Simple, Transparent Pricing
Asset-wise pricing. Pay for what you actually scan. All paid plans start with a 7-day free trial. No charge for 7 days - a card is required to start your trial and is only charged after the trial ends, unless you cancel first.
Loading plans...
Compare tiers
What each tier includes, capability by capability. Pricing is not repeated here: the current price, included asset quota and overage rate for every tier render live from our platform in the plan cards above, so you never read a stale number.
Scroll the table sideways to see every tier.
| Capability | Starter | ProfessionalMost popular | EnterpriseSales-led | Partner / MSPSales-led |
|---|---|---|---|---|
| Scanning and testing | ||||
| External network scanning | Included | Included | Included | Included |
| Internal network scanning via the on-premise agent | Included | Included | Included | Included |
| Web application scanning | Included | Included | Included | Included |
| API scanning | Included | Included | Included | Included |
| Mobile application scanning | Not included | Included | Included | Included |
| Cloud posture audit (AWS, Azure, GCP, M365) | Not included | Included | Included | Included |
| Email security audit | Not included | Not included | Included | Included |
| Microsoft 365 audit | Not included | Not included | Included | Included |
| Unlimited scans within fair use | Included | Included | Included | Included |
| Exploitation and AI | ||||
| Advanced exploitation | Not included | Not included | Included | Included |
| AI-guided remediation | Not included | Included | Included | Included |
| Threat intelligence | Not included | Included | Included | Included |
| Reporting and analytics | ||||
| Basic compliance reporting | Included | Included | Included | Included |
| Full compliance reporting (8 frameworks plus CIS Benchmarks) | Not included | Included | Included | Included |
| Scan comparison and trending | Not included | Included | Included | Included |
| Operations and access | ||||
| Scheduled scans | Not included | Included | Included | Included |
| Integrations | Not included | Included | Included | Included |
| Team management | Not included | Included | Included | Included |
| Scan capacity | Shared | Isolated workload | Isolated workload | Isolated workload |
| Continuous monitoring (EASM) | Not included | Not included | Included | Included |
| Single sign-on (SSO) | Not included | Not included | Included | Included |
| Custom integrations | Not included | Not included | Included | Included |
| On-premise deployment option | Not included | Not included | Included | Included |
| Data and governance | ||||
| Findings and scan-data retention | 1 year | 3 years | Custom, up to 7 years | 7 years |
| 365-day audit-log retention | Included | Included | Included | Included |
| Data-residency options | Not included | Not included | Included | Included |
| Commercial and support | ||||
| Annual billing and invoicing | Included | Included | Included | Included |
| MSA, DPA and negotiated terms | Not included | Not included | Included | Included |
| Dedicated security review | Not included | Not included | Included | Included |
| Dedicated account manager | Not included | Not included | Included | Included |
| Service level agreement | Not included | Not included | Included | Included |
| Partner and MSP | ||||
| Fully isolated, dedicated environment per client | Not included | Not included | Not included | Included |
| Custom domain with auto-managed SSL | Not included | Not included | Not included | Included |
| Fleet-wide agent management | Not included | Not included | Not included | Included |
| White-label or resell under your own brand | Not included | Not included | Not included | Included |
| Next step | Start 7-day trial | Start 7-day trial | Contact sales | Contact sales |
The 8 compliance reporting frameworks are what your findings are mapped to in reports. They are not a statement that PentestOps or your organisation is certified against them. See our methodology for how reporting works, or the Trust Centre for how we handle your data.
How asset counting works
An asset is one item the platform can scan or monitor: a public IP address, a hostname, a web application, an internal subnet target, a cloud account or a Kubernetes cluster. You pay for the scope you put under test, not for seats, scanners or per-tool licences.
Take an organisation running 12 public hostnames, 2 cloud accounts and 1 Kubernetes cluster. That is 15 assets, and it stays 15 assets however many workloads sit inside those accounts and that cluster. Here is what follows from that:
- Each cloud account counts as one asset, whatever number of resources, regions or services it holds.
- Each Kubernetes cluster counts as one asset, whatever number of nodes, namespaces or workloads it runs.
- Scans against the assets in scope are unlimited within fair use, so retesting after every change costs the same as testing once a quarter.
- Go past the quota included in your tier and each extra asset is charged at that tier's overage rate. The portal shows a live asset counter and warns you before any additional charge applies.
- Upgrades take effect immediately. Downgrades take effect at the start of your next billing cycle.
- Not sure how your environment maps to assets? Talk to sales and we will scope it with you.
Need Enterprise Features?
For large organisations with complex security requirements, we offer custom enterprise plans with dedicated infrastructure, advanced integrations, and white-glove support services.
Reselling to your own clients? Apply to the partner programme or read about the MSP platform.
Frequently Asked Questions
What counts as an asset?
An asset is one item the platform can scan or monitor: a public IP address, a hostname, a web application, an internal subnet target, a cloud account or a Kubernetes cluster. Each cloud account counts as one asset and each Kubernetes cluster counts as one asset, no matter how many resources or nodes sit inside them. That is what asset-wise pricing means in practice: you pay for the scope you put under test, not for seats, scanners or per-tool licences.
How does the 7-day free trial work?
All paid plans start with a 7-day free trial. No charge for 7 days: a card is required to start your trial and is only charged after the trial ends, unless you cancel first. You get the tier you selected for the whole trial, so you can run real assessments against your own assets rather than a sandbox. Pick a tier and start a trial, or run a free demo scan first if you would rather see output before signing up.
Are scans limited, or can I test as often as I like?
Scans against the assets in your plan are unlimited within fair use, so testing weekly costs the same as testing once a quarter. That is deliberate: the point of continuous penetration testing is to retest after every change, and a per-scan meter would push you to test less. Fair use exists only to stop a single tenant monopolising shared capacity; if your programme is unusually scan-heavy, talk to us and we will size the right tier with you.
Is Kubernetes and cloud auditing included, and does it need an agent?
Cloud posture auditing is included from the Professional tier and covers AWS, Azure, GCP and M365 with 800+ automated checks plus CIS Benchmark coverage. Kubernetes auditing is agentless and works on GKE (including Autopilot), EKS (including Fargate), AKS, OpenShift, k3s and self-managed or on-prem clusters. Neither needs the on-prem agent: cloud auditing uses read-only credentials you issue, and Kubernetes uses a customer-supplied read-only kubeconfig with no DaemonSet to install. Each account or cluster counts as one asset.
Can I upgrade or downgrade my plan?
Yes. Upgrades take effect immediately, so the extra capability and asset quota are available as soon as the change is confirmed. Downgrades take effect at the start of your next billing cycle, which keeps the tier you already paid for running until that period ends. You can also switch between monthly and annual billing; annual saves around 25 percent against the equivalent monthly rate.
What happens if I add more assets than my tier includes?
Nothing breaks and nothing stops scanning. Once you pass the included quota you pay for each additional asset at your tier's overage rate. The portal shows a live asset counter and warns you before any additional charge applies, so an overage is always a decision you make rather than a surprise on an invoice. If you are consistently paying overage, moving up a tier is usually the cheaper option, and upgrades take effect immediately.
What payment methods do you accept?
All major credit cards, ACH bank transfers, and wire transfers for enterprise customers. Invoicing is available for annual plans. Card payments and billing are processed by our payment sub-processor, which is listed in the Trust Centre. Enterprise agreements can also be set up with invoicing, an MSA and a signed DPA; ask us through sales.
How do Enterprise and Partner or MSP pricing work?
Enterprise is sales-led because the scope varies: dedicated infrastructure, custom integrations, an on-premise deployment option, SLA terms, custom retention, data-residency arrangements, SSO and a dedicated account manager. The Partner and MSP programme is separate again, with its own tiers, so you can white-label or resell asset-wise testing with a fully isolated environment per client. Talk to sales or apply to the partner programme.