Security-service pricing

A defined scope.
A written quote.

Security testing is a professional engagement, not a software plan. We quote the work after understanding your environment, objectives, authorization, and the depth of testing required.

Request a scope discussion

What shapes the quote

Price follows
the work.

No fixed security-service fees are published here. A proposal states the assessment type, methods, coverage, deliverables, exclusions, schedule, and commercial terms before you decide.

Physical/combined assessments and full adversary simulation are proposed services, not available for scheduling. Field work is not currently offered or contracted.

Assets and complexity
Networks, applications, APIs, user roles, environments, and the depth of manual validation.
Physical locations
Site count, approved scenarios, access arrangements, travel, and safety constraints.
Operational requirements
Testing windows, coordination, third-party permissions, and handling of sensitive evidence.
Reporting and follow-up
Report format, debrief, remediation support, and any agreed retest scope and window.

Digital + physical

Coordinate the work.
Avoid duplication.

If launched after readiness review, the proposed combined service could share scoping, reporting, and travel rather than repeat them for separate assessments.

Any savings depend on the same agreed scope and logistics. We identify shared work in the quote rather than promise a percentage discount or cut testing depth to create one.

What happens next?

  1. Send a non-sensitive outline of your organization, likely scope, and timing.
  2. Discuss objectives, authority, constraints, and capability fit.
  3. Review a written quote and engagement scope. Testing begins only after the required agreement and authorization.
Start a scope inquiry

Common questions

Before you request a quote.

Is a vulnerability scan the same as a penetration test?

No. A scan can inform an assessment. A penetration test requires scoped manual validation and analysis of the evidence, not just raw scanner output. The proposal identifies the depth you are buying.

Is retesting included?

Only when it is part of the agreed proposal. The retest scope, window, access requirements, and fee are defined upfront. New assets or expanded testing require a scope change.

Do we need a subscription or an app account?

No. Security-service inquiries begin with an email conversation. Engagement and payment terms are agreed in the written proposal; there is no public security-service checkout.

What if we are looking for CodeFlow?

CodeFlow is a separate existing product. Its product resources, proposals, and agreements remain separate from security-testing services.

Physical and combined assessments are proposed services, not available for scheduling. We are accepting non-binding scope inquiries only. Field work and full adversary simulation remain unavailable until activity-specific legal/licensing review, demonstrated competence, insurance, written authorization, and capability review are complete. An inquiry is not a booking or authorization to test.