close
Pricing

Plans that fit how you ship.

A paid plan is pentest credits every month, with continuous monitoring, alerts and audit-ready reports included. Start with a free scan, no signup. Larger estates talk to sales.

Free
$0/mo

No credit card required.

Get started

Top-up pentest credits

No plan needed. Buy credits and spend them on a pentest whenever you want. Buy credits

  • Core passive, read-only scans
  • Step-by-step remediation
  • Security score history
Business
Custom

Priced to what you run.

Contact sales
  • Everything in Essential, plus:
  • Volume-priced pentest credits
  • Scoped pentest engagements
  • Daily passive monitoring, 10 domains
  • Slack & Teams alerts
  • Priority support, dedicated contact
  • Tailored scale & integrations
  • SoonTeams & organizations
  • SoonAPI access
Compare plans side-by-side
Credits

Pentests are paid for in credits.

Credits come two ways. A plan is a monthly bundle at its own price, and the bigger the bundle the less each credit works out to. A one-off top-up costs $0.50 a credit, however many you buy. Every pentest runs at a level, and the level sets how many credits that test can spend.

LevelWhat it doesExpert reviewCredits
LightOne agent, one fast pass over every attack class. A quick read between deeper runs.None200
StandardFive specialist agents at once, each owning an area. A full pentest on a regular cadence.1 h1,000
DeepTwenty agents, more waves and user roles, chaining findings through the authenticated surface. For larger apps, or the one test you run all year.2 h4,000
ExtendedFifty agents on one app with many roles and tenants, tested end to end. For large products.4 h10,000
MaximumA hundred agents, the most waves and the deepest chaining, with the most expert review. Everything we have, on one target.8 h20,000

Every level attacks the same 8 areas, mapped to all 97 OWASP WSTG cases. A deeper level puts more agents, more attack waves and more user roles on the same ground, so it digs further into every case. From Standard up it also includes expert review.

  • Injection
  • Access control
  • Authentication & sessions
  • Client-side attacks
  • Information exposure & config
  • Transport & crypto
  • Business logic
  • Server-side & infra
A level is a limit, not a price

A run holds its level's credits, is charged for what it actually used, and the rest goes straight back. A failed run costs nothing; a cancelled one pays only for the work it got through.

Credits come with the plan

Essential grants 200 to 1,070 a month; Business is sized to what you run. Buy more from your dashboard whenever you need them.

They last

Credits you buy last a year from the purchase. Credits your plan grants last the cycle they belong to, plus a grace month.

Compare plans

Side-by-side, feature by feature.

FeatureFreeEssentialBusiness
AI pentesting
AI pentest creditsTop-ups onlyMonthly bundle, from 200Volume-priced to what you run
Passive scan checks1835+35+
Passive scans per day550500
Pages per passive scan320200
Continuous monitoring (passive)1 domain + subdomains, weekly10 domains + subdomains, daily
Vulnerability alertsEmailEmail, Slack, Teams
Scan report
AI stack guidance3/monthUnlimited*Unlimited*
GitHub Repo Connections0120
AI Remediation PRs5/monthUnlimited*
SupportBasicStandardPriority

* Unlimited within fair use. Usage that affects service performance may be throttled.

FAQ

Frequently asked.

What is a credit?
A credit is the unit an AI pentest is paid in. Every pentest runs at a level, and the level sets how many credits that test may spend: Light 200, Standard 1,000, Deep 4,000, Extended 10,000, Maximum 20,000. Credits come with an Essential plan every month, or as a one-off top-up at $0.50 a credit. Passive scanning, monitoring, alerts and their reports come with your plan and never touch your balance.
What does a paid plan include?
Essential is a monthly bundle of pentest credits, from 200 a month, and the Essential plan itself comes with it at no extra charge: complete passive scans, continuous monitoring for one domain, email alerts. A bigger bundle works out to less per credit. Business is priced to what you run, through sales, credits included, and adds daily monitoring across 10 domains (more through sales), Slack and Teams alerts, priority support and scoped engagements. Free includes no credits.
How am I charged for a pentest?
You pick a level when you set the test up, and the run holds that level's credits when it starts. When it finishes you are charged for what it actually used, never less than 100 credits and never more than the hold, and the rest goes straight back to your balance. A test that fails is not charged at all. One you cancel is charged only for the work it got through, with no minimum. The full report comes with the run: there is no second payment to read the findings.
What if I run out of credits?
Buy a top-up, whenever you want, at $0.50 a credit: 100, 200, 400, 1,000, 2,000 credits, or any whole amount from 100 up. A top-up is an amount, not a test; what it funds depends on the level you run at. If you keep running short, moving to a bigger bundle is the cheaper fix, because a bigger bundle costs less per credit and a top-up is always the flat rate. If your balance is short when you set a pentest up, the Summary step shows exactly how many credits you need.
Do credits expire, and what happens if I cancel?
Credits your plan grants last the cycle they belong to plus a grace month, so an unused grant is still spendable when the next one lands. Credits you buy last twelve months from the purchase. Spending always takes the credits closest to expiring first. Cancelling stops the next charge and the next grant; it does not empty your balance, and what is in it stays spendable until its own expiry date.
Are credits refundable?
Unused credits are not cashed out, but you are never charged for testing you did not get: a failed test returns its whole hold, a cancelled one returns everything except the work it had done, and a finished test is charged for what it used with a 100 credit minimum. Paid plans have a 14-day refund window from the first charge. And if a report does not hold up, email contact@barrion.io and we return the credits it spent.
Is a human involved, or is it only the AI?
Both, from Standard up. The agent does the testing, and at Standard and deeper levels a security engineer reviews the report before it is released to you; a Light test releases its report as soon as it finishes. Expert review hours come with the level you test at rather than off your credit balance: a standard test includes 1 hour, a deep test 2, a maximum test 8.
Do I get a retest after fixing the findings?
Yes, and it costs nothing. Once you have shipped fixes you can rerun the same pentest as a retest: it reuses the original scope and credentials, checks each finding again, and marks it fixed or still exploitable. A retest holds no credits.
What is included in the free plan?
The Free plan runs 18 core passive security checks with 5 scans a day across 3 pages per scan, with step-by-step remediation, score history and PDF export, for as long as you want and with no card. It includes no pentest credits, but you can buy a top-up and run a pentest from a free account.
How much does paying yearly save?
About 20% against twelve monthly payments, on the whole subscription: the credits are the plan, so the discount is on them too. A year of credits is granted on day one rather than a month at a time.
Can I change or cancel my plan?
Yes, anytime, from your plan page: pick a bigger or smaller bundle on the Essential card, or cancel through Manage Subscription. A bigger bundle applies right away and a smaller one from your next renewal.

Anything else? Email contact@barrion.io.