Pricing

Two ways to work with us.

Service engagements for scoped VAPT and red team work. Platform tiers for continuous self-serve scanning. Pick what fits — most teams use both.

Service Engagements

Operator-led VAPT & Red Team

Scoped engagements delivered by a named senior operator. Indicative pricing — written quote within one business day after a scoping call. GST invoice (India) and W-8BEN-E available for international buyers.

Starter VAPT

from ₹1.5L
from $2k · 5–7 working days

Single asset — one web app, mobile app, or API. Pre-seed and seed-stage SaaS.

Best for: Founders, CTOs preparing for a SOC 2 / ISO audit
  • Black-box + grey-box on one asset
  • OWASP Top 10 + ASVS L1 coverage
  • PDF report with CVSS v3.1 + reproducible PoCs
  • Live engineer debrief (60 min)
  • 1 free retest within 30 days
Scope a Starter →
MOST POPULAR

Professional VAPT

from ₹4L
from $5k · 2–3 weeks

Multi-asset programme — web + API + mobile + selected infra. Series A–C SaaS, fintech.

Best for: VPs of Engineering, CISOs, Heads of Security
  • Up to 5 assets in scope
  • OWASP Top 10 + ASVS L2 + API Top 10
  • Authenticated and unauthenticated testing
  • Executive + technical reports
  • 1 free retest per finding within 30 days
  • Compliance mapping (SOC 2 / ISO / PCI / DPDP)
Scope a Professional →

Enterprise / Red Team

Custom
from $20k · Multi-week to multi-quarter

Full kill-chain or rolling VAPT programme. Banks, insurers, government, large enterprise.

Best for: Regulated BFSI, government, large enterprise
  • External + internal + Active Directory + cloud
  • MITRE ATT&CK adversary emulation
  • Mobile (iOS / Android) MASVS testing
  • Regulator-ready report pack (RBI / SEBI / CERT-In / regional MENA)
  • Wave-based retest cadence
  • Dedicated operator + named SOC liaison

All engagements include a free 30-min scoping call, NDA on request, and a written scope before billing.

Estimator

Get a rough number in 20 seconds.

A rough estimate. Final scope changes price ±30% typically — final price after a free 30-min scoping call.

2 assets
15101520+
Indicative range
₹4L₹6L

Indian buyers · GST extra (18%)

Indicative only. Final price after free 30-min scoping call.

Book Scoping Call →
Platform Tiers

Or use the platform yourself.

Real Nuclei scanner. Full CVE + OWASP Top 10 coverage. No agents, no setup. Cancel anytime.

Billed monthly. Cancel anytime — no contract.

Free

Free

A starting point for solo developers running occasional checks against a single asset.

Best for: Solo dev / hobbyist
  • 1 scan/month
  • OWASP Top 10
  • 7-day history
Start Free
MOST POPULAR

Pro

$199/mo
billed monthly

Suited to founders, security engineers, and consultants who want broader Nuclei coverage and exportable PDF + JSON reports.

Best for: Founder / solo security engineer
  • 10 scans/month
  • $49/extra scan
  • Real Nuclei scanner
  • Full CVE + OWASP Top 10
  • PDF exports
  • API keys
  • 90-day history
  • Scan completion emails
Upgrade to Pro

Team

$999/mo
billed monthly

Designed for internal AppSec teams that want shared scope, role separation, and evidence packs aligned to SOC 2 / PCI-DSS reviews.

Best for: Series A–C SaaS / fintech AppSec team
  • 100 scans/month
  • 5 team members
  • API keys + IP whitelists
  • 2FA enforced
  • Compliance reports (SOC2, PCI-DSS)
  • Slack / webhook alerts
  • Priority support + SLA
Start Team Trial

Enterprise

Custom

For regulated organisations that need on-prem deployment, SAML SSO, custom templates, and a named customer success contact.

Best for: Bank, insurer, healthcare, or large enterprise
  • Unlimited scans
  • Unlimited users
  • Custom Nuclei templates
  • On-prem deployment
  • SAML SSO
  • Dedicated engineer + SLA
Contact Sales
Compare tiers

What you get at each level

Side-by-side breakdown. Numbers reflect production billing; quotas reset on the first of every calendar month UTC.

FeatureFreeProTeamEnterprise
Scans / month110 (+$49 overage)100Unlimited
ScannerOWASP Top 10Full Nuclei (10k+ templates)Full Nuclei (10k+ templates)Full Nuclei + custom templates
ExportsPDF + JSONPDF + JSON + CSVPDF + JSON + CSV + raw evidence
History retention7 days90 days1 yearCustom (incl. on-prem retention)
Team members115Unlimited
API accessYesYesYes
IP whitelistingYesYes
MFA enforcementOptionalOptionalEnforced (2FA)Enforced (2FA + SAML)
Compliance reportsSOC 2 + PCI-DSSSOC 2 + PCI-DSS + ISO 27001
SAML SSOYes
Dedicated CSMYes
Retest includedRe-run scan1 free retest / findingUnlimited retests
Why buyers trust the number

No surprises before, during, or after.

Written scope before billing

Every service engagement starts with a fixed written scope, price, and timeline — sent within one business day of the scoping call. No surprise line items.

NDA on request

Mutual NDA available before any sensitive detail is shared, and we'll sign your standard form too. Typical turnaround is same-day.

Stripe-secured payments

Platform subscriptions and engagement deposits are processed by Stripe Checkout. We never see or store card data; tax-compliant invoices are issued on every charge.

Real scanner, real evidence

Findings ship with CVE ID, CVSS v3.1 vector, CWE, OWASP mapping, and reproducible request/response evidence — not a templated checklist.

Free retest to confirm fixes

Team and Enterprise include a free retest per finding within 30 days. Service engagements include a retest to verify remediation landed.

Cancel anytime

Self-serve plans are month-to-month with one-click cancellation. Annual plans are refundable within 14 days; monthly subscriptions are pro-rated on cancellation.

Billing FAQ

Questions buyers actually ask