Pricing
Fixed scope, fixed price, no surprise costs.
The ideal starter package to quickly gauge your site’s external security posture and close basic risks.
Reviews your external configuration posture together: SSL/TLS, security headers, DNS/email, CORS and CSP. Discounted vs buying separately.
A deep discovery bundle that maps your external attack surface and detects abandoned/exposed assets.
Passive external-surface discovery; no active endpoint injection or authenticated testing.
All seven active-light verification checks in one bundle: Injection, IDOR, SSRF, File Upload, Business Logic, Race/Mass-Assignment and RCE. Proves presence, never exploits; a single authorization declaration covers all. Strongly discounted vs buying separately. Scope: this bundle tests the unauthenticated (no-login) surface. Deep authorization/business-logic vulnerabilities that only appear after login are out of scope; results depend on the target’s structure.
A deep, deterministic security scan after login with a TEST account you provide: authenticated injection/IDOR, authorization & session, client-side/JS, API (OWASP API Top 10), CORS & security headers, TLS, configuration exposure and email/DNS. No exploitation; results vary with the target’s surface.
See what each package covers in one table. Values come from the package definitions.
Three questions; guidance only, not a commitment.
Is this your first scan?
What is your priority?
You can scroll the table sideways.
Basic Scan
External Surface & Configuration Bundle
PopularDiscovery Bundle
Active Verification Bundle
Full-Scope Pentest Bundle
Most CompleteSample Reports
Preview each package’s sample report as a PDF before buying.
To begin
You only pay when you start a scan. Get started by verifying your domain.
Verify Free & Start