Skip to content

Penetration testing packages: pricing and frequency.

Choose by rate of change and attack surface. Every package combines automated external testing with my professional assessment and time for your operations team. We agree the specific testing scope before starting.

Packages & pricing

#2 VDP Researcher · HackerOne · Germany · Q1/2026 · See public security research

Turn findings into better security practices.

I do more than deliver a report. Working with operations and development, I help establish clear ownership, priorities and workflows for remediation and retesting.

We build on your existing tickets, release processes and team routines, so each finding reaches the right team and is tracked through to verified remediation.

Planning recurring security assessments

Three cadences. One accountable specialist.

You receive actionable evidence, knowledge transfer and support in establishing security workflows. Scope and cadence are agreed around your systems and teams.

Monthly

Regular price: €1,999 Promotional price: €1,399

per month, excl. VAT

Monthly testing and a comprehensive findings update.

For stable applications with limited changes. A practical starting point when your external attack surface changes infrequently.

Includes expert assessment, a prioritized report and collaboration with your teams on remediation, security workflows and knowledge transfer.

Weekly

Regular price: €5,999 Promotional price: €4,199

per month, excl. VAT

Weekly testing and an updated findings report.

For product teams shipping regular releases, new APIs and ongoing changes to internet-facing systems.

Includes expert assessment, a prioritized report and collaboration with your teams on remediation, security workflows and knowledge transfer.

Daily

Regular price: from €9,999 Promotional price: from €6,999

per month, excl. VAT

Daily testing and an updated findings report.

For high-output startups, enterprises with multiple teams and critical infrastructure operators where frequent changes or critical exposure justify daily testing. With infrequent changes, monthly or weekly is usually enough.

Includes expert assessment, a prioritized report and collaboration with your teams on remediation, security workflows and knowledge transfer.

Prices apply to the jointly agreed scope. Systems, methods, testing windows and communication channels are defined before work starts. The cadence describes the agreed testing and report updates.

What is inside your hardware?

Custom reverse engineering for commercial routers, appliances and other devices you use. We investigate firmware and interfaces for previously unknown vulnerabilities (zero-days).

From device to vendor

Within an agreed, authorized scope, we analyze the device, document substantiated findings and coordinate reporting to the vendor: on your behalf or through your existing support program. Finding a vulnerability is not guaranteed.

Pricing on request

The device, firmware, complexity and research objectives determine the effort. Depending on the engagement, we may need a test device, a loan unit or an isolated test environment. Provisioning and any additional costs are agreed before work begins.

From attack surface to retest.

Automation makes recurring testing practical. My role is to define the scope, assess results professionally and help your team take the next steps.

01 · Agree scope

Agree authorized systems, access, methods and testing windows together.

02 · Test & assess

The agent framework supports testing. I review results for reproducibility and relevance.

03 · Work with operations

Evidence and priorities in the report. Establish ownership, handoffs and workflows for remediation and retesting together.

04 · Retest changes

Retest remediated findings within the agreed scope and update their status.

Agents backed by experience.

I combine security research with platform engineering and operational experience. That helps identify which vulnerabilities matter and which remediation works in your architecture.

Professional accountability

An agent framework I built, public security research and personal assessment underpin the service. You speak directly with the engineer handling your engagement.

Specialist cyber models at work

I use specialist cyber models available to me for my professional security work under their applicable access conditions. You receive the pentest service, reports and collaboration with me. Customers receive no access to models, accounts, APIs or model weights.

Planning recurring security assessments

Knowledge that stays with your organization.

Using concrete findings, I explain root causes, mitigations and testing criteria. Your teams learn to recognize similar risks earlier and make informed security decisions in their daily work.

The conversation extends beyond operations. We involve development and other responsible teams, document what they learn and improve how they work together. The goal is stronger security practices across the organization, not just the next closed finding.

Security and implementation experience together.

If your needs extend beyond external pentests, explore the other areas of my work.

Questions about cost and scope

How much does recurring penetration testing cost?

Regular monthly fees are €1,999 for monthly testing, €5,999 for weekly testing and from €9,999 for daily testing, excluding VAT. Expert review and time with your operations team are included. We agree the specific scope before starting. The introductory price shown on this page applies to the first ten clients for their agreed contract term.

What determines the testing scope?

The authorized websites, APIs and internet-facing services, their complexity, available test access and operational constraints determine scope. The proposal records the systems and coverage. Custom reverse engineering is quoted separately based on the device, complexity and required test hardware.

Is monthly testing enough?

For stable applications with limited changes, monthly testing is often a practical start. Weekly testing suits regular releases. We recommend daily testing for high code output, multiple teams or critical external exposure, rather than for every business by default.

How is this different from an automated vulnerability scanner?

You receive more than an unreviewed list of potential findings. I define scope, assess results personally and help your team prioritize fixes and establish lasting security workflows. We operate the agent framework and models ourselves; clients receive no access to those models.

Security inquiry

Request a non-binding quote for a pentest package or custom reverse engineering. The first ten customers receive 30% off for the entire contract term, for both services. Availability and terms are confirmed in your quote.

Do not send passwords, credentials, confidential vulnerability details or firmware files. We will agree secure exchange and testing authorization personally.

Privacy notice

This is not a purchase or a discount-slot reservation. After submitting, please confirm your email address.