Human-readable pricing

Always-on pentesting with pricing you understand.

Standard

€350 /month

Always-on pentesting covering 200 endpoints and web app routes.

  • Every endpoint and route tested every month
  • Extra pressure testing of high-risk assets
  • Automated workflow integrations
  • MCP access
  • Dedicated security expert at no additional cost
  • Unlimited retesting
Get started

Scale

€1.50 /additional endpoint

Predictable price scaling, same rigorous security services.

  • Security checksOWASP ASVS 5.0 · 17 categories
  • Encoding and Sanitization
  • Validation and Business LogicPartial coverage
  • Web Frontend Security
  • API and Web Service
  • File Handling
  • Authentication
  • Session Management
  • Authorization
  • Self-contained Tokens
  • OAuth and OIDCComing soon
  • Cryptography
  • Secure Communication
  • ConfigurationComing soon
  • Data Protection
  • Secure Coding and Architecture
  • Security Logging and Error Handling
  • WebRTCComing soon
  • Integrations
  • TicketingAzure DevOpsLinearJira
  • Sync vulnerabilities to your backlog
  • Automatically trigger retests when issues are closed
  • Codebase accessBitbucketAzure DevOps Code
  • Find routes and endpoints not accessible from the web app
  • Cross-check source code with the running application to find and verify vulnerabilities
  • CommunicationSlack
  • Set alerts for findings above severity threshold
  • MCPClaudeCodexCursor
  • Manage and control Heist
  • Hand issues to your code agents
  • Support
  • Dedicated support in Slack, at no additional cost

Frequently asked questions

What do we need to get started with Heist?

To get started, all you need is a target and a set of credentials. Heist can test web applications and APIs. You will be asked to verify your domains during onboarding.

Codebase access is optional.

What type of pentesting does Heist do?

Heist performs grey-box testing, emulating an attacker with access to your platform but not your codebase. Granting Heist access to your codebase is optional and enables whitebox pentesting.

Testing whether one user can access features meant for a higher-privilege role or data from another workspace is included.

Can Heist safely test our production environment?

For most companies, yes. Heist agents do not receive unrestricted terminal access. They operate through purpose-built tools with guardrails that enforce the verified scope and restrict dangerous actions.

  • Credentials are scoped to the workspace you provide.
  • Exploitation is designed to prove impact without destructive actions or affecting real customer data.
  • Testing can be scheduled during off-hours, traffic can be rate-limited, and testing can be stopped with a kill switch.

Heist requires a dedicated workspace that does not contain or affect real customer data. If that is not possible in production, we recommend running Heist in a staging or testing environment.

How can we identify and control Heist's traffic?

IP address
34.88.253.84
Header
X-Heist-Agent: heist/1.0
Region
Finland (europe-north1)

Use the IP address or header to identify Heist in your logs and allow its traffic through your firewall or WAF. We can also set a requests-per-second limit for your workspace to match your infrastructure.

How is pricing calculated? What do you mean by routes?

The Standard plan includes 200 routes for €350 per month. Each additional route costs €1.50.

Web app and API routes are counted separately, so /users and /api/users count as two routes. Multiple HTTP methods on the same API URL pattern count as one route. Running exploration is free.

You choose which apps to include and get a price overview before testing starts.

Is there an annual commitment?

No. Heist is billed monthly by default, with no annual commitment. We want to prove our value every month.

Customers who prefer annual invoicing can still pay annually. If you leave early, you receive a partial refund for the unused months.

How often does Heist test our app?

Heist runs continuously, keeps the scope up to date as your application changes, and ensures that every route is tested at least once every month. Retesting is free and unlimited, and issues closed in your ticket system can be retested automatically through our integrations.

Can Heist replace our annual pentest?

For most companies, yes. Some regulated organizations still require human led or threat led testing, such as TIBER-EU testing under DORA. For them, Heist is a strong complement that provides continuous testing between those assessments. Heist can also provide human attestation when you need it.

How does Heist avoid false positives?

Heist tests your running application instead of judging source code in isolation. OWASP ASVS guides what we test, and a separate verification system reproduces findings before they are reported. Each run adds application context that deepens future coverage. To avoid incentives to generate noise, we do not guarantee findings of a certain severity.

Can we use Heist reports for SOC 2 or ISO 27001 audits?

Customers have used Heist reports for SOC 2 audits. Every endpoint is tested against the recognized OWASP ASVS 5.0 framework, with an audit trail that records every test, network event, and outcome. Heist can provide human attestation if needed.

How does Heist handle customer data?

Heist uses the access you provide to test your application. If you add Heist to a workspace containing customer data, Heist will be exposed to customer data. We process data in the EU, while some model inference may be processed globally. We only use models with zero data retention policies. See our data processing agreement and Terms of Service for details about how we handle customer data.

We use analytics cookies to understand what's useful and improve Heist. Choose what you're comfortable with. Cookie policy