[ Pricing ]

Pay for findings you can act on.

Start with a scope you own and see what we prove on it. Nothing about that first run is gated behind a contract.

Proof run

FreeOne scope, once

Point us at something you own. You see whatever we can prove, whether or not you ever become a customer.

  • Full OSINT and attack-surface map
  • One agentic pentest pass
  • Working proof-of-concept per finding
  • No credit card, no sales call required
Start free pentest

Continuous

Most teams
ScopedPriced by attack surface

The platform running against your perimeter on every deploy, instead of once a quarter when someone remembers.

  • Everything in the proof run
  • Re-tests triggered on each deploy
  • Static analysis, secrets and IaC on merge
  • Cloud misconfiguration to attack-path mapping
  • Findings routed into Jira, Slack or GitHub
  • Verified fix confirmation, not just a close button
Get a quote

Engagement

CustomPlatform plus humans

When the target is unusual enough that the interesting bug will not be found by any agent on its own.

  • Everything in Continuous
  • Human-led review by the research team
  • Source-code and architecture review
  • Signed DPA, custom retention and data handling
  • Coordinated disclosure handled for you
  • Named point of contact
Talk to us

Why there are no numbers on this page

Because we would be making them up. Attack surface varies by orders of magnitude between two companies of the same headcount — a twelve-person team with four hundred subdomains and three clouds costs more to test properly than a fifty-person team with one monolith. A price list here would either be wrong for you or padded to cover the worst case.

The proof run costs nothing and produces the number. After it we know your surface, and can quote against it rather than against a guess.

The parts people ask about

  • The free run is genuinely free. No card, no trial clock, no findings withheld until you upgrade. You keep the report either way.
  • You must own or be authorized to test the scope. This is the one thing we verify before anything runs. See the authorization terms.
  • Findings are yours. Use them internally, send them to your vendors, publish them. We do not gate remediation advice behind a higher tier.
  • We will tell you if we are the wrong fit. If your problem is a compliance checkbox rather than an attacker, a cheaper tool will serve you better and we will say so.

Questions

hello@rootxlabs.ai — a person reads it.