About The PenTest Index

Updated

The PenTest Index is an independent buyer’s index for penetration testing. It helps software companies in the United States compare web application and API testing offers, check published terms against a realistic purchase, and prepare clear questions before they contact providers.

Why it exists

A penetration testing price is useful only when you know what it buys. Two offers can differ in the applications and APIs covered, access required, who does the testing, report delivery, annual commitment and time allowed for checking fixes.

Our job is to make those differences inspectable. We put the terms beside the offer, keep missing information visible and turn consequential conditions into questions a buyer can take to a provider.

Who it is for

People who need to buy a penetration test for a software product: founders, engineering and security leads, and the person asked to “get a pentest” because a customer, auditor or security team requires one. You do not need a security background to use it.

What it covers

The current comparison covers selected offers from 8 companies, focused on web applications and APIs, with prices in US dollars:

  • managed testing offers led by people;
  • managed testing offers led by AI; and
  • scanning tools you operate yourself, shown separately because they are a different purchase.

It is a selected sample, not a census of the market. Being listed is not an endorsement, and the order is A to Z within each group, not a ranking. The full comparison was checked on October 7, 2026; specific terms were rechecked on October 8, 2026.

What it does not do

The PenTest Index is not a penetration testing company, consultancy, auditor or compliance platform. It does not perform or authorize testing, certify providers or reports, or promise that a report will be accepted by anyone. Providers handle scoping, contracts, authorization, testing and delivery. You confirm requirements with the customer, auditor or team that will rely on the report.

Three kinds of information

The site keeps these apart, and labels which is which:

  1. Provider-published terms. What a provider states on its own public pages, with the page, section and date checked.
  2. Our calculations and interpretations. Starting amounts worked out from published formulas, and Purchase Check findings that compare published terms with an example purchase. These are labeled as ours.
  3. Firsthand testing. None. We have not purchased the listed services or assessed the quality of their testing.

The original work is the offer-level comparison, the treatment of conditions and conflicts, and the application of published terms to an explicit purchasing brief. Those findings are purchasing analysis, not evidence that one provider discovers more vulnerabilities than another.

Who is responsible for the research

The PenTest Index is published and operated by Kozi Publishing LLC. The publisher is responsible for the research, comparisons, editorial decisions and corrections on this site.

“By The PenTest Index” is our organizational byline. It identifies the publication responsible for the page. It does not imply that a certified penetration tester wrote it, that a panel reviewed it, or that we purchased the services being compared.

AI tools helped structure the research records, draft copy and build the website. The editorial standards explain their role and the limits of source citations and automated checks.

Arithmetic and rule outputs for the current Purchase Checks are reproduced by automated tests. No competent technical review of these findings has been recorded. Each finding shows its review status; a source check and a technical review are different work.

Read the methodology, the editorial standards and how we make money.

Independence

We do not sell penetration testing services. Payment cannot buy inclusion, a better comparison position, a favorable finding or a different correction. Companies appear A to Z within each group, and the rules used for Purchase Checks do not use commission amounts or commercial relationships.

The commercial disclosure describes the current recorded position. A provider’s ability to pay is not evidence that its offer fits a buyer.

Contact and corrections

Write to Partners@thepentestindex.com. The contact page explains what to include for corrections, provider evidence, privacy, accessibility and website problems.

If a fact, calculation or conclusion is wrong, send the statement and the evidence that changes it. Material corrections belong in the public update record, along with the affected source and finding changes.

Browse the offer comparison or prepare your penetration testing scope without an account or contact form.

Find My PenTest Match