Pentesting
Test the application your customers use the way an outside attacker would, from a zero-traffic exposure check to a four-hour active test, with every attack result checked against its evidence.
One-time run
Priced per run, so you can pentest your services every week instead of once a year, and hand each report to a customer or an auditor.
- Price
From $20per run
- Black-box scan$20
- Active test, Quick$20
- Active test, Standard$50
- Active test, Deep$100
- You provide
- A domain you prove you control, and credentials if the app should be tested behind its login
- Runs
- A zero-traffic black-box scan, or an active test in Quick, Standard or Deep mode
- Takes
- Up to 15 minutes, 1 hour or 4 hours, by mode
- You get back
- Evidence-checked findings with a curl proof of concept, a PDF with an A to F risk grade, and JSON
Nothing is scanned until you prove you control the domain with a DNS CNAME, a DNS TXT record or a file on the site. Tests only reach the exact host you configure inside that domain, signed in with Basic, Bearer or cookie credentials if you add them.
Built only from public records (certificate transparency, public DNS and network registration data), it maps the hostnames you expose, where they are hosted and how your email is protected, with an A to F email-security grade. Your application receives no traffic.
Quick crawls the app and runs critical and high signature checks in up to 15 minutes. Standard also attacks the parameters it finds, from SQL injection to XSS and template injection, in up to an hour. Deep adds a browser-driven crawl and low-severity checks in up to four hours.
OWASP ZAP, Nuclei, sqlmap and dalfox find the candidates. An AI review then reads the exact request and response behind each attack result and drops the ones the evidence does not support.
Each confirmed finding comes with a curl proof of concept, a CVSS 3.1 score, its CWE and remediation. Export a PDF with an A to F risk grade and what was resolved since the last scan, or the full JSON with request and response evidence.
Domains
2 verifiedMore Features
- Model EvaluationEvaluate your LLM feature with tests written from what it is meant to do.
- ReviewsContext-aware pull request review with summaries, requirement tracking, re-reviews and autofix.
- Security ScansSecrets, injection, auth gaps, dependency risk and an org-wide SBOM, caught before the merge.
- GovernanceMerge gates, policy checks and review rules, enforced on every pull request.
- Code NavigationA live architecture map, component health from Repo X-Ray, and answers across every repository.
- Developer AnalyticsReview latency, rework, throughput and DORA metrics per team and repository.
- Monitoring & InsightsContinuous repository monitoring with anomaly detection and deployment insight.
- Repo ScanA one-off, whole-repository review by eight specialist reviewers.

