Three plans,
no surprises

Start with 2 free scans, then $35 per scan. Scale to a full team plan when you're ready. Every plan includes the complete PenScan platform.

Starter
$35 per scan
2 free scans on signup, then pay as you go — no commitment
What's included
1 domain
1 seat
All 7 security scanners
Technical Assessment PDF
Asset & subdomain discovery
Trust certificate & badge
Email support
Scheduled / recurring scans
Scan comparison
Multi-domain management
Team seats
Remediation tracking
Executive & Compliance PDFs
Combined multi-target PDF report
Vulnerability triage & assignment
Get started free

2 free credits included · No card required

Enterprise
Custom
Pricing on request
Everything in Growth, plus
Unlimited scans
Unlimited domains & seats
Premier customer support (SLA-backed)
Cyber security expert access — remediation guidance from vetted professionals
Enterprise-grade audit logs & compliance reports
Custom contract & invoicing
SSO / SAML & advanced RBAC
Talk to sales

Typically responds within 1 business day

Everything side by side

Starter Growth Enterprise
Price $35 / scan $99 / mo Custom
Domains 1 10 Unlimited
Seats 1 5 Unlimited
Scans included Pay per scan 75 / year Unlimited
Support Email Priority Premier (SLA)
All 7 scanners
Technical Assessment PDF
Executive & Compliance PDFs
Combined multi-target PDF report
Asset & subdomain discovery
Cross-scanner deduplication
Severity-ranked findings
Trust certificates & badges
Vulnerability triage & assignment
Remediation progress tracking
Scheduled / recurring scans
Scan comparison (diff)
Multi-domain management
Team seats
Audit logs
White-glove onboarding
Cyber security expert access
Enterprise compliance reports
SSO / SAML
Custom contract & invoicing
Get started Start Growth Talk to sales

Full platform access on every plan

Every plan — including a single $35 scan — gives you the complete PenScan platform. No crippled free tier, no feature walls.

All 7 scanner types (ZAP, Nuclei, Wapiti, Nikto, SSLyze, Nmap, Dalfox)
Combined & deduplicated vulnerability report
Severity-ranked findings (Critical → Low)
Asset & subdomain discovery
DNS ownership verification
Trust certificates & embeddable widgets
Vulnerability management dashboard
Audit & action logs
Technical Assessment PDF report

Common questions

Everything you need to know about PenScan.

Yes — PenScan enforces ownership verification via DNS TXT records before any scan begins. You can only scan domains you demonstrably control. Additionally, users must accept a legal disclaimer confirming they have authorization to test the target. This makes PenScan both legally sound and ethically responsible.
A full combined scan typically completes in 15–30 minutes, depending on the size and complexity of your target. All seven scanners run concurrently — ZAP accounts for 35% of the scan weight and usually takes the longest. You'll receive a notification when results are ready.
One credit is worth $1 and powers approximately one full combined scan of a single target. A "full scan" runs all seven scanners simultaneously. Passive asset discovery (subdomain enumeration) on target creation is free and doesn't consume credits.
No. Credits never expire. Buy what you need now and use them at your own pace — whether that's tomorrow or six months from now.
Yes. PenScan supports team collaboration with role-based access control. Invite team members as Owners (full access), Analysts (can run and review scans), or Viewers (read-only access to reports). All roles operate within your organization's isolated workspace.
PenScan orchestrates seven industry-standard tools: OWASP ZAP (web app scanning), Nuclei (CVE & misconfiguration templates), Wapiti (SQLi, XSS, CSRF), Nikto (web server fingerprinting), SSLyze (TLS/SSL analysis), Nmap (port & service discovery), and Dalfox (advanced XSS fuzzing). Results from all tools are merged and deduplicated into a single report.
Absolutely. Each organization's data is isolated in a multi-tenant architecture — no other user or organization can access your targets, scans, or vulnerability reports. Data is encrypted in transit (TLS 1.3) and at rest.

Your next scan is
minutes away

Add a target, verify ownership with a DNS record, and run your first full security scan. No setup, no infrastructure, no waiting.

No credit card required  ·  Credits never expire  ·  Cancel any time