Cost and scope
What determines the cost of a penetration test
There's no single price list for every system. Cost follows from the test scope, so we build a proposal after a short scoping call.
Factors that affect the scope
More on defining a penetration test scope →
Application size
The number of screens, processes and flows that actually need coverage — not just the size of the codebase.
User types and permissions
Every additional role multiplies the cross-checks needed to validate access control.
APIs
The number of endpoints, whether documentation exists, and the complexity of the API permission model.
Business logic complexity
Multi-step processes, payments, subscriptions or organizational rules require deeper understanding.
Tenant isolation
Multi-tenant SaaS systems require cross-organization checks, which adds work.
Retesting
A retest, if included, is defined in the agreement and affects scope and cost.
How you get a proposal
- Send a request with basic details about the system
- Scoping call: users, permissions, APIs and environments
- We agree what's in and out of scope, including a retest if relevant
- You receive a written proposal matching the defined scope
There's no automated pricing, price list or time-limited discount on this site. The proposal is built according to scope.