⟶ PRICING & ENGAGEMENT MODELS
Transparent packages built around what we test and how deep we go. No hidden retests, no compliance markups, no "enterprise" pricing for SMBs. Start with a $2,000 diagnostic — scale to continuous coverage when it makes sense.
Our diagnostic assessment — designed for teams who want to see how we work before committing to a full engagement.
Every pentest product below ships in three tiers. Same methodology — different depth, cadence, and support.
| Capability | Essential | AdvancedPOPULAR | Continuous |
|---|---|---|---|
| OSINT & enumeration | ● | ● | ● |
| Manual + automated testing | ● | ● | ● |
| Privilege escalation & lateral movement | ● | ● | ● |
| Technical + executive report | ● | ● | ● |
| Methodology | Gray box | Black / Gray / White | Black / Gray / White |
| Business logic deep-dive | Standard | Extended | Extended |
| Threat modeling | — | ● | ● |
| Retests | 1× / 30 days | 2× / 90 days | Unlimited |
| Jira / Slack integration | — | ● | ● |
| Dev remediation support | — | ● | ● |
| Attestation letter (SOC 2 / ISO / PCI) | — | ● | ● |
| Kickoff SLA | 10 business days | 5 business days | 3 business days |
| Frequency | One-shot | One-shot | 2–4× / year |
Six standardized products. Custom scopes available upon request.
P01 · Application Layer
One web application. Up to 2 user roles and 1 environment. Authentication, session, business logic, and OWASP Top 10 coverage.
Essential
7 business days
R$ 16.000
Advanced
12 business days
R$ 28.000
Continuous
4 tests / year
R$ 75.000/yr
ADD-ONS
+ Extra role: R$ 3.000 · Extra env: R$ 4.000
P02 · Application Layer
REST, GraphQL, or SOAP. Authentication, authorization, rate limiting, schema introspection, and business logic abuse.
Essential
6 business days
R$ 14.000
Advanced
10 business days
R$ 24.000
Continuous
4 tests / year
R$ 62.000/yr
ADD-ONS
+ Até 50 endpoints. A cada +25: R$ 2.500
P03 · Application Layer
iOS or Android. Static analysis, dynamic instrumentation, and backend coverage. Reverse engineering and runtime manipulation.
Essential
8 business days
R$ 18.000
Advanced
13 business days
R$ 32.000
Continuous
4 tests / year
R$ 82.000/yr
ADD-ONS
+ Segunda plataforma: +60%
P04 · Infrastructure
Internet-facing IP ranges, perimeter services, VPN gateways, exposed admin panels. The attacker's view from the outside.
Essential
6 business days
R$ 14.000
Advanced
10 business days
R$ 24.000
Continuous
4 tests / year
R$ 62.000/yr
ADD-ONS
+ Até 50 IPs. A cada +50: R$ 3.000
P05 · Infrastructure
Active Directory, lateral movement, segmentation testing, domain escalation. Simulates an established foothold inside your perimeter.
Essential
10 business days
R$ 35.000
Advanced
15 business days
R$ 55.000
Continuous
2 tests / year
R$ 135.000/yr
ADD-ONS
+ Até 250 IPs · Assumed breach: R$ 7.500
P06 · Cloud
AWS, Azure, or GCP. IAM policies, storage exposure, network segmentation, identity boundaries, and secret hygiene.
Essential
8 business days
R$ 24.000
Advanced
13 business days
R$ 40.000
Continuous
2 reviews + monitoring
R$ 100.000/yr
ADD-ONS
+ Conta extra: +30% · Multi-cloud: +50%
Annual subscription combining multiple products with unlimited retests and async support. Built for SaaS teams shipping weekly.
For teams running 1–2 critical assets
por ano · cobrança anual
For SaaS in active expansion
por ano · cobrança anual
Custom scope, custom scale
por ano · scoping customizado
Engagements that require custom scoping. The ranges below are starting points — final pricing after a 30-minute scoping call.
Objective-based · multi-vector · 3–6 weeks
R$ 100K – 250K
TTP emulation · purple team · MITRE ATT&CK aligned
R$ 90K – 200K
Targeted campaigns · vishing · pretexting
R$ 12K – 35K
Manual + SAST · architecture-aware
R$ 20K – 60K
Firmware · radio · embedded · supply chain
R$ 50K – 150K
Prompt injection · model abuse · data leakage
R$ 25K – 75K
// Fine print worth reading
Book a 30-minute scoping call. No sales theater. We'll tell you which package fits — or that you don't need us yet.