// pricing

Pricing, in plain numbers.

Every rate is on this page. Pick what you want tested, choose how deep, and work out your own total. One base per test type per order, and a per-target rate that falls as you scale.

Start with what you want tested

Four test types, each with its own depth. A type charges one base per order at the depth you chose for it, however many targets or tests that order covers, and picking more than one type brings the bases down.

External

Your internet-facing targets, tested from our infrastructure.

Targets price on the external curve.

Internal

Your internal network, tested through an appliance you run on it.

Targets price on the internal curve, a flat step above external.

Cloud

One cloud account. A control-plane posture review of identity, exposure, data protection, and detection gaps.

One flat base at any depth: it buys the posture pass. Add the VMs and apps inside as targets, and individual resources as flat add-ins, and your chosen depth applies to those.

Domain

One network range. Active Directory enumeration, certificate services, and the coercion surface.

One base for the range, higher at Deep. Add hosts in it as targets on the internal curve.

Base, by test type and depth

Test typeQuickVulnerabilityStandardDeep
External$60$350$750$1,200
Internal$80$450$850$1,300
Cloud$750(Full read-only always)(Discovered resource tests)
Domain$750$1,200

Pick one depth per row, not one for the whole order: Deep across your internet-facing estate and Standard inside is a single order. Each type's targets then ride their own volume curve at their own depth. Where a base does not move with depth, the depth you pick governs the targets and resources inside that test rather than the base. A dash means that test type is not offered at that depth.

Combine test types and pay less

25%
off the bases with 2 test types
30%
off the bases with 3 test types
35%
off the bases with 4 test types

Ten internet-facing and ten internal targets at Standard Pentest: $1,900 in one order, against $2,300 bought separately. Combining is cheaper by construction, never the other way round.

Then choose how deep

Test your internet-facing targets from our infrastructure.

Quick Test

A fast first look across your network and web apps, inside or out, in under an hour.

$75per test
flat, one target per test
Estimated time: ~30-60 min
A fast read on your network and web apps, internal or internet-facing
Open ports and running services, mapped
Known-CVE and common-misconfiguration checks
AI-reviewed results, ranked by priority
A full report you can act on

Vulnerability Assessment

Most popular

Find what's vulnerable, validated, not a scanner's pile of maybes.

$375for one target
$350 base + $25/target for your first ten
Estimated time: ~1-2 hours
Every port, service, and endpoint checked (all 65,535 ports)
CVEs, OWASP Top 10, and misconfigurations across network and web apps
TLS/SSL configuration reviewed
AI validates each finding and clears the false positives
Findings ranked so you know what to fix first
A report structured for your audit

Standard Pentest

Best for a pentest report

Proof, not guesses. We safely exploit what we find and show you the evidence.

$780for one target
$750 base + $30/target for your first ten
Estimated time: ~2-4 hours
Everything in the Vulnerability Assessment
Safe exploitation to prove each finding is genuine
The evidence with it: command, output, steps to reproduce
Attack paths identified and documented
Every high and critical independently re-verified

Deep Pentest

Most thorough

The full attacker simulation, for your highest-value targets.

$1,250for one target
$1,200 base + $50/target for your first ten
Estimated time: ~4-8 hours
Everything in the Standard Pentest
Full exploitation, chained the way an attacker would
Privilege-escalation and lateral-movement testing, within scope
API and business-logic testing
Authenticated testing included
Add-on

Add authenticated testing

Give Prober credentials and it tests behind the login: session handling, access controls, and the pages a signed-in user reaches.

+$50 and +$10/target on Vulnerability
+$100 and +$10/target on Standard
Included in Deep

Per-target rates, published

Your first 10 targets are half the full rate, and volume brings you back to half price by target 101. The whole table is here.

Tier
1-10
Half price
11-25
Full rate
26-50
 
51-100
 
101+
Half price
Quick Testflat$15$15$15$15$15
Vulnerability Assessment$25$50$42$33$25
Standard Pentest$30$60$50$40$30
Deep Pentest$50$100$84$67$50

Rates are per target, external. Between the two ends the rate steps down bracket by bracket. Quick Test takes no volume bracket, at a flat $15 per target.

What you pay per target, all in

1 target
$780
$780 total
10 targets
$105
$1,050 total
25 targets
$78
$1,950 total
50 targets
$64
$3,200 total
100 targets
$52
$5,200 total
200 targets
$41
$8,200 total

Base included. One base per test type per order, however many targets or tests it covers.

A retest comes with every target

Fix something and prove it. Every target you test carries one discounted retest, good for 90 days after that test finishes. A retest is the per-target rate with no base, and no volume bracket on top.

TierExternalInternal
Quick$15$20
Vulnerability$25$35
Standard$30$40
Deep$50$60

Per target. A target that failed or came back unqualified is re-run free, in place, and does not spend the retest.

Price your order

The same function that charges your order. Pick a depth for each test type: Deep across your internet-facing estate and Standard inside is one order, one payment.

Depth
// your order
External baseStandard Pentest
$750
10 internet-facing targets, Standard10 x $30
$300
Order total$1,050
$105 per target, all in

Runs as 1 test, launched when you are ready.

Every target carries one discounted retest for 90 days after its test finishes, at its own depth's rate and with no base.

On a monthly schedule this order is $840 with annual billing.

Compare the tiers

FeatureQuickVulnerabilityStandardDeep
Network testing
Web app testing
CVE detection
AI validation
Audit-ready report
Authenticated testingOptionalOptionalIncluded
Safe exploitation
Proof of concept
Attack chaining
Business-logic testing
API testing

Save with a testing schedule

Lower pricing on every order when you test on a cadence. The discount applies to the whole order, base and targets alike.

Monthly testing

A test a month on your targets.

Pay per period
Billed each month
10% off
every order
Pay annually
Billed once per year
20% off
Best value

Quarterly testing

A test each quarter, the cadence auditors expect.

Pay per period
Billed every 3 months
8% off
every order
Pay annually
Billed once per year
15% off
Best value
Built for the audit

Every report includes the executive summary, methodology, and per-finding detail an auditor expects, structured to support your SOC 2, ISO 27001, PCI-DSS, and HIPAA evidence.

Add a human expert

The engine does the testing. Bring in a security professional to validate findings, test by hand, or run a full human-led engagement.

Expert Review

from $750

A pentester reviews your findings, clears the false positives, and prioritizes by business impact.

Manual + Automated

from $1,900

An expert runs and validates the whole engagement by hand and delivers a combined report.

Expert Traditional

from $3,400

A full human-led pentest on traditional methodology, with executive and technical reports.

Pricing FAQ

What counts as a target?

A single IP, domain, or web app. A CIDR range counts as its addresses (10.0.0.0/24 = 254 targets).

How does volume pricing work?

The more targets you test, the less each one costs you. Your first ten sit at half the full rate, and volume brings you back to half price by the hundred-and-first. All in, with the base included, a Standard Pentest external target works out at $105 at ten targets, $78 at twenty-five, and $52 at a hundred. It only ever falls.

Do I pay twice if my order runs as several tests?

No. A base is charged once per test type per order, whatever the order breaks out into. The per-target curve runs continuously across every group, so splitting targets into more tests never costs more than keeping them together.

How long does a test take?

Rough ranges: Quick ~30-60 min, Vulnerability ~1-2 hours, Standard ~2-4 hours, Deep ~4-8 hours, depending on your infrastructure.

Do I need authorization to test?

Yes. You must have explicit permission to test every target; testing systems you don't own or aren't authorized to test is illegal. We supply a liability waiver, but the authorization is yours to hold.

What if my test runs out of time?

We save progress as the test runs. If it hits the time limit, you get a partial report with everything found so far, and you can add time with the Continue Testing add-on.

Are the reports audit-ready?

Yes. Each report carries the executive summary, methodology, and per-finding detail auditors expect.

// ready when you are

Ready to test?

Start with a Quick Test at $75, or a full Vulnerability Assessment from $375.

Go Probe →
Prober Penetration - Automated Security Testing | Prober