A full pentest every month. €995 per app.
Professional runs the same autonomous pentest as a one-time €1,995 engagement, every month, at half the per-pentest price. Each run re-tests your open findings, proves what changed, and refreshes your certificate.
A pentest proves a moment. Your product moves on.
Every deploy, dependency bump, and config change lands after your last pentest. Professional keeps the proof as current as the product.
Evidence stays current
An annual report proves last year's build. A monthly run proves the application you are shipping now.
Fixes get verified
Each run re-tests every open finding and marks it Fixed, Regressed, or New. You see whether a fix held, not whether someone remembered to re-check it.
Certificate stays fresh
A clean run refreshes your shareable certificate, so the proof you show customers and procurement is weeks old, not a year old.
Questionnaires unblocked
Enterprise security questionnaires ask for recent testing. With a current report on file, the answer is a download, not a six-week project.
What a Professional run does
- Full pentest. The same engine as a one-time engagement: reconnaissance, real exploitation, and independent verification of every finding, aligned with OWASP Top 10, OWASP API Security Top 10, and the OWASP Web Security Testing Guide. Results in 24 hours.
- Re-test of open findings. Everything still open from previous runs is tested again and marked Fixed, Regressed, or New, so remediation progress is measured, not assumed.
- Updated reports. Compliance-ready reports refresh with every run: current evidence for ISO 27001, SOC 2, NIS2, and DORA Article 24 penetration-testing requirements.
- Certificate and alerts. A run with no high or critical findings refreshes your shareable public certificate. New or regressed findings trigger an alert.
Run it when you are ready, or set a monthly schedule. Billing is per app, monthly via Stripe. Cancel anytime.
One-time pentest or Professional
| One-time pentest | Professional | |
|---|---|---|
| Price per pentest | €1,995 | €995 |
| Cadence | Once, on demand | Every month, per app |
| Open findings | Free retest of a fixed finding, triggered by you | Re-tested on every run: Fixed, Regressed, New |
| Certificate | Issued on a clean result | Refreshed after each clean run |
| Commitment | One charge, no auto-renewal | Monthly, cancel anytime |
| Best for | Annual audit evidence, a point-in-time check | Teams that ship faster than an annual test can prove |
Honest math: twelve months of Professional is €11,940 per app. If one pentest a year for the audit file is all you need, the €1,995 one-time pentest is the cheaper choice. Professional is for products that change faster than an annual test can prove.
Watch exposure weekly, prove it monthly
The free Attack Surface shows what is publicly visible on your domain: subdomains, TLS, headers, open ports. It observes what is exposed; it never tests. With a SQUR account, your scopes are re-checked weekly and you are alerted when new exposure appears.
The scan shows what's exposed. Only a pentest proves what's exploitable, because only a pentest actually tests. Professional closes that loop every month.
Common questions
How does billing work?
Stripe, monthly, per app. No lock-in: cancel anytime and the subscription simply stops at the end of the period.
Do runs start automatically?
Your choice: trigger each monthly pentest when you are ready, for example after a release, or set a monthly schedule and let it run.
We have several apps.
Professional is priced per app. For a portfolio, request a quote or look at bulk credits and Enterprise on the pricing page.
Does it cover compliance?
Every run produces compliance-ready reports structured to support ISO 27001, SOC 2, NIS2, and DORA Article 24 penetration-testing evidence, refreshed monthly instead of annually.
Start continuous testing
Create a free account to see a ready-made demo pentest with a full sample report, then put your first app on a monthly cadence. No scoping calls.