Home Services About Pricing OWASP Top 10 Web OWASP Top 10 AI Get a Quote
Pricing

Transparent pricing.
No surprises.

Fixed-scope packages for common engagements, or fully custom scoping for complex environments. Every package includes a free retest. Always.

Starter
Custom
For startups & small teams running their first pentest. Scoped to a single target.
1 target application or scope
OWASP Top 10 coverage
Full technical report
Executive summary included
48h report delivery
1 free retest included
Dedicated Slack channel
Debrief call with testers
Enterprise / Red Team
Custom
For large organisations, complex environments, and multi-vector red team simulations.
Unlimited scope & targets
Multi-vector red team simulation
MITRE ATT&CK-mapped TTPs
Attack narrative & path report
Priority 48h report delivery
Free retest on all findings
Dedicated Slack + direct line
Full debrief with board-ready deck

All pricing is bespoke — final cost depends on scope, complexity, and timeline.
Request a free scoping call and we'll provide a fixed quote within 24 hours.

Compare

What's included in each plan

Feature Starter Professional Enterprise
Number of targets1Up to 3Unlimited
OWASP Top 10 coverage
Business logic testing
API security testing
Technical report
Executive summary
CVSS severity ratings
Remediation guidance
Free retest
Report delivery SLA48h48hPriority 48h
Dedicated Slack channel
Debrief call
Red team / multi-vector
MITRE ATT&CK mapping
Board-ready presentation
Social engineering add-on+ quote+ quoteIncluded
Add-ons

Extend any engagement

Every add-on can be appended to any package at time of scoping.

Social Engineering Campaign

Phishing, vishing, or pretexting campaign against your staff. Includes per-department metrics and training recommendations.

// Quoted per campaign

Mobile App Testing

iOS or Android. Static + dynamic analysis, runtime tampering, certificate pinning bypass, OWASP MASVS aligned.

// Per platform

OSINT Exposure Report

Full open-source intelligence sweep: leaked credentials, exposed infrastructure, GitHub leaks, dark web monitoring.

// Flat rate

Cloud Security Review

AWS, GCP, or Azure. IAM privilege audit, public storage, exposed secrets, Kubernetes, serverless functions.

// Per cloud provider

AI / LLM Security Assessment

Prompt injection, jailbreak testing, RAG poisoning, agentic risks — aligned to OWASP Agentic Top 10 2026.

// Per AI system

Extra Retest Round

Additional retest beyond the included one — useful for complex remediation phases or compliance requirements.

// Per retest round
FAQ

Common questions

Penetration testing costs vary significantly based on scope complexity, number of endpoints, authentication requirements, and desired depth. A 3-page marketing site and a complex multi-tenant SaaS platform with 200 API endpoints are both "web app pentests" — but completely different engagements. We scope accurately and give you a fixed price before any work begins. No surprises.
After you've remediated the findings in our report, we retest every single vulnerability we identified — not just a sample. We verify that the fix is correct, complete, and hasn't introduced new issues. You get an updated report confirming each item's status. This is included at no extra cost in every engagement we do.
Typically within 3–5 business days of signing the agreement. For urgent situations — pre-launch testing, compliance deadlines, or emergency response — we can often start within 24–48 hours. Tell us your timeline when you reach out and we'll do our best to accommodate it.
Absolutely — in fact, this is where our plain-English reporting style makes the biggest difference. We write for developers and CTOs, not security professionals. Every finding includes a clear explanation of what the issue is, why it matters, and exactly how to fix it. No security background required to act on our reports.
Yes. Our reports are structured to satisfy the penetration testing requirements of SOC 2 Type II, ISO 27001, PCI DSS, and other frameworks. If you have specific formatting or content requirements from an auditor, let us know before the engagement starts and we'll ensure the report meets those specifications.
Critical and high-severity findings are flagged to you immediately — we don't wait until the final report. You'll get a real-time notification with enough detail to start remediation right away. This means your team can often be fixing critical issues before we've even finished the engagement.
Get started

Get a fixed quote
in 24 hours

Tell us what you need. We'll come back with a clear scope and fixed price — no sales calls, no bloated proposals.

Request a Quote