Applications, APIs, cloud, AI systems and user roles.
Pay for the testing motion you actually need.
Start with one critical scope or build an always-on offensive program. Pricing follows the attack surface, complexity and depth of testing, with the scope agreed before kickoff.
Release assurance, authenticated deep-dive or continuous coverage.
Live findings, operator collaboration, signed report and retest.
Start focused. Scale when the risk demands it.
Every model includes verified evidence, remediation guidance and direct access to the people doing the work.
One-time pentest
For a release, compliance milestone or high-risk application.
- Defined web, mobile, API or cloud scope
- Certified operator-led testing
- Live finding delivery
- Signed report and retest
Continuous PTaaS
For teams shipping frequently across multiple assets.
- Reusable testing capacity
- Oqtrix autonomous coverage
- Operator verification
- On-demand retesting and reporting
Managed program
For broad attack surfaces and mature security teams.
- Managed bug bounty
- Vetted researcher network
- 24/7 triage and deduplication
- Program operations and analytics
No add-on required for a useful result.
No unreviewed scanner output or speculative issues passed to your team.
PoC, CVSS, business impact and remediation guidance on each issue.
Validate the fix and close the engagement with evidence stakeholders can trust.
A clear quote starts with a clear attack surface.
Share the target
Tell us what changed, what matters and what the test needs to support.
Define the depth
We map assets, roles, integrations and the attack paths worth exploring.
Choose the model
Get a transparent recommendation, timeline and price tied to the work.