adense
Open console Get started

Pricing

No seats. No feature gates.
You pay for work done.

Every assessment runs the whole engine over your whole codebase. External testing is priced per window by depth and target count. Both are stated here, in full, before you make an account.

One credit
R250
Everything on this page is bought in credits, and every tier is simply the credits that piece of work costs. Price includes VAT. There is no markup between the credit and the work — what you see is what it draws down.
Pillar 1 · the core per assessment

Pre-deployment codebase assessment

Priced once per assessment, by the decompressed size of what you upload. Find your band in the table below — size sets the price, and nothing else.

TierCodebase sizeCreditsPrice
Small up to 4 MB 10 R2 500
Standard 4 MB – 12 MB 20 R5 000
Large 12 MB – 24 MB 40 R10 000
X-Large 24 MB – 32 MB 72 R18 000
Enterprise over 32 MB Talk to us →
Size is measured server-side from your upload, decompressed — never taken from the client. Every tier runs the identical check set across the entire codebase.
Over 32 MB · enterprise

Past this size, the tier ladder is the wrong answer.

An application over 32 MB is an enterprise system in practice. We could keep adding tiers above this line, but the price would climb while the value of each additional rand fell — so we don't. We scope it with you instead, and at that volume the economics usually come out better per assessment than an extrapolated tier, not worse.

There's a second reason, and it matters more. Systems at this scale carry risk that a non-intrusive assessment cannot reach — the kind only found by a human actively attacking a running system. Kadense is read-only and detect-only by design, and we won't cross that line to look more capable than we are. So our honest recommendation at enterprise scale is both: Kadense for continuous, evidence-cited coverage of the code every window, and a specialist firm for the deep offensive work.

Scope a custom engagement What Kadense is, and isn't
Pillar 2 · supporting per testing window

Go-live external evidence check

A detect-only look at your live public surface, anchored to the OWASP Web Security Testing Guide. Priced by depth and how many targets are in scope. Scope and rules of engagement are agreed and authorised before anything runs.

Essential L0 · L1
R1 000 · 4 credits

19 checks. Passive observation plus GET-only forced browsing. Non-intrusive, near-zero risk.

Standard L0 · L1 · L2
R2 000 · 8 credits

29 checks. Everything in Essential, plus benign detect-only active probes under the safety envelope.

What we actually check at go-live Mapped to OWASP WSTG · nothing here is destructive
L0 Passive observation — zero payloads sent · 11 checks
01Deprecated TLS versions still negotiated
02HSTS missing on the HTTPS response
03Content-Security-Policy missing
04Clickjacking protection missing
05MIME-sniffing not blocked
06Referrer-Policy missing — referrer leakage
07Permissions-Policy missing
08Insecure cookie flags — Secure / HttpOnly / SameSite
09Permissive or origin-reflecting CORS
10Version banner disclosure
11robots.txt exposing sensitive paths
L1 Forced browsing — idempotent GETs only · 8 checks
12Exposed .git directory
13Exposed .env file — secret material
14Exposed backups and database dumps
15Source maps served in production
16Exposed config files and dotfiles
17Admin, debug or metrics endpoints reachable unauthenticated
18Directory listing enabled
19Verbose errors leaking stack traces
L2 Detect-only active probes — Standard only · bounded, never exploited · 10 checks
20Reflected input — XSS surface, non-executing marker
21SQL-error surface — syntax only, never exploited
22Open redirect honouring external URLs
23Path-traversal surface — no file exfiltrated
24Template-injection surface — arithmetic only
25Host-header injection — cache-poisoning surface
26Dangerous HTTP methods advertised
27Username enumeration on login
28No auth rate-limit or lockout
29No request rate-limit on a bounded burst
Each additional target in scope +R1 000 4 credits

A target is a single IP address or domain. Each one is a separate test vector — the full catalogue is run against it independently, and it gets its own findings and its own section in the report. So a deployment spread across three domains, or an application behind multiple IPs, is three targets, priced over and above the window.

Every target's ownership is verified and every action is logged to a forensic timeline. An evidence layer — not a penetration test, and never sold as one.

Included in every assessment

The whole engine, every time.

The assessment
  • The complete check set, across all mapped frameworks
  • Multiple independent passes, cross-validated into a confidence band
  • Your entire codebase — never a sample
What you get back
  • A downloadable report citing file and line for every finding
  • A publicly verifiable badge once you clear the threshold
  • A prioritised remediation queue with fix instructions
Between runs
  • CVE watch against your dependencies, continuously
  • Assessment cadence, windows and reminders
  • Contextual re-assessment with your own documents, bundled

Before you buy

The questions we get asked.

Can I try it before spending a credit? Yes. Sign up and run a free quick check on your own application — a handful of our most common checks — before you buy anything.
What happens if a scan fails? You are never charged until a scan completes in full. If it doesn't, the run is marked failed and no credits are spent — try again at no cost.
Do credits expire? No. Credits you buy stay on your balance until you use them. No monthly minimum, no forfeiture.
Does a cheaper tier get a lighter assessment? No. Every tier runs the entire engine across the entire check set. Size affects the price and nothing else.
What if my codebase is over 32 MB? That's enterprise territory, so it leaves self-serve and we scope custom pricing with you — usually better economics than an extrapolated tier. We'd also recommend pairing Kadense with a third-party invasive pentest at that scale; that depth of offensive work sits outside what we do.
Are there per-seat costs? None. Invite your whole team, add as many applications and projects as you like. You only ever pay for assessments and testing windows.
Do you keep my code? Never. It is analysed in an isolated, no-network sandbox and destroyed after the run, with the deletion logged. We keep the report, not the source.

See it on your own code before you spend anything.

Sign up, run the free quick check, and decide from there.

Start free See the live demo