Start free with continuous discovery, turn on safe active testing when you are ready, and move up to exploit-proven validation as your surface grows. You pay for verified domains and the depth of testing you choose, nothing you cannot count. Tell us your scope and we will confirm the right plan and a fixed price.
Every tier reports the same way: reproduced findings, CVSS v3.1 severity, and the evidence attached. What changes as you move up is how deep the agent tests and how much you steer it. Tell us your scope and we will confirm the right plan.
See everything you have exposed, continuously.
Exploit-proven findings with chaining, continuously.
A deep, steered engagement on a target that matters.
Continuous coverage across everything, on your terms.
Plans scale with the number of verified domains and, on Full-Validate, the Operator-hours you steer. Non-destructive testing runs by default; anything with real side effects requires your written authorization. Tell us your scope and we will confirm the right plan and a fixed price — no obligation.
No per-seat math, no sliding definition of an "application." Two things move your price, and both are auditable.
You are billed on domains you have verified you own. It is a countable, honest unit — and the verification step is what keeps testing inside authorized scope.
Passive discovery, safe active testing, or full exploit validation. Depth is the multiplier: you turn up rigor on the assets that need it and leave the rest cheap.
On Full-Validate you can steer a run yourself from the Operator Console. Time spent actively steering is metered, so heavy, hands-on engagements pay for what they use — and passive coverage stays flat.
Verified domains multiplied by the depth of testing you turn on, plus Operator-hours when you actively steer a run. It is a unit you can count and audit — not a per-seat charge that punishes you for adding teammates, and not a sliding definition of an "application" that grows after you sign.
Actually free. Recon runs continuous asset and attack-surface discovery at no cost on domains you verify you own. It is the on-ramp: you see your real exposure first, then decide what depth of testing to turn on.
No, and we will not sell it as if it did. Operator gives you continuous breadth — it maps a changing attack surface and catches exposure from drift and deployment, day after day. A human engagement gives you depth on business logic and creative, chained attacks. They share a report format and severity scale, so the two views reinforce each other. Deep Validate and Enterprise both include human sign-off when you want a person accountable.
A registrable domain you have proven you control, through a DNS or file-based check. Subdomains and hosts under a verified domain are covered by it — you are not billed per subdomain. Verification is also what keeps Operator inside authorized scope, which is a requirement, not a formality.
Autonomous runs are covered by your plan. On Full-Validate you can also open the Operator Console and steer a run yourself — pause it, redirect it at business logic, or push deeper on a finding. Time spent actively steering is metered by the hour, with a monthly cap you set, so a hands-on engagement pays for what it uses and passive coverage stays flat.
Self-serve tiers are billed by card, monthly or annually. Deep Validate and Enterprise can be invoiced with standard terms, under an MSA and DPA. If you already run periodic testing with us, a subscription slots alongside that work on the same terms.
Verify a domain and Operator maps your exposure at no cost. Turn on testing when you are ready, or talk to us about whole-estate coverage.