---
title: Heist pricing
description: Pricing, features, and route limits for Heist continuous penetration testing.
canonical: https://heist.security/pricing
last-updated: 2026-08-22
currency: EUR
---

# Heist pricing

## Standard

- **Price:** €350 per month
- **Included scope:** Up to 200 web application and API routes
- **Additional routes:** €1.50 per route per month
- **Test frequency:** Every included route is tested at least once every month
- **Retesting:** Free and unlimited

### Included

- Continuous outside-in penetration testing against OWASP ASVS 5.0
- Extra pressure testing of high-risk assets
- Automated workflow integrations
- MCP access for authenticated customer workspaces
- A dedicated security expert at no additional cost
- Current reports and an audit trail of tests and outcomes

## How routes are counted

Web application and API routes are counted separately, so `/users` and `/api/users` count as two routes. Multiple HTTP methods on the same API URL pattern count as one route. Running exploration is free. Customers choose which applications to include and receive a price overview before testing starts.

## Notes

- Heist only tests systems that the customer is authorized to test.
- Source-code access is not required.
- Some regulated organizations may still require separate human-led or threat-led testing.
- For a tailored scope or procurement question, [contact Heist](https://heist.security/contact).
- To begin onboarding, use the Get started action on the [Heist homepage](https://heist.security/).
