Transparent pricing
Three plans,
no surprises
Start with 2 free scans, then $35 per scan. Scale to a full team plan when you're ready. Every plan includes the complete PenScan platform.
Starter
$35
per scan
2 free scans on signup, then pay as you go — no commitment
What's included
1 domain
1 seat
All 7 security scanners
Technical Assessment PDF
Asset & subdomain discovery
Trust certificate & badge
Email support
Scheduled / recurring scans
Scan comparison
Multi-domain management
Team seats
Remediation tracking
Executive & Compliance PDFs
Combined multi-target PDF report
Vulnerability triage & assignment
2 free credits included · No card required
Most popular
Growth
$99
/ month
Billed annually — $1,188/yr
What's included
10 domains
5 seats (Owner / Analyst / Viewer)
75 scans / year included, granted when your subscription activates
Extra scans beyond that: $35 per scan
All 7 security scanners
Asset & subdomain discovery
Trust certificates & badges
All 3 PDF reports (Technical, Executive, Compliance)
Combined multi-target PDF report
Vulnerability triage & assignment
Scheduled / recurring scans
Scan comparison (diff)
Multi-domain management
Team seats
Remediation tracking
Priority support
White-glove onboarding
Cyber security expert access
Annual billing · Cancel anytime
Enterprise
Custom
Pricing on request
Everything in Growth, plus
Unlimited scans
Unlimited domains & seats
Premier customer support (SLA-backed)
Cyber security expert access — remediation guidance from vetted professionals
Enterprise-grade audit logs & compliance reports
Custom contract & invoicing
SSO / SAML & advanced RBAC
Typically responds within 1 business day
Compare plans
Everything side by side
| Starter | Growth | Enterprise | |
|---|---|---|---|
| Price | $35 / scan | $99 / mo | Custom |
| Domains | 1 | 10 | Unlimited |
| Seats | 1 | 5 | Unlimited |
| Scans included | Pay per scan | 75 / year | Unlimited |
| Support | Priority | Premier (SLA) | |
| All 7 scanners | |||
| Technical Assessment PDF | |||
| Executive & Compliance PDFs | |||
| Combined multi-target PDF report | |||
| Asset & subdomain discovery | |||
| Cross-scanner deduplication | |||
| Severity-ranked findings | |||
| Trust certificates & badges | |||
| Vulnerability triage & assignment | |||
| Remediation progress tracking | |||
| Scheduled / recurring scans | |||
| Scan comparison (diff) | |||
| Multi-domain management | |||
| Team seats | |||
| Audit logs | |||
| White-glove onboarding | |||
| Cyber security expert access | |||
| Enterprise compliance reports | |||
| SSO / SAML | |||
| Custom contract & invoicing | |||
| Get started | Start Growth | Talk to sales |
Always included
Full platform access on every plan
Every plan — including a single $35 scan — gives you the complete PenScan platform. No crippled free tier, no feature walls.
All 7 scanner types (ZAP, Nuclei, Wapiti, Nikto, SSLyze, Nmap, Dalfox)
Combined & deduplicated vulnerability report
Severity-ranked findings (Critical → Low)
Asset & subdomain discovery
DNS ownership verification
Trust certificates & embeddable widgets
Vulnerability management dashboard
Audit & action logs
Technical Assessment PDF report
FAQ
Common questions
Everything you need to know about PenScan.
Yes — PenScan enforces ownership verification via DNS TXT records before any scan begins.
You can only scan domains you demonstrably control. Additionally, users must accept a legal
disclaimer confirming they have authorization to test the target. This makes PenScan both
legally sound and ethically responsible.
A full combined scan typically completes in 15–30 minutes, depending on the size and complexity
of your target. All seven scanners run concurrently — ZAP accounts for 35% of the scan weight
and usually takes the longest. You'll receive a notification when results are ready.
One credit is worth $1 and powers approximately one full combined scan of a single target.
A "full scan" runs all seven scanners simultaneously. Passive asset discovery (subdomain enumeration)
on target creation is free and doesn't consume credits.
No. Credits never expire. Buy what you need now and use them at your own pace —
whether that's tomorrow or six months from now.
Yes. PenScan supports team collaboration with role-based access control. Invite team members
as Owners (full access), Analysts (can run and review scans), or Viewers (read-only access
to reports). All roles operate within your organization's isolated workspace.
PenScan orchestrates seven industry-standard tools:
OWASP ZAP (web app scanning),
Nuclei (CVE & misconfiguration templates),
Wapiti (SQLi, XSS, CSRF),
Nikto (web server fingerprinting),
SSLyze (TLS/SSL analysis),
Nmap (port & service discovery), and
Dalfox (advanced XSS fuzzing).
Results from all tools are merged and deduplicated into a single report.
Absolutely. Each organization's data is isolated in a multi-tenant architecture — no other user
or organization can access your targets, scans, or vulnerability reports. Data is encrypted
in transit (TLS 1.3) and at rest.
Get started today
Your next scan is
minutes away
Add a target, verify ownership with a DNS record, and run your first full security scan. No setup, no infrastructure, no waiting.
No credit card required · Credits never expire · Cancel any time