Home / Pricing
How pricing works
We publish one price and the structure behind it, rather than a full price list. Packages depend on how many assets you have and which modules you select, so a complete list would either be wrong or so hedged it told you nothing.
The base package
Surface and Perimeter. Surface finds everything you expose and keeps the register current; Perimeter tests what is reachable on it without credentials, including the long jobs a one-week engagement never gets to finish.
12-month term, billed annually in advance. AUD, excluding GST. That works out to around $833 a month, though billing is annual rather than monthly.
What arrives each month
- Validated findings, each reproduced or confirmed by a consultant
- A written monthly report, including what changed since the last one
- Critical and high findings notified within one business day of validation
- Verification of fixes you have applied
- Portal access for your team throughout
- A review call once a quarter
The module is bounded by those deliverables rather than by a published number of hours, so the conversation stays on findings rather than timesheets. Fair use is set out in the service agreement.
What drives the price of everything else
Two factors.
How many assets are in scope. A hundred external hosts is not the same job as a hundred web applications, and neither is the same as a hundred API endpoints behind authentication. Because asset counts are not interchangeable, published bands would be misleading.
Which modules you select. The base package is unauthenticated, which is why it can be priced up front. Anything authenticated sits outside it: Network for services, Access for applications and APIs. Authenticated work costs more because it takes longer and needs more consultant judgement, and how much depends entirely on your role model and how much logic sits behind the login.
Every module other than the base package is quoted on your scope, once we understand what is in it. Final pricing is confirmed in a written proposal.
How a package is put together
Surface and Perimeter are mandatory, and they work as a pair: Surface establishes what exists, Perimeter tests what is reachable on it. We cannot test an application we have not discovered, and an unverified asset register is where missed exposure tends to hide.
The other five modules are optional and independent. Add Identity without Cloud, or People without Access, if that matches your risk. Add one later and remove it at the end of a term.
Terms are the same across all of it: a 12-month term, billed annually in advance, all figures in AUD and excluding GST, final pricing confirmed in a written proposal.
Why it costs what it does
The base package is priced against the thing it replaces. A single one-off external penetration test costs about the same amount, once.
| Measure | Annual external penetration test | Continuous — base package |
|---|---|---|
| Testing days per year | About 5 | 365 |
| Time to learn about a new exposure | Up to 12 months | 1 business day |
| Covers assets deployed after testing began | No | Yes |
| Report accuracy | Accurate on the day it was issued | Current |
| Tasks that take weeks to finish, such as password spraying and content discovery | Rarely completed inside a one-week test | Run to completion |
| Cost | About $10,000 a year | About $10,000 a year |
A penetration test tells you what was true in March. This tells you what’s true today.
Continuous, not unlimited
One thing worth clarifying: this price buys continuous coverage within a defined asset scope, with the monthly deliverables listed above. It is continuous rather than unlimited.
If your scope grows, the price changes, and we raise that with you in advance. A deep two-week engagement on a single application is a separate piece of work, scoped and quoted on its own.