€500 per audit.
Flat pricing. No subscriptions, no seat counts, no surprise overage. Buy a single audit, or talk to us about continuous scanning.
Single audit
One full AppCheck run against one domain. Scorecard, prioritized fix list, and an FPSEC certificate valid for 360 days — with 2 free rescans and re-issued certificates within 3 months of delivery.
- Full coverage across 10 areas (120+ checks)
- External AppCheck + optional authenticated mode
- Detailed fix list mapped to standards
- FPSEC certificate valid for 360 days
- 2 free rescans & re-issued certificates within 3 months
- PDF export for SOC 2 evidence
Continuous
For teams that want AppCheck on a schedule — daily, weekly, or every release — with alerts, history, and on-prem options.
- Scheduled AppCheck runs (daily / weekly / per release)
- Webhook + email + Slack alerts on regressions
- Score history with delta tracking
- Quarterly rescans & certificates included by default
- On-prem scanner option
- Dedicated security team contact
Every audit includes the full matrix.
No tiered feature gates. Single audits and continuous engagements all run the same 120+ checks.
- All 10 coverage areas — TLS, headers, cookies, auth, exposed endpoints, OWASP Top 10, dependencies, DNS, API, source-code review
- End-to-end audit by our security team with AI-native automation in support
- Dependency CVE scan across JavaScript, Python, JVM, Go, Ruby, and Rust stacks
- Authenticated mode with read-only test user credentials
- Detailed fix list mapped to OWASP / CVSS / RFC references
- FPSEC certificate valid for 360 days with tamper-evident public URL
- 2 free rescans and re-issued certificates within 3 months of delivery
- PDF export for SOC 2, ISO 27001, or vendor security reviews
Pricing questions, answered.
Is the price really flat at €500?
Yes. One AppCheck against one domain is €500, full stop. Continuous engagements are quoted based on scan volume.
What counts as one audit?
One domain plus its primary subdomains in scope (e.g. app.example.com and api.example.com together count as one). Separate products or environments are separate audits.
How long is the certificate valid?
Each certificate is valid for 360 days from issue. After that, you can order a fresh audit at the same flat price.
How many free rescans do I get?
Every audit includes 2 free rescans (with a fresh certificate) within 3 months of the original delivery. Rescans beyond that — or after the 3-month window — are billed at the standard audit rate.
Can I expense this?
Yes. We send a proper invoice with VAT details, and Enterprise / Continuous customers get a DPA on request.
What if my audit needs custom checks?
Custom checks for proprietary APIs or internal standards are available on Continuous engagements. Single audits use the standard 120+ check matrix.
Ready when you are.
Send us the URL, app access, and (if you can) your source. We confirm scope the same day and deliver the score + certificate in days, not weeks.