Home / Pricing
Pricing & tiersRight-sized engagements, priced before we start.
No surprise invoices and no padded scopes. We quote a fixed price against an agreed objective, and the retest is always included. Indicative figures below; final pricing follows scoping.
Focused
A scoped test of one application, network segment, or cloud account. Ideal for compliance cycles and pre-launch sign-off.
- 1 application or network scope
- Up to 5 operator-days
- Executive + technical report
- CVSS-rated findings
- Free remediation retest
- Email support during fixes
Program
A continuous testing partnership across your estate, with recurring assessments and a named lead operator who learns your environment.
- Multi-asset rolling scope
- Up to 20 operator-days / quarter
- Dedicated lead operator
- Cloud + appsec coverage
- Quarterly trend reporting
- Slack / Teams collaboration channel
- Priority critical alerting
Red Team
Threat-intel-led adversary emulation against people, process, and technology — measuring detection and response, not just controls.
- Objective-based engagement
- Phishing & physical (optional)
- Stealth & persistence testing
- Purple-team replay & tuning
- Detection gap analysis
- Executive board briefing
- Strategic uplift roadmap
All figures in USD and indicative only. Pricing varies with scope, environment complexity, and timing windows.
What's included where.
| Capability | Focused | Program | Red Team |
|---|---|---|---|
| Manual, operator-led testing | ✓ | ✓ | ✓ |
| Reproduction steps for every finding | ✓ | ✓ | ✓ |
| Free remediation retest | ✓ | ✓ | ✓ |
| <48h critical alerting | ✓ | ✓ | ✓ |
| Dedicated lead operator | — | ✓ | ✓ |
| Rolling / continuous scope | — | ✓ | — |
| Detection & response measurement | — | — | ✓ |
| Social-engineering vectors | — | — | ✓ |
| Executive board briefing | — | ✓ | ✓ |
Bolt on what your scenario needs.
Phishing simulation
Targeted credential-harvest and payload campaigns with awareness metrics.
Physical intrusion
Badge cloning, tailgating, and on-site access testing under signed authorization.
Source code review
Deep grey-box review of a critical codebase with secure-coding guidance.
Tabletop exercise
Facilitated incident-response simulation for your leadership and SOC.
Tell us the objective. We'll quote it.
Scoping calls are free, and you'll have a fixed proposal within two business days.
Request a proposal →