Monthly
Annual Save 25%

Loading plans...

Compare tiers

What each tier includes, capability by capability. Pricing is not repeated here: the current price, included asset quota and overage rate for every tier render live from our platform in the plan cards above, so you never read a stale number.

Scroll the table sideways to see every tier.

Capability Starter ProfessionalMost popular EnterpriseSales-led Partner / MSPSales-led
Scanning and testing
External network scanning Included Included Included Included
Internal network scanning via the on-premise agent Included Included Included Included
Web application scanning Included Included Included Included
API scanning Included Included Included Included
Mobile application scanning Not included Included Included Included
Cloud posture audit (AWS, Azure, GCP, M365) Not included Included Included Included
Email security audit Not included Not included Included Included
Microsoft 365 audit Not included Not included Included Included
Unlimited scans within fair use Included Included Included Included
Exploitation and AI
Advanced exploitation Not included Not included Included Included
AI-guided remediation Not included Included Included Included
Threat intelligence Not included Included Included Included
Reporting and analytics
Basic compliance reporting Included Included Included Included
Full compliance reporting (8 frameworks plus CIS Benchmarks) Not included Included Included Included
Scan comparison and trending Not included Included Included Included
Operations and access
Scheduled scans Not included Included Included Included
Integrations Not included Included Included Included
Team management Not included Included Included Included
Scan capacity Shared Isolated workload Isolated workload Isolated workload
Continuous monitoring (EASM) Not included Not included Included Included
Single sign-on (SSO) Not included Not included Included Included
Custom integrations Not included Not included Included Included
On-premise deployment option Not included Not included Included Included
Data and governance
Findings and scan-data retention 1 year 3 years Custom, up to 7 years 7 years
365-day audit-log retention Included Included Included Included
Data-residency options Not included Not included Included Included
Commercial and support
Annual billing and invoicing Included Included Included Included
MSA, DPA and negotiated terms Not included Not included Included Included
Dedicated security review Not included Not included Included Included
Dedicated account manager Not included Not included Included Included
Service level agreement Not included Not included Included Included
Partner and MSP
Fully isolated, dedicated environment per client Not included Not included Not included Included
Custom domain with auto-managed SSL Not included Not included Not included Included
Fleet-wide agent management Not included Not included Not included Included
White-label or resell under your own brand Not included Not included Not included Included
Next step Start 7-day trial Start 7-day trial Contact sales Contact sales

The 8 compliance reporting frameworks are what your findings are mapped to in reports. They are not a statement that PentestOps or your organisation is certified against them. See our methodology for how reporting works, or the Trust Centre for how we handle your data.

How asset counting works

An asset is one item the platform can scan or monitor: a public IP address, a hostname, a web application, an internal subnet target, a cloud account or a Kubernetes cluster. You pay for the scope you put under test, not for seats, scanners or per-tool licences.

12 public hostnames
2 cloud accounts
1 Kubernetes cluster
15 assets in scope

Take an organisation running 12 public hostnames, 2 cloud accounts and 1 Kubernetes cluster. That is 15 assets, and it stays 15 assets however many workloads sit inside those accounts and that cluster. Here is what follows from that:

  • Each cloud account counts as one asset, whatever number of resources, regions or services it holds.
  • Each Kubernetes cluster counts as one asset, whatever number of nodes, namespaces or workloads it runs.
  • Scans against the assets in scope are unlimited within fair use, so retesting after every change costs the same as testing once a quarter.
  • Go past the quota included in your tier and each extra asset is charged at that tier's overage rate. The portal shows a live asset counter and warns you before any additional charge applies.
  • Upgrades take effect immediately. Downgrades take effect at the start of your next billing cycle.
  • Not sure how your environment maps to assets? Talk to sales and we will scope it with you.

Need Enterprise Features?

For large organisations with complex security requirements, we offer custom enterprise plans with dedicated infrastructure, advanced integrations, and white-glove support services.

Dedicated infrastructure
Custom integrations
On-premise deployment
SLA guarantees
Dedicated account manager
Custom training
Contact sales

Reselling to your own clients? Apply to the partner programme or read about the MSP platform.

Frequently Asked Questions

What counts as an asset?

An asset is one item the platform can scan or monitor: a public IP address, a hostname, a web application, an internal subnet target, a cloud account or a Kubernetes cluster. Each cloud account counts as one asset and each Kubernetes cluster counts as one asset, no matter how many resources or nodes sit inside them. That is what asset-wise pricing means in practice: you pay for the scope you put under test, not for seats, scanners or per-tool licences.

How does the 7-day free trial work?

All paid plans start with a 7-day free trial. No charge for 7 days: a card is required to start your trial and is only charged after the trial ends, unless you cancel first. You get the tier you selected for the whole trial, so you can run real assessments against your own assets rather than a sandbox. Pick a tier and start a trial, or run a free demo scan first if you would rather see output before signing up.

Are scans limited, or can I test as often as I like?

Scans against the assets in your plan are unlimited within fair use, so testing weekly costs the same as testing once a quarter. That is deliberate: the point of continuous penetration testing is to retest after every change, and a per-scan meter would push you to test less. Fair use exists only to stop a single tenant monopolising shared capacity; if your programme is unusually scan-heavy, talk to us and we will size the right tier with you.

Is Kubernetes and cloud auditing included, and does it need an agent?

Cloud posture auditing is included from the Professional tier and covers AWS, Azure, GCP and M365 with 800+ automated checks plus CIS Benchmark coverage. Kubernetes auditing is agentless and works on GKE (including Autopilot), EKS (including Fargate), AKS, OpenShift, k3s and self-managed or on-prem clusters. Neither needs the on-prem agent: cloud auditing uses read-only credentials you issue, and Kubernetes uses a customer-supplied read-only kubeconfig with no DaemonSet to install. Each account or cluster counts as one asset.

Can I upgrade or downgrade my plan?

Yes. Upgrades take effect immediately, so the extra capability and asset quota are available as soon as the change is confirmed. Downgrades take effect at the start of your next billing cycle, which keeps the tier you already paid for running until that period ends. You can also switch between monthly and annual billing; annual saves around 25 percent against the equivalent monthly rate.

What happens if I add more assets than my tier includes?

Nothing breaks and nothing stops scanning. Once you pass the included quota you pay for each additional asset at your tier's overage rate. The portal shows a live asset counter and warns you before any additional charge applies, so an overage is always a decision you make rather than a surprise on an invoice. If you are consistently paying overage, moving up a tier is usually the cheaper option, and upgrades take effect immediately.

What payment methods do you accept?

All major credit cards, ACH bank transfers, and wire transfers for enterprise customers. Invoicing is available for annual plans. Card payments and billing are processed by our payment sub-processor, which is listed in the Trust Centre. Enterprise agreements can also be set up with invoicing, an MSA and a signed DPA; ask us through sales.

How do Enterprise and Partner or MSP pricing work?

Enterprise is sales-led because the scope varies: dedicated infrastructure, custom integrations, an on-premise deployment option, SLA terms, custom retention, data-residency arrangements, SSO and a dedicated account manager. The Partner and MSP programme is separate again, with its own tiers, so you can white-label or resell asset-wise testing with a fully isolated environment per client. Talk to sales or apply to the partner programme.