Penetration Testing Pricing:
Starter, Growth & Enterprise

Start with 2 free credits, then $35 per scan. Scale to a full team plan when you're ready. Every plan includes the complete PenScan platform.

Starter
$35 per scan
1 free credit on signup, then pay as you go — no commitment
What's included
1 domain
1 seat
All 7 security scanners
Technical Assessment PDF
Asset & subdomain discovery
Trust certificate & badge
Email support
Scheduled / recurring scans
Scan comparison
Multi-domain management
Team seats
Remediation tracking
Executive & Compliance PDFs
Combined multi-target PDF report
Vulnerability triage & assignment
Get started free

2 free credits included · No card required

Enterprise
Custom
Pricing on request
Everything in Growth, plus
Unlimited scans
Unlimited domains & seats
Premier customer support (SLA-backed)
Cyber security expert access — remediation guidance from vetted professionals
Enterprise-grade audit logs & compliance reports
Custom contract & invoicing
SSO / SAML & advanced RBAC
Talk to sales

Typically responds within 1 business day

Everything side by side

Starter Growth Enterprise
Price $35 / scan $99 / mo Custom
Domains 1 3 Unlimited
Seats 1 3 Unlimited
Scans included Pay per scan 50 / year Unlimited
Support Email Priority Premier (SLA)
All 7 scanners
Technical Assessment PDF
Executive & Compliance PDFs
Combined multi-target PDF report
Asset & subdomain discovery
Cross-scanner deduplication
Severity-ranked findings
Trust certificates & badges
Vulnerability triage & assignment
Remediation progress tracking
Scheduled / recurring scans
Scan comparison (diff)
Multi-domain management
Team seats
Audit logs
White-glove onboarding
Cyber security expert access
Enterprise compliance reports
SSO / SAML
Custom contract & invoicing
Get started Start Growth Talk to sales

Full platform access on every plan

Every plan — including a single $35 scan — gives you the complete PenScan platform. No crippled free tier, no feature walls.

All 7 scanner types (ZAP, Nuclei, Wapiti, Nikto, SSLyze, Nmap, Dalfox)
Combined & deduplicated vulnerability report
Severity-ranked findings (Critical → Low)
Asset & subdomain discovery
DNS ownership verification
Trust certificates & embeddable widgets
Vulnerability management dashboard
Audit & action logs
Technical Assessment PDF report

Questions we hear before the first scan

No sales call required to get answers.

Yes. PenScan enforces ownership verification via DNS TXT records before any scan begins — you can only scan domains you demonstrably control. Users must also acknowledge a legal disclaimer confirming authorisation before initiating a scan. This makes PenScan both legally sound and ethically enforced, not just policy-stated.
A full combined scan typically completes in 15–30 minutes, depending on the size and complexity of your target. All seven scanners run concurrently — OWASP ZAP accounts for the largest share of scan weight and usually takes the longest. You'll receive a notification when your results are ready.
One credit powers one full combined scan of a single target — all seven scanners running concurrently, results merged and deduplicated into a single report. Starter credits are $35 each with no minimum purchase or subscription required. Passive asset discovery (subdomain enumeration) when you add a new target is always free and never consumes a credit.
Credits are valid for one year from the date of purchase. Buy what you need and use them at your own pace — whether that's this afternoon or several months from now.
Yes — and this is one of PenScan's key advantages over a traditional pentest. With a consultant, getting a fix re-verified meant a new scoping conversation and often a new invoice. With PenScan, mark a finding as fixed, run a new scan, and confirm the remediation actually worked. The audit log captures the full timeline for compliance purposes.
Yes. PenScan supports team collaboration with role-based access control. Invite team members as Owners (full access), Analysts (can run and review scans), or Viewers (read-only access to reports). All roles operate within your organisation's isolated workspace — completely separate from every other account on the platform.
PenScan orchestrates seven industry-standard tools: OWASP ZAP (web application scanning), Nuclei (CVE & misconfiguration templates), Wapiti (SQLi, XSS, CSRF), Nikto (web server fingerprinting), SSLyze (TLS/SSL analysis), Nmap (port & service discovery), and Dalfox (advanced XSS fuzzing). All results are merged and deduplicated into a single prioritised report.
Yes. Each organisation's data is isolated in a multi-tenant architecture — no other user or organisation can access your targets, scans, or vulnerability reports. Data is encrypted in transit (TLS 1.3) and at rest. Scan results and API tokens are never stored in plaintext.

Stop hoping you're secure.
Know that you are.

Add your domain, verify ownership with a DNS record, and run your first full security assessment. No consultants, no contracts, no infrastructure to manage.

2 free credits included  ·  No credit card required  ·  Credits valid for 1 year