Skip to content
Pricing

Fixed price. Quoted before we start.

Testing is priced on what is being tested, so the honest answer is a quote rather than a headline figure. Here is what moves the number, what is included, and what we commit to before you start.

Single assessment

A first assessment, or a single application ahead of a customer security review.

In scope
One application
Testing
One engagement

Also includes 3 platform users

  • Live findings with evidence, during the test
  • Hand-verified retest included
  • Comprehensive and executive reports
Get a fixed quote
Recommended

Annual programme

Teams testing several applications a year and answering security questionnaires regularly.

In scope
Several applications
Testing
Through the year

Also includes 8 platform users · 5 self-service scans a month · 5 assets monitored

  • All 6 report profiles including PCI DSS, SOC 2, ISO 27001 and HIPAA
  • Monitoring between tests: daily checks, weekly full scan
  • Application-scoped access for contractors
  • Your own report template
Get a fixed quote

Continuous testing

Continuous programmes across an estate, with several teams and their own administrators.

In scope
Your estate
Testing
Continuous

Also includes 20+ platform users · 20 self-service scans a month · 20 assets monitored

  • Weekly host discovery across the estate
  • Custom permission groups and team administration
  • Negotiated seats and scan allowance
  • Named testing team
Talk to us

Every engagement is priced on scope and fixed before work starts. The platform is included with every engagement - there is no separate licence to buy. Scan allowances reset monthly, and seats and allowances can be agreed separately where a published plan does not fit.

Compare

What is included at each level

Single assessment

Manual testing by certified testers
Included
Findings published live during the test
Included
Evidence: request/response pairs and screenshots
Included
Hand-verified retest included
Included
Platform users
3
Self-service scans per month
Not included
Monitored assets
Not included
Daily attack surface checks
Not included
Weekly host discovery
Not included
Comprehensive and executive reports
Included
PCI DSS, SOC 2, ISO 27001, HIPAA profiles
Included
Application-scoped access for contractors
Included
Your own report template
Not included
Custom permission groups
Not included
Named testing team
Not included
Negotiated seats and scan allowance
Not included

Annual programme

Manual testing by certified testers
Included
Findings published live during the test
Included
Evidence: request/response pairs and screenshots
Included
Hand-verified retest included
Included
Platform users
8
Self-service scans per month
5
Monitored assets
5
Daily attack surface checks
Included
Weekly host discovery
Included
Comprehensive and executive reports
Included
PCI DSS, SOC 2, ISO 27001, HIPAA profiles
Included
Application-scoped access for contractors
Included
Your own report template
Included
Custom permission groups
Not included
Named testing team
Not included
Negotiated seats and scan allowance
Not included

Continuous testing

Manual testing by certified testers
Included
Findings published live during the test
Included
Evidence: request/response pairs and screenshots
Included
Hand-verified retest included
Included
Platform users
20+
Self-service scans per month
20
Monitored assets
20
Daily attack surface checks
Included
Weekly host discovery
Included
Comprehensive and executive reports
Included
PCI DSS, SOC 2, ISO 27001, HIPAA profiles
Included
Application-scoped access for contractors
Included
Your own report template
Included
Custom permission groups
Included
Named testing team
Included
Negotiated seats and scan allowance
Included

Not sure which fits? Tell us your scope and we will tell you, including if the answer is the smallest one.

Pricing FAQ

What people ask about cost

What decides the price of an engagement?

Scope, almost entirely. The number of applications, the size of each one, how many distinct user roles need testing, whether an API and a mobile client are in scope, and whether internal network testing is included. We price on scope rather than on hours, so a tester finding something quickly does not cost you less and a difficult application does not cost you more.

Are there any costs beyond the quoted price?

No. The quote is the price. If we discover more attack surface partway through we tell you what we found and what it would take to cover it, and you decide whether to extend the scope for a future engagement. We do not issue change orders mid-engagement.

Is the platform charged separately?

No. Vexil is included with every engagement. There is no separate licence, and the platform stays available to you afterwards so reports can be regenerated and retests requested.

How many people can we give access to?

Three on Single assessment, eight on Annual programme and twenty or more on Continuous testing. Seats can be agreed separately where a published plan does not fit what you need.

Is a retest really included?

Yes, and it is a real retest: you mark a finding fixed, request a retest, and a tester verifies it by hand and records whether it passed or failed. It is not a rescan and it is not billed as new work.

Do you offer ongoing or continuous testing?

Yes, as an annual programme rather than a single engagement. That suits teams shipping continuously, where a once-a-year test is out of date within a sprint. Talk to us about scope and cadence and we will price the programme.

What if we only need one small application tested?

That is what a single assessment is for: a single focused scope, fixed price, with the platform and a retest included. Many teams start there ahead of a customer security review and expand later.

Get the number.

Thirty minutes on a call and you have a fixed price, a testing date and a walkthrough of the platform. If we are not the right fit we will say so. The questions we will ask are published, so there is nothing to prepare.