Go beyond continuous monitoring. Identify real exploitable vulnerabilities with controlled, authorized scanning.
Six ways to look at the same target
Price per delivery, VAT excluded. Every assessment ends with a report, not a raw export.
Exposure Assessment · 99 EUR
Safe, non-intrusive. What is already in the open on your target: the exposed surface and leaked secrets.
- Site crawl and inventory of the exposed surface
- Security headers, cookies, mixed content, known component versions
- API keys and tokens exposed in JavaScript bundles, source maps and HTTP responses
- Live verification of each found token’s validity, where possible
- No attack payloads, nothing written to your target
- Every secret is masked in the report - we never send you the raw key
Active Assessment · 279 EUR
Real attack payloads (SQLi, XSS, path traversal) under controlled conditions.
- The crawl and passive analysis from the Exposure Assessment
- SQL injection, XSS, path traversal, file inclusion
- Rate limited, run inside the window we agree with you
- Every finding carries the request that produced it
- Remediation steps, ordered by what gets exploited first
Authenticated Assessment · 379 EUR
Tests protected areas after login.
- Everything in the active assessment
- A real user session, on a test account you provide
- The areas behind the login, where the data lives
- Access control checks: what one account can reach and should not
- A separate report for what is only visible once logged in
AI-Agent Pentest (METATRON) · 890 EUR
An AI agent drives the recon and attempts exploitation, like a tester who improvises.
- An LLM-driven agent decides what to test, step by step, based on what it finds
- Real tools in a sandbox: nmap, nikto, whatweb, sqlmap, DNS/WHOIS lookups, HTTP requests
- Goes beyond fixed payloads: actively tries to confirm what it discovers
- Every finding carries the tool evidence behind it, so you can check it yourself
- The deepest level: requires full authorization (two proofs, one at server level, plus a signed document)
Autonomous AI Pentest (Strix) · 990 EUR
An autonomous AI agent attempts exploitation and proves each finding with a proof of concept.
- Strix, an open-source pentest agent with its own isolated sandbox: HTTP proxy, browser and terminal
- Does not just flag: tries to confirm every vulnerability with a proof of concept
- Looks for what fixed-payload scanners miss: access control, business logic, chained injections
- Every finding comes with the evidence from the run and the steps to reproduce it
- The deepest level: requires full authorization (two proofs, one at server level, plus a signed document)
Full Package · 1890 EUR
All five assessments on the same target, plus an executive summary and a 30 min review call.
- Exposure, active and authenticated assessment (on a test account you provide)
- Both AI-agent pentests: METATRON and Strix
- Executive summary, written without jargon
- A 30 minute call to walk through the findings
- False positives separated from what has to be fixed now
- One verification re-run after you remediate
-15% with a Pro or Ultra subscription.