Self-serve pricing
Evaluate one authorized target and scan. The shared business-domain evaluation lasts up to 14 days from first account creation, with no card or automatic charge; write access then becomes view-only unless you choose a paid plan.
Prices are shown in your selected region's currency when available. Checkout and invoices use the same localized pricing; settlement is in euros per Stripe's conversion.
Choose a Team or Growth subscription for recurring capacity, or Pay as you go for completed scans. Billing terms and totals are shown before activation or checkout.
Planning can incorporate public vulnerability intelligence and stack-matched advisories. Verification still follows target authorization, the selected profile, and recorded scope.
Company evaluation
Inspect the workflow with no card or automatic charge
- 1 target application
- 1 scan
- Finding evidence and basic reports
- Email notifications
Team
Full platform for small teams
- 1 target application
- 1 scan per month (12 per year)
- Capabilities selected by profile and target context
- API access & attack graph
- Fix-verification retest loop
- Engagement health dashboard
- Standards-aligned reports & PDF branding
- 90-day activity audit trail
- 10 team seats
Growth
Scale coverage across more applications
- 5 target applications
- 5 scans per month (60 per year)
- Capabilities selected by profile and target context
- API access & attack graph
- Fix-verification retest loop
- Engagement health dashboard
- Standards-aligned reports & PDF branding
- 90-day activity audit trail
- 10 team seats
Enterprise
Custom annual program for larger organizations
- Custom targets and scan volume
- Consent-gated phishing simulations
- Annual contract with dedicated onboarding
- Priority support
- Custom integrations and SLAs
- Everything in Growth, scaled to your program
Prefer usage billing?
Pay as you go
Same rate as one Team month — only when a web scan completes.
No monthly fee. Zero completed scans = €0. Net-60 invoice.
- Unlimited targets & seats
- Unlimited web scans (billed per scan)
- Capabilities selected by profile and target context
- API access & attack graph
- Compliance reports & PDF branding
- Net-60 monthly Stripe invoice
- No subscription to cancel
Frequently Asked Questions
What happens after my free trial?
The workspace and existing results remain available to read, but write actions require a paid plan when the evaluation ends. Each business domain receives one shared evaluation lasting up to 14 calendar days from its first account creation, including one authorized target and one scan, with no card or automatic charge.
Can I change plans later?
You can request plan changes through billing. The effective date and any billing adjustment are shown before you confirm the change.
What payment methods do you accept?
We accept all major credit cards and debit cards. All payments are processed securely through Stripe.
How are billing issues handled?
Contact support with the relevant invoice or payment details. We review billing errors and correction requests individually and explain the available resolution before making a change.
Can I delete a target?
Yes. Targets can be deleted if they have never been scanned or have not been scanned in the last 6 months. Detailed findings and tool output follow the published 90-day service retention period; exported PDF and HTML reports are retained for up to 365 days.
Is the target domain validated?
Yes. When you add a target, we verify that the domain is reachable via DNS and HTTP. This prevents typos and ensures the target is valid before using up a plan slot.
How is Agent Breach different from Intruder or a traditional DAST subscription?
Signature DAST remains useful for broad CVE and configuration coverage. Agent Breach adds response-aware planning, authenticated application testing, explicit confirmation states, source evidence, CI/CD checks, and fix retests in one workspace.
Why Agent Breach instead of periodic pentests or PTaaS?
Periodic pentests and PTaaS provide scoped human assessments. Agent Breach supports repeatable validation between them, with authenticated testing, PR checks, evidence records, reports, and fix retests.
What report templates are included?
Paid plans include PDF templates for executives (AI Explained, Executive Report), developers, and compliance standards (OWASP WSTG/ASVS, NIST 800-115 & CSF 2.0, CREST, PCI-DSS ASV-style, CIS Controls), plus JSON/CSV exports. Team and higher include full-matrix framework mapping JSON (SOC 2, PCI-DSS, HIPAA, ISO 27001, MITRE ATT&CK, CIS, NIST CSF 2.0, OWASP ASVS) with applicability by app type, and Evidence Pack ZIP.
Is PCI-DSS ASV-style the same as PCI certification?
No. ASV-style templates document vulnerability findings for your audit package. They do not replace a PCI ASV scan, QSA attestation, or formal PCI compliance certification.
Ready to Get Started?
Evaluate one authorized target and scan for up to 14 days from the first account created for your business domain. Work email required; no card or automatic charge.
Start free evaluation