Skip to main content
Custom-Tailored Security

Security That Fits
Where You Are

Published starting prices for every service, plus autonomous testing from Lory billed by the credit. Free retesting and portal access on every engagement.

Published Pricing Free Retesting No Hidden Fees Client Portal Access Auditor-Ready Reports

What We Do, and What It Costs

Prices are the starting point for a typical scope — more endpoints, roles, or integrations move it up. Every test includes free retesting once you have remediated.

A controlled attack against your systems, run by people, so you find the holes before someone else does. Every test ends in a report you can hand to an engineer and a round of free retesting once you have fixed things.

Service Starting at Typical window Details
Web Application Pentest OWASP Top 10, business logic, auth and session handling $9,500 1–2 weeks
API Penetration Testing REST, GraphQL and gRPC against the OWASP API Top 10 $8,500 1–2 weeks
Network & Infrastructure Internal and external, credential and relay attacks, lateral movement $8,000 1–3 weeks
Cloud Pentesting AWS, Azure and GCP — IAM, storage, serverless $12,000 2–3 weeks
Mobile App Pentest iOS and Android against OWASP MASVS, plus runtime manipulation $10,500 1–2 weeks
Active Directory Domain escalation, Kerberoasting, BloodHound attack paths $12,500 2–3 weeks
Container & Kubernetes Escapes, RBAC, admission control, supply chain $9,500 1–2 weeks
AI Agent & LLM Pentest Prompt injection, tool abuse, data exfiltration through agents $11,000 1–2 weeks
Security Code Review Manual review over the whole codebase, plus SAST triage $6,500 3–5 days
Vibe Coding Review For apps an AI wrote — the failure modes models reliably ship $4,500 2–5 days
Desktop Application Thick clients — binary analysis, IPC, local privilege $10,000 1–2 weeks
Wireless Pentesting Rogue AP, WPA2/3 attacks, guest network segmentation $5,500 3–5 days
Social Engineering Pretext calls, physical tailgating, targeted campaigns $7,500 2–4 weeks
Phishing Simulation Campaigns against your staff, with who-clicked-what reporting $3,500 1–2 weeks
Physical Pentesting Badge cloning, lock bypass, and what happens once we are in $9,500 1–2 weeks
IoT & Hardware Firmware extraction, UART/JTAG/SPI, wireless protocols $16,000 2–4 weeks
Smart Contract Audit Web3 and DeFi — economic attacks, flash loans, code review $15,000 1–3 weeks
ATM & Banking Terminal Physical security, firmware, PCI PTS, skimming $15,000 2–3 weeks
Vending & Kiosk Unattended terminals — payment path, tamper, network pivot $12,000 1–2 weeks
Red Team Operations Full adversary simulation, physical and digital, custom TTPs $35,000 4–8 weeks
Vulnerability Scanning Authenticated and unauthenticated sweeps, triaged by a human $250/scan 1–2 days
Retesting & Validation We re-run the test after you fix it and reissue the report Included After remediation

There is no such thing as a “SOC 2 pentest” — it is one pentest, scoped and reported so your auditor accepts it as evidence. We map the same engagement to whichever framework you are being held to, and cover the rest of the readiness work around it.

Service Starting at Typical window Details
Compliance-Scoped Pentest One pentest, reported against the framework your auditor uses $8,500 1–2 weeks
Federal & Defense Scope FedRAMP and CMMC — heavier control set, 3PAO-aligned evidence $18,000 3–4 weeks
Gap Assessment Where you stand against the framework, control by control $6,500 1–2 weeks
Policies & Procedures Written for your business, not lifted from a template pack $4,500 1–2 weeks
Evidence & Audit Support We collect the artifacts and answer the auditor directly $5,500 Through the audit
Access Reviews User entitlements, least-privilege gaps, stale accounts $3,500 2–5 days
Findings Remediation Our engineers fix the findings rather than hand them over $4,000 1–2 weeks
vCISO / Security Retainer A named security lead on your leadership calls $4,000/month Ongoing
Security Advisory Architecture reviews and design calls, billed by the hour $350/hour On demand
VC Due Diligence Security posture review before you write or take the cheque $7,500 1 week

Testing tells you where you are weak. This is the half that watches the estate the rest of the year, and the number you call at 2am when something has already gone wrong.

Service Starting at Typical window Details
Managed Detection & Response Our analysts watch your alerts and act on them, 24/7 $2,800/month Ongoing
SOC as a Service A full security operations centre without hiring one $3,500/month Ongoing
24/7 Continuous Monitoring Always-on coverage across endpoints, cloud and network $2,200/month Ongoing
SIEM Management Log pipeline, detection rules, and tuning that keeps up $1,800/month Ongoing
EDR / XDR Endpoint agent rollout, policy, and day-to-day management $1,100/month Ongoing
Incident Response Retainer Guaranteed response time and hours banked before you need them $1,500/month Ongoing
Ransomware Response Containment, eradication, and getting the business back up $25,000 Immediate
BEC Response Mailbox compromise — scope it, evict them, prove it is over $8,500 3–5 days
Digital Forensics Defensible imaging and analysis that holds up in a dispute $12,000 1–3 weeks
Log Analysis & Review Reconstruct what happened from the evidence you kept $6,000 1–2 weeks
Threat Hunting Hypothesis-led hunts for what your tooling did not flag $4,500 1–2 weeks
Purple Team We attack, your defenders watch, and the detections improve $18,000 2–3 weeks
Tabletop Exercise Walk your leadership through a breach before it is real $6,500 1–2 days
Threat Intelligence What is being used against your sector, filtered to you $1,200/month Ongoing
Dark Web Monitoring Your credentials and data, watched where they get traded $650/month Ongoing
Vulnerability Management Continuous scanning and prioritised remediation, SLA-backed $1,200/month Ongoing
Patch Management Risk-based deployment with a rollback path $950/month Ongoing
Email Security SPF, DKIM, DMARC and the gateway rules that stop the rest $850/month Ongoing
Endpoint Protection Hardening and managed AV/EPP across the fleet $900/month Ongoing
Network Security Firewall, segmentation and egress control, managed $1,400/month Ongoing
Zero Trust Implementation Identity-first architecture, rolled out in stages $15,000 4–8 weeks

Lory runs scoped engagements against your assets on her own, and a human reviews every finding before it reaches you. Billed by the credit — $1 buys 1 credit, and nothing starts that you have not funded.

Service Starting at Typical window Details
Lory Recon One asset kept under standing review. 275 credits a month. $250/month Ongoing
Lory Operator Continuous coverage across a real production estate. 1,150 credits a month. $1,000/month Ongoing
Lory Continuous Always-on testing with deep-depth headroom. 3,000 credits a month. $2,500/month Ongoing
Lory Credits No plan and no seats — load a balance and Lory draws from it as she works $1/credit $25 – $25,000

Autonomous Testing, Priced by the Credit

Lory runs scoped engagements against your assets on her own and every finding is human-reviewed before it reaches you. $1 buys 1 credit — she draws from your balance as she works, so nothing starts that you haven't funded.

Recon

One asset kept under standing review.

$250/month
275 credits land in your wallet

  • 275 credits every month — $25 free
  • At least 1 standard engagement, typically 3
  • Or ~13 surface sweeps across your estate
  • Unused credits roll forward — they never expire
Start Recon

Continuous

Always-on testing with deep-depth headroom.

$2,500/month
3,000 credits land in your wallet

  • 3,000 credits every month — $500 free
  • At least 2 deep engagements, typically 6
  • Or ~37 standard engagements per month
  • Unused credits roll forward — they never expire
Start Continuous
$1 = 1 credit No seats, no licences Credits never expire Pay as you go from $25 Every finding human-reviewed

Metered Rates

Off-plan or over your monthly credits, this is what Lory charges. Same rates on every plan.

MCP RPC call Every tool call your agents make through an MCP token — findings, KB lookups, scope checks.
0.1 crper call
Engine tokens Input + output tokens Lory burns reasoning about your target during an engagement.
0.02 crper 1,000 tokens
Scanner compute Wall-clock time in the sandboxed toolbelt — port scans, nuclei, fingerprinting, screenshots.
0.1 crper minute

Cost per Engagement

Engagements bill by depth. “Typical” is what a real run costs; “max” is the hard budget ceiling the engine will not exceed.

Surface Recon sweep and the obvious attack surface.
~$21max $57
Standard Full vector plan, the default for a scoped asset.
~$81max $223
Deep Exhaustive — chained exploitation, long-running tooling.
~$501max $1,380

Lory is included in the Offensive and Defensive annual bundles below. See how Lory works →

Save Big with an Annual Program

Most companies save 15–20% by bundling. Each includes testing hours, retesting, client portal, and dedicated account management. Prices below are the standard program rate — scope adjusts it.

Defensive Security

24/7 monitoring, detection, and incident response

$4,500/month
$54,000 billed annually
SOC + EDR + IR combined
  • SOC as a Service (24/7/365)
  • SIEM & Log Management
  • Endpoint Detection & Response
  • Incident Response Retainer
  • Lory AI Pentester
  • Threat Intelligence Feed
  • Monthly Security Reports
Book a Scoping Call

Compliance Package

Get audit-ready and stay compliant with Anchorpoint

$2,300/month
$27,600 billed annually
Pentest + full audit prep
  • Compliance Pentest (SOC 2, ISO, or PCI)
  • Gap Assessment & Readiness Review
  • Policy & Procedure Templates
  • 80 testing hours / year
  • 16 retesting hours included
  • Continuous Compliance Monitoring
  • Quarterly Security Reviews
  • Add Vanta/Drata (ask for details)
Book a Scoping Call

Need everything? The Full Stack Bundle combines offensive + defensive + compliance from $99,000/year — ~15% below the three bought separately. Contact us for details →

What Affects Pricing?

Every engagement is scoped individually based on your environment. Here's what we look at.

Scope & Complexity

Number of endpoints, user roles, integrations, and application size directly affect testing time and cost.

Testing Approach

Black box (no access), gray box (partial), or white box (full source) — each requires different effort.

Compliance Requirements

SOC 2, PCI-DSS, HIPAA, and other frameworks require additional testing controls and specialized reporting.

Pricing FAQ

How much does a penetration test cost?

A web application pentest starts at $9,500, network and infrastructure at $8,000, and a compliance-scoped pentest at $8,500. The starting price covers a typical single-application or single-environment scope; more endpoints, user roles, integrations, or compliance requirements move it up. Every service on this page shows its starting price, and a free scoping call turns that into an exact quote.

Is there such a thing as a “SOC 2 pentest”?

Not really, and we would rather say so. SOC 2 does not mandate a penetration test by name — your auditor asks for evidence that you test your systems, and a pentest is how you produce it. The engagement is the same one we would run anyway; what changes is the scoping and the report, which we map to the Trust Services Criteria, or ISO Annex A, or PCI requirement 11.4, or whichever framework you are being held to. That is why the rate card carries one compliance-scoped pentest at $8,500 rather than a dozen framework-branded products at a dozen prices. FedRAMP and CMMC are the real exceptions — the control set is genuinely heavier, so they are priced separately.

Is retesting included?

Yes. All penetration testing engagements include one round of free retesting after you remediate the findings. This ensures your fixes work and gives you a clean report for compliance or stakeholders.

Do you offer startup or bundle pricing?

Yes. Three annual bundles: Offensive Security at $3,000/month, Compliance at $2,300/month, and Defensive Security at $4,500/month, each billed annually. They run 15–20% below buying the same services individually. The Full Stack Bundle combines all three from $99,000/year. Early-stage startups should ask — we scope smaller programs too.

What's included in the Compliance Package Vanta add-on?

The Vanta or Drata compliance automation add-on provides a license for continuous infrastructure monitoring, automated evidence collection, and year-round audit readiness. We handle integration, onboarding, and auditor coordination. Contact us for pricing details.

How is Lory AI Pentester priced?

By the credit, where $1 buys 1 credit. Lory draws down as she works — 0.1 credit per MCP tool call, and engagements billed by depth (a typical standard engagement runs about $81, a deep one about $501). Monthly plans start at $250/month for 275 credits, and every plan discounts the credits you buy. Credits never expire, so an unused month rolls forward. You can also pay as you go from $25 with no plan at all.

Can Lory replace a human pentest?

No — they do different jobs. Lory gives you continuous coverage between engagements at a fraction of the cost, and every finding she reports is reviewed by one of our testers before it reaches you. A scheduled human pentest is still what you want for business logic, chained exploitation, and an auditor-facing report. Most clients run both, which is why Lory is bundled into the Offensive and Defensive annual programs.

What do I get in the report?

Every engagement delivers an executive summary, detailed technical findings with CVSS scores, proof-of-concept exploits, step-by-step reproduction instructions, prioritized remediation guidance, and compliance mapping. Formatted for both technical teams and executive stakeholders.

How quickly can you start?

Typical lead time is 1-2 weeks from scoping to kickoff. For urgent engagements (compliance deadlines, insurance requirements, pre-launch testing), we can often accommodate faster timelines.

Ready to Get Started?

Book a free scoping call to talk through your needs with a security engineer and get a custom quote.

Contact Us for Pricing Book a Free Consultation
Lory

Not sure which service fits?

Ask Lory — our AI assistant knows every service and can help you find the right fit. Get instant answers.

Ask Lory
Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!