Pricing
Plans that scale with your testing
1 deep pentest = 100 credits
1 whitebox pentest = 150 credits
1 PR review = 15 credits
Starter
For teams running their first real pentests.
$99 /mo$299
500 credits / month67% off
Includes:
- Blackbox pentesting
- Whitebox pentesting
- PR review on every pull request
- Full findings, agent trace & reports
- Email support
Start on StarterNo credit card required
Most popular
Pro
For teams shipping continuously and testing often.
$299 /mo$999
2,000 credits / month70% off
Everything in Starter, plus:
- 4x the monthly credit allotment (2,000 credits)
- Priority queue for pentest runs
- Priority support
Start on ProNo credit card required
Enterprise
For organizations with dedicated security requirements.
Talk to us
Custom credit allotment
Everything in Pro, plus:
- Custom credit allotment & pricing
- Dedicated onboarding
- SSO & audit-log export
Talk to UsCustom onboarding & SLA
Every plan includes a monthly credit allotment, spent at a flat, predictable price per action — never a surprise bill. A free trial starts the moment you sign up, no card required.
Frequently asked questions
What is Vulnix?
Vulnix is an agentic pentesting platform that continuously tests your attack surface, proves exploitable findings, and validates every fix — combining automated reconnaissance, exploitation, and reporting into one continuous workflow instead of a one-off annual pentest.
How does Vulnix pricing work?
Vulnix uses a monthly credit allotment billed at a flat, predictable price per action — never a surprise bill. Starter is $99/month with 500 credits, Pro is $299/month with 2,000 credits, and Enterprise offers a custom credit allotment and pricing.
How many credits does a pentest cost?
A deep pentest costs 100 credits, a whitebox pentest costs 150 credits, and a PR review costs 15 credits.
Is there a free trial?
Yes. A free trial starts the moment you sign up — no credit card required.
What's the difference between Blackbox and Whitebox pentesting on Vulnix?
Blackbox pentesting tests your live domains, applications, APIs, and public IP ranges from the outside, the way an external attacker would, with no access to your source code. Whitebox pentesting connects directly to your repository so Vulnix can test with full visibility into your codebase.
Can Vulnix test infrastructure or IP ranges, not just web apps?
Yes. Alongside web apps and APIs, a blackbox target can be a public IP address or CIDR range. Vulnix port- and service-scans the internet-facing hosts in that range, fingerprints exposed services, and checks them for known CVEs and misconfigurations. It tests external, internet-facing infrastructure only — it does not test internal/RFC-1918 networks or Active Directory.
Can I cancel or change plans anytime?
Starter and Pro are self-serve plans you subscribe to directly from your account after signing up, so you can manage or change your plan at any time. Enterprise plans are provisioned directly by the Vulnix team.