Security That Fits
Where You Are
Published starting prices for every service, plus autonomous testing from Lory billed by the credit. Free retesting and portal access on every engagement.
What We Do, and What It Costs
Prices are the starting point for a typical scope — more endpoints, roles, or integrations move it up. Every test includes free retesting once you have remediated.
A controlled attack against your systems, run by people, so you find the holes before someone else does. Every test ends in a report you can hand to an engineer and a round of free retesting once you have fixed things.
| Service | Starting at | Typical window | Details |
|---|---|---|---|
| Web Application Pentest OWASP Top 10, business logic, auth and session handling | $9,500 | 1–2 weeks | Details |
| API Penetration Testing REST, GraphQL and gRPC against the OWASP API Top 10 | $8,500 | 1–2 weeks | Details |
| Network & Infrastructure Internal and external, credential and relay attacks, lateral movement | $8,000 | 1–3 weeks | Details |
| Cloud Pentesting AWS, Azure and GCP — IAM, storage, serverless | $12,000 | 2–3 weeks | Details |
| Mobile App Pentest iOS and Android against OWASP MASVS, plus runtime manipulation | $10,500 | 1–2 weeks | Details |
| Active Directory Domain escalation, Kerberoasting, BloodHound attack paths | $12,500 | 2–3 weeks | Details |
| Container & Kubernetes Escapes, RBAC, admission control, supply chain | $9,500 | 1–2 weeks | Details |
| AI Agent & LLM Pentest Prompt injection, tool abuse, data exfiltration through agents | $11,000 | 1–2 weeks | Details |
| Security Code Review Manual review over the whole codebase, plus SAST triage | $6,500 | 3–5 days | Details |
| Vibe Coding Review For apps an AI wrote — the failure modes models reliably ship | $4,500 | 2–5 days | Details |
| Desktop Application Thick clients — binary analysis, IPC, local privilege | $10,000 | 1–2 weeks | Details |
| Wireless Pentesting Rogue AP, WPA2/3 attacks, guest network segmentation | $5,500 | 3–5 days | Details |
| Social Engineering Pretext calls, physical tailgating, targeted campaigns | $7,500 | 2–4 weeks | Details |
| Phishing Simulation Campaigns against your staff, with who-clicked-what reporting | $3,500 | 1–2 weeks | Details |
| Physical Pentesting Badge cloning, lock bypass, and what happens once we are in | $9,500 | 1–2 weeks | Details |
| IoT & Hardware Firmware extraction, UART/JTAG/SPI, wireless protocols | $16,000 | 2–4 weeks | Details |
| Smart Contract Audit Web3 and DeFi — economic attacks, flash loans, code review | $15,000 | 1–3 weeks | Details |
| ATM & Banking Terminal Physical security, firmware, PCI PTS, skimming | $15,000 | 2–3 weeks | Details |
| Vending & Kiosk Unattended terminals — payment path, tamper, network pivot | $12,000 | 1–2 weeks | Details |
| Red Team Operations Full adversary simulation, physical and digital, custom TTPs | $35,000 | 4–8 weeks | Details |
| Vulnerability Scanning Authenticated and unauthenticated sweeps, triaged by a human | $250/scan | 1–2 days | Details |
| Retesting & Validation We re-run the test after you fix it and reissue the report | Included | After remediation | Details |
There is no such thing as a “SOC 2 pentest” — it is one pentest, scoped and reported so your auditor accepts it as evidence. We map the same engagement to whichever framework you are being held to, and cover the rest of the readiness work around it.
| Service | Starting at | Typical window | Details |
|---|---|---|---|
| Compliance-Scoped Pentest One pentest, reported against the framework your auditor uses | $8,500 | 1–2 weeks | Details |
| Federal & Defense Scope FedRAMP and CMMC — heavier control set, 3PAO-aligned evidence | $18,000 | 3–4 weeks | Details |
| Gap Assessment Where you stand against the framework, control by control | $6,500 | 1–2 weeks | Details |
| Policies & Procedures Written for your business, not lifted from a template pack | $4,500 | 1–2 weeks | Details |
| Evidence & Audit Support We collect the artifacts and answer the auditor directly | $5,500 | Through the audit | Details |
| Access Reviews User entitlements, least-privilege gaps, stale accounts | $3,500 | 2–5 days | Details |
| Findings Remediation Our engineers fix the findings rather than hand them over | $4,000 | 1–2 weeks | Details |
| vCISO / Security Retainer A named security lead on your leadership calls | $4,000/month | Ongoing | Details |
| Security Advisory Architecture reviews and design calls, billed by the hour | $350/hour | On demand | Details |
| VC Due Diligence Security posture review before you write or take the cheque | $7,500 | 1 week | Details |
Testing tells you where you are weak. This is the half that watches the estate the rest of the year, and the number you call at 2am when something has already gone wrong.
| Service | Starting at | Typical window | Details |
|---|---|---|---|
| Managed Detection & Response Our analysts watch your alerts and act on them, 24/7 | $2,800/month | Ongoing | Details |
| SOC as a Service A full security operations centre without hiring one | $3,500/month | Ongoing | Details |
| 24/7 Continuous Monitoring Always-on coverage across endpoints, cloud and network | $2,200/month | Ongoing | Details |
| SIEM Management Log pipeline, detection rules, and tuning that keeps up | $1,800/month | Ongoing | Details |
| EDR / XDR Endpoint agent rollout, policy, and day-to-day management | $1,100/month | Ongoing | Details |
| Incident Response Retainer Guaranteed response time and hours banked before you need them | $1,500/month | Ongoing | Details |
| Ransomware Response Containment, eradication, and getting the business back up | $25,000 | Immediate | Details |
| BEC Response Mailbox compromise — scope it, evict them, prove it is over | $8,500 | 3–5 days | Details |
| Digital Forensics Defensible imaging and analysis that holds up in a dispute | $12,000 | 1–3 weeks | Details |
| Log Analysis & Review Reconstruct what happened from the evidence you kept | $6,000 | 1–2 weeks | Details |
| Threat Hunting Hypothesis-led hunts for what your tooling did not flag | $4,500 | 1–2 weeks | Details |
| Purple Team We attack, your defenders watch, and the detections improve | $18,000 | 2–3 weeks | Details |
| Tabletop Exercise Walk your leadership through a breach before it is real | $6,500 | 1–2 days | Details |
| Threat Intelligence What is being used against your sector, filtered to you | $1,200/month | Ongoing | Details |
| Dark Web Monitoring Your credentials and data, watched where they get traded | $650/month | Ongoing | Details |
| Vulnerability Management Continuous scanning and prioritised remediation, SLA-backed | $1,200/month | Ongoing | Details |
| Patch Management Risk-based deployment with a rollback path | $950/month | Ongoing | Details |
| Email Security SPF, DKIM, DMARC and the gateway rules that stop the rest | $850/month | Ongoing | Details |
| Endpoint Protection Hardening and managed AV/EPP across the fleet | $900/month | Ongoing | Details |
| Network Security Firewall, segmentation and egress control, managed | $1,400/month | Ongoing | Details |
| Zero Trust Implementation Identity-first architecture, rolled out in stages | $15,000 | 4–8 weeks | Details |
Lory runs scoped engagements against your assets on her own, and a human reviews every finding before it reaches you. Billed by the credit — $1 buys 1 credit, and nothing starts that you have not funded.
| Service | Starting at | Typical window | Details |
|---|---|---|---|
| Lory Recon One asset kept under standing review. 275 credits a month. | $250/month | Ongoing | Details |
| Lory Operator Continuous coverage across a real production estate. 1,150 credits a month. | $1,000/month | Ongoing | Details |
| Lory Continuous Always-on testing with deep-depth headroom. 3,000 credits a month. | $2,500/month | Ongoing | Details |
| Lory Credits No plan and no seats — load a balance and Lory draws from it as she works | $1/credit | $25 – $25,000 | Details |
Autonomous Testing, Priced by the Credit
Lory runs scoped engagements against your assets on her own and every finding is human-reviewed before it reaches you. $1 buys 1 credit — she draws from your balance as she works, so nothing starts that you haven't funded.
Recon
One asset kept under standing review.
- 275 credits every month — $25 free
- At least 1 standard engagement, typically 3
- Or ~13 surface sweeps across your estate
- Unused credits roll forward — they never expire
Operator
Continuous coverage across a real production estate.
- 1,150 credits every month — $150 free
- At least 5 standard engagements, typically 14
- Headroom for MCP agent traffic on top
- Unused credits roll forward — they never expire
Continuous
Always-on testing with deep-depth headroom.
- 3,000 credits every month — $500 free
- At least 2 deep engagements, typically 6
- Or ~37 standard engagements per month
- Unused credits roll forward — they never expire
Metered Rates
Off-plan or over your monthly credits, this is what Lory charges. Same rates on every plan.
Cost per Engagement
Engagements bill by depth. “Typical” is what a real run costs; “max” is the hard budget ceiling the engine will not exceed.
Lory is included in the Offensive and Defensive annual bundles below. See how Lory works →
Save Big with an Annual Program
Most companies save 15–20% by bundling. Each includes testing hours, retesting, client portal, and dedicated account management. Prices below are the standard program rate — scope adjusts it.
Offensive Security
Find and fix vulnerabilities before attackers do
- 2x Web Application Pentests
- 1x Network / Infrastructure Pentest
- 1x API Security Assessment
- 160 testing hours / year
- 24 retesting hours included
- Lory AI Pentester
- Quarterly Vulnerability Scanning
- Client Portal & Remediation Tracking
Defensive Security
24/7 monitoring, detection, and incident response
- SOC as a Service (24/7/365)
- SIEM & Log Management
- Endpoint Detection & Response
- Incident Response Retainer
- Lory AI Pentester
- Threat Intelligence Feed
- Monthly Security Reports
Compliance Package
Get audit-ready and stay compliant with Anchorpoint
- Compliance Pentest (SOC 2, ISO, or PCI)
- Gap Assessment & Readiness Review
- Policy & Procedure Templates
- 80 testing hours / year
- 16 retesting hours included
- Continuous Compliance Monitoring
- Quarterly Security Reviews
- Add Vanta/Drata (ask for details)
Need everything? The Full Stack Bundle combines offensive + defensive + compliance from $99,000/year — ~15% below the three bought separately. Contact us for details →
What Affects Pricing?
Every engagement is scoped individually based on your environment. Here's what we look at.
Scope & Complexity
Number of endpoints, user roles, integrations, and application size directly affect testing time and cost.
Testing Approach
Black box (no access), gray box (partial), or white box (full source) — each requires different effort.
Compliance Requirements
SOC 2, PCI-DSS, HIPAA, and other frameworks require additional testing controls and specialized reporting.
Pricing FAQ
How much does a penetration test cost?
Is there such a thing as a “SOC 2 pentest”?
Is retesting included?
Do you offer startup or bundle pricing?
What's included in the Compliance Package Vanta add-on?
How is Lory AI Pentester priced?
Can Lory replace a human pentest?
What do I get in the report?
How quickly can you start?
Ready to Get Started?
Book a free scoping call to talk through your needs with a security engineer and get a custom quote.