---
title: Heist
description: Always-on penetration testing for companies with a high bar for security.
canonical: https://heist.security
last-updated: 2026-08-22
---

# Heist

> Always-on penetration testing for companies with a high bar for security.

Heist continuously tests live web applications and APIs from the outside in. It maps routes, endpoints, roles, and authentication flows, then tests every applicable endpoint against OWASP ASVS 5.0. Findings include reproducible evidence, remediation guidance, and a timestamped retest trail.

## When to use Heist

Use Heist when a software team needs pentesting to keep pace with frequent releases, current evidence for SOC 2 or ISO 27001, or a credible pentest report without granting source-code access. Heist is especially suited to startups and scaleups that ship often and sell to security-conscious customers.

## How Heist works

1. **Map:** Heist logs into the application and records every route, endpoint, role, tenant boundary, form, and authentication flow.
2. **Test:** Every applicable endpoint is checked methodically against OWASP ASVS 5.0, including authentication, authorization, cryptography, business logic, and API security.
3. **Prove:** A finding is reported only with a safe, reproducible exploit and the exact request and response.
4. **Fix and retest:** Findings can flow into Linear or Slack, and each fix is verified by replaying the original exploit.
5. **Report:** The pentest report and audit trail stay current as the application changes.

## Key facts

- Onboarding is self-serve and requires a target, dedicated credentials, and domain verification.
- Heist tests the running application; source-code access is not required.
- Testing follows roughly 350 requirements across 17 OWASP ASVS 5.0 categories.
- Pricing starts at €350 per month for up to 200 routes.
- Heist is built in Oslo, Norway, with infrastructure in Europe.

## Explore

- [Method](https://heist.security/method) — testing process and evidence
- [Pricing](https://heist.security/pricing) — plans and included checks
- [Machine-readable pricing](https://heist.security/pricing.md) — tiers, features, and route limits
- [Verify a badge](https://heist.security/verify) — what a Heist badge means
- [About](https://heist.security/about) — company and mission
- [Contact](https://heist.security/contact) — reach the Heist team
- [Agent instructions](https://heist.security/llms.txt) — detailed agent guidance
- [Sitemap](https://heist.security/sitemap.xml) — indexable pages
