Every engagement is manual testing by a named OSWE, OSCP or CREST-qualified engineer, peer-reviewed before it reaches you, with a full retest included. The tiers below differ in scope and depth, not in standard.

Focused
$1,500starting from

One web application, one API, or your external perimeter. The right size for a first SOC 2, a customer security review, or a single new product going live.

  • ✓One asset in scope
  • ✓Authenticated and unauthenticated testing
  • ✓10 working days, kick-off to report
  • ✓Full retest included
Programme
$12,000per year, starting from

For teams shipping continuously or carrying a recurring compliance obligation. Testing becomes a rhythm rather than an annual scramble before an audit.

  • ✓Multiple assets across the year
  • ✓Two full assessments, quarterly retesting
  • ✓Advisory access between engagements
  • ✓Standing answers for customer security questionnaires

Included in every engagement

  • ✓A named engineer, introduced before kick-off and reachable directly throughout
  • ✓Peer review by a second senior engineer before the report is issued
  • ✓Critical findings reported within four hours, not held until the report
  • ✓Executive summary written for your board and your auditor
  • ✓Technical findings with reproduction steps, CVSS vectors and remediation guidance
  • ✓A live walkthrough call with the engineer who ran the test
  • ✓A full retest of every finding, at no extra cost
  • ✓An attestation letter for auditors, customers and compliance programmes

How pricing works

These are starting points, not quotes. Final pricing depends on scope — how many assets, how many user roles, whether source code is available, and whether testing is against production or staging. A twenty-minute scoping call gets you a fixed-price proposal within 48 hours.

Fixed price, not day rates. You know the number before we start. If scope changes mid-engagement we tell you before doing the work, not after.

Payment terms. 50% on kick-off, 50% on delivery of the report. Indian clients are invoiced in INR at the prevailing rate.

Agencies and consultancies. We take white-label engagements on your paper, at day rates, for firms that need overflow capacity. We never approach your clients — and we will sign that.

Before you decide anything — read a full 30-page sample report. It is the actual work product, and the only honest way to judge a penetration testing firm before you hire one. No email required.

Not sure which one you need?

Tell us what you have and what is driving the deadline. We will tell you the smallest engagement that actually solves it — including when that is nothing at all.

Book a scoping call