Simple, Transparent Pricing

From quick vulnerability checks to enterprise-wide protection. Pay for what you need.

Quick Assessments

Fast, affordable vulnerability testing. No commitment required.

Free Scan

Basic attack surface check

$0 / scan
  • Single domain scan
  • 12 common subdomain checks
  • 6 CDN providers detected
  • Basic risk summary
  • Full subdomain discovery
  • DDoS simulation

DoS Quick Check

Test your rate limits work

$99 / test
  • 15-minute assessment
  • HTTP flood testing
  • Cache bypass testing
  • Rate limit validation
  • Basic report included
  • Slowloris / Slow POST
Get Started

DoS Professional

Full attack vector coverage

$399 / test
  • 1-hour assessment
  • 10,000 RPS testing
  • All attack vectors
  • SSL exhaustion testing
  • Executive + Technical report
  • 30-min consultation call
Get Started

Discovery & DDoS Simulation

Complete attack surface mapping with optional synthetic DDoS testing.

Discovery Assessment

Full attack surface mapping

$2,500 / domain
  • 500+ subdomain discovery
  • 12 CDN/WAF providers detected
  • Origin IP exposure check
  • API endpoint discovery
  • Architecture topology map
  • Executive PDF report
  • CLI remediation commands
  • DDoS simulation
Request Quote

Load Testing

Distributed load testing from multiple cloud regions.

Basic

Quick smoke test

$99
  • 100 virtual users
  • 15-minute duration
  • 1 region
  • Real-time metrics
  • JSON report
Get Started

Standard

Pre-launch validation

$299
  • 500 virtual users
  • 30-minute duration
  • 3 regions
  • P50/P90/P99 latencies
  • HTML report
Get Started

Enterprise

Maximum scale

Custom
  • 10,000+ virtual users
  • Custom duration
  • Global distribution
  • Custom traffic patterns
  • Dedicated support
Contact Sales

Continuous Validation

Ongoing protection with regular assessments and real-time monitoring.

Starter

1 domain

$2,500 / month
  • 1 primary domain
  • Monthly discovery scans
  • Quarterly DDoS simulation
  • Dashboard access (2 seats)
  • Email alerts
  • Standard support
Get Started

Enterprise

Unlimited

Custom
  • Unlimited domains
  • Continuous monitoring
  • On-demand simulations
  • Dedicated TAM
  • Custom integrations
  • 24/7 support (4hr SLA)
  • Executive QBRs
Contact Sales

Annual plans save 15%. Contact us for custom pricing.

Compare Plans

Find the right level of protection for your needs.

Feature Free Scan DoS Assessment Discovery Full Assessment
Subdomain Discovery 12 prefixes - 500+ 500+
CDN/WAF Detection 6 providers 12 providers 12 providers 12 providers
Origin IP Check Basic Yes Deep scan Deep scan
Rate Limit Testing - Yes - Yes
Slowloris Testing - Standard+ - Yes
DDoS Simulation - - - Lab-based
Architecture Map - - Yes Yes
PDF Report - +$99 Included Included
CLI Commands - - Included Included
Starting Price Free $99 $2,500 $7,500

Enterprise Solutions

For organizations with 100+ domains, we offer ceiling-based annual contracts with dedicated support and custom integrations.

🔒

Unlimited Domains

Up to 2,500 domains

📞

24/7 Support

4-hour SLA

📈

Quarterly Reviews

Executive briefings

Custom Integrations

SIEM, CI/CD, API

Talk to Sales

Platform Subscription Plans

Choose the plan that fits your needs. All plans include access to the DDactic platform.

Feature Free Pro Business Enterprise
Price $0 $99/mo $499/mo Custom
Domains Visible 1 HTTP domain 5 domains 25 domains Unlimited
Company Search ✓ Limited ✓ Full ✓ Full ✓ Full
Database Discovery 🔒 Blurred ✓ Full Details ✓ Full Details ✓ Full Details
API Findings 🔒 Blurred ✓ Full Details ✓ Full Details ✓ Full Details
Active Recon ✓ 1 domain only ✓ 50/day ✓ Unlimited ✓ Unlimited
Topology Visualization ✓ Basic ✓ Full ✓ Full ✓ Full + Custom
Reports ✓ Basic ✓ Full ✓ Full + White-label ✓ Full + Custom
SSO / SAML
Team Members 1 5 25 Unlimited
Admin Verification ✓ Required ✓ Required
Support Community Email Priority Dedicated TAM
Get Started Upgrade Contact Sales Contact Sales

🔒 Security Note

For Business and Enterprise plans, all discovered domains are shown to organization members, but actions require admin (CISO) email verification. This ensures proper authorization before performing scans or accessing sensitive infrastructure data.

Frequently Asked Questions

What's the difference between DoS and DDoS assessment?
DoS (Denial of Service) assessment uses a single high-powered server to test your rate limits, connection pools, and timeout configurations. It answers "do my defenses work?" DDoS simulation uses our distributed load fleet infrastructure to simulate real-world distributed attacks and answers "can I survive a real attack?"
Is DDoS testing safe for production?
Yes. Our Full Assessment simulations run from controlled lab infrastructure, not against your production systems directly. We test your CDN/WAF's ability to absorb and mitigate attacks without ever overwhelming your origin servers.
What's included in the CLI commands?
Our reports include ready-to-run commands for hardening your infrastructure. Examples: Cloudflare WAF rule updates, AWS WAF configurations, nginx rate limiting snippets, and origin IP rotation scripts for major cloud providers.
Can I get a discount for multiple domains?
Yes! We offer bundle packages with up to 50% savings. For 10+ domains, contact us for custom enterprise pricing. First-time customers also get 20% off with code FIRSTSCAN.
Do you offer a money-back guarantee?
Yes. If our assessment doesn't find any actionable findings, we'll refund 100% of your payment. We're confident in our methodology.

Ready to Find What Your Defenses Miss?

Start with a free scan or talk to our team about your specific needs.

Get Started Contact Sales