Two ways to work with us.
Service engagements for scoped VAPT and red team work. Platform tiers for continuous self-serve scanning. Pick what fits — most teams use both.
Operator-led VAPT & Red Team
Scoped engagements delivered by a named senior operator. Indicative pricing — a written quote within one business day of a scoping call. Fixed-price USD invoice, with tax documentation (W-8BEN-E, VAT or GST) available on request.
Starter VAPT
Single asset — one web app, mobile app, or API. Pre-seed and seed-stage SaaS.
- Black-box + grey-box on one asset
- OWASP Top 10 + ASVS L1 coverage
- PDF report with CVSS v3.1 + reproducible PoCs
- Live engineer debrief (60 min)
- 1 free retest within 30 days
Professional VAPT
Multi-asset programme — web + API + mobile + selected infra. Series A–C SaaS, fintech.
- Up to 5 assets in scope
- OWASP Top 10 + ASVS L2 + API Top 10
- Authenticated and unauthenticated testing
- Executive + technical reports
- 1 free retest per finding within 30 days
- Compliance mapping (SOC 2 / ISO / PCI / GDPR)
Enterprise / Red Team
Full kill-chain or rolling VAPT programme. Banks, insurers, government, large enterprise.
- External + internal + Active Directory + cloud
- MITRE ATT&CK adversary emulation
- Mobile (iOS / Android) MASVS testing
- Regulator-ready report pack (SOC 2 / NIS2 · DORA / MAS / CBUAE · SAMA / RBI · SEBI · CERT-In)
- Wave-based retest cadence
- Dedicated operator + named SOC liaison
All engagements include a free 30-min scoping call, NDA on request, and a written scope before billing.
Get a rough number in 20 seconds.
A rough estimate. Final scope changes price ±30% typically — final price after a free 30-min scoping call.
International buyers · USD invoice, W-8BEN-E available
Indicative only. Final price after free 30-min scoping call.
Book Scoping Call →Or use the platform yourself.
The same Nuclei engine we run in engagements, pointed at your own targets. It checks published CVEs, misconfigurations, exposed services, and OWASP Top 10 categories, authenticated or unauthenticated, with every result in your dashboard.
Billed monthly in USD. Plans are month-to-month; cancel from billing settings whenever you like.
Free
A starting point for solo developers running occasional checks against a single asset.
- 1 scan/month
- OWASP Top 10
- 7-day history
Pro
Suited to founders, security engineers, and consultants who want broader Nuclei coverage and exportable PDF + JSON reports.
- 10 scans/month
- $49/extra scan
- Nuclei engine, 10k+ templates
- CVEs, misconfigs, OWASP Top 10
- PDF exports
- API keys
- 90-day history
- Scan completion emails
Team
Designed for internal AppSec teams that want shared scope, role separation, and evidence packs aligned to SOC 2 / PCI-DSS reviews.
- 100 scans/month
- 5 team members
- API keys + IP whitelists
- 2FA enforced
- Compliance reports (SOC2, PCI-DSS)
- Slack / webhook alerts
- Priority support + SLA
Enterprise
For regulated organisations that need on-prem deployment, SAML SSO, custom templates, and a named customer success contact.
- Unlimited scans
- Unlimited users
- Custom Nuclei templates
- On-prem deployment
- SAML SSO
- Dedicated engineer + SLA
What you get at each level
Side-by-side breakdown. Numbers reflect production billing; quotas reset on the first of every calendar month UTC.
| Feature | Free | Pro | Team | Enterprise |
|---|---|---|---|---|
| Scans / month | 1 | 10 (+$49 overage) | 100 | Unlimited |
| Scanner | OWASP Top 10 | Full Nuclei (10k+ templates) | Full Nuclei (10k+ templates) | Full Nuclei + custom templates |
| Exports | — | PDF + JSON | PDF + JSON + CSV | PDF + JSON + CSV + raw evidence |
| History retention | 7 days | 90 days | 1 year | Custom (incl. on-prem retention) |
| Team members | 1 | 1 | 5 | Unlimited |
| API access | — | Yes | Yes | Yes |
| IP whitelisting | — | — | Yes | Yes |
| MFA enforcement | Optional | Optional | Enforced (2FA) | Enforced (2FA + SAML) |
| Compliance reports | — | — | SOC 2 + PCI-DSS | SOC 2 + PCI-DSS + ISO 27001 |
| SAML SSO | — | — | — | Yes |
| Dedicated CSM | — | — | — | Yes |
| Retest included | — | Re-run scan | 1 free retest / finding | Unlimited retests |
No surprises before, during, or after.
Written scope before billing
Every service engagement starts with a fixed written scope, price, and timeline — sent within one business day of the scoping call. No surprise line items.
NDA on request
Mutual NDA available before any sensitive detail is shared, and we'll sign your standard form too. Typical turnaround is same-day.
Stripe-secured payments
Platform subscriptions and engagement deposits are processed by Stripe Checkout. We never see or store card data; tax-compliant invoices are issued on every charge.
Reproducible evidence
Findings ship with CVE ID, CVSS v3.1 vector, CWE, OWASP mapping, and reproducible request/response evidence — not a templated checklist.
Free retest to confirm fixes
Team and Enterprise include a free retest per finding within 30 days. Service engagements include a retest to verify remediation landed.
Month-to-month billing
Self-serve plans bill monthly and cancel from billing settings in one click. Monthly subscriptions are pro-rated for unused time when you cancel.
Our own posture, honestly stated
We are working toward our own SOC 2 Type II attestation — in progress, not yet complete. We hold ourselves to the same evidence standard we test against.
Questions buyers actually ask
Service engagements are scoped after a free 30-minute call. We send a written scope, fixed price, and timeline within one business day. You receive a formal invoice; international terms available on request.
Yes. NDA on request before any sensitive scoping detail is shared. Mutual NDA template available; we accept your standard form too. Typical turnaround: same day.
Yes — download the anonymised sample PDF instantly at axveil.com/sample-report, no NDA required. A fuller redacted report from a real engagement is available after a short mutual NDA; the case studies at /case-studies show the engagements it draws on.
One scan = one full Nuclei run against one root target (domain or host) at a point in time. Subdomain enumeration and the entire OWASP Top 10 / CVE template set count as a single scan, not one per finding. Re-running against the same target is a new scan.
No. Free is genuinely free — sign up with email and run your first scan within minutes. We only ask for a card when you upgrade to Pro or Team via Stripe Checkout.
Yes. Cancel from billing settings in one click — your plan stays active until the end of the current period, then downgrades to Free. Scan history within your retention window is preserved; older scans are pruned per your previous tier's retention.
Yes. Stripe issues a tax-compliant invoice on every charge with your billing entity, address, and tax registration — VAT ID, GSTIN, or equivalent — once you add it in billing settings. Invoices download as PDF from your dashboard.
Pro and above export every finding with CVE ID (where assigned), CVSS v3.1 vector + base score, CWE category, OWASP Top 10 mapping, affected URL, request/response evidence, and a remediation note. Both PDF and JSON formats are available.
On Pro and Team you can define custom scope (allowed domains, excluded paths, auth headers). Enterprise adds private custom Nuclei templates maintained alongside our internal template library, plus on-prem deployment so your scope never leaves your network.
Team and Enterprise include one free retest per finding within 30 days of the original scan to confirm remediation. Pro users can simply re-run a full scan against their target — it counts toward the monthly quota or $49 overage.
Team and Enterprise produce SOC 2 / PCI-DSS / ISO 27001 evidence reports suitable for auditor review; we ourselves are working toward SOC 2 Type II attestation. Refunds: Stripe-processed monthly subscriptions are pro-rated for unused time on cancellation.