Skip to content
Vaptiq logo mark — V orientationVAPTIQ

[ Pricing ]

Fixed prices. Written scopes. No sales engineer.

Two of these numbers are real starting prices, not anchors designed to start a negotiation. Everything else is scoped against your estate, and you see the figure before you commit to anything.

AI-powered pentesting

01

Scan

$399per scan

Automated discovery and exploitation of known vulnerability classes, triaged by AI and reviewed by a tester before release.

  • Results within 24 hours
  • Human review before any finding reaches you
  • Unlimited re-runs on a monthly plan
  • Findings delivered in the platform
  • CVSS v4.0 scoring and fix guidance
  • Business logic testing
  • Letter of attestation

Manual penetration test

02

Engagement

$700from, per engagement

A named, certified tester tests your target by hand for days, chaining findings until each has a working proof. This is the one auditors mean.

  • Certified tester, CREST CRT, OSCP, OSWE
  • Business logic and access control tested by hand
  • Live findings while the test runs
  • Executive summary and technical report
  • Letter of attestation for customers and auditors
  • One free retest within 90 days

Continuous testing

03

Programme

Customannual, billed quarterly

Scheduled engagements across your estate, continuous scanning between them, and a red team exercise once your defences are worth testing.

  • Annual test calendar agreed up front
  • Continuous scanning between engagements
  • Red team or purple team exercise included
  • Dedicated testing team, same faces each time
  • Unlimited retests
  • SSO, audit logs and custom data retention

Prices in USD, excluding tax. Manual engagement pricing scales with scope, the figures below are typical starting points, confirmed in writing before any work begins.

[ New ]

No high or critical findings?
We refund the invoice.

For qualifying manual assessments where we have full access. If the engagement produces no High or Critical findings under the agreed classification, we refund 100% of the assessment fee back on your invoice. Confirmed in writing before we touch a packet.

Applies to grey box and white box engagements. Excludes black box, scans, and retests. Terms set in the engagement letter.

[ 02 / By engagement ]

What each test typically costs.

Duration is the honest range for a mid-size scope. Where a figure says scoped, the spread between a small and a large estate is wide enough that quoting a number would be guessing.

EngagementTypical durationYou provideFrom
Black Box Penetration Testing3-5 daysTarget name only$700
Grey Box Penetration Testing5-10 daysLow-privilege credentials, basic architecture notesScoped
White Box Penetration Testing10-15 daysSource code, architecture, admin credentialsScoped
Web Application Penetration Testing5-10 daysCredentials for each roleScoped
API Penetration Testing4-8 daysSpec or collection, plus per-role tokensScoped
Mobile Application Penetration Testing6-10 daysBuilds for both platforms, test accountsScoped
External Network Penetration Testing3-7 daysIP ranges and domainsScoped
Internal Network Penetration Testing5-10 daysNetwork access, standard user accountScoped
Active Directory Security Assessment5-10 daysOne standard domain accountScoped
Cloud Penetration Testing5-10 daysRead-only audit role, plus a low-privilege identityScoped
Firewall Configuration Review3-5 daysRead-only access to firewall configurationsScoped
Red Team Assessment3-6 weeksObjective only, agreed with a small internal groupScoped
AI & LLM Penetration Testing5-10 daysSystem access, tool definitions, prompt architectureScoped

[ 03 / Always included ]

Things other providers charge extra for.

  • Retest

    One full retest of every finding, within 90 days.

  • Platform access

    Unlimited seats for your team, for as long as you are a client.

  • Attestation letter

    Shareable proof of testing for customers and auditors.

  • Debrief call

    Ninety minutes with the tester who ran the test.

  • Remediation guidance

    Specific fixes, not links to generic OWASP pages.

  • Out-of-hours testing

    Where your change window requires it.

[ 04 / Questions ]

About the money.

Scope size and depth: the number of live hosts, applications, user roles and API endpoints, and how many days of manual testing that implies. Not your company size, not your industry, and not how urgently you need it.

Yes. The scope document contains the price, and it does not change unless you change the scope. If we find during the engagement that the scope was described inaccurately, we tell you immediately and you decide what happens next.

No. One retest of every confirmed finding is included with each manual engagement, valid for 90 days after the report. You do not need a new purchase order and it does not need a new scoping call.

Yes. A single AI-powered scan is $399 with no commitment. A monthly plan works out cheaper if you are running scans on every release, and we will tell you when you have crossed that line.

Our starting prices are already set low enough that we do not run a separate startup programme. If a genuine budget constraint is the only thing standing between you and a test, say so on the call.

Get a fixed price in writing.

Describe the target and the deadline. Most scopes come back the same working day, with the number on the first page.