Transparent pricing
Penetration Testing Pricing:
Starter, Growth & Enterprise
Start with 2 free credits, then $35 per scan. Scale to a full team plan when you're ready. Every plan includes the complete PenScan platform.
Starter
$35
per scan
1 free credit on signup, then pay as you go — no commitment
What's included
1 domain
1 seat
All 7 security scanners
Technical Assessment PDF
Asset & subdomain discovery
Trust certificate & badge
Email support
Scheduled / recurring scans
Scan comparison
Multi-domain management
Team seats
Remediation tracking
Executive & Compliance PDFs
Combined multi-target PDF report
Vulnerability triage & assignment
2 free credits included · No card required
Most popular
Growth
$99
/ month
Billed annually — $1,188/yr
What's included
3 domains
3 seats (Owner / Analyst / Viewer)
50 scans / year included, granted when your subscription activates
Extra scans beyond that: $35 per scan
All 7 security scanners
Asset & subdomain discovery
Trust certificates & badges
All 3 PDF reports (Technical, Executive, Compliance)
Combined multi-target PDF report
Vulnerability triage & assignment
Scheduled / recurring scans
Scan comparison (diff)
Multi-domain management
Team seats
Remediation tracking
Priority support
White-glove onboarding
Cyber security expert access
Annual billing · Cancel anytime
Enterprise
Custom
Pricing on request
Everything in Growth, plus
Unlimited scans
Unlimited domains & seats
Premier customer support (SLA-backed)
Cyber security expert access — remediation guidance from vetted professionals
Enterprise-grade audit logs & compliance reports
Custom contract & invoicing
SSO / SAML & advanced RBAC
Typically responds within 1 business day
Compare plans
Everything side by side
| Starter | Growth | Enterprise | |
|---|---|---|---|
| Price | $35 / scan | $99 / mo | Custom |
| Domains | 1 | 3 | Unlimited |
| Seats | 1 | 3 | Unlimited |
| Scans included | Pay per scan | 50 / year | Unlimited |
| Support | Priority | Premier (SLA) | |
| All 7 scanners | |||
| Technical Assessment PDF | |||
| Executive & Compliance PDFs | |||
| Combined multi-target PDF report | |||
| Asset & subdomain discovery | |||
| Cross-scanner deduplication | |||
| Severity-ranked findings | |||
| Trust certificates & badges | |||
| Vulnerability triage & assignment | |||
| Remediation progress tracking | |||
| Scheduled / recurring scans | |||
| Scan comparison (diff) | |||
| Multi-domain management | |||
| Team seats | |||
| Audit logs | |||
| White-glove onboarding | |||
| Cyber security expert access | |||
| Enterprise compliance reports | |||
| SSO / SAML | |||
| Custom contract & invoicing | |||
| Get started | Start Growth | Talk to sales |
Always included
Full platform access on every plan
Every plan — including a single $35 scan — gives you the complete PenScan platform. No crippled free tier, no feature walls.
All 7 scanner types (ZAP, Nuclei, Wapiti, Nikto, SSLyze, Nmap, Dalfox)
Combined & deduplicated vulnerability report
Severity-ranked findings (Critical → Low)
Asset & subdomain discovery
DNS ownership verification
Trust certificates & embeddable widgets
Vulnerability management dashboard
Audit & action logs
Technical Assessment PDF report
FAQ
Questions we hear before the first scan
No sales call required to get answers.
Yes. PenScan enforces ownership verification via DNS TXT records before any scan begins —
you can only scan domains you demonstrably control. Users must also acknowledge a legal
disclaimer confirming authorisation before initiating a scan. This makes PenScan both
legally sound and ethically enforced, not just policy-stated.
A full combined scan typically completes in 15–30 minutes, depending on the size and
complexity of your target. All seven scanners run concurrently — OWASP ZAP accounts for
the largest share of scan weight and usually takes the longest. You'll receive a
notification when your results are ready.
One credit powers one full combined scan of a single target — all seven scanners running
concurrently, results merged and deduplicated into a single report. Starter credits are
$35 each with no minimum purchase or subscription required. Passive asset discovery
(subdomain enumeration) when you add a new target is always free and never consumes a credit.
Credits are valid for one year from the date of purchase. Buy what you need and use them
at your own pace — whether that's this afternoon or several months from now.
Yes — and this is one of PenScan's key advantages over a traditional pentest. With a
consultant, getting a fix re-verified meant a new scoping conversation and often a new invoice.
With PenScan, mark a finding as fixed, run a new scan, and confirm the remediation actually
worked. The audit log captures the full timeline for compliance purposes.
Yes. PenScan supports team collaboration with role-based access control. Invite team members
as Owners (full access), Analysts (can run and review scans), or Viewers (read-only access
to reports). All roles operate within your organisation's isolated workspace — completely
separate from every other account on the platform.
PenScan orchestrates seven industry-standard tools:
OWASP ZAP (web application scanning),
Nuclei (CVE & misconfiguration templates),
Wapiti (SQLi, XSS, CSRF),
Nikto (web server fingerprinting),
SSLyze (TLS/SSL analysis),
Nmap (port & service discovery), and
Dalfox (advanced XSS fuzzing).
All results are merged and deduplicated into a single prioritised report.
Yes. Each organisation's data is isolated in a multi-tenant architecture — no other user
or organisation can access your targets, scans, or vulnerability reports. Data is encrypted
in transit (TLS 1.3) and at rest. Scan results and API tokens are never stored in plaintext.
Get started today
Stop hoping you're secure.
Know that you are.
Add your domain, verify ownership with a DNS record, and run your first full security assessment. No consultants, no contracts, no infrastructure to manage.
2 free credits included · No credit card required · Credits valid for 1 year