~/pricingPricing

Fixed Quote. No Hourly Billing.

Every engagement is scoped on a thirty minute call and quoted as one fixed price, agreed in writing before any work starts. It does not move unless you change the scope, and we do not bill by the hour. What the price actually depends on is set out below, so the call is a conversation rather than a discovery process.

Every engagement

What you receive

The same delivery standard on every engagement, offensive or compliance, whatever the size. The price is discussed on the scoping call and fixed in writing; what you get for it does not vary.

Offensive security12 services

Find it before someone else does

Manual penetration testing, red teaming and code review across web, API, network, cloud, mobile, AI and smart contracts, with phishing simulation and dark web monitoring alongside. Every finding proved with a working exploit.

Fixed priceafter a 30 minute scoping call
Book a scoping call

Every engagement includes:

  • Manual testing across every role and interface in scope
  • A working proof of exploit for every finding
  • Access control, privilege and tenant isolation testing
  • Business logic and workflow testing
  • Coverage matrix showing exactly what was tested
  • Executive summary and technical report, auditor-ready
  • Developer-ready remediation for every finding
  • Report walkthrough call with your engineers
  • Retest of every finding within 90 days
  • Letter of attestation after the retest

Cloud identity review, targeted source code review and threat model review are added where the scope calls for them, agreed during scoping and inside the fixed price.

Compliance and readiness10 frameworks

Ready before the assessor arrives

Readiness against PCI DSS, ISO/IEC 27001, 42001 and 27701, SOC 2 Type 1 and Type 2, HITRUST, HIPAA, GDPR and the India DPDP Act.

Quoted per engagementscoped by framework and evidence
Book a scoping call

Every engagement includes:

  • Scope and applicability review before anything else
  • Requirement-by-requirement gap assessment
  • Control design and operating evidence review
  • Prioritised remediation roadmap
  • Policy and documentation review
  • Readiness sign-off before your external assessor
  • Re-review of the gaps you have closed

We do not issue the certificate. That comes from your QSA, a licensed CPA firm, HITRUST or an accredited body, and we work alongside whoever you choose.

Paid by Cryptocurrency, Stripe Payment or Bank transfer. Invoices are raised in USD unless agreed otherwise.

By service

Everything we run

Every service, with how long a typical engagement takes. The price for any of them is agreed on the scoping call and fixed in writing before work starts.

ServiceTypical duration
Web penetration testing5 to 12 working days
API penetration testing4 to 10 working days
Network penetration testing5 to 10 working days
Phishing simulation2 to 4 weeks
Dark web monitoring & threat intelligenceOngoing, monthly reporting
Red teaming3 to 6 weeks
Source code review5 to 12 working days
AI / LLM penetration testing5 to 10 working days
Mobile application testing5 to 10 working days
Thick client application testing5 to 12 working days
Cloud security review5 to 12 working days
Blockchain & smart contract audit1 to 4 weeks
Compliance and readiness
PCI DSS readinessReadiness
ISO/IEC 27001 readinessReadiness
ISO/IEC 42001 readinessReadiness
ISO/IEC 27701 (PIMS) readinessReadiness
SOC 2 Type 1 readinessReadiness
SOC 2 Type 2 readinessReadiness
HITRUST readinessReadiness
HIPAA readinessReadiness
GDPR readinessReadiness
India DPDP Act readinessReadiness
Scope

What changes the price

Two targets of the same apparent size can differ by a factor of three in effort. These are the variables that actually move a quote, so you can estimate roughly where you will land before you talk to us.

Offensive engagements

06
Roles and privilege levels
More roles means more boundaries to cross. On any authenticated target this is the single biggest driver.
Size of the tested surface
Endpoints, hosts, screens or contracts, counted properly, including the undocumented ones.
Tenancy and isolation
Where one customer, tenant or account could reach another, isolation testing is added.
Source and credential access
Code and working credentials make testing faster and deeper. They usually lower the price rather than raise it.
Environments
Testing staging and production separately costs more than testing one.
Reporting and retest needs
Attestation letters, auditor-ready formats and additional retests are scoped up front rather than billed later.

Compliance and readiness

06
Frameworks in scope
One framework or several, and how far they overlap. ISO/IEC 27001 and 27701 share most of their evidence; PCI DSS and SOC 2 share very little.
Environment and entities covered
How much of the organisation the requirements apply to, across systems, sites and legal entities.
Assessment type
PCI merchant level and SAQ type, SOC Type I or Type II, HITRUST e1, i1 or r2. Each changes the depth of evidence required.
Control maturity
An organisation with documented, operating controls is assessed far faster than one starting from nothing.
Existing evidence
Whether policies, risk assessments and prior audit output already exist in a form an assessor will accept.
Depth of support
Gap assessment alone, or gap assessment through to remediation and readiness sign-off before the external assessor.
Terms

Commercial terms

Fixed price
Agreed in writing after the scoping call. We do not bill by the hour, and we do not raise change requests mid-engagement unless you change the scope.
Quotation validity
Quotations are valid for 30 days from the date of issue. After this period, pricing and scope may be reviewed based on the project requirements.
Payment schedule
50% at kickoff, 50% on final report delivery. Flexible payment terms are available for ongoing engagements.
Currency
Invoiced in USD. Clients paying from an Indian account can settle in INR at the rate stated on the invoice. Cryptocurrency is accepted on request; the coins, networks and conversion rate are agreed in writing before the invoice is issued.
How to pay
Bank transfer or cryptocurrency. Beneficiary details and SWIFT code, or a wallet address and network, are issued with the invoice.
Taxes
Any tax that applies is shown as a separate line on the invoice rather than folded into the quoted price.
Retest included
On an offensive engagement, one full retest of every finding within 90 days, included in the engagement price. On a compliance engagement, one re-review of the gaps you have closed before your external assessment.
Retainers
Engagements booked across a year in advance are priced below the sum of the individual engagements. Offensive and compliance work can be mixed within one retainer, and the terms are agreed on the scoping call.

Get a fixed number for your scope.

Thirty minutes on a call is enough for us to quote accurately. You are not obliged to buy anything.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.