Every attack surface is different.
We don't sell subscriptions or scanner licences. An External Attack Surface Check is a scoped, human-delivered engagement — priced accordingly.
Final pricing is confirmed in a proposal, before any commitment.
Final pricing depends on:
- Organizational footprint (domains, subsidiaries, brands)
- Number of known and discovered assets
- Applications and APIs in scope
- Complexity of the environment
- Required testing depth
- Engagement constraints and timeline
Why we don't publish a price list
A meaningful External Attack Surface Check reflects your actual footprint — not a generic tier. A company with three domains and a company with forty subsidiaries and a sprawling cloud estate require fundamentally different amounts of work to assess properly. We'd rather scope it accurately than force it into a package that under- or over-delivers.
There's no online checkout and no automated pentest purchase. After your request, we have a short scope conversation and send a straightforward, itemized proposal — so you know exactly what you're paying for before you commit to anything.