Polar.sh Merchant of Record · VAT handled in 47 countries

One platform. Three simple plans.

Real AI pentest from $69 — consultancy pentests typically cost $5,000+. No per-finding charges, no surprise costs. Failed scans release the full credit reservation. EU data residency at every tier.

Get started — from $69 per scan → View sample report
EU data residency No model training Failed scan = full credit refund Instant surface preview — no signup

Pricing plans

Starter
For solo developers and one-off security audits.
$ 69
one-time purchase

One-time purchase — no subscription, no auto-renew. Want a look before you pay? The surface scan on our homepage needs no signup.

  • 1 web pentest — one-time (or one API / GitHub scan). $69 scan credit included.
  • Larger engines (Cloud $399, SAP $899, AD $299) need a credit top-up
  • PDF + JSON report delivered by email
  • 1 user seat
  • Free intel toolkit (14 tools)
  • No recurring billing
Business
For security-conscious teams with ongoing compliance needs.
$ 599
per month
  • 15 web pentests / month — scan credit works on any engine.
  • Unused scan credit rolls over — up to 2x monthly cap
  • All live engines — your scan credit works on any engine, no per-engine add-on
  • Exportable findings JSON for CI/CD integration
  • 10 user seats + role-based access
  • Dedicated EU residency + custom DPA terms on request
  • ISO 27001 / DORA / NIS2 evidence mapping
Enterprise
For organizations that need a scoped annual volume agreement and a named security contact.
$ 1,999
per month
  • Custom scan credit allocation, agreed with you and sized to your estate
  • All live engines, including Cloud / SAP / AD at volume
  • Unlimited user seats with role-based access
  • Dedicated EU residency + custom DPA
  • Named security contact + priority onboarding
Need more? Top up scan credit any time — bonus on larger packs (shown below).
Scan credit top-ups

Top up scan credit any time.

Larger packs add bonus credit — the effective value per dollar is shown on every pack so you can compare honestly.

Small
$50
$50 scan credit
No bonus · covers a GitHub SAST or API test
Large
$250
$275 scan credit (+10% bonus)
+10% bonus · covers ~4 web pentests
XL
$899
$1,030 scan credit (+14% bonus)
+14% bonus · covers ~1 SAP pentest or ~15 web pentests

Credit top-ups are one-time purchases via Polar.sh hosted checkout. VAT collected automatically in 47 countries. Credit is added on successful payment and never expires. One balance works on every engine — the XL pack covers ~1 SAP pentest ($899 each) or ~15 web pentests ($69 each).

Attack surfaces

11 engines live today.

Every plan includes access to all live engines. Your scan credit works across any engine — no engine-specific add-ons needed.

LIVE
Web Pentest
OWASP Top 10, 16 AI agents, real exploit + reproducible PoC. Auth bypass, XSS, IDOR, SSRF, injection.
LIVE
API Pentest
OWASP API Top 10 2023. REST & GraphQL. 10 agents — broken auth, object-level auth, mass assignment, rate limiting.
LIVE
GitHub SAST
8 agents — exposed secrets, vulnerable dependencies, IaC misconfigs, auth review, supply chain checks.
LIVE
Cloud Pentest
AWS / Azure / GCP / K8s. CIS Benchmarks, IAM misconfiguration, exposed storage, Kubernetes API. 8 agents. $399/scan.
LIVE
AD Security Assessment
Active Directory: Kerberoasting, ACL gaps, DC recon. Read-only, non-destructive. 7 agents. $299/scan.
LIVE
SAP Pentest
NetWeaver, ABAP, S/4HANA. RFC misuse, auth gaps, read-only analysis. 8 agents. $899/scan.
LIVE
Email Security
SPF / DKIM / DMARC validation, phishing-kit detection, passive reconnaissance. $149/scan.
LIVE
Network / Host Pentest
TCP port/service discovery, product fingerprinting, no-auth exposure detection (open Redis/ES/Mongo/Docker API, anon FTP, SMTP relay). Detection only, no exploitation. $99/scan.
LIVE
OSINT / Recon
WHOIS/RDAP, certificate-transparency subdomain enumeration, full DNS, CDN origin-IP discovery, live subdomain probing. Passive + light-active external footprinting. $29/scan.
LIVE
Scan Import
Import a Nessus, OpenVAS, Nmap, Burp, CSV or PDF report and get an AI-triaged summary mapped to GDPR/NIS2/ISO. Raw findings into prioritised insight. $9/import.
LIVE
PCI-DSS External Vuln Scan
Quarterly external vulnerability scan, PCI-DSS Req 11.3.2, ASV-aligned methodology. $149/scan.
Compare plans

Every feature, side by side.

No fine print. If a plan has it, it is on this table.

Starter Pro Business
Pricing
Price $69 one-time $599 / mo
Billing One-time Monthly
Credit top-up From $50 From $50
Coverage
Scan credit $69 one-time 15 web pentests / mo (rollover up to 2×)
Web Pentest LIVE
API Pentest LIVE
GitHub SAST LIVE
Cloud Pentest LIVE
AD Security Assessment LIVE
SAP Pentest LIVE
Email Security LIVE
Network / Host Pentest LIVE
OSINT / Recon LIVE
Scan Import LIVE
PCI-DSS External Vuln Scan LIVE
Workspace
User seats 1 10
Role-based access
TOTP 2FA
Append-only audit log
Report formats PDF + JSON PDF + JSON + findings export
Free intel toolkit
Trust & Compliance
EU data residency
No model training
Data Processing Addendum GDPR Art. 28 DPA — every plan GDPR Art. 28 DPA + custom terms on request
ISO 27001 / DORA / NIS2 evidence
Support
Channel Email Priority email
Response SLA Best-effort Business hours
Product Roadmap

What we are building next.

Alternative domain verification, Slack & Teams alerts, and agent-to-agent threat feeds are on the way. See our full roadmap →

Pricing FAQ

Questions about billing, in plain English.

What counts as a scan?
A scan is one complete automated test run against one application or surface — for example, a full OWASP Top 10 pass on your web app. There are no per-finding or per-request charges. Successful scans consume the listed per-engine credit from your balance; failed scans release the reservation in full so you are never charged for an inconclusive result.
How does scan rollover work?
Unused scan credit rolls over to the next billing cycle, up to 2× your monthly grant — Pro caps at 2× six web pentests, Business at 2× fifteen web pentests. A quieter month banks credit for a heavier audit month. Starter is one-time and does not roll over.
Can I switch or cancel my plan?
Yes. Upgrade or downgrade at any time from your dashboard — changes take effect at the next billing cycle. Cancel any time with one click. No retention calls, no lock-in beyond the current billing month.
What payment methods do you accept?
Credit and debit cards via Polar.sh (Merchant of Record). VAT is automatically calculated and collected in 47 countries — you never need to handle tax separately. EU business customers can enter a VAT registration number at checkout to apply the reverse charge mechanism.
Will my code or scan data be used to train AI models?
No. Every scan runs in a tenant-isolated environment. Your source code, URLs, screenshots and scan results are never used to train AssurePort's models or any third-party model. This commitment is written into our Data Processing Addendum. Anthropic's EU endpoint API agreements independently prohibit training on API traffic.
Where exactly is my data stored?
Exclusively in the European Union. We use Cloudflare Workers (EU edge regions), Fly.io (Frankfurt), Cloudflare R2 (EU jurisdiction), and Resend (EU). AI inference routes to Anthropic's EU endpoint. No data crosses the EU border.
What happens to my reports if I cancel?
You can export every report (PDF, JSON) for 60 days after cancellation. After 60 days your data is permanently deleted from our EU-hosted storage in accordance with our retention policy and GDPR Article 17.

Run your first scan in the next ten minutes.

No credit card to sign up. No sales call. Point us at a domain and get a real report.

No credit card to sign up EU data residency Failed scan = full credit refund