Plan Terms
A clear explanation of what each plan includes, how validity works, and how our Enterprise program is structured.
Detailed Plan Comparison
Same criteria as on the pricing page for transparency.
| Feature | Starter | Professional | Enterprise |
|---|---|---|---|
| Core Testing | |||
| Pentests/Targets | 1 pentest | 3 pentests | Program-based |
| Manual Testing Hours | 90 hrs | 90 hrs | 90 hrs |
| Testing Methodology | 70% manual | 70% manual | 70% manual |
| Re-scans Included | 3 (60-day) | 3/target | Program-based |
| OWASP/SANS/PTES | |||
| Reports & Compliance | |||
| Executive Summary | |||
| Technical Report | |||
| Compliance Mapping | SOC2, ISO, HIPAA | Limited + Custom | Limited (Industry) |
| Custom Compliance | — | Industry | |
| CVSS Scoring | |||
| PoC Exploits | |||
| Pentest Certificate | Public | Public | Public |
| Support & Service | |||
| Support Level | Quick | + Slack | 24/7 |
| Account Manager | — | Named | Team |
| Slack Channel | — | Shared | Private |
| Remediation Guidance | Limited (Basic) | Limited (Priority) | Dedicated |
| PTaaS Dashboard | Limited + Custom | ||
| Consultation Calls | — | Monthly | QBRs |
| Advanced Services | |||
| Infrastructure Testing | — | Limited (Advanced) | |
| Business Logic Testing | Limited (Basic) | Advanced | Advanced |
| Red Team Exercises | — | 1 scenario | Multi‑phase |
| Purple Team Exercises | — | — | |
| Incident Response | — | Readiness | Full IR |
| Security Training | — | 1 session | Comprehensive |
| Continuous Testing | — | — | |
| Custom SLA | — | — | |
Quick Overview
| Plan | Who it’s for | Pentests | Validity | Re-scans | Pricing |
|---|---|---|---|---|---|
| Starter | First pentest, MVPs, early startups | 1 pentest | 12 months | 3 (60-day window) | $900/test |
| Professional | Growing apps, small teams, Series A–B | 3 pentests | 12 months | 3/target (60-day window) | $2700/test |
| Enterprise Program | Larger teams, regulated orgs, ongoing needs | Program-based | Program term | Program-based | Custom |
- 90 hours of manual testing (3× industry standard)
- 70% manual + 30% automated methodology
- Guided scoping and kickoff
- Risk‑prioritized remediation guidance
- Executive summary + technical report, CVSS scoring, evidence and PoCs where applicable
- PTaaS dashboard access with compliance mapping (SOC2, ISO27001, HIPAA, PCI‑DSS, GDPR)
- Typical turnaround: 12–16 days depending on scope
Starter
$900/test- 1 pentest (1 target: Web OR Mobile OR API)
- Executive summary + technical report
- Compliance mapping on PTaaS dashboard
- Add‑on pentests available after using the included pentest, during validity
Professional
$2700/test- 3 pentests (any mix of Web, Mobile, API)
- Named account manager • Shared Slack channel
- Infrastructure & business logic testing • Red team (1 scenario)
- Add‑on pentests available after using included pentests, during validity
Enterprise Program
CustomA program with agreed cadence and reserved capacity tailored to your roadmap and compliance needs.
- Program‑based pentests (defined in agreement)
- Cadence & volume tailored to your roadmap
- Program‑based re‑scan policy (extended windows)
- Dedicated security team & 24/7 priority support
- Advanced red/purple team exercises
- Custom SLA options
- Executive + technical reporting, CVSS scoring
- Compliance mapping and certifications as applicable
How Enterprise pricing is determined
- Scope complexity, target mix, and volume
- Testing cadence (monthly/quarterly/continuous)
- Compliance requirements and assurance needs
- SLAs and support model (response times, IR readiness)
- Additional services (red/purple team, IR readiness, training)
Common models: annual programs with committed units and reserved capacity, volume‑based tiers, and optional IR retainers.
FAQ
What counts as a target?
One web application, OR one mobile app (iOS/Android counted separately), OR one API (multiple endpoints under same API count as one).
Do you re‑test fixes?
Yes. Within the plan’s re‑scan limits and window, we re‑test remediations to verify fixes.
What happens after I use my included pentest(s)?
You can purchase add‑on pentests any time during validity; support continues for your plan features through the validity period.