No token games, no per-finding charges, no surprise top-ups. Pay for what you scan — failed scans release the reservation in full. EU data residency at every tier.
1 token = $0.01, always. Larger packs add bonus tokens; the effective per-token rate is shown on every pack so you can compare honestly.
Token packs are one-time purchases via Polar.sh hosted checkout. VAT collected automatically in 47 countries. Tokens are added on successful payment and never expire. One wallet runs every engine — the XL pack alone covers a single SAP Pentest (89,900 tokens).
Every plan includes access to all live engines. Scan credits work across any engine — no engine-specific add-ons needed.
No fine print. If a plan has it, it is on this table.
| Starter | Pro | Business | |
|---|---|---|---|
| Pricing | |||
| Price | $99 one-time | $349 / mo | $899 / mo |
| Billing | One-time | Monthly | Monthly |
| Top-up rate | $0.01 / token | $0.01 / token | $0.01 / token |
| Coverage | |||
| Token grant | 9,900 one-time | 40,000 / mo (rollover up to 80,000) | 110,000 / mo (rollover up to 220,000) |
| Web Pentest LIVE | ✓ | ✓ | ✓ |
| API Pentest LIVE | ✓ | ✓ | ✓ |
| Mobile APK LIVE | ✓ | ✓ | ✓ |
| GitHub SAST LIVE | ✓ | ✓ | ✓ |
| Cloud Pentest LIVE | ✓ | ✓ | ✓ |
| AD Security Assessment LIVE | ✓ | ✓ | ✓ |
| SAP Pentest LIVE | ✓ | ✓ | ✓ |
| Email Security LIVE | ✓ | ✓ | ✓ |
| Workspace | |||
| User seats | 1 | 3 | 10 |
| Role-based access | — | ✓ | ✓ |
| TOTP 2FA | ✓ | ✓ | ✓ |
| Append-only audit log | — | ✓ | ✓ |
| Report formats | PDF + JSON | PDF + JSON | PDF + JSON + findings export |
| Free intel toolkit | ✓ | ✓ | ✓ |
| Trust & Compliance | |||
| EU data residency | ✓ | ✓ | ✓ |
| No model training | ✓ | ✓ | ✓ |
| Data Processing Addendum | — | — | Standard DPA included |
| ISO 27001 / DORA / NIS2 evidence | — | — | ✓ |
| Support | |||
| Channel | Priority email | Priority email | |
| Response SLA | Best-effort | Business hours | Business hours |
No credit card to sign up. No sales call. Point us at a domain and get a real report.