Single engagement
A customer asked for a pentest, an audit is coming, or you’re shipping something big.
- One price for the scope we agree with you
- Retest of fixes within 30 days
- Attestation letter for customers and auditors
// Pricing
What each kind of test usually costs and how long it takes. Your own price is worked out from your scope and agreed with you before any work starts. No hourly billing, no surprise invoices.
// Typical prices
Most of our quotes land in these ranges, in USD. Each one covers testing, the report, a readout call and a retest of your fixes.
$4,000 to $10,000
5 to 12 days · Most apps with 2 to 4 user roles
Get a quote for a web app pentest$3,500 to $8,000
4 to 10 days · Most APIs with 20 to 80 endpoints
Get a quote for an API pentest$2,500 to $8,000
3 to 10 days · External perimeter to a small internal network
Get a quote for a network pentest$1,500 to $3,000
2 to 4 days · Up to 25 hosts or a few websites
Get a quote for a vulnerability assessment$6,000 to $12,000
7 to 15 days · A web app plus your external network
Get a quote for a compliance pentest| Test | Typical price | Typical effort | Quote |
|---|---|---|---|
| Web App Pentest Most apps with 2 to 4 user roles | $4,000 to $10,000 | 5 to 12 days | Get a quote for a web app pentest |
| API Pentest Most APIs with 20 to 80 endpoints | $3,500 to $8,000 | 4 to 10 days | Get a quote for an API pentest |
| Network Pentest External perimeter to a small internal network | $2,500 to $8,000 | 3 to 10 days | Get a quote for a network pentest |
| Vulnerability Assessment Up to 25 hosts or a few websites | $1,500 to $3,000 | 2 to 4 days | Get a quote for a vulnerability assessment |
| Compliance Pentest A web app plus your external network | $6,000 to $12,000 | 7 to 15 days | Get a quote for a compliance pentest |
Very small scopes can come in under these ranges, and large or complex ones above them. Combining tests, such as a web app and its API, usually costs less than buying them separately. For what the wider market charges, read how much a penetration test costs.
// Ways to work with us
All three include the same testing, reporting and retest. They differ in how often we test and whose name is on the report.
A customer asked for a pentest, an audit is coming, or you’re shipping something big.
You ship often, or need testing evidence all year for SOC 2 Type II.
You’re an agency, MSP or dev shop whose clients ask for security testing.
// Quoting
Through the form or a 20‑minute call. Add your budget if you have one; it helps us scope honestly.
We confirm targets, user roles, environments and dates. An NDA is signed first if you need one.
A written quote with the scope, the number of testing days, what’s excluded and the dates. Want something changed? We adjust it with you before you sign. After that, the price only moves if the scope does.
Statement of work and authorization signed, testing window booked. Payment: 50% to book the testing window, 50% on report delivery.
// Included
No add-ons for the things that should be standard.
// What affects price
The number of days a thorough test needs comes down to four things.
Number of pages and features, API endpoints, or IP addresses in scope.
Each role (admin, member, viewer, tenant) multiplies the access-control checks.
Payment flows, multi-tenancy, file processing and third-party integrations take longer to test properly.
Production-only testing, narrow windows or on-site work add coordination time.
// FAQ
Because a five-page marketing site and a multi-tenant SaaS platform are both “a web app test”, but not the same job. One fixed price would either overcharge the small one or under-test the large one. The ranges show where most scopes land; your quote is worked out from your targets, user roles and constraints, and agreed with you before any work starts.
Yes. A single small app or a handful of hosts can come in below it, and large or unusually complex scopes above it. If yours is outside the range, the proposal says why, in terms of days and what they cover.
Yes. Tell us the number and we’ll scope a test that fits it, starting with the areas that carry the most risk, and say plainly what’s left out. If the budget can’t buy a meaningful test, we’ll tell you that too, and suggest a vulnerability assessment instead.
Yes, through the scope. If the number is more than you planned, we can test the highest-risk areas first, cover fewer roles or environments, split the work into phases, or combine tests into one engagement, which usually costs less than separate ones. What we won’t do is keep the scope and cut the testing days, because that’s how findings get missed.
You’ll hear back within one business day. Most quotes follow within a day or two of the scoping call, once targets and roles are clear.
50% to book the testing window, 50% on report delivery. Invoices can be paid by bank transfer or card.
We’re usually well below them for the same scope. No sales team, account managers or office overheads: you pay for the days spent testing and reporting, not for the layers around them.