Home / Pricing

Clear. Fixed price.

You know what you pay, and what you get. Three plans, from automated scan to in-depth audit. TO ADJUST indicative pricing.

Automated
Express Scan
The scanner, delivered fast.
€690
  • 68 modules · 4 surfaces (params, headers, cookies, JSON)
  • White-label HTML + PDF report
  • 0 false positives guaranteed (every finding replayed)
  • Delivered within 48 h
Choose Express
Most chosen
Standard Audit
The scan + a pentester’s eye.
€2,400
  • Everything in Express Scan
  • Manual review by a pentester
  • Prioritised report + concrete fixes
  • 30-min debrief call
Choose Standard
Complete
In-depth Audit
Business logic, on top of the technical.
€4,500
  • Everything in Standard Audit
  • Logic testing, IDOR, attack chaining
  • Executive + technical report
  • Action plan + retest included
Choose In-depth
IncludedExpressStandardIn-depth
68 automated modules
0 false positives guaranteed
HTML / PDF / SARIF reports
Manual pentester review
Debrief call
Business-logic & IDOR testing
Action plan + retest
Frequently asked

What we get asked most.

What is a false positive, and why “zero”?

A false positive is a false alarm: the scanner reports a flaw that doesn’t actually exist. Most tools produce hundreds, and your team spends its days triaging. At SauronSec, every flaw is replayed and confirmed before it enters the report; anything that doesn’t confirm is dropped. So you only get real, verified findings — never noise.

Is the scan dangerous for my site?

No. Detection is non-destructive: never a destructive query (DROP/DELETE), no uploads, no writes. The rate is adjustable to spare fragile targets.

Do you extract data from my site?

No by default. The scanner proves the flaw without extracting or storing any data. Bounded proof extraction only happens with the --exploit option and explicit written authorization.

Do I need authorization to scan?

Yes. You must own the target or hold written authorization. It’s a legal requirement, reminded on every scan.

What report formats are delivered?

HTML, PDF, JSON and SARIF. SARIF plugs straight into your CI (GitHub, DefectDojo…).

Can I scan an authenticated app?

Yes. Via cookie, header, Bearer token, automatic login, or by pasting a “Copy as cURL” from your DevTools. The session is monitored and auto-reconnected.

A plan speaks to you?

Or let us advise you. Reply within 24 business hours.

Ready to scan without a shadow of doubt? Request an audit