The One-Line Difference
Astra Security sells human review as an upgrade: Pentest Auto is fully autonomous, and a certified human pentester is added on the pricier Pentest Expert tier.
Lory countersigns every finding with a named Lorikeet Security pentester at every depth - human review isn't a paid add-on, it's the default.
Astra is also one of the few vendors in this space with genuinely clear, published per-target pricing - a real point in its favour worth crediting up front.
At a Glance
| Dimension | Astra Security | Lory by Lorikeet |
|---|---|---|
| Model | Attack AI automation, human review as a paid tier upgrade | On-demand or repeating engagements, human review at every depth |
| Human sign-off | Pentest Auto: none. Pentest Expert / Enterprise: certified human pentesters (OSCP, CEH, CCSP) | A named pentester countersigns every finding, no exceptions, at every depth |
| Pricing | $1,999/target/yr (Auto), $5,999/target/yr (Expert), custom (Enterprise) | Prepaid credits, itemised quote within 24 hours, no per-target subscription |
| DAST depth | 10,000+ tests, authenticated scanning incl. TOTP MFA and custom login scripts | Auth testing as part of standard web/API engagement |
| Compliance mapping | PCI DSS, HIPAA, SOC 2, ISO 27001, GDPR | CWE plus control mapping across 7 frameworks |
| Vendor's own credentials | CREST, CERT-In, PCI-ASV, ISO 27001, SOC 2 Type II | Not published in a comparable credential list |
| Source code | Touches code mainly to generate a fix, not a dedicated review engagement | Yes, secret hunting, sink tracing, supply chain |
| Coverage record | Not published | Vectors planned, run, and never reached, with the reason attached |
Coverage, Side by Side
| Asset Type | Astra | Lory |
|---|---|---|
| Web app | Yes | Yes |
| API | Yes | Yes, crawl, auth testing, injection, access control |
| Mobile | Yes, code and communication flow analysis | Yes, iOS and Android plus their backends |
| Network | Yes | Yes, external directly and internal via the mesh connector |
| Cloud | Yes | Yes, AWS, Azure, GCP, Kubernetes, containers, serverless |
| AI / LLM targets | Yes | Not offered as a dedicated engagement type |
| Source code review | Fix generation, not a review engagement | Yes, secret hunting, sink tracing, supply chain |
| Physical | Not published | Human-led, never run by Lory |
Where Astra Differentiates
- Genuinely clear, published pricing. $1,999 or $5,999 per target per year is a real number a buyer can compare against anything else on this list without a sales call - most vendors in this comparison series, Lorikeet included on complex scopes, don't publish that plainly.
- Deep, mature DAST. 10,000+ tests with strong authenticated-scanning support, including TOTP-based MFA and custom login scripts, reflects a lot of engineering on the runtime scanning side specifically.
- Its own certifications as a company. CREST, CERT-In, PCI-ASV, ISO 27001, and SOC 2 Type II accreditations for Astra itself are a credibility signal beyond what any individual finding proves.
- AI/LLM target testing is offered today, which is ahead of where most of the vendors in this comparison series have published equivalent coverage.
- Flexibility to choose your depth. A buyer who genuinely doesn't need human review for a given target can pay less and get exactly that with Pentest Auto.
Where Lory Differentiates
- Human sign-off isn't a pricing tier. Every Lory finding is countersigned by a named pentester at every depth - surface, standard, or deep - not only on an upgraded plan.
- Source code review as a real engagement, not just a fix-generation feature bolted onto other findings.
- A coverage record showing which vectors were planned, run, and never reached, and why.
- Scope as an enforced technical gate - every tool call checked against a signed allowlist before it fires.
- Findings leave the report. SARIF 2.1.0 and MCP mean findings land in GitHub code scanning and in your agents.
Picking Between Them
- You want clear, published per-target pricing you can budget against without a sales call
- You're comfortable choosing autonomous-only testing for some targets and paying more for human review on others
- You need AI/LLM target testing specifically
- Deep authenticated DAST scanning is your primary need
- You want a named human signing every finding regardless of budget or tier
- You need a real source code review engagement, not just fix generation
- You want a written record of what wasn't tested, not just what was
- You'd rather scope one engagement across your whole estate than buy per-target subscriptions
If you're price-sensitive and comfortable with autonomous-only results on lower-priority targets, Astra's tiered model gives you that choice explicitly. If you want the same signature on every finding regardless of budget, that's Lory's default rather than an upsell.
See a Signed Engagement in Action
Book a scoping call and we'll show you why human sign-off isn't a pricing tier for us - every finding, every depth, one signature.
Book a Consultation