Plans that fit how you ship.
A paid plan is pentest credits every month, with continuous monitoring, alerts and audit-ready reports included. Start with a free scan, no signup. Larger estates talk to sales.
No credit card required.
Get startedTop-up pentest credits
No plan needed. Buy credits and spend them on a pentest whenever you want. Buy credits
- Core passive, read-only scans
- Step-by-step remediation
- Security score history
Cancel anytime.
SubscribeAbout 2 Light pentests a month.
- Everything in Free, plus:
- 410 pentest credits a month
- Complete passive, read-only scans
- Weekly passive monitoring, 1 domain
- Email alerts
- Standard support
Priced to what you run.
Contact sales- Everything in Essential, plus:
- Volume-priced pentest credits
- Scoped pentest engagements
- Daily passive monitoring, 10 domains
- Slack & Teams alerts
- Priority support, dedicated contact
- Tailored scale & integrations
- SoonTeams & organizations
- SoonAPI access
Pentests are paid for in credits.
Credits come two ways. A plan is a monthly bundle at its own price, and the bigger the bundle the less each credit works out to. A one-off top-up costs $0.50 a credit, however many you buy. Every pentest runs at a level, and the level sets how many credits that test can spend.
| Level | What it does | Expert review | Credits |
|---|---|---|---|
| Light | One agent, one fast pass over every attack class. A quick read between deeper runs. | None | 200 |
| Standard | Five specialist agents at once, each owning an area. A full pentest on a regular cadence. | 1 h | 1,000 |
| Deep | Twenty agents, more waves and user roles, chaining findings through the authenticated surface. For larger apps, or the one test you run all year. | 2 h | 4,000 |
| Extended | Fifty agents on one app with many roles and tenants, tested end to end. For large products. | 4 h | 10,000 |
| Maximum | A hundred agents, the most waves and the deepest chaining, with the most expert review. Everything we have, on one target. | 8 h | 20,000 |
Every level attacks the same 8 areas, mapped to all 97 OWASP WSTG cases. A deeper level puts more agents, more attack waves and more user roles on the same ground, so it digs further into every case. From Standard up it also includes expert review.
- Injection
- Access control
- Authentication & sessions
- Client-side attacks
- Information exposure & config
- Transport & crypto
- Business logic
- Server-side & infra
A run holds its level's credits, is charged for what it actually used, and the rest goes straight back. A failed run costs nothing; a cancelled one pays only for the work it got through.
Essential grants 200 to 1,070 a month; Business is sized to what you run. Buy more from your dashboard whenever you need them.
Credits you buy last a year from the purchase. Credits your plan grants last the cycle they belong to, plus a grace month.
Side-by-side, feature by feature.
| Feature | Free | Essential | Business |
|---|---|---|---|
| AI pentesting | ✓ | ✓ | ✓ |
| AI pentest credits | Top-ups only | Monthly bundle, from 200 | Volume-priced to what you run |
| Passive scan checks | 18 | 35+ | 35+ |
| Passive scans per day | 5 | 50 | 500 |
| Pages per passive scan | 3 | 20 | 200 |
| Continuous monitoring (passive) | – | 1 domain + subdomains, weekly | 10 domains + subdomains, daily |
| Vulnerability alerts | – | Email, Slack, Teams | |
| Scan report | ✓ | ✓ | ✓ |
| AI stack guidance | 3/month | Unlimited* | Unlimited* |
| GitHub Repo Connections | 0 | 1 | 20 |
| AI Remediation PRs | – | 5/month | Unlimited* |
| Support | Basic | Standard | Priority |
* Unlimited within fair use. Usage that affects service performance may be throttled.
Frequently asked.
What is a credit?
What does a paid plan include?
How am I charged for a pentest?
What if I run out of credits?
Do credits expire, and what happens if I cancel?
Are credits refundable?
Is a human involved, or is it only the AI?
Do I get a retest after fixing the findings?
What is included in the free plan?
How much does paying yearly save?
Can I change or cancel my plan?
Anything else? Email contact@barrion.io.