Transparent & program‑based

Plan Terms

A clear explanation of what each plan includes, how validity works, and how our Enterprise program is structured.

Detailed Plan Comparison

Same criteria as on the pricing page for transparency.

FeatureStarterProfessionalEnterprise
Core Testing
Pentests/Targets1 pentest3 pentestsProgram-based
Manual Testing Hours90 hrs90 hrs90 hrs
Testing Methodology70% manual70% manual70% manual
Re-scans Included3 (60-day)3/targetProgram-based
OWASP/SANS/PTES
Reports & Compliance
Executive Summary
Technical Report
Compliance MappingSOC2, ISO, HIPAALimited + CustomLimited (Industry)
Custom Compliance Industry
CVSS Scoring
PoC Exploits
Pentest CertificatePublicPublicPublic
Support & Service
Support LevelQuick+ Slack24/7
Account ManagerNamedTeam
Slack ChannelSharedPrivate
Remediation GuidanceLimited (Basic)Limited (Priority)Dedicated
PTaaS DashboardLimited + Custom
Consultation CallsMonthlyQBRs
Advanced Services
Infrastructure TestingLimited (Advanced)
Business Logic TestingLimited (Basic)AdvancedAdvanced
Red Team Exercises1 scenarioMulti‑phase
Purple Team Exercises
Incident ResponseReadinessFull IR
Security Training1 sessionComprehensive
Continuous Testing
Custom SLA

Quick Overview

PlanWho it’s forPentestsValidityRe-scansPricing
StarterFirst pentest, MVPs, early startups1 pentest12 months3 (60-day window)$900/test
ProfessionalGrowing apps, small teams, Series A–B3 pentests12 months3/target (60-day window)$2700/test
Enterprise ProgramLarger teams, regulated orgs, ongoing needsProgram-basedProgram termProgram-basedCustom
What does a Vulncure pentest include?
  • 90 hours of manual testing (3× industry standard)
  • 70% manual + 30% automated methodology
  • Guided scoping and kickoff
  • Risk‑prioritized remediation guidance
  • Executive summary + technical report, CVSS scoring, evidence and PoCs where applicable
  • PTaaS dashboard access with compliance mapping (SOC2, ISO27001, HIPAA, PCI‑DSS, GDPR)
  • Typical turnaround: 12–16 days depending on scope

Starter

$900/test
Valid 12 months • Support included • 3 re‑scans (60‑day window)
  • 1 pentest (1 target: Web OR Mobile OR API)
  • Executive summary + technical report
  • Compliance mapping on PTaaS dashboard
  • Add‑on pentests available after using the included pentest, during validity

Professional

$2700/test
Valid 12 months • Support included • 3 re‑scans per target (60‑day window)
  • 3 pentests (any mix of Web, Mobile, API)
  • Named account manager • Shared Slack channel
  • Infrastructure & business logic testing • Red team (1 scenario)
  • Add‑on pentests available after using included pentests, during validity

Enterprise Program

Custom

A program with agreed cadence and reserved capacity tailored to your roadmap and compliance needs.

  • Program‑based pentests (defined in agreement)
  • Cadence & volume tailored to your roadmap
  • Program‑based re‑scan policy (extended windows)
  • Dedicated security team & 24/7 priority support
  • Advanced red/purple team exercises
  • Custom SLA options
  • Executive + technical reporting, CVSS scoring
  • Compliance mapping and certifications as applicable

How Enterprise pricing is determined

  • Scope complexity, target mix, and volume
  • Testing cadence (monthly/quarterly/continuous)
  • Compliance requirements and assurance needs
  • SLAs and support model (response times, IR readiness)
  • Additional services (red/purple team, IR readiness, training)

Common models: annual programs with committed units and reserved capacity, volume‑based tiers, and optional IR retainers.

FAQ

What counts as a target?

One web application, OR one mobile app (iOS/Android counted separately), OR one API (multiple endpoints under same API count as one).

Do you re‑test fixes?

Yes. Within the plan’s re‑scan limits and window, we re‑test remediations to verify fixes.

What happens after I use my included pentest(s)?

You can purchase add‑on pentests any time during validity; support continues for your plan features through the validity period.