Pricing

Pricing that pays for itself

A single manual pentest costs $15,000+ and expires on your next deploy. SaaS runs all year for less than a tenth of that.

Dev plan · no credit card · 14-day money-back guarantee · cancel anytime

Deployment models

SaaS or dedicated — same coverage

One subscription covers however you ship your product. Every deployment gets its own project, schedule and certificate.

SaaS product

Continuous monitoring of your multi-tenant API across dev, staging and production. Every deploy re-tests the same paths — release fast without re-checking by hand.

Dedicated product for your customer

Single-tenant or on-premise deployment at a customer's site? Point us at its URL — it gets separate scans, separate findings and a separate certificate you can hand to that customer's security team as onboarding evidence.

Pricing

Plans that grow with you

A single manual pentest costs $15,000+ and expires on your next deploy. SaaS runs all year for less than a tenth of that.

Dev

$0/mo

For developers and freelancers. CLI-only, no online certificate.

Total endpoints5,000
Live test frequency— (CLI only)
Manual tests / month30
Projects1
Users1
OWASP Top 10 suite✓
Baseline scans (8 tests)✓
Deep-scan suite✓
CLI + Developer API✓
Online certificate / Trust Page—
Hacker mode (AI) pentest—

Autonomous AI pentest — dev/staging only

Ask mode (code questionnaire)—
SupportCommunity

Live

$49/mo

Online-only testing for APIs and SaaS — continuous monitoring, no CLI or CI/CD.

Total endpoints200
Live test frequencyEvery 24 h
Manual tests / month0
Projects1
Users3
OWASP Top 10 suite✓
Baseline scans (8 tests)✓
Deep-scan suite✓
CLI + Developer API—
Online certificate / Trust Page✓
Hacker mode (AI) pentest—

Autonomous AI pentest — dev/staging only

Ask mode (code questionnaire)—
SupportCommunity
Most popular

SaaS

$129/mo

Full CI/CD path + online monitoring + public certificate — built for growing teams.

Total endpoints5,000
Live test frequencyEvery 24 h
Manual tests / month50
Projects1
Users10
OWASP Top 10 suite✓
Baseline scans (8 tests)✓
Deep-scan suite✓
CLI + Developer API✓
Online certificate / Trust Page✓
Hacker mode (AI) pentest✓

Autonomous AI pentest — dev/staging only

Ask mode (code questionnaire)✓
SupportEmail

Team

$399/mo

For API-heavy organizations at scale. Everything, unlimited projects.

Total endpoints25,000
Live test frequencyEvery 1 h
Manual tests / month2,000
ProjectsUnlimited
Users50
OWASP Top 10 suite✓
Baseline scans (8 tests)✓
Deep-scan suite✓
CLI + Developer API✓
Online certificate / Trust Page✓
Hacker mode (AI) pentest✓

Autonomous AI pentest — dev/staging only

Ask mode (code questionnaire)✓
SupportPriority

Enterprise

Contact us

For security-minded organizations at scale.

Total endpointsCustom / ∞
Live test frequencyEvery 15 min / custom
Manual tests / monthUnlimited
ProjectsUnlimited
UsersUnlimited
OWASP Top 10 suite✓
Deep-scan suite✓
CLI + Developer API✓
Online certificate / Trust Page✓
Hacker mode (AI) pentest✓

Autonomous AI pentest — dev/staging only

Ask mode (code questionnaire)✓
SupportDedicated
Talk to sales

Also included

  • ✓ Priority scan queue
  • ✓ SOC 2 evidence report
  • ✓ SSO / SAML
  • ✓ SLA & dedicated support

Dev plan — no credit card required · 14-day money-back guarantee · Cancel anytime

Every plan, every feature

Compare every capability side by side — no hidden limits, no fine print. Every plan is the full product.

FeatureDevLiveSaaSTeamEnterprise
Continuous API security testing
OWASP API Top 10 suite
8 deterministic test categories: BOLA/IDOR, broken auth, mass assignment, injection, rate limiting, CORS, security headers, sensitive params
✓✓✓✓✓
Deep-scan suite (deterministic)
JWT weaknesses (alg=none, weak HMAC, missing exp), HTTP method tampering, privilege escalation via mass assignment, server tech fingerprint + EOL versions, information disclosure (.git/.env/debug/actuator/stack traces), differential rate limits + XFF bypass, old API versions, GraphQL introspection + complexity, OAuth redirect_uri check, CORS null-origin + allowlist bypass + CSRF preflight, SSRF canary callback, shadow APIs
✓✓✓✓✓
API formats supported
REST (OpenAPI/Swagger), RAML 0.8/1.0, GraphQL (introspection/SDL), SOAP (WSDL)
✓✓✓✓✓
Auto-discovery of endpoints
Crawls HTML/JS bundles, sitemap, probes common API paths — no OpenAPI needed
✓✓✓✓✓
Shadow API & drift detection
Undocumented endpoints, regressions and config changes caught between deploys
✓✓✓✓✓
AI-generated test payloads
Payloads tailored to your spec by an LLM
✓✓✓✓✓
AI triage & false-positive filtering
LLM verdicts (real / false positive) with confidence — backed by a deterministic core
✓✓✓✓✓
Continuous monitoring limits
Total endpoints
Unique endpoints across all your projects
5,0002005,00025,000Custom / ∞
Live test frequency
How often we re-test your APIs around the clock (CLI-only on Dev)
— (CLI only)Every 24 hEvery 24 hEvery 1 h15 min / custom
Manual tests / month
On-demand scans you can trigger anytime
300502,000Unlimited
Projects
Separate products, environments or customers, each with its own certificate
111UnlimitedUnlimited
Environments (dev / staging / prod)
Test the same API against every release stage
UnlimitedUnlimitedUnlimitedUnlimitedUnlimited
Team users
Members of your organization with dashboard access
131050Unlimited
Developer experience & CI/CD
CLI + Developer API
liveapisec CLI (push, scan, gate releases) and REST API for agents — required for CI/CD
✓—✓✓✓
CI/CD webhooks
Private tests triggered on every deploy — no impact on public status
✓—✓✓✓
CI verdict vs baseline
Block deploys only on new findings (pass/fail + new/fixed/persisting counts)
✓—✓✓✓
GitHub / GitLab deploy triggers
Auto-connect repositories for post-deploy testing
✓—✓✓✓
Live scan progress & agent log
Watch every step of a scan in real time
✓✓✓✓✓
Advanced AI testing
Hacker mode (AI) live pentest
Autonomous human-style pentest that plans, probes and pivots
——✓✓✓
Attack plan + revision
Agent keeps an explicit attack plan and revises it as it learns
——✓✓✓
Sandboxed code execution
Agent writes and runs its own probe code in an isolated sandbox
——✓✓✓
Guided attack goals
Focus the agent on IDOR, escalation, secrets or injections
——✓✓✓
Ask mode (code questionnaire)
270 checkable questions for what the scanner cannot see from outside (code, RBAC, tenant isolation, crypto, SDLC) — answered by you or your AI assistant, with AI follow-ups
——✓✓✓
Trust & compliance
Public Trust Page
Live certificate with scan history you can show your customers
—✓✓✓✓
Embeddable widgets
Badge, banner, card, counter, alert — drop-in embed on your site
—✓✓✓✓
Domain verification
DNS TXT / CNAME / HTTP file proof of ownership (audit log)
✓✓✓✓✓
AES-256 encrypted credentials
API keys encrypted at rest, never logged
✓✓✓✓✓
Scanner IP allowlist
Stable egress IPs to whitelist in your firewall/WAF
✓✓✓✓✓
SOC 2 evidence report
Procurement-ready security report
————✓
Compliance mapping (PCI DSS / SOC 2 / ISO 27001 / GDPR / NIS2)
Open findings grouped per framework requirement — indicative mapping for your auditor (not a certification)
——✓✓✓
SSO / SAML
Single sign-on for your organization
————✓
Priority scan queue
Your scans jump the queue
————✓
SLA & dedicated support
Guaranteed uptime and a named engineer
————✓

Every plan includes full coverage

One subscription covers all formats, all OWASP API Top 10 categories and the whole toolchain — nothing is sold separately.

Hacker mode (AI) live pentest

Autonomous human-style pentest: the agent plans an attack, probes endpoints step by step, writes and runs its own sandboxed code, and delivers an AI-written evaluation with fixes. Available from SaaS — dev/staging only, never production.

API formats

REST · OpenAPI / SwaggerRAML 0.8 / 1.0GraphQL · introspection / SDLSOAP · WSDL

OWASP API Top 10 — tested

BOLA / IDORBroken authenticationMass assignmentPrivilege escalation via mass assignmentJWT weaknesses · alg=none / weak HMAC / missing expHTTP method tamperingInjection · SQL / NoSQL / JSONRate limitingDifferential rate limits + XFF bypassOAuth redirect_uri checkCORS misconfigurationCORS null-origin + allowlist bypass + CSRF preflightSSRF canary callbackSecurity headersSensitive parametersShadow APIsServer tech fingerprint + EOL versionsOld API versions (v1 vs v2)GraphQL introspection + complexityInformation disclosure · .git / .env / debug / actuator / stack traces

Languages & frameworks detected by the CLI (scan-code)

FastAPI · PythonFlask · PythonDjango · PythonNext.js · App & PagesNestJS · NodeExpress · NodeLaravel · PHPPHP / Slim / LumenSpring · JavaGo · Gin / Echo / Fiber / ChiRust · axum / actix-web / rocket / warp

✨ More formats and tests are added regularly. Enterprise gets custom protocol support and a dedicated roadmap.

FAQ

Pricing questions

Why is SaaS the most popular?+

It is the cheapest plan with the full CI/CD path, the public certificate, compliance mapping and 1 project — everything a SaaS team needs to pass enterprise procurement. Most teams land on SaaS after the free Dev scan.

Is there a free trial of paid plans?+

The Dev plan is free forever and runs the full OWASP baseline suite over the CLI, so you can evaluate the product with zero risk. Upgrade to Live for online monitoring and a certificate, or to SaaS for the full CI/CD path, Hacker mode, Ask mode and compliance exports.

Is my API safe to test?+

Yes. The scanner runs in a sandbox with strict pacing, timeouts and request caps. You choose the schedule and can pause anytime.

Is this a real penetration test?+

Yes — an automated API penetration test. We run OWASP API Top 10 attack simulations (BOLA/IDOR, broken auth, injection, mass assignment, rate limiting, CORS, security headers, shadow APIs) plus deep-scan tests (JWT weaknesses, HTTP method tampering, privilege escalation via mass assignment, server tech fingerprint with EOL versions) on demand or on a schedule, like an automated pentester. It complements a human-led manual pentest rather than replacing it.

Can I run a live penetration test right from the site?+

Yes. Add your API or paste an OpenAPI spec and hit “Run live pentest” — the sandbox starts testing immediately and you watch it live in the terminal. The same test is also available from our CLI (liveapisec scan) for your CI/CD.

What is “Hacker mode (AI)”?+

An autonomous AI agent that runs a real, human-style penetration test on your API (dev/staging only, never production): it plans an attack, probes endpoints step by step — trying IDOR, broken auth, injections, secrets and mass assignment — observes the responses, self-corrects and writes a final evaluation with fixes. It can even write and run its own probe code in a sandbox. It runs manually on demand, requires a verified domain for public targets (localhost / private IPs are exempt), and your URL and credentials are never sent to the AI. We strongly discourage running it against production — it can break or destroy a system.

Do you store my credentials?+

Credentials are encrypted with AES-256-GCM at rest and are only decrypted in memory during a scan. They are never logged and never shown in plaintext.

What does “passed” on the certificate actually mean?+

It means the API passed the automated OWASP API Top 10 tests in the tested scope on a specific date. We never claim absolute security — the certificate wording is deliberately precise.

How do you verify I own the API?+

You prove ownership with a DNS TXT record (or a manual confirm in lower tiers). Every authorization is recorded with timestamp and scope.

How are endpoints counted?+

An endpoint is a unique HTTP method + path in a project (e.g. GET /users). Endpoints are summed across all your projects; environments share the same spec, so they do not multiply the count. Your dashboard shows live usage (X / Y endpoints) so you always know where you stand.

Do all plans include CI/CD and the full OWASP suite?+

Every plan includes the OWASP API Top 10 baseline suite and the full Deep-scan suite. The Dev plan is CLI-only for developers (no online certificate, no scheduled scans). The Live plan adds continuous online monitoring and a public Trust Page, but no CLI/CI-CD. The SaaS plan gives you both CLI/CI-CD and the certificate, plus compliance mapping. Hacker mode (AI) starts at SaaS; Ask mode (the code questionnaire) starts at SaaS. Enterprise extras (SOC 2 report, SSO, priority queue, SLA) are on Enterprise.

How is this different from a manual pentest?+

A manual pentest is a snapshot: $15k+, 2–4 weeks of waiting, outdated on your next deploy. We run the same OWASP attack classes continuously — every deploy, every night — for less than a tenth of the price. Use us to stay clean year-round and bring humans in once a year for the exotic stuff.

Will this break my production?+

No. Standard scans are read-only probes with polite pacing, hard time/request budgets and an isolated sandbox — they cannot modify your data. Only Hacker mode (AI) is destructive, which is exactly why it is blocked from production entirely and runs on dev/staging only.

What happens when you find something critical at 3 AM?+

You get an alert in seconds — email, Slack or webhook, your choice — with the finding, the evidence and the fix. Critical and high findings can also block the deploy via our CI verdict endpoint, so the vulnerability never reaches production in the first place.

Can I upgrade or downgrade anytime?+

Yes. Upgrade is instant, downgrades apply at the next billing cycle, and you keep every existing scan and certificate. Paid plans include a 14-day money-back guarantee.

Your first 340-test pentest is free

No credit card. No sales call. Results in ~2 minutes — then decide with evidence, not promises.

Run my free pentest →