SQUR vs XBOW: two on-demand pentest platforms, one built for the EU
XBOW is the best-funded on-demand pentesting startup in the category, with $270M+ raised, a valuation above $1B, disclosed self-serve pricing, and a growing list of real production CVE credits. It's also the closest business-model match to SQUR of any competitor: per-test pricing, self-serve access, no MSSP layer required. The overlap is real. Here's where each is the right call, and one connection between the two companies' own published benchmark numbers worth knowing about.
The headline
| SQUR | XBOW | |
|---|---|---|
| Primary use case | On-demand web + API pentest report | On-demand web app pentest, self-serve |
| Target buyer | EU SME / mid-market (20–500 employees) | Primarily US companies, self-serve through enterprise |
| Entry pricing | €1,995 per pentest, one flat price | $4,000 (lightweight apps) to $8,000 (complex apps) per test, self-serve |
| Turnaround | 24 hours from start to report | Up to 5 business days |
| Compliance fit | DORA Article 24, NIS2 Article 21(2)(e), GDPR Article 32 | Not documented as DORA- or EU-compliance-specific |
| Data residency | GCP Brussels (europe-west1), documented per-engagement | Not documented as EU-region; infrastructure and GTM are US-centric |
| Funding / scale signal | Tens of customers, expanding | $270M+ raised, valuation above $1B, real production CVE credits in 2026 |
| Best for | EU compliance-driven SME pentest with an audit-ready report | US companies wanting fast self-serve access to a high-profile, well-funded platform |
Where XBOW wins decisively
XBOW is the best-capitalised company in this comparison by a wide margin. A $120M Series C (announced March 2026) plus a $35M extension (May 2026) brought total funding past $270M at a valuation above $1B, with strategic backers including Accenture Ventures and SentinelOne S Ventures, corporate investors that also function as distribution channels. XBOW also discloses its pricing outright, which most of this category (Pentera, Horizon3.ai) still doesn't do, and it backs its claims with real, named production CVE credits from 2026: CVE-2026-21536 (a CVSS 9.8 RCE in Microsoft's Devices Pricing Program), CVE-2026-32194 and CVE-2026-32191 (CVSS 9.8 RCEs in Bing Image Search), and CVE-2026-45185 (an unauthenticated RCE in Exim). XBOW's own materials also state it holds the #1 spot on HackerOne; worth noting that some secondary coverage describes the scope of that ranking as US-leaderboard-specific rather than global, so we're stating the claim as XBOW's own rather than independently confirming its scope.
If your situation is:
- US-headquartered, with no DORA, NIS2, or EU-data-residency requirement.
- Comfortable with $4,000–$8,000 per test and a turnaround of up to 5 business days.
- Looking for a well-capitalised, high-profile vendor with a public CVE-credit track record.
- Want self-serve access without an MSSP intermediary: XBOW, like SQUR, sells direct.
Then XBOW is a strong, credible option, and one of the very few in this category that tells you the price before you talk to sales.
Where SQUR wins
SQUR is purpose-built for the EU SME under DORA Article 24 or NIS2 Article 21(2)(e) scope: a company that needs an audit-ready pentest report, at a price that doesn't require a five-figure budget line, on a timeline that fits a compliance calendar, with data that never leaves the EU.
If your situation is:
- EU-headquartered, regulated under DORA, NIS2, GDPR, or ISO 27001.
- Need EU data residency as a hard requirement: regulator-driven, customer-driven, or board-driven.
- Want one flat price (€1,995) with no per-complexity pricing tiers to negotiate.
- Need the report inside 24 hours rather than up to 5 business days.
- Need the report pre-mapped to DORA Article 24 and NIS2 Article 21(2)(e) evidence requirements, not FedRAMP- or NIST-style language.
Then SQUR is the fit. At current disclosed pricing, SQUR's €1,995 sits below XBOW's $4,000–$8,000 range at both ends, and the 24-hour turnaround is meaningfully faster than XBOW's up to 5 business days, a genuine advantage on both axes for a buyer who doesn't specifically need XBOW's US enterprise positioning or CVE-credit brand.
The benchmark connection
SQUR's headline quality claim, 91 of 104 flags found (87.5%) on an independent pentest benchmark and beating the best reported human score of 85%, is measured against a human baseline that XBOW itself published. XBOW's own research post (xbow.com/blog/xbow-vs-humans) established the 85% top-human figure that SQUR's independently run benchmark subsequently exceeded. We're not claiming SQUR's AI out-performed XBOW's own AI on this benchmark: XBOW hasn't published a comparable head-to-head figure for its own agent, and we won't invent one. What's genuinely notable is that two competing autonomous-pentest vendors are now measuring quality against the same public human baseline, which is a rarer and more falsifiable comparison than most vendor benchmark claims in this category. Full methodology: SQUR beats human pentesters in an independent benchmark.
Honest gaps in SQUR
- No comparable CVE-credit portfolio. XBOW has a public, named track record of production CVEs found in 2026. SQUR hasn't published an equivalent list.
- No enterprise self-serve tiering. SQUR is one flat price for one scope; XBOW's $4,000–$8,000 range signals it can flex to larger, more complex applications than a single fixed price naturally accommodates.
- Smaller balance sheet. XBOW's $270M+ raised and corporate-VC backing (Accenture, SentinelOne) buys distribution and staying power that a smaller, EU-focused company can't match dollar-for-dollar.
- No public HackerOne leaderboard presence. XBOW's community-hacking reputation, disputed scope aside, is a proof point SQUR doesn't compete on.
Decision framework
- Geography and compliance regime: EU entity under DORA/NIS2? SQUR. US company with no EU requirement? XBOW.
- Data residency: Must the data stay in the EU? SQUR (GCP Brussels). No hard requirement? Either works.
- Price at your app's complexity: SQUR is flat at €1,995. XBOW ranges $4,000–$8,000 by complexity, so compare against your actual scope.
- Turnaround: Need the report inside 24 hours? SQUR. Up to 5 business days acceptable? XBOW.
- Vendor profile: Want the best-funded, CVE-credentialed name in the category? XBOW. Want the EU compliance specialist? SQUR.
Try SQUR's free attack-surface scan
15 checks on your domain in under 60 seconds. No signup. Honest preview of what a €1,995 SQUR pentest would surface. If you're under DORA scope and need a real Article 24 report after that, the paid engagement takes 24 hours.
Free attack-surface scan → See SQUR vs Pentera