Pricing/Managed services
Managed security services

Security testing with the price on the page

VAPT, vulnerability assessment, cloud review and AI security testing, delivered by OSCP-certified researchers working alongside our AI agents. Three defined engagements from $2,500 to $12,000, each with patch verification and compliance-ready reporting included.

Request a demo or proposal
Fixed price, no hourly billing
Retest included
NDA and DPA ready
Reply within 24 hours

Engagements

Pick the envelope that fits your estate

Each plan covers a defined set of assets. If your environment is larger, we price the extra targets at scoping and show you the complete figure before you commit.

Essential

Fast, focused testing on a single external target.

From$2,500

per engagement, for the scope below


Scope

One unauthenticated web application, or up to 50 host IPs

Surface

External · Web or host

Team

AI agents leading, one certified penetration tester verifying

Timeline

4 days from kickoff to report


What you get

  • AI-led discovery with human verification of every finding

  • Manual exploitation to prove real impact, never raw scanner output

  • Patch verification retest once your team ships fixes

  • Compliance-ready report with CVSS ratings and fix steps

  • Certificate of assessment on completion

Best for: Pre-launch checks, vendor security questionnaires and first assessments.

Most chosen

Assurance

Human-led testing built to stand up to an auditor.

From$5,000

per engagement, for the scope below


Scope

Up to 3 unauthenticated web apps, or 1 low-complexity authenticated web app, or up to 100 host IPs

Surface

Internal and external · Web, host, API and mobile

Team

Two OSCP-certified testers working alongside AI agents

Timeline

5 days to 2 weeks, fixed at scoping


What you get

  • Everything in Essential

  • Authenticated testing across user roles and privilege boundaries

  • Internal network testing alongside the external perimeter

  • API testing across REST, GraphQL, gRPC and WebSocket interfaces

  • Mobile application testing for iOS and Android

  • Evidence mapped to PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR

  • Patch verification retest and developer-ready remediation guidance

  • Findings walkthrough call with your engineering team

Best for: SOC 2, ISO 27001 and PCI DSS cycles, and annual testing obligations.

Comprehensive

Your whole attack surface, tested by the whole team.

From$12,000

per engagement, for the scope below


Scope

Up to 20 unauthenticated web apps, 3 authenticated web apps, or up to 200 host IPs

Surface

Internal and external · Web, host, API and mobile

Team

Full research team with AI agents running in parallel

Timeline

2 to 4 weeks, phased by target group


What you get

  • Everything in Assurance

  • Estate-scale coverage: up to 20 web apps and 200 hosts in one engagement

  • Deep authenticated testing across 3 applications and every user role

  • Attack-path chaining across targets, not siloed per-app reports

  • Cloud configuration review across AWS, Azure and GCP

  • Executive summary for leadership alongside the technical report

  • Patch verification retest and a post-engagement debrief session

Best for: Funding diligence, enterprise customers and larger estates.

Enterprise

Custom

Built around your programme, not around a package. Scoped and quoted against your environment.

Talk to us

Best for: Continuous programmes, regulated environments and multi-entity groups.

Scope

Scope

Unlimited assets, multi-region estates and bespoke target types

Surface

Everything above, plus red team, SOC and incident response

Team

Dedicated named team with agreed availability

Timeline

Continuous, quarterly or on your release cadence

What you get

  • Everything in Comprehensive

  • Red team and purple team operations against defined objectives

  • Managed SOC, threat intelligence and incident response retainers

  • Custom Rules of Engagement, MSA, DPA and questionnaire support

  • Named point of contact with agreed response times

  • On-site engagement options and security training for your teams

All prices are in USD and exclusive of local taxes. The figure in your proposal is fixed for the agreed scope: we do not bill by the hour, and we do not raise change orders once testing has begun.

Payment terms

New clients can pay across three milestones

Working with a security firm for the first time is a leap of faith in both directions. Rather than ask for the full fee up front, we split it across the engagement so you pay as the work lands.

1

Phase 1 · On signature

At kickoff

Paid when the scope and Rules of Engagement are signed and the testing window is reserved. This is what books your slot on the team calendar.

2

Phase 2 · At the halfway point

Mid-engagement

Paid at the agreed midpoint, by which time you have already seen interim findings. Anything critical is escalated to you the day we find it, not held back for the report.

3

Phase 3 · On report delivery

Before retesting

Paid once the final report is delivered and walked through, and settled before we run the patch verification retest that closes the engagement.

The split does not change the price. Milestone terms are offered to first-time clients at no premium — the total is the same figure quoted in your proposal. Returning clients and retainer accounts are invoiced on their agreed terms. Tell us at the scoping call and we will write the schedule into the proposal.

Included in every engagement

The things other firms charge extra for

Patch verification included

Every engagement carries a retest window. We confirm your fixes actually closed the issue, at no extra cost.

AI agents at no extra charge

Our autonomous agents run alongside the human team, inside the same Rules of Engagement, with your explicit permission.

Verified findings only

No scanner dumps and no informational padding. If it reaches the report, we proved it was exploitable.

Compliance-ready reporting

Methodology, tooling, CVSS scoring and evidence of testing, structured the way auditors ask for it.

Signed NDA and clear RoE

A mutual NDA, a DPA where personal data is involved, and Rules of Engagement agreed in writing before testing starts.

Strict data handling

Encrypted in transit and at rest, access limited to your assigned researchers, artifacts destroyed after the agreed retention period.

Transparent scaling

What changes the price, and what does not

Six factors move a quote. None of them is a surprise, and all of them are settled at scoping rather than after the work is done.

Number of targets

Each price covers the asset envelope printed on that plan. Additional applications, IP ranges or endpoints are priced per target at scoping.

Authenticated testing

Testing behind a login costs more than testing in front of one, and every additional user role widens the surface we have to cover.

Application complexity

A brochure site and a multi-tenant platform with a payments flow are not the same job, even at identical target counts.

Internal access

Internal network testing needs VPN or jump-host access, coordination windows and additional testing time.

Timeline pressure

Standard turnaround is in the price. Compressed timelines cost more because they consume more of the team at once.

Evidence depth

Standard reporting is included. Auditor-facing evidence packs, questionnaire responses and letters of attestation can be added.

Coverage

What we can put in scope

Any combination of these can be scoped into a plan. AI and LLM testing is a first-class target type here, not an add-on.

Web applications

Authentication flows, business logic, session management, input validation and access control.

Network and hosts

External perimeter, internal segmentation, firewall rules, VPN configuration and wireless.

APIs and microservices

REST, GraphQL, gRPC and WebSocket, including authorisation flaws and rate-limit abuse.

Mobile applications

iOS and Android — local storage, API communication, certificate pinning and runtime manipulation.

Cloud environments

AWS, Azure and GCP — IAM policy, storage permissions, serverless functions and container security.

AI and LLM systems

Prompt injection, RAG poisoning, agent and MCP tooling abuse, mapped to the OWASP LLM Top 10.

Reports written for your auditors

Every engagement produces evidence structured for the frameworks our clients are actually assessed against, with methodology, tooling, CVSS scoring and remediation verification.

PCI DSS
SOC 2
ISO 27001
HIPAA
GDPR
NIST CSF
CIS Controls

How it runs

From first call to verified fix

The full nine-step methodology is documented on our workflow page. Commercially, it comes down to four moments.

01

Scoping call

Thirty minutes to map your assets, objectives, compliance deadlines and testing windows. No obligation and no sales script.

02

Fixed-price proposal

A written proposal with the exact scope, the team assigned, the timeline and one fixed price. Nothing changes once it is signed.

03

Testing under agreed RoE

Testing runs inside the agreed windows with a named team, a live communication channel and immediate escalation for anything critical.

04

Report, fix, retest

You get the report and a walkthrough. Your team ships fixes. We retest, confirm they hold, and issue the certificate.

Prefer to run the testing yourself?

XHack AI subscriptions give your own team the autonomous agent, vulnerability scanning, GitGuard and the SOC dashboard from $20 a month. Many clients run both, and platform access is included for the duration of any engagement.

See subscription pricing

Questions

Pricing, scope and everything in between

Because scope is what moves the number, and we would rather publish the floor than hide it behind a quote form. Each plan covers a defined asset envelope. If your environment fits inside it, that is the price. If it is larger, we price the additional targets at scoping and you see the complete figure before committing to anything.

Yes. Once the proposal is signed, the price is locked for that scope. We do not bill hourly and we do not raise change orders mid-engagement. If we believe the scope was understated, we tell you before testing starts, not after.

The subscription plans give you access to the XHack AI platform, which your own team operates. These plans are engagements our researchers deliver for you: humans testing your systems, writing the report and verifying the fixes. Many clients use both, and platform access is included for the duration of an engagement.

Yes. First-time clients can split the fee across three milestones: at kickoff when the scope is signed, at the midpoint of testing, and on delivery of the report before the retest is run. The split carries no premium — the total is the figure quoted in your proposal. Mention it on the scoping call and we will write the schedule into the proposal.

Yes, in every plan. After your team ships fixes we retest the affected findings and confirm the remediation actually worked and did not introduce anything new. It is part of the price, not an upsell.

With your explicit permission our autonomous agents run alongside the human researchers at no additional cost, strictly inside the agreed Rules of Engagement. The agents add machine-scale breadth while our testers add depth and judgement, which is precisely why we can price this way.

Our reports are structured for PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR: methodology, tools used, findings with CVSS scoring, evidence of testing and remediation verification. A sample report is published on our Documents page, so you can check the format before you buy.

Yes, and it is among the work we do most. We test for prompt injection, indirect injection through RAG pipelines, system prompt extraction, agent and MCP tool abuse and unsafe function calling, mapped to the OWASP Top 10 for LLMs. It can be scoped into any plan or run as a standalone engagement.

We reply to every enquiry within 24 hours and can usually begin within one to two weeks of a signed proposal. We deliberately cap the number of concurrent engagements so the team assigned to your work is genuinely available for it.

Written authorisation, an agreed scope and Rules of Engagement, target details, any credentials required for authenticated testing, and an escalation contact. We supply the NDA, the DPA and the RoE template, so there is nothing for you to draft.

Get a fixed price for your scope

Thirty minutes on a call is usually all it takes to size an engagement. You leave with a written, fixed-price proposal and no obligation to accept it.