Pricing

Pricing for autonomous penetration testing.

Start free with a full demo scan and sample report. Paid plans add live targets, more credits, mobile and cloud coverage, and compliance reporting. Enterprise is unlimited and custom.

06 · Engagement

Choose your
arsenal.

Scale your offensive security capabilities with plans designed for hackers, red teams, and enterprises. 14-day free trial · no credit card required.

Free
Free

Explore the product with a full demo scan and a sample report.


  • Explore the full dashboard
  • Interactive demo pentest
  • Reports · Penetration Test (sample)
  • Upgrade to Lite for live scanning
Choose Free
Lite
$99/ month

200 credits · live scanning for one program — a domain, IP range, or repo.


  • 200 monthly credits
  • 1 live target · Web · IP range · Repository
  • 1 concurrent scan · Quick + Standard modes
  • Fast AI models · DeepSeek · Qwen · Gemma
  • Reports · Penetration Test · OWASP Top 10 · Bug Bounty
  • Email support
Choose Lite
Hacker★ Recommended
$999/ month

3,000 credits · for individual security researchers and bug bounty hunters.


  • 3,000 monthly credits
  • 5 targets · 3 concurrent scans
  • Web + Mobile scanning · all modes (Aggressive · Thorough)
  • Premium AI models · Claude · GPT
  • Rotating residential proxies Soon
  • Compliance Reports
  • Secrets Vault · API keys · Integrations
  • Priority support · API access
Choose Hacker
Red TeamCOMING SOON
$1,999/ month

8,000 credits · for professional penetration testing teams and security consultants.


  • 8,000 monthly credits
  • 3 team seats · one shared credit balance
  • 5 concurrent scans
  • Web + Mobile + Cloud scanning · AWS · Azure · GCP
  • Uncensored AI models
  • Rotating residential proxies Soon
  • Extended Compliance Reports
  • Team management · seats · groups · roles
  • Premium support · Custom integrations
Coming soon
Enterprise
Custom

Unlimited credits · for organizations requiring comprehensive security coverage.


  • Unlimited credits
  • Unlimited concurrent scans
  • All scan types
  • Custom team seats & role management
  • Company branding · white-label reports
  • SSO · Audit logs
  • Client management
  • Dedicated support · SLA guarantees
  • On-premise option
Contact Sales
All plans include: 24/7 monitoring · automatic updates · encrypted data storage · cancel anytime.Compare all features ↗
07 · FAQ

Anticipated
objections.

Most of these come up in the first meeting. Resolving them here saves us both time.

Yes. Every exploit candidate is rerun against a sandbox replica of your environment before validation. Production-touching probes are rate-limited and tagged. You can also restrict Cyrion to non-prod surfaces with a single policy flag.

Scanners check signatures. Cyrion reasons about your environment — chaining individually-low-severity findings into demonstrable, high-severity attack paths, then validating each one. The output is a reproducible exploit, not a CVE list.

It replaces the toil — the recon, the boilerplate exploitation, the report-writing. Your humans do the work agents can't: business-logic abuse, social engineering, novel exploitation. Most customers see their team shift to higher-leverage work within a quarter.

Cyrion's validation loop runs every candidate finding through a second, independent agent in a sandboxed replica. A finding only ships if it reproduces. Our public false-positive rate is 0% over the last 90 days, audited monthly.

By default, in your nearest Cyrion region (US-East, EU-West, AP-South). Enterprise customers can choose an on-premise deployment and run Cyrion inside their own environment.

Free, Lite and Hacker: sign up and start scanning the same day. Enterprise: onboarding is scoped with your security team, including a security review and SSO setup.

Not sure which plan fits?

Tell us what you need to test — web apps, APIs, mobile, cloud or LLM applications — and we will recommend a plan. Browse solutions →