Every pentest runs in its own sandbox, its network and credentials scoped to that run alone.
Verified targets only
Vulnix only tests domains you've proven you own, by DNS record or through Cloudflare or Vercel.
Encrypted credentials
Test accounts, custom headers and DNS tokens are encrypted at rest and decrypted only inside the run.
Scoped GitHub access
The GitHub App only sees the repositories you choose to track, never your whole account.
Audited staff access
Staff sign in with mandatory two-factor authentication, and every staff action is logged.
FAQ
How do I pick the right plan?
Start with the free trial to see a real pentest on your own scope. Starter ($99/month, 500 credits) suits a team running its first regular pentests, with whitebox testing, scheduled runs and full finding detail. Pro ($299/month, 2,000 credits) is the same product with four times the credits, for teams testing every release. Enterprise is a custom credit allotment and price with dedicated onboarding.
How do credits work?
Every action has a flat price in credits, charged once when it starts: 25 for a quick blackbox pentest, 100 for a deep one, 150 for a whitebox pentest (225 when it also attacks a verified live target) and 15 for a PR review. Chat with the agent is the one exception, billed by the tokens it uses. You always know the cost before you start.
What does the free trial include?
Every new organization gets 25 credits for 14 days, no card required - enough for one quick blackbox pentest or one PR review. High and critical findings, their agent trace and their reports show as a preview on the trial. Whitebox pentesting, scheduled pentests, fix pull requests and chat need a paid plan.
Do unused credits roll over?
Monthly plan credits reset to your plan's full allotment at each renewal; they don't accumulate. The one exception is the first paid month, when whatever is left of your trial carries over on top. Credits you buy as a top-up never expire, and are only spent once your monthly credits run out.
Can I buy more credits?
Yes. Any organization on an active Starter, Pro or Enterprise plan can buy a top-up from its billing settings. Top-up credits never expire.
What happens to my credits if a pentest fails?
If a pentest can't complete, the credits it was charged are refunded to your balance automatically.
Can I change my plan?
You can upgrade from Starter to Pro at any time from your billing settings; it takes effect immediately, starting a new billing cycle at the new plan's price with its full credit allotment. Enterprise plans are set up with the Vulnix team.
Are the API and webhooks included?
Yes, on every plan, including the trial. The REST API uses scoped personal and service tokens, and signed webhooks can notify up to 10 endpoints about runs, PR reviews, findings and domains. A pentest started through the API costs the same credits as one started in the app.
What's the difference between blackbox and whitebox pentesting?
Blackbox pentesting tests your live domains, applications, APIs and public IP ranges from the outside, the way an external attacker would, with no access to your code. Whitebox pentesting connects to your repository so the agent tests with full visibility into your codebase, and can attack a verified live target at the same time.
Is it safe to point Vulnix at my systems?
Vulnix only tests domains you've proven you own, by DNS record or through Cloudflare or Vercel. Every run executes in its own isolated sandbox, test credentials are encrypted and only decrypted inside that run, and you control excluded paths, request rate limits and testing windows.