Synack penetration testing: prices, platform fee and terms

By The PenTest Index · Published offers and terms checked October 9, 2026

Synack penetration testing starts at $4,181 for AI-led Sara Pentest, $10,283 for SynackST (one human tester) and $27,120 for Synack14 (a researcher team). Those are test fees, not totals. Synack bills its platform separately: $16,000 for 12 months on its AWS Marketplace listing, though it also describes a free Basic tier. Ask which applies to you.

Below we add the platform to each package, show where Synack's own pages disagree, and give you the questions to send before you sign.

Our read, in three lines. Synack is worth a closer look if you test many assets across a year, want a team of researchers instead of one or two named testers, buy for a federal agency, or have cloud marketplace budget to spend. It is probably not your first stop if you need one small web app tested once and have less than about $25,000: the lowest human-led total we could add up from Synack's published AWS list is $26,010, and that package covers one user role. Either way, the first question is the same: which platform tier does your order need, and what does it cost?

Already know your package? Synack's own page has the details.

See Synack's pricing page

How much does Synack penetration testing cost?

Synack's published test fees run from $4,181 for one AI-led test to $27,120 for a 14-day test by a researcher team. The platform is extra. On Synack's AWS Marketplace price list, where the platform has a published price, the smallest human-led purchase adds up to $26,010 for 12 months.

There are two public price lists. Keep them apart, because the numbers and the scope wording are not the same.

Price list 1: Synack's own pricing page

PackageWho testsScope limit as listedWindowStarting test fee
Sara PentestAI-led1 low-complexity web app, or 100 host IPs. External targets only4–5 daysFrom $4,181 per test
SynackST1 human testerUp to 25 unauthenticated web apps, or 1 low-complexity authenticated web app, or 100 host IPs. Web or host5 daysFrom $10,283 per test
Synack14 / Synack365Team of researchersUp to 50 unauthenticated web apps, or 1 authenticated web app, or 250 host IPs. Web, host, API, mobile14 or 365 daysFrom $27,120 for one Synack14
EnterpriseRotating teamsCustomVariesQuote only

Source: Synack pricing, provider-published, checked October 9, 2026. The page shows "$" with no currency label. "Authenticated" means the tester logs in; "unauthenticated" means they test from the outside without an account. The window is the calendar period for testing. It is not a count of working hours and it is not a report date.

The condition that changes every row: Synack's note under this table says the Synack Platform "is required to purchase any of the testing products and is a separate line item." No paid-platform price is shown on this page, so none of these fees is a confirmed complete total.

Price list 2: Synack's AWS Marketplace listing, with the platform added

Synack's AWS listing does price the platform. It is a line item called "Synack Testing Platform (required for testing packages)" at $16,000 for a 12-month contract. That lets us do the sum Synack's own page leaves out.

AWS line item (12-month contract)Listed priceOur total with the $16,000 platform
SynackST for Compliance, Small: 5 days. Up to 100 IPs, or 1 small/medium single-tenant web app with 1 user role, or up to 2 non-dynamic small apps, or up to 20 unauthenticated URLs$10,010$26,010
SynackST for Compliance, Large: 5–10 days. Up to 250 IPs, or 1 large web app (2–3 roles, multi-tenant), or 2 small/medium apps (single tenant, 1 user role), or up to 4 non-dynamic apps, or up to 50 unauthenticated URLs$16,720$32,720
Synack S14: 14 days. 1 authenticated web app, or up to 50 unauthenticated URLs, or up to 250 active IPs, or up to 25 headless API endpoints, or 1 mobile app$26,400$42,400
Synack S14 for AI/LLM$26,400$42,400
Synack S365: year-long continuous testing, same asset units as S14$136,400$152,400
4-pack SynackST Small$46,040$62,040
4-pack SynackST Large$71,560$87,560

Source: Synack Human-led Penetration Testing on AWS Marketplace, provider-published, checked October 9, 2026. Our rule is simple: one test line plus one platform line. These are list prices in US dollars for that listing only. They leave out tax, any AWS charges, extra scope and any private-offer discount. They are not a quote, and we have not added the AWS platform price to the fees on Synack's own page, because the two lists may carry different terms.

Think of it like a gym that lists a class price but also needs a membership. The class is the test. The membership is the platform. You can't judge the price until you know both.

What the sums show

  • The platform is most of the smallest bill. $10,010 + $16,000 = $26,010. The platform is about 61% of that.
  • The 4-packs are listed above four singles. Four Small tests bought one at a time come to $40,040. The 4-pack is $46,040, which is $6,000 more ($11,510 per test instead of $10,010). Four Large singles come to $66,880; the 4-pack is $71,560, or $4,680 more. The listing describes the packs as a saving. The pack may include something the single doesn't, but the listing doesn't say what. Ask.
  • Synack's own page runs about 2.7% above the AWS list for the same-named tests: $10,283 against $10,010, and $27,120 against $26,400.
  • The test fee for a year of continuous testing on one asset is about 5.2 times the fee for one 14-day test ($136,400 ÷ $26,400).
  • Scope is counted in defined units. The S14 line joins web app, API endpoints and mobile app with "or." A web app plus its API may be two tests. We come back to this below, because it can double the testing charge.

If these totals are out of range for what you need, skip to alternatives. For how test prices are built in general, see our guide to penetration testing cost.

Is the Synack platform free or $16,000?

Both statements are published, and they can both be true. What Synack doesn't publish is which one applies to your order. Until you have that in writing, treat your total as incomplete, not as the test fee alone.

Here is what we read on October 9, 2026:

  • Synack's pricing page says "The Basic Platform is available at no cost" and lists what Basic includes: self-service test launch, vulnerability management, patch verification, a findings report per engagement, access controls and managed access to its researcher community.
  • The same page says the Synack Platform "is required to purchase any of the testing products and is a separate line item." The paid tier adds attack surface discovery, analytics and history, integrations (Jira, ServiceNow, Splunk and others) and single sign-on.
  • Synack's AWS listing prices the "Synack Testing Platform (required for testing packages)" at $16,000 for 12 months.

A free tier and a paid line item can sit side by side. The open question is whether a paid test can run on Basic. Send Synack this: "Which platform tier does this exact order require, and what is its price for 12 months?"

Which Synack package fits what you need tested?

Pick by who needs to do the testing and how much there is to test. For one web app where testers log in as more than one kind of user, AWS SynackST Large explicitly lists 2–3 roles; Sara Pentest and Synack14 need role coverage confirmed.

Sara Pentest: AI-led. Sara is Synack's AI agent. Synack's Sara page says it tests external web and host targets only, that logins using multi-factor authentication or one-time passwords are not supported yet, and that CAPTCHA is a problem. Synack's terms add that AI services "may fail to identify all vulnerabilities" and that use is at the customer's risk. A larger version, Sara Pentest+, covers one large web app or up to 250 host IPs; we found no published fee for it. Sara suits broad outside-in coverage at a low per-test fee. If the person who will read your report asked for testing led by people, Sara alone doesn't match that request.

SynackST: one assigned human tester. Synack's offering table describes a guided, checklist-based assessment by one assigned researcher, with an OWASP checklist, over 5 days. A larger size, SynackST+, runs 5 to 10 days and covers one large authenticated web app. The "Large" line on AWS looks like this larger size: same 5–10 day window, same 250-IP limit. Synack decides what counts as "low complexity," based on tenancy, user roles and other factors. This is the package aimed at a defined test for a customer or auditor.

Synack14, Synack90 and Synack365: a pool of researchers. These run for 14, 90 or 365 days. Synack calls the method "open vulnerability discovery": researchers from its Synack Red Team hunt for flaws and are rewarded for what they find, while your fee stays flat. Checklists (OWASP, NIST 800-53) are an optional add-on for the 14- and 90-day versions; the 365-day version includes two. If your report reader wants a checklist showing what was covered, ask for that add-on by name.

API Assessment. Synack lists API testing as its own offering: "One API with up to 25 endpoints," with add-ons for more.

Enterprise. A custom mix, by quote.

Sources: Synack pricing, Synack platform offering table (dated June 24, 2026), Sara AI pentesting, Product Specific Terms. All checked October 9, 2026.

Will Synack cover your app, its API and your user roles?

Not automatically. Synack's API page says it plainly: "Not all API endpoints are accessible through a web UI or tested during a web app pentest." Its AWS listing presents web-app and headless-API scope as alternatives. So name every API, role and tenant in your scope, and ask whether they sit inside one test or two.

A quick word on terms. An API is the set of endpoints your app, your mobile client or your partners call to send and fetch data. A user role is a type of account, such as admin or standard user. Multi-tenant means one app serves many customer organizations whose data must stay apart. Each of these can move you from a small package to a larger one.

A worked Purchase Check

We use the same illustrative brief as on our homepage, so the results line up. It is not a real buyer, and Synack has not quoted against it.

The brief: one SaaS web app and its API, two authenticated user roles, no source code access, and a manual check of fixes requested 45 days after findings are reported.

The result first: the closest published fit is SynackST Large for the app at $32,720 on the AWS list, if Synack confirms the API is inside that test. If the API fits one separate S14 unit of up to 25 endpoints, the listed components total $59,120 (SynackST Large + one S14 unit for the API + platform) or $68,800 (two S14 units + platform). One answer from Synack separates those numbers. SynackST Small doesn't match two logged-in roles as published; the base Sara Pentest remains unresolved.

Requirement in the briefSara PentestSynackSTSynack14
Web app with two logged-in rolesUnresolved. Low-complexity apps only; Synack sets complexity partly on user roles; MFA logins not supportedMismatch for AWS Small (1 role). Supported for AWS Large (2–3 roles)Unresolved. 1 authenticated web app is listed; confirm both user roles
API includedUnresolved. Listed for web or hostUnresolved. Listed for web or host; API is a separate offeringUnresolved. API endpoints listed as an "or" unit
No source code neededSupported. Nothing we read requires code accessUnresolvedUnresolved
Manual fix check requested on day 45Unresolved. Patch verification is listed; no count or deadline is publishedUnresolvedUnresolved
Complete priceUnresolved. No paid-platform price on the direct listUnresolved. AWS-listed subtotal: $32,720 before any API unitUnresolved. AWS-listed subtotal: $42,400, or $68,800 if the API fits one separate unit

"Supported" means the published terms support that one requirement. It is not a verdict on Synack's quality and not a promise your report will be accepted. A "Mismatch" on a must-have removes that package for this brief. "Unresolved" means you need Synack's answer in writing. Sources as listed above, checked October 9, 2026. The $59,120 and $68,800 figures are our sums from the AWS list ($16,720 + $26,400 + $16,000, and 2 × $26,400 + $16,000). More about the method: how we check offers.

Three checks that change your branch

  • Did your customer or auditor ask for human-led testing? If yes, Sara Pentest alone is out, and you are choosing between SynackST and Synack14. If they didn't say, ask them before you buy.
  • Do your testers need to log in through MFA? Sara doesn't support it yet. Don't switch off a production control to fit a test. Ask Synack for an approved way in, or use a human-led package.
  • Is any of your scope internal? Sara tests external targets only. SynackST and Synack14 list internal and external.

Synack counts scope by app, role, tenant, API endpoint and IP. Write yours down the same way before you ask for a quote, so the answer you get is for the right package. Our free scope checklist walks you through it. You can copy or print it, and it asks for no contact details. It prepares your questions; it does not pick a provider for you.

Find My PenTest Match

Is Synack a bug bounty or a penetration test?

It depends on the package. SynackST is one assigned researcher working through a checklist on a fixed scope. Synack14, Synack90 and Synack365 work more like a private, managed bug bounty sold at a flat fee: a pool of vetted researchers looks for flaws and Synack pays them for what they find.

That incentive model is Synack's own description. Its offering table calls the longer packages "incentive-based open vulnerability discovery testing performed by the Synack Red Team." Its CREST listing says an engagement includes "incentive-driven vulnerability discovery" and that "all testing is offered on a flat-fee basis." Its application testing page says "Synack handles researcher payments" and "the cost to you remains fixed." So you don't pay per bug. Synack puts the Red Team at more than 1,500 researchers; that is a company figure, and it is the size of the pool, not the number of people on your test.

What this means for you:

  • A reward for finding flaws does not itself prove coverage. If your report reader needs proof that specific things were checked, ask for the checklist add-on and a coverage report.
  • Three jobs are easy to blur: who tests, who reviews, who checks the fix. On Sara Pentest, the offering table lists the tester as "AI agent driven." Synack's Sara page says Red Team researchers validate findings. Ask whether a person reviews every finding in the base Sara report, and note that Synack marks Sara and SynackST reports as carrying AI-generated summaries of findings.
  • We did not test Synack's work, so this page makes no claim about how good the findings are.

Sources: offering table, CREST Marketplace listing, application testing. Checked October 9, 2026.

Will a Synack report satisfy your auditor or customer?

Synack labels every package's report "compliance ready" and names frameworks such as SOC 2, PCI, HIPAA and FISMA. That is Synack's description of its report. The person who asked you for the test decides what they accept, so check with them before you buy, above all if you are looking at the AI-led package.

Ask the report reader three things: Does testing have to be led by people? Does the tester have to be independent of us? Do you need proof that fixes were re-checked?

Two things you can check yourself:

  • A sample report. Synack links a sample API report from its API page. It is an older file (its web address puts it in 2022), so use it to see the format, then ask Synack: "Can you send a current sample for the exact product on our quote?"
  • Listings. The CREST Marketplace lists Synack, Inc with a Penetration Testing accreditation; we read that listing on October 9, 2026. Synack states that its platform is FedRAMP Moderate Authorized, sponsored by the U.S. Department of Health and Human Services. The official FedRAMP Marketplace entry lists Synack's On-Demand Security Testing Platform as FedRAMP Certified, Class C (Moderate); we checked it on October 9, 2026.

We are a publisher. We don't perform tests, and nothing here means a given report will be accepted.

What happens after the test: fix checks, credits and expiry

Fix checks are included, but with no published count or deadline. Credits carry the bigger risk, because Synack's FAQ and its contract terms give two different expiry rules.

Fix checks. Synack calls a retest "patch verification": after you fix a finding, you ask in the platform and a researcher checks that the flaw can no longer be exploited. Every package lists it, and so does the free Basic tier. Synack's application page says apps "will continue to get tested until secure posture is confirmed." We found no number of rounds, no last date to ask, and no extra charge stated. Because requests go through the platform, our reading is that the practical cutoff is the end of your subscription. Get the date in writing.

Credits. Synack sells testing as credits you spend through the year. Two published rules cover when they run out:

  • The pricing page FAQ: "credits expire one year from purchase date."
  • The Product Specific Terms, section 3.2, and the offering table: credits are valid "only during the Subscription Period" defined in the work order where they were purchased and expire when it ends or when the agreement is terminated, whichever comes first. They have no cash value and are non-refundable.

The Product Specific Terms say they win over the main agreement where the two conflict. Here is a made-up case to show why it matters. Say you top up credits nine months into a 12-month subscription, under a work order that ends with that subscription. Read the FAQ and you have 12 months to use them. Read the terms and you have 3. If you buy everything on day one, the two dates match and the problem goes away.

Refunds. Synack's AWS listings say refunds follow its End User Agreement. We found no refund clause in that agreement. The Master Service Agreement gives a prorated refund in one case only: when Synack ends the contract for its own reasons. Otherwise it says fees are not refunded.

Sources: Synack pricing FAQ, Product Specific Terms (updated April 28, 2026), application testing, End User Agreement and Master Service Agreement (both updated March 12, 2026). Checked October 9, 2026.

What's in Synack's contract that you should read first?

Three terms stand out in Synack's published Master Service Agreement: renewals re-price at list unless your order says otherwise, Synack can end the contract on 30 days' notice but you can't, and Synack can hand the contract to another company without asking you.

This is the online agreement that applies when you buy direct and have no signed contract of your own. A negotiated contract can differ. This is our reading of published text, not legal advice. For an annual commitment in the tens of thousands of dollars, a legal review is money well spent.

TermWhat the published text saysWhy you care
Renewal price (section 4.1)Renewal fees update to Synack's list price at the time, unless the work order says otherwiseAsk for a renewal cap in the order
Payment (4.2)Invoiced before services start; due in 30 days; 1.5% a month or the maximum legal rate, whichever is less, on late amountsYou are invoiced before work starts
Ending early (11.2, 11.3)Synack may end the contract for any reason on 30 days' notice and refund the remaining full months. You get no matching right. Otherwise no refundsThe exit runs one way
Assignment (14.4)Synack may assign the contract freely. You need Synack's consent to assign yoursMatters after a merger
Liability cap (10.3)Capped at the fees you paid in the 12 months before the first event giving rise to the claim, with listed exceptionsA small cap if you bought one test
Your name and logo (14.1)Synack may show you as a clientStrike it if you don't want that
Benchmarks (3.4(g))No publishing comparative tests of Synack without written consentLimits what you can say in public
Credit prices (Product Specific Terms 3.2)Catalog services and the credits they cost "may change at any time"A credit is not a fixed amount of testing
AI testing (Product Specific Terms 1.4–1.6)You are responsible for what the AI agent does inside your agreed scope, and for backupsRead this before pointing Sara at production
Your right to test (8.3)You warrant that you own or can authorize testing of every targetCheck hosting and third-party systems first
Product changes (12)Synack may change or drop features at its discretionRelevant during integration

Source: Synack Master Service Agreement and Product Specific Terms, checked October 9, 2026. If you buy through a reseller, the End User Agreement applies instead; it reads much the same but lacks the prorated-refund sentence. The AWS listing separately attaches an older End User Agreement; confirm which version your order incorporates.

What changed after the NetSPI merger?

For a test you already have running, nothing, according to NetSPI. For a contract you are about to sign, one thing is worth asking: which company you are signing with.

NetSPI and Synack announced an agreement to merge on September 2, 2026. NetSPI's page for customers now says the merger "officially closed in October 2026." It says current engagements keep the same testing cadence, scope, platform access and contacts. It also says Synack's FedRAMP status applies to the Synack platform only and does not extend to NetSPI products. The page does not name the legal entity on new contracts and does not mention pricing.

When we checked on October 9, 2026, Synack's packages and prices were still published under the Synack name, and its online agreement still named Synack, Inc. Remember the assignment term above: Synack can transfer your contract without your consent. So ask now, and don't assume that a NetSPI price, team or credential carries over to a Synack package, or the other way round.

Source: NetSPI and Synack: what customers need to know, company-stated, checked October 9, 2026.

Questions to send Synack before you sign

Send these with your scope and ask for one itemized proposal back. Each question closes a gap in what Synack publishes.

First, the places where Synack's own pages don't line up. These are worth raising by name.

TopicOne Synack source saysAnother saysWhat we make of it
Platform costBasic Platform is available at no costThe platform is required and is a separate line item; $16,000 for 12 months on AWSUnresolved: which tier your order needs
Credit expiryOne year from purchase date (pricing FAQ)Only during the applicable work-order subscription period (terms; offering table says subscription period)Conflicting when the dates differ
What SynackST covers1 low-complexity authenticated app (pricing page)1 single-tenant app with 1 user role (AWS Small)Unresolved: get roles and tenants in writing
Unauthenticated scope25 or 50 "web apps" (pricing page)25 or 50 "URLs" (offering table); 20 or 50 "URLs" (AWS)Conflicting: a URL is not an app
API coverageSynack14 lists API alongside web (pricing page)API is its own offering, and an "or" unit on AWSUnresolved: one test or two
What Sara can reachAgents explore cloud, SaaS apps, APIs and internal systems (one FAQ answer)External web and host assets only; no MFA logins yet (another answer on the same page)Conflicting: the narrower answer is the product-specific one
People in the AI testRed Team validates each finding (Sara page)Tester listed as "AI agent driven," no reviewer named (offering table)Unresolved
4-pack priceDescribed as a saving (AWS)Priced above four singles (AWS)Conflicting on the list as published
RefundsAWS: follows the End User AgreementNo refund clause found thereUnresolved

All read on October 9, 2026, from the sources linked in the sections above.

The questions

  1. 1. Which exact testing product and platform tier do you recommend for our scope, and what does each cost for 12 months?
  2. 2. Which applications, APIs, endpoints, user roles, tenants and environments are included, and what is excluded? Does our app and its API count as one test or two?
  3. 3. Is the work AI-led, led by one assigned researcher, or done by a researcher pool? Does a person review every finding in the report?
  4. 4. Does the proposal include the specific checklists or tests our report reader asked for?
  5. 5. Please itemize testing, platform access, scope extras, fix checks and any other required charge, with currency, term and billing schedule.
  6. 6. On what calendar date do our credits expire, including any we add later? Please write it on the order.
  7. 7. When can the test start once access is ready, and on what date will the final report arrive?
  8. 8. How many patch verifications are included, who performs them, what is the last date to request one, and will the report be updated?
  9. 9. What is our renewal price, and will you cap it in the work order? What are the cancellation and refund terms?
  10. 10. Please send a current sample report for the same product.
  11. 11. Who can see our scope and findings, where is the data kept, and what stop controls and testing windows apply?
  12. 12. After the NetSPI merger, which legal entity is our contract with, and does anything in this order change at renewal?

One limit: these questions and any scope checklist help you buy. They do not authorize testing. Written authorization has to cover the actual targets and activities, and it comes from your agreement with the provider and from whoever owns the systems.

If your scope is ready, send it with these questions and ask Synack for one itemized proposal.

Request an itemized Synack quote

To line a returned proposal up against others, see our guide to comparing a penetration testing quote.

Synack alternatives, or keeping the tester you have

If your current tester's report already meets what your customer or auditor asked for, you may not need to buy anything new. If you need one web app tested and Synack's total is out of range, start with offers that publish a per-test or per-target price for human testing.

Your situationWhere to lookWhat to keep in mind
Your current test already covers the requestConfirm scope, date and fix evidence with the report reader and your current providerA new purchase may be unnecessary. Continuous testing is worth adding only for a need the current test doesn't meet
One web app, logged-in roles, small budgetPentest-Tools.com managed gray-box test: from $3,400 plus $900 per user role, so $5,200 for two roles as a starting amount. Astra Pentest Expert: $5,999 per year per targetDifferent scope and terms from Synack; not like for like. API coverage and fix checks need confirming for both
You want quotes from other platform-based providersCobalt, BreachLock and Bishop Fox, all quote-required on our comparisonSend the same scope to each so the answers line up
You were weighing Synack against NetSPIThey are now one companyAsk which team and which contract you would get

Prices in this table come from the provider-published records on our homepage comparison, checked October 7 and 8, 2026. The order is by situation, not a ranking, and no provider pays to appear here.

Compare published penetration testing offers

What do Synack reviews tell you?

Reviews are good for finding questions to ask. They can't tell you the scope, report or fix-check terms of your own order. Synack has review pages on G2 and Gartner Peer Insights. We have not analyzed them and draw no conclusion from them here.

In one public buyer thread, a founder comparing Synack with Cobalt and NetSPI asked about the following: whether findings are real or scanner noise, whether the report will look credible to a customer, how fast a test can start, and whether there are surprises on pricing or retesting. Those are the right questions, and the list above turns each one into something Synack can answer in writing.

To be plain about our own work: we read Synack's published offers, prices and terms on October 9, 2026 and did the sums on this page. We have not bought a Synack test.

Quick answers

Is Synack FedRAMP authorized?

Synack states that its platform is FedRAMP Moderate Authorized and that pricing for those offerings is on request. NetSPI's merger page says that status applies to the Synack platform only. We checked the official FedRAMP Marketplace entry on October 9, 2026: Synack's On-Demand Security Testing Platform is listed as FedRAMP Certified, Class C (Moderate).

Can you buy Synack through AWS, Azure or Google Cloud?

Synack says yes to all three. We read its AWS Marketplace human-led listing, which is where the $16,000 platform price and the totals on this page come from. We did not open the Azure or Google Cloud price plans.

Does Sara train on your data?

Synack's Sara page says the underlying models do not retain or train on customer data, and that Synack does not use customer data to train its AI features "at this time." That is a company statement. If it matters to you, ask for it in your contract.

Sources and how we checked

Every price and term on this page is provider-published unless we say otherwise. We read each source on October 9, 2026, and the sums are our own. Where Synack's pages disagree or leave something out, we say so and give you the question to ask. We are an independent publisher: we don't sell or perform testing. See how we make money.

Find My PenTest Match