Pricing

Priced like software.
Not like consultants.

Manual pentests cost $20K to $50K and arrive twice a year. HackZero starts at $2,999 a month for a continuous pentest on one product, billed monthly. No seat pricing. No scope haggling. Cancel any time.

Startup deal · $299/mo

AI-led pentesting plus SOC 2 controls, for teams of 10 or fewer, with no funding or company-age limit. The same engine, a fraction of the price. We read every application and reply within two business days.

Apply for the Startup deal →

Monthly

Most popular
$2,999 /mo

1 pentest a month · cancel any time

One pentest a month. No commitment.

  • Continuous LLM-agent attack runs on one product
  • Exploit-validated findings with remediation steps
  • Findings into GitHub, Slack, Linear, and Jira
  • On-demand extra pentests at $2,999 each

Custom volume

from $4,148 /mo

2 to 20 pentests a month · per pentest down to $1,799

Built around your volume.

  • Volume pricing: the more you run, the less each costs
  • Save up to 17% on annual, 8% on a 6-month term
  • $2,999 per overflow pentest beyond your plan
  • Lock your per-pentest price for the term

Enterprise+ & Government

Let's talk

Unlimited pentests · SaaS or on-prem

Everything procurement asks for.

  • Dedicated security engineer
  • SSO / SAML + audit support letter
  • MSA, DPA, BAA: procurement-ready
  • Custom integrations + on-prem / VPC option
  • Data residency (US / EU / your VPC)

Free to set up. You pay when you run.

Pricing questions

Pricing, answered.

The Startup deal is founder pricing at $299 a month, a fraction of standard pricing, so we keep it to small teams. You qualify with 10 or fewer people and a live product in production, with no funding or company-age limit. We read every application and reply within two business days.

Both run a pentest every month on one product and include SOC 2 controls. The Startup deal at $299 is AI-led: our own agents run the attack and validate findings. Monthly at $2,999 adds a human in the loop, a hacker who validates exploitability and writes the report reviewers read. If you are past the startup gate or want human-led testing, Monthly is the plan.

We build and run the controls and the pentest; the attestation is signed by an independent AICPA-member CPA, and you pay that CPA directly. That separation is what keeps the audit independent (we have no fee split with them). Their fee starts around $2,500 for a startup-scope SOC 2 Type 2 and around $15,000 for a standard company. Ask us for the introduction.

There is no free scan tier, because every run costs real compute and runs under a signed agreement. Creating an account and configuring a target costs nothing; you pay when you run.

Two options. Turn on on-demand pentests inside the dashboard (each runs on demand and is billed at $2,999), or build a Custom volume plan with the calculator (2 to 20 pentests a month) for a lower per-pentest price and a fixed term.

A pentest is a live LLM-agent attack against your running app, with hours of recon, exploitation, and validation. That is the unit we meter and price. Scans read your code (per-PR diff or whole-repo) and map the attack surface; they run alongside your pentests and are not metered separately.

Yes. Annual billing saves 17 percent (two months free). The Custom volume plan also offers a 6-month term at 8 percent off. The Monthly plan stays month to month with no lock.

Build your plan

Your custom plan.

Dial in pentests per month and a term. See the price instantly.

Pentests per month

Commitment

Your quote

$7,300 / mo

billed annually · $87,600 per cycle

Per pentest

$1,825

was $2,199

Extra pentest

$2,999

beyond plan