Skip to main content

Pricing

Pay for targets, not for noise.

Credits for flexibility. Subscription for unlimited pentests. The full pipeline runs on every tier — no feature gating.

Every new workspace starts with one free credit — one pentest, no card required.

Pick the tier that matches your portfolio

These are live list prices — every plan here is purchasable in the app today. Annual is our recommended cadence: Professional carries a lower per-target rate billed annually. Need month-to-month flexibility? Switch to Monthly.

  • Pay Per Scan

    $125per credit · lower per-credit rate in larger packs

    Pay-as-you-go credits for unlimited targets. One credit, one pentest, any target. Buy a small pack to evaluate, scale up when you ship more — the per-credit rate drops with volume.

    • Credit packs: 1 for $125, 5 for $545 ($109 each), 15 for $1,485 ($99 each)
    • One credit, one pentest, any target
    • Unlimited application targets
    • Both pentest modes — Web App + API
    • Every in-pentest capability included
    • AI remediation guidance on every finding
    • Executive summary and per-finding evidence bundle
    • Credits valid for 365 days
    • New workspaces start with one free credit — no card required
  • Professional

    Most Popular
    $1,999per target / year · billed annually

    Target-based unlimited pentests for product and AppSec teams shipping continuously.

    • Unlimited pentests per included target
    • Both pentest modes — Web App + API
    • Every in-pentest capability included
    • AI remediation, executive summaries, sensitive-data + cloud insights
    • Authenticated pentests and business-logic testing
    • Thirty-day retest window per finding
    • Slack / Teams / Discord / Email / Webhook notifications
    • CI gating templates: GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure, Bitbucket
  • Enterprise

    Custom

    Custom pricing for organisations that need volume targets, RBAC pentesting, and a countersigned DPA for procurement.

    • Everything in Professional
    • Volume target pricing across business units
    • RBAC and tenant-isolation pentest packages
    • Countersigned DPA on request, plus the published sub-processor list
    • Custom retention and deletion policy
    • Custom support SLA

Feature comparison

Tiers gate scope — application targets, retest window, and the Enterprise support services — not pipeline features. Every Pentrova engagement runs the full pipeline regardless of tier.

Pentrova pricing feature comparison by tier
Feature Pay Per Scan Professional Recommended Enterprise
Scope and scale
Application targets Pay-per-credit Per target Volume / unlimited
Pentest modes (Web App + API)
Pipeline capabilities
Adaptive test planner
Live-target finding verification
Sandbox PoC validation
Attack chain escalation (curated + dynamic)
DOM XSS source-to-sink analysis
Authorization Matrix (multi-role replay)
AI remediation guidance
Distribution and operations
Notification destinations (Slack / Teams / Discord / Email / Webhook)
CI gating templates (GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure, Bitbucket)
RBAC and tenant-isolation pentest packages
Retest window per finding 30 days Custom
Custom retention and deletion policy

Pay Per Scan

Scope and scale

Application targets
Pay-per-credit
Pentest modes (Web App + API)

Pipeline capabilities

Adaptive test planner
Live-target finding verification
Sandbox PoC validation
Attack chain escalation (curated + dynamic)
DOM XSS source-to-sink analysis
Authorization Matrix (multi-role replay)
AI remediation guidance

Distribution and operations

Notification destinations (Slack / Teams / Discord / Email / Webhook)
CI gating templates (GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure, Bitbucket)
RBAC and tenant-isolation pentest packages
Retest window per finding
Custom retention and deletion policy

Professional

Recommended

Scope and scale

Application targets
Per target
Pentest modes (Web App + API)

Pipeline capabilities

Adaptive test planner
Live-target finding verification
Sandbox PoC validation
Attack chain escalation (curated + dynamic)
DOM XSS source-to-sink analysis
Authorization Matrix (multi-role replay)
AI remediation guidance

Distribution and operations

Notification destinations (Slack / Teams / Discord / Email / Webhook)
CI gating templates (GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure, Bitbucket)
RBAC and tenant-isolation pentest packages
Retest window per finding
30 days
Custom retention and deletion policy

Enterprise

Scope and scale

Application targets
Volume / unlimited
Pentest modes (Web App + API)

Pipeline capabilities

Adaptive test planner
Live-target finding verification
Sandbox PoC validation
Attack chain escalation (curated + dynamic)
DOM XSS source-to-sink analysis
Authorization Matrix (multi-role replay)
AI remediation guidance

Distribution and operations

Notification destinations (Slack / Teams / Discord / Email / Webhook)
CI gating templates (GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure, Bitbucket)
RBAC and tenant-isolation pentest packages
Retest window per finding
Custom
Custom retention and deletion policy

Total cost of ownership

Pentrova pricing is designed so procurement conversations stay short. Three promises carry every tier.

  • Two pricing shapes

    Pay Per Scan credits when you want a small commitment to evaluate; a per-target plan when you want unlimited pentests on the same application. Neither auto-renews.

  • Unlimited pentests on Professional

    Continuous pentests, CI gating, scheduled runs, and manual re-runs are all included on Professional. Pricing scales with included targets, never with pentest volume.

  • Retest window on Professional

    On Professional, each fixed finding can be re-tested within thirty days without burning a credit; Enterprise windows are custom. Pay Per Scan has no retest window — one credit buys one pentest.

Talk to sales when procurement gets involved

List pricing covers the platform, the notification destinations, the CI templates, and the retest window. For Enterprise contracts — RBAC and tenant-isolation pentest packages, volume target pricing — we ship a written quote and a redlinable order form alongside a countersigned DPA.

Sign up → Run → Evidence.

Pentrova is self-serve. Sign up, configure a target, and run your first pentest — no sales call required. The free credit every new workspace starts with covers that first pentest, so you can see real evidence before you pay anything.

  1. Sign up

    Create a workspace, invite your team, and configure your first target in under five minutes.

  2. Run your first pentest

    Point Pentrova at a staging URL, pick an auth mode, and click Run. Pentrova handles crawl, testing, exploitation, and verification autonomously.

  3. Review evidence

    Open the chain report. Every confirmed finding ships with a replayable evidence bundle; Critical and High findings include a reproducible command and a response hash.

Frequently asked questions

  • How does Pentrova pricing work?
    Two pricing shapes, both purchasable in the app today. Pay Per Scan is credit-based: one credit runs one pentest on any target, packs are 1 for $125, 5 for $545 ($109 each), or 15 for $1,485 ($99 each), and credits stay redeemable for 365 days. Professional is a per-target plan for unlimited pentests on that target — $199 per target / month, or $1,999 per target / year for a lower per-target rate. Nothing auto-renews: coverage runs for the period you pay for and then lapses. Enterprise is custom pricing for volume targets, RBAC packages, and a countersigned DPA. Prices shown are USD; accounts with an Indian billing country are billed in INR with 18% GST added at checkout.
  • Are some capabilities only available in higher tiers?
    The pipeline runs the same on every tier. Web App pentesting, API pentesting, Sandbox PoC, the Authorization Matrix, attack-chain escalation, and DOM XSS taint tracking are included regardless of tier. Tiers differ on scope (target count and retest window) and the Enterprise support services (RBAC pentesting, a dedicated point of contact, and help interpreting results).
  • Who is Pentrova built for?
    AppSec, platform, and compliance teams in fintech, healthtech, AI-native SaaS, and other regulated domains. Reference calls are available on request once we have early customers live.
  • Can I try Pentrova without talking to sales?
    Yes. Every new workspace starts with one free credit — that is one full pentest on a target of your choosing, with no card required and no sales call. After that, the smallest credit pack is the lowest-friction way to keep evaluating.
  • How do targets work and what counts as one?
    A target is one logical application — usually one base URL plus its API surface. A front-end and its API gateway pentested under shared auth count as one target. Staging and production of the same application count as one target.
  • How does Pentrova handle my data?
    Artifacts are encrypted at rest and in transit, payloads sent against the target are bounded by the sandbox-egress proxy and a hard URL/IP blocklist (RFC1918, link-local, cloud-metadata IPs), and retention is configurable per engagement. Full detail lives in the Trust Center.
  • What happens if I need to downgrade or cancel?
    There is nothing to cancel mid-term, because nothing auto-renews. Professional coverage runs for the period you paid for and then lapses, and credits are bought outright and stay redeemable for 365 days. A pentest that never ran does not cost a credit — those are returned automatically. If one failed in a way that wasted a credit, support reviews it and returns the credit where the failure was ours. Unused credits are not refunded when an account closes. Full terms are in the Cancellation and Refund Policy.
  • We already have a scanner — why add another tool?
    Most scanners score findings probabilistically, which is why AppSec queues grow faster than they shrink. Pentrova only publishes findings our verifier can reproduce, so you are not adding a second queue — you are retiring the unreproducible half of the first one. The product is engineered so backlog should shrink as Pentrova lands, not expand.
  • Aren't you too expensive compared to free open-source tools?
    Free scanners are excellent at what they do. Pentrova replaces the human hours teams spend triaging and reproducing probabilistic findings, not the scanners themselves. The pricing is set so a verified PoC bundle costs less than the engineering time a probabilistic queue would consume.
  • We're a ten-person team — isn't Pentrova overkill?
    Small teams are the teams that benefit most from deterministic proof, because they cannot afford to read every probabilistic alert. A single Pay Per Scan credit covers one pentest on one application, ships the same Sandbox PoC and chain catalog as Enterprise, and is priced so a founding engineer can adopt it without a procurement review — and the first credit in a new workspace is free.
  • Our auditor requires a pentest report — can Pentrova satisfy that?
    Pentrova generates a compliance-mapped PDF report plus a per-finding evidence bundle. Every finding is tagged to the relevant ISO 27001:2022, PCI DSS 4.0, HIPAA Security Rule, and GDPR controls so audit teams have the evidence per control.
  • Integrating yet another tool costs us weeks — how painful is Pentrova?
    Notification routing (Slack, Microsoft Teams, Discord, email, custom webhook) is a tenant-admin form, not custom code. CI gating ships as drop-in templates for GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure Pipelines, and Bitbucket.
  • Our stack is unusual — GraphQL, gRPC, WebSockets, Protobuf. Does Pentrova handle it?
    Pentrova parses OpenAPI, Postman, GraphQL, Protobuf, and WSDL natively, and authenticated sessions support bearer, API-key, basic, OAuth 2.0, custom script-driven schemes, and mTLS. Novel protocols drop in through the same schema the first-class integrations use, so an "unusual" stack is usually just a configuration file.
  • We already run manual pentests — why automate?
    Manual pentests produce excellent depth for a single point-in-time scope and we recommend running them alongside Pentrova, not in place of it. Pentrova covers the gap between engagements: continuous chain coverage, authorization replay, and deterministic artifacts that engineering can re-run any day of the quarter, not only on the week the pentester is booked.
  • Will running Pentrova break production?
    Destructive actions are held back in favour of read-only equivalents by default, engagements can be scoped per target, and customer data is redacted before any artifact leaves the scan host. Full-chain runs are designed for staging, with conservative runs in production.
  • Do you sell or train on our data?
    No. Customer scan data is never used to train models, never sold, and never shared with third parties beyond the named subprocessors. Artifacts are encrypted at rest and in transit, redacted by our sandbox before leaving the scan host, and retention is configurable per engagement.
  • What happens to our evidence if Pentrova shuts down?
    Your reports are downloadable, and every finding inside them carries the captured request and response plus a reproducible command. Re-running that command does not depend on Pentrova, so the proof stays valid in whatever ticketing or audit system it already lives in. If service ends or you cancel, your workspace stays accessible for thirty days so you can export your reports — there is no lock-in on the artifact.
  • How fast will my team see real value?
    Onboarding takes minutes: sign up, configure one target, and click Run. The first pentest typically surfaces two to four high-impact chains. Every finding ships with a replayable evidence bundle you can hand to engineering immediately.

Next step

Ready to talk to sales?

Share your portfolio and timeline. We come back with a quote, a deployment plan, and a sandbox target for trial.

Site search

↑↓ navigateEnter openEsc close