Security testing with the price on the page
VAPT, vulnerability assessment, cloud review and AI security testing, delivered by OSCP-certified researchers working alongside our AI agents. Three defined engagements from $2,500 to $12,000, each with patch verification and compliance-ready reporting included.
Engagements
Pick the envelope that fits your estate
Each plan covers a defined set of assets. If your environment is larger, we price the extra targets at scoping and show you the complete figure before you commit.
Essential
Fast, focused testing on a single external target.
per engagement, for the scope below
Scope
One unauthenticated web application, or up to 50 host IPs
Surface
External · Web or host
Team
AI agents leading, one certified penetration tester verifying
Timeline
4 days from kickoff to report
What you get
AI-led discovery with human verification of every finding
Manual exploitation to prove real impact, never raw scanner output
Patch verification retest once your team ships fixes
Compliance-ready report with CVSS ratings and fix steps
Certificate of assessment on completion
Best for: Pre-launch checks, vendor security questionnaires and first assessments.
Assurance
Human-led testing built to stand up to an auditor.
per engagement, for the scope below
Scope
Up to 3 unauthenticated web apps, or 1 low-complexity authenticated web app, or up to 100 host IPs
Surface
Internal and external · Web, host, API and mobile
Team
Two OSCP-certified testers working alongside AI agents
Timeline
5 days to 2 weeks, fixed at scoping
What you get
Everything in Essential
Authenticated testing across user roles and privilege boundaries
Internal network testing alongside the external perimeter
API testing across REST, GraphQL, gRPC and WebSocket interfaces
Mobile application testing for iOS and Android
Evidence mapped to PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR
Patch verification retest and developer-ready remediation guidance
Findings walkthrough call with your engineering team
Best for: SOC 2, ISO 27001 and PCI DSS cycles, and annual testing obligations.
Comprehensive
Your whole attack surface, tested by the whole team.
per engagement, for the scope below
Scope
Up to 20 unauthenticated web apps, 3 authenticated web apps, or up to 200 host IPs
Surface
Internal and external · Web, host, API and mobile
Team
Full research team with AI agents running in parallel
Timeline
2 to 4 weeks, phased by target group
What you get
Everything in Assurance
Estate-scale coverage: up to 20 web apps and 200 hosts in one engagement
Deep authenticated testing across 3 applications and every user role
Attack-path chaining across targets, not siloed per-app reports
Cloud configuration review across AWS, Azure and GCP
Executive summary for leadership alongside the technical report
Patch verification retest and a post-engagement debrief session
Best for: Funding diligence, enterprise customers and larger estates.
Custom
Built around your programme, not around a package. Scoped and quoted against your environment.
Talk to usBest for: Continuous programmes, regulated environments and multi-entity groups.
Scope
Scope
Unlimited assets, multi-region estates and bespoke target types
Surface
Everything above, plus red team, SOC and incident response
Team
Dedicated named team with agreed availability
Timeline
Continuous, quarterly or on your release cadence
What you get
Everything in Comprehensive
Red team and purple team operations against defined objectives
Managed SOC, threat intelligence and incident response retainers
Custom Rules of Engagement, MSA, DPA and questionnaire support
Named point of contact with agreed response times
On-site engagement options and security training for your teams
All prices are in USD and exclusive of local taxes. The figure in your proposal is fixed for the agreed scope: we do not bill by the hour, and we do not raise change orders once testing has begun.
Payment terms
New clients can pay across three milestones
Working with a security firm for the first time is a leap of faith in both directions. Rather than ask for the full fee up front, we split it across the engagement so you pay as the work lands.
Phase 1 · On signature
At kickoff
Paid when the scope and Rules of Engagement are signed and the testing window is reserved. This is what books your slot on the team calendar.
Phase 2 · At the halfway point
Mid-engagement
Paid at the agreed midpoint, by which time you have already seen interim findings. Anything critical is escalated to you the day we find it, not held back for the report.
Phase 3 · On report delivery
Before retesting
Paid once the final report is delivered and walked through, and settled before we run the patch verification retest that closes the engagement.
The split does not change the price. Milestone terms are offered to first-time clients at no premium — the total is the same figure quoted in your proposal. Returning clients and retainer accounts are invoiced on their agreed terms. Tell us at the scoping call and we will write the schedule into the proposal.
Included in every engagement
The things other firms charge extra for
Patch verification included
Every engagement carries a retest window. We confirm your fixes actually closed the issue, at no extra cost.
AI agents at no extra charge
Our autonomous agents run alongside the human team, inside the same Rules of Engagement, with your explicit permission.
Verified findings only
No scanner dumps and no informational padding. If it reaches the report, we proved it was exploitable.
Compliance-ready reporting
Methodology, tooling, CVSS scoring and evidence of testing, structured the way auditors ask for it.
Signed NDA and clear RoE
A mutual NDA, a DPA where personal data is involved, and Rules of Engagement agreed in writing before testing starts.
Strict data handling
Encrypted in transit and at rest, access limited to your assigned researchers, artifacts destroyed after the agreed retention period.
Transparent scaling
What changes the price, and what does not
Six factors move a quote. None of them is a surprise, and all of them are settled at scoping rather than after the work is done.
Number of targets
Each price covers the asset envelope printed on that plan. Additional applications, IP ranges or endpoints are priced per target at scoping.
Authenticated testing
Testing behind a login costs more than testing in front of one, and every additional user role widens the surface we have to cover.
Application complexity
A brochure site and a multi-tenant platform with a payments flow are not the same job, even at identical target counts.
Internal access
Internal network testing needs VPN or jump-host access, coordination windows and additional testing time.
Timeline pressure
Standard turnaround is in the price. Compressed timelines cost more because they consume more of the team at once.
Evidence depth
Standard reporting is included. Auditor-facing evidence packs, questionnaire responses and letters of attestation can be added.
Coverage
What we can put in scope
Any combination of these can be scoped into a plan. AI and LLM testing is a first-class target type here, not an add-on.
Web applications
Authentication flows, business logic, session management, input validation and access control.
Network and hosts
External perimeter, internal segmentation, firewall rules, VPN configuration and wireless.
APIs and microservices
REST, GraphQL, gRPC and WebSocket, including authorisation flaws and rate-limit abuse.
Mobile applications
iOS and Android — local storage, API communication, certificate pinning and runtime manipulation.
Cloud environments
AWS, Azure and GCP — IAM policy, storage permissions, serverless functions and container security.
AI and LLM systems
Prompt injection, RAG poisoning, agent and MCP tooling abuse, mapped to the OWASP LLM Top 10.
Reports written for your auditors
Every engagement produces evidence structured for the frameworks our clients are actually assessed against, with methodology, tooling, CVSS scoring and remediation verification.
How it runs
From first call to verified fix
The full nine-step methodology is documented on our workflow page. Commercially, it comes down to four moments.
01
Scoping call
Thirty minutes to map your assets, objectives, compliance deadlines and testing windows. No obligation and no sales script.
02
Fixed-price proposal
A written proposal with the exact scope, the team assigned, the timeline and one fixed price. Nothing changes once it is signed.
03
Testing under agreed RoE
Testing runs inside the agreed windows with a named team, a live communication channel and immediate escalation for anything critical.
04
Report, fix, retest
You get the report and a walkthrough. Your team ships fixes. We retest, confirm they hold, and issue the certificate.
Also available
Engagements scoped individually
These are priced per engagement because no two are alike. Every one of them can also be folded into an Enterprise agreement.
Prefer to run the testing yourself?
XHack AI subscriptions give your own team the autonomous agent, vulnerability scanning, GitGuard and the SOC dashboard from $20 a month. Many clients run both, and platform access is included for the duration of any engagement.
Questions
Pricing, scope and everything in between
Because scope is what moves the number, and we would rather publish the floor than hide it behind a quote form. Each plan covers a defined asset envelope. If your environment fits inside it, that is the price. If it is larger, we price the additional targets at scoping and you see the complete figure before committing to anything.
Yes. Once the proposal is signed, the price is locked for that scope. We do not bill hourly and we do not raise change orders mid-engagement. If we believe the scope was understated, we tell you before testing starts, not after.
The subscription plans give you access to the XHack AI platform, which your own team operates. These plans are engagements our researchers deliver for you: humans testing your systems, writing the report and verifying the fixes. Many clients use both, and platform access is included for the duration of an engagement.
Yes. First-time clients can split the fee across three milestones: at kickoff when the scope is signed, at the midpoint of testing, and on delivery of the report before the retest is run. The split carries no premium — the total is the figure quoted in your proposal. Mention it on the scoping call and we will write the schedule into the proposal.
Yes, in every plan. After your team ships fixes we retest the affected findings and confirm the remediation actually worked and did not introduce anything new. It is part of the price, not an upsell.
With your explicit permission our autonomous agents run alongside the human researchers at no additional cost, strictly inside the agreed Rules of Engagement. The agents add machine-scale breadth while our testers add depth and judgement, which is precisely why we can price this way.
Our reports are structured for PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR: methodology, tools used, findings with CVSS scoring, evidence of testing and remediation verification. A sample report is published on our Documents page, so you can check the format before you buy.
Yes, and it is among the work we do most. We test for prompt injection, indirect injection through RAG pipelines, system prompt extraction, agent and MCP tool abuse and unsafe function calling, mapped to the OWASP Top 10 for LLMs. It can be scoped into any plan or run as a standalone engagement.
We reply to every enquiry within 24 hours and can usually begin within one to two weeks of a signed proposal. We deliberately cap the number of concurrent engagements so the team assigned to your work is genuinely available for it.
Written authorisation, an agreed scope and Rules of Engagement, target details, any credentials required for authenticated testing, and an escalation contact. We supply the NDA, the DPA and the RoE template, so there is nothing for you to draft.
Get a fixed price for your scope
Thirty minutes on a call is usually all it takes to size an engagement. You leave with a written, fixed-price proposal and no obligation to accept it.