Honest pricing for serious work.
Three tiers cover most engagements. Anything bigger or stranger โ scope it with us. All prices in USD; PKR invoicing available for local clients.
External attack surface review with a focused web/API pentest.
- External recon & OSINT
- Single web/API pentest (โค 25 endpoints)
- OWASP Top 10 coverage
- Executive + technical PDF report
- 1 retest within 30 days
Full-scope pentest, custom tooling and a defender-ready report.
- Web + API + network internal/external
- Authenticated & unauthenticated paths
- Custom exploit / tooling where needed
- Detailed PoCs with reproduction steps
- Threat-modeled report + remediation calls
- 2 retests within 60 days
Adversary emulation, red-team, purple-team and continuous testing.
- Full red-team simulation (TTPs mapped to MITRE)
- Phishing, social-engineering, physical optional
- Custom C2, payloads & implants
- Purple-team debrief with your SOC
- Quarterly retainer available
- NDA + dedicated secure comms
ร la carte.
Need a single deliverable? Pick it up standalone โ no full engagement required.
We take your raw findings and turn them into a board-grade report.
Custom scanners, parsers, automations. Built in Go / Python / Rust.
Manual + SAST review for one repo, with prioritized fixes.
AWS / Azure / GCP hardening against CIS + custom benchmarks.
On-site or remote, tailored to your stack and team level.
Continuous testing slot โ priority response, rolling scope.
Not sure which tier?
Tell us about the system. We'll suggest scope honestly โ even if it's smaller than you asked.
Get a scoped quote