Fixed price. No hidden fees. No hourly surprises.
Every engagement gets a free scoping call and a written proposal with a fixed price and timeline before anything starts. These are starting prices — your exact number depends on scope, confirmed in writing within 24 hours of the call.
Web Application
Manual OWASP Top 10, auth, business logic, API testing
Scoped to role count, endpoint surface, and API presence
- OWASP Top 10 coverage
- Authentication & authorization testing
- Business logic & workflow abuse
- API testing (REST / GraphQL)
- Executive + technical report, CVSS-rated
- 3–5 business day timeline
Network & Active Directory
Full internal/external network + AD attack-path testing
Scoped to domain size, host count, and trust relationships
- Internal & external network testing
- ADCS, Kerberoasting, ACL abuse
- BloodHound-mapped attack paths
- Segmentation validation
- Executive + technical report, CVSS-rated
- 5–10 business day timeline
SOC 2 and PCI DSS testing follow the same underlying pricing — from $500 for an application-only scope, from $1,500 where network infrastructure or segmentation testing is included. The compliance framework changes how the report is formatted for your auditor or QSA, not the base pricing structure. Other frameworks (ISO 27001, HIPAA, and similar) follow the same logic — if your framework requires independent penetration testing evidence, mention it on the scoping call. See SOC 2 testing or PCI DSS testing for details.
Larger or multi-environment engagements — multiple applications, multi-domain forests, ongoing retainers — are scoped individually on the call rather than forced into a fixed tier. You'll still get a fixed price in writing before anything starts.
Pricing questions
Because scope changes the work: a 5-endpoint API and a 40-endpoint multi-role application are not the same engagement, even though both are "a web app." Every project gets a fixed price in writing after a free scoping call — you'll know the exact number before anything starts, with no hourly billing and no surprise add-ons.
For web applications: number of user roles, number of endpoints, and whether an API is in scope. For network and Active Directory: domain size, number of hosts, number of trust relationships, and whether segmentation testing is required. Compliance-driven tests (SOC 2, PCI DSS) follow the same logic — the compliance framework changes the report format, not the underlying pricing structure.
A re-test of previously reported findings, once your team has remediated, is included at no extra cost within a reasonable window after the original report — ask during scoping for the exact terms for your engagement.
Yes, for clients who need testing on a recurring cadence (quarterly, per-release, or annual for compliance renewal). Mention it on the scoping call and it'll be priced as an ongoing arrangement rather than a one-off.
Standard terms are confirmed in the written proposal alongside scope and timeline — no engagement starts without a signed agreement covering price, scope, and rules of engagement.
Get your exact price in 24 hours
Free 30-minute scoping call, then a fixed-price written proposal — no commitment either way.