Pricing

Per-test pricing.
No surprises.

Pay for the engagement, not seats. Every tier includes the full 41+‑module pentest, AI chat, compliance‑mapped PDF, and the zero‑FP guarantee. Upgrade for the full 13‑agent orchestrator, internal‑network scanning, and continuous monitoring.

Lightspeed Plus
Lightweight apps. Marketing sites, simple SaaS, low integration depth.
$2,500/ test
≈ 2‑week manual pentest equivalent
  • Full 41+‑module external pentest
  • Chat‑driven workflow + AI follow‑ups
  • Authenticated scans (form‑login, JWT, OAuth)
  • AI‑validated, zero false positives
  • Compliance‑mapped PDF (SOC 2, ISO 27001, HIPAA, GDPR, PCI, NIST CSF, OWASP)
  • PoC + remediation per finding
  • 1 free re‑test after fixes
  • Full 13‑agent orchestrator
  • Internal / network scan
  • Continuous monitoring
Sign in to start
Enterprise
Mature portfolios, multi‑product SaaS, regulated industries. Continuous offensive coverage.
Quote
Continuous · unlimited targets · custom SLA
  • Everything in Premium, plus:
  • Continuous monitoring (1h, 6h, 12h, 24h, 48h, weekly)
  • Diff‑based new‑finding alerts (Slack, webhook, email)
  • Unlimited targets, unlimited subdomains
  • Internal scan agents, unlimited
  • SSO, RBAC, audit log, multi‑seat
  • API access for CI/CD integration
  • White‑label PDF reports
  • Dedicated CSM, custom SLA, private deployment
Request a quote
Feature Plus Premium Enterprise
External pentest
Full 41+‑module scan
Chat‑driven workflow + AI follow‑ups (grounded)
Zero‑FP AI validation (Validator agent)
Authenticated scans (form‑login, JWT, OAuth)
Quick (~10 min) & deep (~20 min) scan modes
Risky‑subdomain auto deep‑scan·
Exploitation & analysis
Full 13‑agent orchestrator·
Cross‑user BOLA / IDOR detector (secondary account)·
WAF detection + 70+ bypass‑payload scoring·
Attack‑path graph + blast‑radius·
MITRE ATT&CK mapping·
Dark‑web / breached‑credential check·
Internal & continuous
Internal / network scan (agent‑based)·1 agentUnlimited
Continuous monitoring (1h, 6h, 12h, 24h, 48h, weekly)··
Diff‑based new‑finding alerts (Slack, webhook, email)··
Reporting & compliance
Compliance‑mapped PDF (7 frameworks + CWE / CVSS / MITRE)
White‑label reports··
Free re‑tests after remediation12Unlimited
Team & integrations
SSO + RBAC + audit log··
API access for CI/CD··
Dedicated CSM, custom SLA, private deploy··
Reasoning trace per agent··
Pricing
Per test$2,500$5,000Quote
FAQ

Common questions

How long does a scan actually take?

Quick mode: about 8 to 12 minutes. Deep mode: about 15 to 25 minutes. The PDF is ready the moment the scan completes; no waiting on a consultant. You can keep working in the dashboard or chat while it runs in the background.

Is the price really per test, not per seat?

Yes. One target, one full engagement, one report. Add team seats at no extra cost. Pricing scales with engagements, not headcount.

What counts as a "target"?

One root domain plus its subdomains. Auto‑discovered subdomains are included; risky‑subdomain auto‑deep‑scan (admin, staging, dev, vpn, api) is bundled in Premium and Enterprise.

Can I just sign in and try it?

Yes. Sign‑up is free, no card required. By default you can scan your own email‑domain and its subdomains, so a user@acme.com can scan acme.com and staging.acme.com without paperwork. Larger or out‑of‑domain engagements move to a paid tier.

How is this different from a Burp / Nessus scanner?

Those scanners ship findings. Zeroday IQ ships validated findings. The Validator agent drops anything without raw evidence and a working PoC, so what reaches your inbox is what a human pentester would have written down. Not a queue of "potential" issues.

Do you do retests for free?

Plus: 1 retest. Premium: 2. Enterprise: unlimited. We re‑run the same modules against the same target so you get a clean diff of what was fixed.

How does the internal scan agent work?

You install a small Docker‑packaged agent on a host inside your network. It registers with a token issued by your super‑admin, runs the same pipeline against private CIDRs (network discovery, AD checks, lateral‑movement & privesc analysis), and ships findings back over an authenticated channel.

Can I run this in our private cloud?

Yes. Enterprise includes a private deployment. We ship the same Flask app + MongoDB + agents, and you keep the keys.

Start free, upgrade when you outgrow it.

Sign in and run scans on your own email‑domain today. Talk to us when you need cross‑domain scope, the full agent orchestrator, or continuous monitoring.