Pricing

Simple, One-Time Pricing

No subscriptions. No retainers. Pay once, get a full pentest report.

Single Scan

One full-depth pentest. Own your domain, get a PDF report.

$150/scan
Within 3-4 hours
Buy Single Scan
Full reconnaissance & subdomain enumeration
Nuclei — all severity levels
OWASP ZAP passive + active scan
SSL/TLS & security headers audit
Tech stack detection & tuning
CVSS v3.1 scoring per finding
Compliance mapping (SOC 2, PCI DSS, GDPR)
PDF report + interactive dashboard
GitHub / Linear issue export
Extended remediation guides
Best Value — Save $100

Bundle — 3 Scans

Pre-pay for 3 scans and save $100. Credits never expire.

$350for 3 scans

~$116/scan — save $34 vs single

3 scan credits, use any time
Buy Bundle
Everything in Single Scan
3 scan credits — use on any domain
Credits never expire
Priority queue (scans start faster)
Bulk PDF download
~$116/scan (save $34 vs single)
No subscriptionDomain verified scans onlyPDF + dashboardOWASP WSTG v4.2CVSS v3.1 scoring
Comparison

How we stack up

Full pentest depth without the agency retainer.

NexusVoid VAPT
$150/scan
or $117 in bundle
3-4 hrs
Nuclei, ZAP, SQLMap, Nmap, SSLyze
PDF + Dashboard
None
Maced AI
$249/mo
subscription
Continuous
Surface-level scanning
Dashboard only
Monthly
BreachMe
~$200+/mo
subscription
Continuous
Limited DAST
Dashboard
Monthly
Traditional Pentest
$5K – $50K
per engagement
2–4 weeks
Manual + automated
PDF report
Annual
Doing Nothing
$0
until breach
N/A
None
Incident report
Avg $4.45M
Features

Single vs Bundle

Both tiers include the full scan depth. Bundle adds credits and priority.

Feature
Single
Bundle
Nuclei (all severities)
OWASP ZAP active scan
SQLMap injection testing
Full port scan (65535)
SSL/TLS & header audit
Subdomain enumeration
Tech stack detection
CVSS v3.1 scoring
Compliance mapping
SOC 2, PCI, GDPR, HIPAA
SOC 2, PCI, GDPR, HIPAA
PDF report
Interactive dashboard
GitHub / Linear export
Priority queue
Credits never expire
Bulk PDF download
Cost per scan
$150
~$117
FAQ

Common questions

Do scan credits expire?

No. Bundle credits never expire. Buy today and use them months later.

Can I scan any domain?

You must verify domain ownership via DNS TXT record before any scan runs. This protects third parties.

What's in the PDF report?

Executive summary, severity breakdown, detailed findings with PoC evidence, CVSS scores, OWASP mappings, compliance checklist, and remediation code snippets.

How is this different from SaaS scanners?

We run full tool chains (Nuclei + ZAP + SQLMap + Nmap) on your actual app — not just header checks or surface pings. You get a pentest-grade report, not a dashboard.

Can I use credits on different domains?

Yes. Each credit can be used on any verified domain. Great for agencies or founders with multiple products.

Ready to find vulnerabilities?

Drop your URL. Get a pentest report. Under $150. Within 3-4 hours.

Start Your Scan