Commercial transparency

Price is built.
Not copied from a table.

We don’t publish fixed price lists. Every organization has a different scope, risk profile and timeline — the quote reflects what actually needs to be tested, not a standardized package.

💳 Pay per project — no monthly subscription, no long-term contract.
The scanning platform

Scan yourself, pay only for what you open

Check your organization’s security posture for free. You only pay when you open a detailed report or add advanced scans — or choose a subscription.

Pay-as-you-go
Free
check posture, pay per report
  • Posture scans: Quick, Standard, Deep
  • See your overall security level
  • €175 — to open a detailed report
  • +€25 — each specialized scan
Start free
Unlimited
€499 / month
for teams and continuous programs
  • Unlimited reports
  • All scan options
  • Recurring and compliance scans
  • Priority support
Contact us
Optional specialized scans — +€25 each:
XSS DetectionSQL InjectionWeak PasswordsCrawl & DiscoveryMalware Detection
Why we don’t show prices

Penetration testing isn’t a standard product

A price shown without context creates the wrong expectations: either you overpay for a narrow scope, or you underpay for a complex environment.

1

Scope differs significantly

An internal app, an organization of hundreds of users and a hybrid data center can’t require the same effort — in time or in risk exposure.

2

Depth is set contractually

Black-box, gray-box or white-box; with or without exploitation proof; with or without re-testing — each option changes the team’s effort.

3

Compliance needs documentation

NIS2, GDPR or auditor requirements demand additional documentation, not just a standard technical report.

Cost factors

What shapes the final quote

During the initial consultation we define these parameters together — you get a reasoned estimate, not a value pulled from a generic table.

Attack surface

Number of apps, IP addresses, domains, environments (production, staging) and external integrations.

Type of testing

Network, web apps and API, mobile, cloud, social engineering — individually or combined.

Access & information

Access accounts, documentation, VPN, on-site presence — richer context enables more efficient testing.

Rules of engagement

Testing windows, DoS restrictions, critical systems — they define the way of working and project duration.

Deliverables & retest

Leadership report, presentation, post-remediation verification included or separate, follow-up assistance.

Urgency & timeline

Standard turnaround (2–4 weeks) versus an accelerated project with dedicated resources.

Process

From request to tailored quote

You won’t find “from €X” phrasing on the site. Before the contract you get a clear description of the services included.

1

Analysis meeting

30–45 min. We clarify goals: audit, incident, contractual requirements, NIS2 compliance. No obligation.

2

Scope definition

Scope, exclusions, rules of engagement, deliverables — all documented in writing.

3

Commercial proposal

Estimate in person-days, execution timeline, total value. Usually a reply within one business day.

4

Contract and payment

Contract, NDA, invoice (MDL, EUR or RON). For large projects, staged payments.

Testing domains

What we can assess for your organization

Every project receives a tailored quote after the scope is defined.

Infrastructure & Network

Network scanning, firewall & ACL, wireless & VPN. Black-box, gray-box or comprehensive.

Web Security

Full OWASP Top 10, SQLi, XSS, CSRF, IDOR, REST / GraphQL API audit. Free re-testing.

Mobile Security

Static (APK/IPA) + dynamic analysis, OWASP Mobile Top 10, API & local storage.

Cloud Security

IAM, policies, permissions review, exposed public resources, CIS Benchmarks compliance.

Social Engineering

Phishing, vishing, pretexting, physical access & impersonation, awareness training included.

Phishing Campaigns

Custom landing pages, tracking, detailed report with statistics, post-campaign recommendations.

What you get

Included in every standard project

Regardless of the quote value, the structure of the delivered documentation stays clear and predictable.

  • Technical report with CVSS severity and reproduction steps
  • Executive summary for leadership
  • Findings prioritized by business impact
  • Concrete, actionable remediation recommendations
  • Assistance for clarifications during the project
  • Post-remediation verification for critical vulnerabilities
Frequently asked

About quotes and budget

After the scoping discussion we can indicate an indicative range based on complexity. Without a defined scope, any figure would be misleading.

Yes. For a fair comparison, make sure the scope, deliverables and retest are identical across quotes.

Yes. Tell us the cap — we propose a realistic scope that maximizes risk coverage within the budget.

B2B contract, NDA, invoice by bank transfer in MDL, EUR or RON. For large projects, staged payments at contractual milestones.

Request a quote tailored to your context

Send a short description of the scope or book a discussion — we’ll come back with a clear proposal, with no surprise costs.