Pricing
No seats. No feature gates.
You pay for work done.
Every assessment runs the whole engine over your whole codebase. External testing is priced per window by depth and target count. Both are stated here, in full, before you make an account.
Pre-deployment codebase assessment
Priced once per assessment, by the decompressed size of what you upload. Find your band in the table below — size sets the price, and nothing else.
Past this size, the tier ladder is the wrong answer.
An application over 32 MB is an enterprise system in practice. We could keep adding tiers above this line, but the price would climb while the value of each additional rand fell — so we don't. We scope it with you instead, and at that volume the economics usually come out better per assessment than an extrapolated tier, not worse.
There's a second reason, and it matters more. Systems at this scale carry risk that a non-intrusive assessment cannot reach — the kind only found by a human actively attacking a running system. Kadense is read-only and detect-only by design, and we won't cross that line to look more capable than we are. So our honest recommendation at enterprise scale is both: Kadense for continuous, evidence-cited coverage of the code every window, and a specialist firm for the deep offensive work.
Go-live external evidence check
A detect-only look at your live public surface, anchored to the OWASP Web Security Testing Guide. Priced by depth and how many targets are in scope. Scope and rules of engagement are agreed and authorised before anything runs.
19 checks. Passive observation plus GET-only forced browsing. Non-intrusive, near-zero risk.
29 checks. Everything in Essential, plus benign detect-only active probes under the safety envelope.
A target is a single IP address or domain. Each one is a separate test vector — the full catalogue is run against it independently, and it gets its own findings and its own section in the report. So a deployment spread across three domains, or an application behind multiple IPs, is three targets, priced over and above the window.
Every target's ownership is verified and every action is logged to a forensic timeline. An evidence layer — not a penetration test, and never sold as one.
Included in every assessment
The whole engine, every time.
- ✓The complete check set, across all mapped frameworks
- ✓Multiple independent passes, cross-validated into a confidence band
- ✓Your entire codebase — never a sample
- ✓A downloadable report citing file and line for every finding
- ✓A publicly verifiable badge once you clear the threshold
- ✓A prioritised remediation queue with fix instructions
- ✓CVE watch against your dependencies, continuously
- ✓Assessment cadence, windows and reminders
- ✓Contextual re-assessment with your own documents, bundled
Before you buy
The questions we get asked.
See it on your own code before you spend anything.
Sign up, run the free quick check, and decide from there.