● PLANCK Operator ← Back
Pricing

Pricing for API security testing

Priced per protected API by endpoint volume. Dev, staging, and production cost the same. Your first full scan is free. Pay only when you scale to recurring, multi-domain coverage.

Build your number

Want a price for your APIs?

Pricing is scoped per engagement, by your API count, endpoint volume, and scan cadence. Tell us about your footprint and a specialist sends a tailored quote, usually within one business day.

Want to explore the numbers first? Try the estimate calculator for an indicative estimate, not a list price.

Free · one full scan

First Scan

$0/ first scan

One complete agentic penetration test of your API, proven, at no cost.

  • Every operation tested for BOLA, BFLA, broken auth, and injection
  • A reproducible proof-of-concept for every finding
  • Request/response evidence and a CVSS v3.1 vector per finding
  • One full scan, one domain, self-serve. No demo or quote
Run your free scan

One test per year

Annual Assessment

Quoted

A single scheduled penetration test, once a year.

  • One scheduled agentic API penetration test per year, not continuous scanning
  • Autonomous exploitation with a proof for every finding
  • Each finding carries request/response evidence and a CVSS v3.1 vector
  • Scope and price confirmed in your quote
Get an Annual Assessment Quote

Custom

Enterprise

Custom

Whole-estate coverage on your terms, with a person accountable.

  • SSO / SAML and roles
  • Private VPC or on-prem deployment
  • SLA and dedicated support
  • Volume pricing for many APIs and seats
Talk to us
Actively building an API?

Your first full scan is always free. The startup design-partner program adds two more full agentic penetration tests against your API, free, so you keep testing as you build.

Apply for 2 Free Scans

One test per year

The Annual Assessment is a single scheduled penetration test. It is not continuous scanning.

Recurring scans

Pro runs repeated scans through the year, wired into your integrations. More scans raise the price.

24/7 scan support

Help with scan-related questions and issues, available around the clock. This is support, not 24/7 threat monitoring or continuous manual testing.

How pricing works

You pay for coverage you can count

Operator is priced per protected API by endpoint volume, on a decreasing per-endpoint curve. Pro includes four runs a month; more runs raise the price. Development, staging, and production cost the same. Your First Scan is free. Final scope and price are quoted.

Per API, by endpoints and scans

Each API is priced by its endpoint count, a decreasing per-endpoint curve plus a small per-API base. On Pro, four scans a month are included, and running more scans raises the price for more frequent, recurring coverage.

Environment is free

Dev, staging, and production are the same price. Test everywhere your API runs without paying a premium to cover the environments that matter.

No surprise units

No per-seat math and no sliding definition of an application. You can count what you pay for, and check it against your own inventory.

Want to see how this compares to a traditional engagement? Read the API penetration testing cost breakdown.

Talk to sales for a tailored quote →