Pricing built around how often you ship.

Use Hector for a single risky feature, one urgent release, recurring release coverage, or a continuous black-box testing program across your application portfolio.

Baseline promise

Included in every
Hector testing offer.

These are Hector's standard promises, not tier differentiators. The plans below change scope, cadence, depth, reporting use, and review priority.

  1. 01Black-box testing of the running application
  2. 02Vulnerability workers for approved scope
  3. 03Findings memo or downloadable report
  4. 04No source-code access required
  5. 05Evidence-backed findings
  6. 06Retest path after remediation
  7. 07Autonomous crawl and attack-path analysis
  8. 08Reproduction steps for every confirmed finding

Plans

Choose the buying motion that
matches your release rhythm.

SmallOne-time · scoped to app or API
$3,500
 

Your launch check. Focused autonomous black-box testing for a small web application, API-only service, or MVP.

Features

  • Autonomous black-box testing
  • Web, API, or API-only targets
  • Complex login flows supported
  • Up to two supplied roles
  • Independent automated validation
  • Vulnerability chaining within scope
  • Engineering report and reproduction steps
  • One fix-verification round
  • Zero-data-retention models
  • Report within 5 business days
Best forSmall app or API · one environment · up to two roles
Get started
MediumOne-time · scoped to app or API
$9,000
 

Your deep release assessment. Parallel agents perform deep black-box testing across a broader surface and chain weaknesses into proven attack paths.

Features

  • Everything in Small
  • Deep autonomous black-box testing
  • Deeper agent runtime
  • Coordinated parallel testing
  • Multi-role and tenant-boundary testing
  • Multi-step vulnerability chains
  • Named expert report review
  • Executive summary and findings readout
  • Zero-data-retention models
  • Report within 3 business days
Best forComplex product · broad API · multiple roles or tenants
Get started
EnterpriseContact Us
Custom
Starting from $9,000

Your continuous program. Reserved capacity for recurring black-box testing across external and authorized internal applications and APIs.

Features

  • Recurring autonomous black-box testing
  • Deep baseline and recurring assessments
  • Reserved depth and parallel capacity
  • Cross-application attack chains
  • External and internal app/API testing
  • Human review of customer-facing results
  • Fix verification after each assessment
  • Custom supported LLM regions
  • Zero-data-retention models
  • Contracted report-delivery SLA
Customized to your platformApplications · regions · release cadence · private access
Get started

Every plan uses an autonomous black-box testing approach and supports web applications, web-and-API products, API-only services, and complex 2FA login workflows. Every confirmed finding discovered inside the agreed scope is included with reproducible evidence and remediation guidance. Assessment processing uses models operating under zero-data-retention terms.

Report clocks begin after scope, required payment, working access, written authorization, and pre-flight checks are complete. Enterprise delivery targets are defined in the order form according to scope, private connectivity, geographic deployment, and reserved parallel capacity.

Scope factors

What changes the
assessment scope?

Hector pricing starts with a simple buying motion, then adjusts when the application requires deeper black-box coverage.

Number of applications or APIs
Number of user roles and privilege levels
Report audience: internal, customer, audit, or leadership
Number of reachable endpoints
Business logic depth
Retest volume after remediation
Number of authenticated areas
Required testing window
Review depth required from Hector's security team

Use cases

From release pressure to reviewed findings.

  1. 01

    Choose the buying motion

    Pick one feature test, one urgent assessment, recurring release coverage, or a continuous program.

  2. 02

    Confirm target and scope

    Define the application, credentials, user roles, allowed windows, and safety constraints.

  3. 03

    Run the assessment

    Hector crawls, analyzes, and runs autonomous workers against the approved black-box scope.

  4. 04

    Review and retest

    Hector reviews reported vulnerabilities, delivers the report, and validates remediation through the retest path.

FAQ

Got any questions?

Everything you need to know about Hector.