Research for buyers

Penetration testing companies, independently compared.

Compare offers by scope, price, testing approach and retest terms. See which options deserve a closer look, what could rule them out and the questions to resolve before booking.

Choose what needs testing and prepare a scope checklist for the providers you contact.

Free scope checklist · Copy or print · No contact details required

Penetration testing companies compared

Selected offers from eight companies, with a focus on web applications and APIs. Compare the specific offer: the same company may sell human testing, AI testing and scanning separately.

Companies appear A to Z within each group. This is not a ranking. Prices are in US dollars for the stated package; “not stated” means the detail was not found in the sources reviewed. Sources and check dates

This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Show

Emphasize a column

Side by side

Choose “Compare” on up to three entries.

Tests led by people

These offers include human testing. The scope, use of automation and amount of testing still need to match your project.

Tests led by people: 8 entries from 7 companies, companies A to Z. Each entry is followed by its sources and check details.
Company and offerWho tests; what is coveredPublished price and commitmentRetestingStated timingNext step
AstraPentest Expert
Human testers plus autonomous agents. One web or SaaS app and its consumed APIs count as one target.
$5,999/year per target. Includes a manual pentest and ongoing scanning; confirm the target count.
Two manual re-scans; request within 30 days of findings being reported. Policy (Astra source: Rescan rules)
Manual exercise: 10–20 working days in its help documentation; scope and workload affect timing. Details (Astra source: Testing duration)
Sources and check details: Astra · Pentest Expert

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • What is covered

    Counts one web or SaaS app and its consumed APIs as one target.

    Plans and pricing (Astra source), Target definition · Checked October 7, 2026

  • Price

    Lists Pentest Expert at $5,999 per year per target, including a manual pentest and ongoing scanning, delivered by human testers plus autonomous agents.

    Limitation: An annual package price, not a quote for your scope. Confirm how many targets your application and APIs count as.

    Plans and pricing (Astra source), Pentest Expert plan · Checked October 7, 2026

  • Retesting

    Allows two manual re-scans, requested within 30 days of findings being reported. Extensions are considered case by case.

    Limitation: The window limits when a re-scan is requested and runs from reported findings. The price of any extension is not stated.

    Rescan rules (Astra source), Rescan Validity Period, Expert row · Checked October 7, 2026; rechecked October 8, 2026

  • Timing

    Gives 10–20 working days for the manual exercise; scope and workload affect timing.

    Limitation: An estimate of testing time, not a booking date or report deadline.

    Conflicts with: Plans and pricing, Pricing FAQ. Ask the provider which term applies to your agreement.

    Testing duration (Astra source), Manual testing duration · Checked October 7, 2026

  • Timing

    Gives 10–15 working days for the manual pentest.

    Limitation: Narrower than the help documentation’s 10–20 working days. The comparison shows the broader estimate and names its source; ask for your schedule in writing.

    Conflicts with: Testing duration, Manual testing duration. Ask the provider which term applies to your agreement.

    Plans and pricing (Astra source), Pricing FAQ · Checked October 7, 2026

Bishop FoxApplication penetration testing
Assessors use manual and automated testing; selected for application type and programming language.
Quote required. Confirm scope, effort and total commitment.
Count and window not stated.
Booking and report dates not stated.
Sources and check details: Bishop Fox · Application penetration testing

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Who tests

    Describes assessors using manual and automated testing, selected for the application type and programming language.

    Limitation: No published price, retest count or window, booking date or report date was found in this source; a quote is needed.

    Application penetration testing (Bishop Fox source), Service description · Checked October 7, 2026

BreachLockStandard / Extended / Extensive
In-house testers. Application and network scope agreed for the project; platform access is optional.
Quote required. Package and scope determine the offer.
One / two / custom manual retests, respectively; window not stated.
Booking and report dates not stated.
Sources and check details: BreachLock · Standard / Extended / Extensive

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Retesting

    Describes in-house testers, application and network scope agreed for the project and optional platform access. Lists one, two and custom manual retests for Standard, Extended and Extensive respectively.

    Limitation: No package price, retest window, booking date or report date was found in this source; package and scope determine the offer.

    Penetration testing packages and pricing (BreachLock source), Standard, Extended and Extensive packages · Checked October 7, 2026

CobaltStandard / Premium / Enterprise
Vetted testers with AI-supported delivery; scoped engagements.
Quote required. Annual credit packages; confirm credits needed and the applicable unused-credit terms.
Six / twelve / twelve months, subject to the active-contract cutoff below.
Advertised starts: three / two / one business days by tier after submitting the pentest for review; submissions after the stated 11 a.m. PST cutoff add one business day. Engagement-dependent. Scheduling rules (Cobalt source: Scheduling and submission cutoff)
Sources and check details: Cobalt · Standard / Premium / Enterprise

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Credits

    Sells Standard, Premium and Enterprise as annual credit packages delivered by vetted testers with AI-supported delivery. One credit represents eight equivalent testing hours across automation and human work. Lists retest periods of six, twelve and twelve months by tier.

    Limitation: Equivalent testing hours are not a promise of eight hours of human testing. Credits needed for your engagement require a quote.

    Pricing and offer terms, including conflicting rollover statements (Cobalt source), Package comparison · Checked October 7, 2026

  • Credits · Enterprise

    Lists credit rollover of up to 10% for Enterprise.

    Limitation: Conflicts with the FAQ on the same page. Ask which term will apply to your agreement, in writing.

    Conflicts with: Pricing and offer terms, including conflicting rollover statements, Pricing FAQ. Ask the provider which term applies to your agreement.

    Pricing and offer terms, including conflicting rollover statements (Cobalt source), Enterprise comparison table · Checked October 7, 2026; rechecked October 8, 2026

  • Credits

    Says credits do not roll into the next contract.

    Limitation: Conflicts with the Enterprise comparison table’s rollover of up to 10%.

    Conflicts with: Pricing and offer terms, including conflicting rollover statements, Enterprise comparison table. Ask the provider which term applies to your agreement.

    Pricing and offer terms, including conflicting rollover statements (Cobalt source), Pricing FAQ · Checked October 7, 2026; rechecked October 8, 2026

  • Retesting

    Documents six- and twelve-month retest periods for Agile and Comprehensive pentests while the contract remains active. Requests close at the earlier of the retest period’s end or ten days before the contract ends.

    Limitation: The applicable cutoff depends on both the tier’s period and the contract end date.

    Retesting policy (Cobalt source), Retest periods and contract end · Checked October 7, 2026

  • Timing

    Advertises test starts of three, two and one business days by tier after the pentest is submitted for review.

    Limitation: A start time after submission for review; not a report date.

    Pricing and offer terms, including conflicting rollover statements (Cobalt source), Package comparison, test start times · Checked October 7, 2026; rechecked October 8, 2026

  • Timing

    Counts start times from submitting the pentest for review; submissions after the stated 11 a.m. PST cutoff add one business day. Timing depends on the engagement.

    Scheduling and submission cutoff (Cobalt source), Test period scheduling · Checked October 7, 2026; rechecked October 8, 2026

NetSPIPTaaS
In-house testers. Application, API, network, cloud and other specialist services.
Quote required. Confirm the exact service and commitment.
Remediation testing listed; count and window not stated.
Booking and report dates not stated.
Sources and check details: NetSPI · PTaaS

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Who tests

    Describes in-house testers and application, API, network, cloud and other specialist services, with remediation testing listed.

    Limitation: No price, retest count or window, booking date or report date was found in this source; confirm the exact service and commitment.

    PTaaS services and delivery (NetSPI source), PTaaS services and delivery · Checked October 7, 2026

Pentest-Tools.comManaged web app testing
Manual testing of a web app. Black box covers an anonymous attacker; gray box includes authenticated roles.
$3,400 for the black-box offer. Gray box starts at $3,400 + $900 per user role.
Count and window not stated.
Black box: three working days, best effort; report on day four. Gray box: four or more working days; report when ready.
Sources and check details: Pentest-Tools.com · Managed web app testing

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price · Black box

    Lists manual testing of a web app as an anonymous attacker at $3,400, with three working days of testing on a best-effort basis and the report on day four.

    Limitation: No retest count or window was found in this source.

    Managed web app testing (Pentest-Tools.com source), Black box web app pentest · Checked October 7, 2026

  • Price · Gray box

    Lists manual testing that includes authenticated user roles, starting at $3,400 plus $900 per user role, with four or more working days of testing and the report when ready.

    Limitation: A starting formula, not a quote. API coverage, complexity, required additions and retesting are not priced by it. No retest count or window was found.

    Managed web app testing (Pentest-Tools.com source), Grey box web app pentest, price section · Checked October 7, 2026; rechecked October 8, 2026

SynackSynackST
One human tester. Up to 25 unauthenticated web apps, one low-complexity authenticated app, or 100 host IPs.
From $10,283/test. Required platform line item is separate.
Patch verification listed; count and window not stated.
Five-day assessment window.
Sources and check details: Synack · SynackST

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Lists SynackST from $10,283 per test: one human tester; up to 25 unauthenticated web apps, one low-complexity authenticated app, or 100 host IPs; a five-day assessment window; patch verification listed.

    Limitation: A starting test component. No patch-verification count or window was found.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Testing packages, SynackST · Checked October 7, 2026; rechecked October 8, 2026

  • Platform

    States that a platform line item is required in addition to the test, and describes a free Basic platform tier.

    Limitation: Which platform tier applies, and its charge, is unresolved. An unknown required charge is not treated as zero, so no complete total is calculated.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Pricing table note and platform tier descriptions · Checked October 7, 2026; rechecked October 8, 2026

  • Credits

    Says purchased credits expire one year from the purchase date.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Credit expiry FAQ · Checked October 7, 2026; rechecked October 8, 2026

SynackSynack14
Researcher team. Up to 50 unauthenticated web apps, one authenticated app, or 250 host IPs.
From $27,120/test. Required platform line item is separate.
Patch verification listed; count and window not stated.
Fourteen-day assessment window.
Sources and check details: Synack · Synack14

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Lists Synack14 from $27,120 per test: a researcher team; up to 50 unauthenticated web apps, one authenticated app, or 250 host IPs; a fourteen-day assessment window; patch verification listed.

    Limitation: A starting test component. No patch-verification count or window was found.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Testing packages, Synack14 · Checked October 7, 2026

  • Platform

    States that a platform line item is required in addition to the test, and describes a free Basic platform tier.

    Limitation: Which platform tier applies, and its charge, is unresolved. An unknown required charge is not treated as zero, so no complete total is calculated.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Pricing table note and platform tier descriptions · Checked October 7, 2026; rechecked October 8, 2026

  • Credits

    Says purchased credits expire one year from the purchase date.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Credit expiry FAQ · Checked October 7, 2026; rechecked October 8, 2026

Cobalt’s retest limit matters: its documented six- and twelve-month periods apply to Agile and Comprehensive pentests while the contract remains active. Requests close at the earlier of the retest period’s end or ten days before the contract ends. Read the retest policy (Cobalt source: Retesting policy)

Cobalt’s credit rollover terms need written clarification: its Enterprise comparison table lists rollover of up to 10%, while the FAQ on the same pricing page says credits do not roll into the next contract. Ask which term will apply to your agreement. Compare both statements (Cobalt source: Pricing and offer terms, including conflicting rollover statements)

Tests led by AI

Read the human role in each offer. Having experts build a system, direct a test or check a fix are different services. Confirm that the testing approach meets your customer’s, auditor’s or security team’s requirements.

Tests led by AI: 4 entries from 4 companies, companies A to Z. Each entry is followed by its sources and check details.
Company and offerWho tests; what is coveredPublished price and commitmentRetestingStated timingNext step
AstraPentest Auto
Autonomous testing for web and SaaS apps.
$2,999/year per target.
One manual re-scan; request within 30 days of findings being reported. Policy (Astra source: Rescan rules)
First report advertised the same day.
Sources and check details: Astra · Pentest Auto

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Lists Pentest Auto at $2,999 per year per target: autonomous testing for web and SaaS apps, with the first report advertised the same day.

    Limitation: An annual package price. Advertised speed is not a contracted report deadline.

    Plans and pricing (Astra source), Pentest Auto plan · Checked October 7, 2026

  • Retesting

    Allows one manual re-scan, requested within 30 days of findings being reported.

    Limitation: A manual re-scan checks fixes; it is not evidence that people performed the initial test.

    Rescan rules (Astra source), Rescan Validity Period · Checked October 7, 2026

CobaltAutonomous Pentest
AI testing with Cobalt Core testers directing scope, execution and quality; web applications.
$3,500/test promotion. Must start and finish before December 31, 2026.
Offer-specific allowance not stated.
Findings within 24 hours; report at engagement close.
Sources and check details: Cobalt · Autonomous Pentest

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Lists the Autonomous Pentest at $3,500 per test as a promotion; the test must start and finish before December 31, 2026. Describes AI testing with Cobalt Core testers directing scope, execution and quality for web applications, findings within 24 hours and a report at engagement close.

    Limitation: After the promotion ends, the replacement price is unresolved until published. No offer-specific retest allowance was found in this source.

    Pricing and offer terms, including conflicting rollover statements (Cobalt source), Autonomous Pentest offer · Checked October 7, 2026

IntruderAI web app pentest
AI-powered white-box web app testing; code repository integration required.
$3,500/test on its pricing page. New-customer pricing differs in another official source; see below.
Unlimited retesting listed; time limit not stated.
Same-day reports advertised.
Sources and check details: Intruder · AI web app pentest

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Access required

    Describes AI-powered white-box web app testing whose workflow requires connecting a code repository.

    Limitation: A different arrangement without repository access would need its own confirmation.

    Pentest pricing (Intruder source), Repository integration and connect-codebase step · Checked October 7, 2026; rechecked October 8, 2026

  • Price

    Lists the AI web app pentest at $3,500 per test, with unlimited retesting and same-day reports advertised.

    Limitation: Another official Intruder source gives different amounts by customer type; which applies to your purchase is unresolved. No time limit for retesting was found.

    Pentest pricing (Intruder source), AI web app pentest offer · Checked October 7, 2026

  • Price · New customers and existing customers

    Lists $4,000 for new customers and $3,500 for existing customers.

    Limitation: Different customer terms do not by themselves establish a contradiction. The amount for your purchase stays unresolved until Intruder confirms it.

    Cost article (Intruder source), Pricing by customer type · Checked October 7, 2026

  • Offer terms

    Advertises a refund if an auditor rejects its report.

    Limitation: A refund promise, not confirmation that your recipient will accept the report.

    Pentest pricing (Intruder source), Auditor refund promise · Checked October 7, 2026

SynackSara Pentest
AI-led test of one low-complexity web app or 100 host IPs.
From $4,181/test. Required platform line item is separate.
Patch verification listed; count and window not stated.
Four- to five-day assessment window.
Sources and check details: Synack · Sara Pentest

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Lists Sara Pentest from $4,181 per test: an AI-led test of one low-complexity web app or 100 host IPs; a four- to five-day assessment window; patch verification listed.

    Limitation: A starting test component. No patch-verification count or window was found.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Testing packages, Sara Pentest · Checked October 7, 2026

  • Platform

    States that a platform line item is required in addition to the test, and describes a free Basic platform tier.

    Limitation: Which platform tier applies, and its charge, is unresolved. An unknown required charge is not treated as zero, so no complete total is calculated.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Pricing table note and platform tier descriptions · Checked October 7, 2026; rechecked October 8, 2026

  • Credits

    Says purchased credits expire one year from the purchase date.

    Testing packages, platform terms and credit expiry FAQ (Synack source), Credit expiry FAQ · Checked October 7, 2026; rechecked October 8, 2026

Price and credit terms to confirm: Intruder’s pricing page (Intruder source: Pentest pricing) lists $3,500 per test, while its cost article (Intruder source: Cost article) lists $4,000 for new customers and $3,500 for existing customers. Ask which applies. Synack requires a separate platform line item and also describes a free Basic tier; ask which platform your purchase requires and its complete price. Synack credits expire one year from the purchase date. Pricing and credit FAQ (Synack source: Testing packages, platform terms and credit expiry FAQ)

Timing above is the provider’s stated start, testing or reporting period—not a reserved delivery date. Ask for your actual report deadline in writing.

Which offers deserve a closer look?

Start with the requirement that would rule an offer out. These starting points follow the documented differences above.

Starting points by buyer priority, with what to confirm before booking.
Your priorityWhere to look firstWhat to confirm
A published price for human testingAstra Pentest Expert and Pentest-Tools.com’s managed web app service.Compare the annual package with the project offer; make sure authenticated roles and APIs are covered.
Several tests across the yearCobalt’s annual credit packages.Credits needed per engagement and written confirmation of the conflicting Enterprise rollover terms above. One credit represents eight equivalent testing hours across automation and human work.
A provider-employed testing teamBreachLock and NetSPI, which describe in-house delivery.Who will test your systems, relevant experience, scope and report requirements.
Assessors familiar with your application technologyBishop Fox describes selecting assessors for application type and language.The proposed team’s relevant work and the testing effort in your quote.
An AI-led web app testAstra Auto, Cobalt Autonomous, Intruder and Synack Sara.Required access, human involvement, report acceptance and a confirmed delivery date.

Already have a provider or a quote? Put it through the same six questions below. The useful outcome may be confirming the option you already have.

Find My PenTest Match

Work out what to compare and copy your scope checklist before you contact anyone.

How we turn offer terms into a buying decision

The PenTest Index Purchase Check applies a buyer’s requirements to the terms of an exact offer—not to a company-wide score. Each finding shows the relevant evidence, what follows from it and the question still worth asking. Missing information remains unresolved.

Six things to settle before you book

Ask each company the same questions about the same project:

  1. What will be tested?

    Name the applications, APIs, user roles and environments. Ask what is excluded and whether testing covers the business workflows that matter to you.

  2. Who will do the work?

    Establish the human testing, AI testing and review included in this specific offer. Ask for experience relevant to your systems.

  3. What report do you need?

    Confirm your customer’s, auditor’s or security team’s requirements. Review a sample for scope, evidence, findings and remediation guidance.

  4. What is the complete commitment?

    Include required subscriptions, platform access, scope charges and renewal terms. Confirm whether you are paying for one test or a continuing package.

  5. Who checks the fixes, and until when?

    Confirm the retest count, window, when the window starts and what happens if remediation takes longer.

  6. When will the report arrive?

    Agree on scoping, access, the test start and report delivery. Include time for fixes and retesting if your recipient needs them completed.

Send each company the same brief so you can compare its answer to the same job.

Four worked Purchase Checks

Example brief: one SaaS web app and its API, two authenticated user roles, no source code access, and a manual check of fixes requested 45 days after findings are reported.

These are selected checks against an illustrative brief. Each row examines one purchase condition; it does not establish that the whole offer fits. Sources for these examples checked October 8, 2026.

Four worked Purchase Checks against the example brief. Each row is one purchase condition of one exact offer and is followed by its rule and provenance.
Purchase conditionWhat the published terms establishQuestion to send the provider
Two authenticated user rolesMandatory in the brief

Supported · starting amount only

Pentest-Tools.com gray box: $5,200 starting amount, calculated as $3,400 + (2 × $900). The complete price for the API, retesting and any additional scope is unresolved. Published formula (Pentest-Tools.com source: Managed web app testing)

“For this app, its API and two roles, what is the complete price, including a manual retest requested 45 days after findings are reported?”

Rule and provenance: Two authenticated user roles, Pentest-Tools.com · Managed web app testing
Offer evaluated
Pentest-Tools.com · Managed web app testing — Gray box. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Two authenticated user roles (mandatory). Managed gray-box web app test as published; two authenticated user roles; no other scope priced.
Evidence applied
  • Price · Provider-published · Managed web app testing (Pentest-Tools.com source), Grey box web app pentest, price section. Lists manual testing that includes authenticated user roles, starting at {{usd:pentest-tools-gray-box.price.amount}} plus {{usd:pentest-tools-gray-box.price.perUserRole}} per user role, with four or more working days of testing and the report when ready. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Published starting base + role count × published role charge (rule version 1.0)
Inputs read
  • Base amount: $3,400
  • Per role amount: $900
  • Roles: 2
  • Price status: starting
Result
Supported. The published formula gives a conditional starting amount for 2 authenticated roles. It does not price API coverage, complexity, required additions or retesting, so the whole-brief price remains unresolved. Amount: $5,200 (Conditional starting amount for 2 authenticated roles; not a quote or complete price).
Still open
  • API coverage, complexity and any required additions
  • A manual retest requested on day 45
  • Delivery dates
What would change it
A confirmed scope and itemized quote can change the whole-brief price finding. Losing the published formula removes this Supported finding.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-01 · Purchase Check method 1.0
Manual retest requested on day 45Mandatory in the brief

Mismatch · included request window

Astra Expert: outside the included request window. Its two manual re-scans must be requested within 30 days of findings being reported. Extensions are considered case by case. Rescan terms (Astra source: Rescan rules)

“Can you include a manual re-scan requested 45 days after findings are reported? Please confirm the extension and any added cost in writing.”

Rule and provenance: Manual retest requested on day 45, Astra · Pentest Expert
Offer evaluated
Astra · Pentest Expert. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Manual retest requested on day 45 (mandatory). Pentest Expert’s included manual re-scans; the window limits the request and runs from reported findings.
Evidence applied
  • Retesting · Provider-published · Rescan rules (Astra source), Rescan Validity Period, Expert row. Allows {{words:astra-pentest-expert.retest.count}} manual re-scans, requested within {{num:astra-pentest-expert.retest.windowDays}} days of findings being reported. Extensions are considered case by case. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Requested day compared with the published retest window and what it limits (rule version 1.0)
Inputs read
  • Request day: 45
  • Window days: 30
  • Deadline applies: request
  • Window trigger: findings being reported
  • Included count: 2
  • Manual: yes
Result
Mismatch. A request on day 45 falls outside the published 30-day window, which runs from findings being reported.
Still open
  • Whether Astra will extend the request window, and at what price
What would change it
A written extension can resolve this condition; its price is not assumed. A request made within the window changes the timing check only.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-02 · Purchase Check method 1.0
No source code accessMandatory in the brief

Mismatch · source code access

Intruder’s listed offer: access mismatch. Its white-box workflow requires connecting a code repository. A different arrangement would need confirmation. Offer and workflow (Intruder source: Pentest pricing)

“Do you offer a test without access to our source code? Please confirm its scope, testing approach and price.”

Rule and provenance: No source code access, Intruder · AI web app pentest
Offer evaluated
Intruder · AI web app pentest. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: No source code access (mandatory). Intruder’s listed AI web app pentest and its connect-codebase workflow.
Evidence applied
  • Access required · Provider-published · Pentest pricing (Intruder source), Repository integration and connect-codebase step. Describes AI-powered white-box web app testing whose workflow requires connecting a code repository. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Required repository access compared with the buyer’s access constraint (rule version 1.0)
Inputs read
  • Buyer provides source code: no
  • Repository required: yes
Result
Mismatch. The offer’s workflow requires connecting a code repository; the brief rules out source code access.
Still open
  • Whether Intruder offers an evidenced alternative without repository access
What would change it
An evidenced alternative offer or a buyer-authorized change to the constraint can change this result only.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-03 · Purchase Check method 1.0
Complete purchase commitmentMandatory in the brief

Unresolved · complete total

SynackST: total unresolved. The test starts at $10,283; a platform line item is required, and a free Basic tier is also described. Which tier applies still needs confirming. Platform and test terms (Synack source: Testing packages, platform terms and credit expiry FAQ)

“Can SynackST cover this app and API, and is the Basic platform tier eligible? Please itemize the test, any required platform charge, when purchased credits expire and the full contractual commitment.”

Rule and provenance: Complete purchase commitment, Synack · SynackST
Offer evaluated
Synack · SynackST. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Complete purchase commitment (mandatory). SynackST as published: a starting test component plus a required platform line item.
Evidence applied
  • Price · Provider-published · Testing packages, platform terms and credit expiry FAQ (Synack source), Testing packages, SynackST. Lists SynackST from {{usd:synack-st.price.amount}} per test: one human tester; up to 25 unauthenticated web apps, one low-complexity authenticated app, or 100 host IPs; a five-day assessment window; patch verification listed. Checked October 7, 2026; rechecked October 8, 2026.
  • Platform · Provider-published · Testing packages, platform terms and credit expiry FAQ (Synack source), Pricing table note and platform tier descriptions. States that a platform line item is required in addition to the test, and describes a free Basic platform tier. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Sum of current required components; unknown required charges make the total incomplete (rule version 1.0)
Inputs read
  • Base amount: $10,283
  • Base status: starting
  • Promotion expired: no
  • Required additions: 1
  • Unknown required additions: 1
Result
Unresolved. A required component has no applicable published charge. An unknown required charge is not treated as zero, so the complete total cannot be calculated.
Still open
  • Whether the free Basic platform tier is eligible
  • The required platform charge
  • How the published one-year credit expiry applies to this purchase
  • An itemized, complete commitment
What would change it
Itemized written confirmation of the test, the applicable platform tier and its charge. Other fit checks remain.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-04 · Purchase Check method 1.0

These are our calculations and interpretations of published terms. No provider has quoted for this illustrative brief.

Carry the unresolved questions into your scope checklist, so each provider answers the requirements that matter to your purchase.

Get the answer for your next decision

Where to start for each buying decision.
What you need to decideStart here
Choose the testing surfaceWhat needs testing and what to compare
Understand published purchase termsPublished prices and commitments
Clarify the recipient’s needsQuestions for your report recipient
Prepare the work descriptionPrepare your scope checklist
Compare proposals consistentlyQuestions to compare offers

Scanning and tools you operate

These are separate purchases from the managed testing offers above. A tool subscription gives you software to use; it does not by itself commission an independent assessment.

Scanning and tools you operate: 3 entries from 3 companies, companies A to Z. Each entry is followed by its sources and check details.
Company and planPublished priceWhat you are buyingNext step
AstraScanner
$199/month or $1,999/year for one target.
Unlimited vulnerability scanning.
Sources and check details: Astra · Scanner

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Lists the Scanner at $199 per month or $1,999 per year for one target, with unlimited vulnerability scanning.

    Limitation: Software you operate; it does not commission an independent assessment.

    Plans and pricing (Astra source), Scanner plan · Checked October 7, 2026

IntruderScanning platform
Plan and target-based pricing; use its calculator.
Ongoing vulnerability scanning; check included target types and plan features.
Sources and check details: Intruder · Scanning platform

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Prices ongoing vulnerability scanning by plan and target, using a calculator.

    Limitation: Check included target types and plan features. Software you operate, separate from commissioned testing.

    Scanning platform pricing (Intruder source), Scanning plans · Checked October 7, 2026

Pentest-Tools.comNetSec
Advertised from $95/month for five assets; price varies by asset count and billing cycle.
A self-service network assessment and discovery toolkit. Its managed testing service is listed separately above.
Sources and check details: Pentest-Tools.com · NetSec

Provider-published: The provider’s own public page states this. It is not an assessment of testing quality.

  • Price

    Advertises NetSec, a self-service network assessment and discovery toolkit, from $95 per month for five assets; price varies by asset count and billing cycle.

    Limitation: Software you operate, separate from the managed testing service.

    Tool subscriptions (Pentest-Tools.com source), NetSec plan · Checked October 7, 2026

Who stands behind the comparison

Published by The PenTest Index. We are responsible for the research, comparisons and corrections on this page. We do not sell penetration testing services.

Our current comparison uses provider-published sources. We have not purchased the listed services or independently assessed their testing quality. Written confirmations, inspected samples and documented buyer outcomes are identified separately when available; they support only what was actually checked.

How we make money

We may earn a referral fee if you choose a provider through this site. Paid relationships are disclosed beside the relevant links.

Payment does not determine editorial inclusion, comparison order or which offer fits your needs. A suitable provider can be listed and recommended without paying us.

A few questions before you choose

Do I have to use Find My PenTest Match?

No. Browse the comparisons or visit a provider directly. Find My PenTest Match helps you choose what needs testing and prepare the questions and scope details to discuss with a provider.

Will a report meet my customer’s or auditor’s requirements?

Confirm the required scope, testing approach and deliverables with the recipient before booking. A provider’s compliance claim is not approval from your recipient. Intruder advertises a refund if an auditor rejects its report; that is a refund promise, not confirmation that your report will be accepted. Intruder’s published offer (Intruder source: Pentest pricing)

Do I need a company near me?

Not necessarily. Ask whether any work needs to happen on site, where the assigned testers will work, and whether your contract restricts tester location or data handling. Include time-zone requirements in your brief.

Get a scope checklist you can act on

Choose what needs testing. See what to compare, which questions to confirm with your report recipient, and the scope details to prepare. Copy or print the checklist, then contact the providers you choose.

The checklist does not submit your selections to us or save them as a form. Analytics may record page interactions on the live site.

Find My PenTest Match

Free scope checklist · Copy or print · No contact details required

Keep comparing providers

Sources

Full offer comparison checked October 7, 2026. Cobalt’s start-time and rollover terms and Synack’s credit-expiry terms were rechecked October 8, 2026. All reported offer details are provider-published unless otherwise noted.

Provider source pages reviewed for this page, with the dates they were checked.
ProviderSources reviewedChecked
AstraChecked October 7, 2026; rechecked October 8, 2026
Bishop FoxChecked October 7, 2026
BreachLockChecked October 7, 2026
CobaltChecked October 7, 2026; rechecked October 8, 2026
IntruderChecked October 7, 2026; rechecked October 8, 2026
NetSPIChecked October 7, 2026
Pentest-Tools.comChecked October 7, 2026; rechecked October 8, 2026
SynackChecked October 7, 2026; rechecked October 8, 2026
Find My PenTest Match