Human-readable pricing
Always-on pentesting with pricing you understand.
Standard
Always-on pentesting covering 200 endpoints and web app routes.
- Every endpoint and route tested every month
- Extra pressure testing of high-risk assets
- Automated workflow integrations
- MCP access
- Dedicated security expert at no additional cost
- Unlimited retesting
Scale
Predictable price scaling, same rigorous security services.
- Security checksOWASP ASVS 5.0 · 17 categories
- Encoding and Sanitization
- Validation and Business LogicPartial coverage
- Web Frontend Security
- API and Web Service
- File Handling
- Authentication
- Session Management
- Authorization
- Self-contained Tokens
- OAuth and OIDCComing soon
- Cryptography
- Secure Communication
- ConfigurationComing soon
- Data Protection
- Secure Coding and Architecture
- Security Logging and Error Handling
- WebRTCComing soon
- Integrations
- Ticketing
- Two way sync of vulnerabilities
- Severity thresholds
- Automatic retesting of closed issues
- Codebase access
- Find routes and endpoints not accessible from the web app
- Communication
- Set alerts for findings above severity threshold
- MCP
- Manage and control Heist
- Hand issues to your code agents
- Support
- Dedicated support in Slack, at no additional cost
Frequently asked questions
What do we need to get started with Heist?
To get started, all you need is a target and a set of credentials. Heist can test web applications and APIs. You will be asked to verify your domains during onboarding.
Can Heist safely test our production environment?
For most companies, yes. Heist needs a dedicated workspace that does not contain or affect real customer data. Where this is not possible in production, most companies can run Heist in staging or testing environments.
Two examples of unsafe production environments:
- An internal company admin dashboard with a shared workspace for all employees.
- Marketplace and social applications where users post and interact with other users' content in public.
If you are unsure, start in a testing environment.
How can we identify and control Heist's traffic?
- IP address
34.88.253.84- Header
X-Heist-Agent: heist/1.0- Region
Finland (europe-north1)
Use the IP address or header to identify Heist in your logs and allow its traffic through your firewall or WAF. We can also set a requests-per-second limit for your workspace to match your infrastructure.
How is pricing calculated? What do you mean by routes?
The Standard plan includes 200 routes for €350 per month. Each additional route costs €1.50.
Web app and API routes are counted separately, so /users and /api/users count as two routes. Multiple HTTP methods on the same API URL pattern count as one route. Running exploration is free.
You choose which apps to include and get a price overview before testing starts. Most of our customers fit within the base plan.
How often does Heist test our app?
Heist runs continuously, keeps the scope up to date as your application changes, and ensures that every route is tested at least once every month. Retesting is free and unlimited, and issues closed in your ticket system can be retested automatically through our integrations.
Can Heist replace our annual pentest?
For most companies, yes. Some regulated organizations still require human led or threat led testing, such as TIBER-EU testing under DORA. For them, Heist is a strong complement that provides continuous testing between those assessments. Heist can also provide human attestation when you need it.
How does Heist avoid false positives?
Heist tests your running application instead of judging source code in isolation. OWASP ASVS guides what we test, and a separate verification system reproduces findings before they are reported. Each run adds application context that deepens future coverage. To avoid incentives to generate noise, we do not guarantee findings of a certain severity.
Can we use Heist reports for SOC 2 or ISO 27001 audits?
Customers have used Heist reports for SOC 2 audits. Every endpoint is tested against the recognized OWASP ASVS 5.0 framework, with an audit trail that records every test, network event, and outcome. Heist can provide human attestation if needed.
How does Heist handle customer data?
Heist uses the access you provide to test your application. If you add Heist to a workspace containing customer data, Heist will be exposed to customer data. We process data in the EU, while some model inference may be processed globally. We only use models with zero data retention policies. Our data processing agreement explains how we handle personal data and which service providers we use.