expert verification, or human led. All three cover all eleven coverage classes — what differs is whose signature the report carries.

Two prices sit on this site: $500 for a scan, and $299 for a trial scan of one target. Anything with a different shape is priced on the call rather than read off a table. The pricing page is the short version of all of this, and the delivery models page covers the third register above.

Self-serve

Five classes go straight through the card

The card flow covers the application layer. The unit is identical across the five — one application, or one target — and so is the list of what a scan includes.

Coverage classWhat one scan of it covers
Web applications One application, and a credential for each role you want exercised. That set of roles is part of the scope you sign off, not something the run decides for itself.
Mobile apps One signed release build, in the state it reaches your users — hardened, and taken apart without the source behind it.
APIs One API and the routes beneath it, measured against an authorisation matrix agreed up front rather than against the documentation.
Thick client One distributed package, and the server behind it in the same unit: what that server still accepts once a check inside the client is gone is not a second scan.
Secure code review The codebase of one application — one codebase, one scan — with every finding landing on a line and carrying the change that closes it.

Web applications

What one scan of it covers
One application, and a credential for each role you want exercised. That set of roles is part of the scope you sign off, not something the run decides for itself.

Mobile apps

What one scan of it covers
One signed release build, in the state it reaches your users — hardened, and taken apart without the source behind it.

APIs

What one scan of it covers
One API and the routes beneath it, measured against an authorisation matrix agreed up front rather than against the documentation.

Thick client

What one scan of it covers
One distributed package, and the server behind it in the same unit: what that server still accepts once a check inside the client is gone is not a second scan.

Secure code review

What one scan of it covers
The codebase of one application — one codebase, one scan — with every finding landing on a line and carrying the change that closes it.

Each class page sets out the defect classes it is worked for and the evidence a finding in it carries, so you can check the fit before buying rather than after. The coverage index lists all eleven.

Scoped on a call

Six classes start with a conversation

Coverage is not what separates these six: all eleven classes are covered, in all three delivery models. Each of them needs something agreed between people before a run can be authorised, and two of them need a position inside your network.

Coverage classWhat the call settles before a run is authorised
External network A scope proposal comes first. What answers on the perimeter is established with you and signed off before any testing begins, so the unit is agreed rather than assumed.
Internal network A run needs a deployed position inside your network, and how far a foothold may travel is fixed in the scope before it begins.
Cloud Which tenancy, which accounts and which permission boundary are in scope is settled with you before a run is authorised.
Active Directory Like internal testing, it needs a deployed position inside the network before privilege paths can be walked.
Social engineering Nothing is sent until there is a written authorisation naming the target population and the window it covers.
LLM applications Which application, which retrieval sources and which tool integrations fall inside the scope is agreed with you before a run is authorised.

External network

What the call settles before a run is authorised
A scope proposal comes first. What answers on the perimeter is established with you and signed off before any testing begins, so the unit is agreed rather than assumed.

Internal network

What the call settles before a run is authorised
A run needs a deployed position inside your network, and how far a foothold may travel is fixed in the scope before it begins.

Cloud

What the call settles before a run is authorised
Which tenancy, which accounts and which permission boundary are in scope is settled with you before a run is authorised.

Active Directory

What the call settles before a run is authorised
Like internal testing, it needs a deployed position inside the network before privilege paths can be walked.

Social engineering

What the call settles before a run is authorised
Nothing is sent until there is a written authorisation naming the target population and the window it covers.

LLM applications

What the call settles before a run is authorised
Which application, which retrieval sources and which tool integrations fall inside the scope is agreed with you before a run is authorised.

Nothing is deployed inside your network for external and application testing. Internal testing needs a deployment, and on-premise and your own cloud tenancy are both available today. Deployment and residency covers that, and the four regions the data can sit in.

Timing

How long a fully autonomous scan runs

In the fully autonomous model, the observed median from scope sign-off to report is one to three business days. It is an observed median and not a service level, and the note below sets out exactly what it measures.

Where the turnaround figure comes from
  • The measurement runs from scope sign-off to the report reaching you, in the fully autonomous model.
  • It is an observed median rather than a service level, which means runs sit on both sides of it.
  • A run that reaches one of the three approval gates waits there until you answer in writing, and that wait sits inside any elapsed time you measure.

Deliberately excluded

  • The expert-verified and human-led models, where a senior auditor sits inside the engagement. No median is stated for either.

Start with one application, or bring us the estate

The five application classes take a card and need no conversation first. The other six, and anything larger than a single scan, open with a call — which is also the quickest way to get a straight answer on scope.