Pricing built around how often you ship.

Use Hector for a single risky feature, one urgent release, recurring release coverage, or a continuous black-box testing program across your application portfolio.

Baseline promise

Included in every
Hector testing offer.

These are Hector's standard promises, not tier differentiators. The plans below change scope, cadence, depth, reporting use, and review priority.

  1. 01Black-box testing of the running application
  2. 02Vulnerability workers for approved scope
  3. 03Findings memo or downloadable report
  4. 04No source-code access required
  5. 05Evidence-backed findings
  6. 06Retest path after remediation
  7. 07Autonomous crawl and attack-path analysis
  8. 08Reproduction steps for every confirmed finding

Plans

Choose the buying motion that
matches your release rhythm.

SmallOne-time | Scoped to app
$2,500

Your launch check. For MVPs, early SaaS, and marketing-plus-light-app builds shipping their first real security evidence or clearing that first vendor questionnaire.

Features

  • Free crawl + attack-surface map
  • Free teaser finding
  • All 8 vulnerability agents
  • Verification pass
  • Audit-grade report + reproduction steps
  • Guaranteed results
  • Results in a few hours
  • Credits toward continuous testing
Best for≤ 75 endpoints1 role (or unauthenticated)
Get started
EnterpriseCustom | Scoped to platform
Custom
Starting from $9,000

Your continuous program. For large platforms, complex RBAC, and multi-tenant systems where the attack surface is big, the stakes are high, and “good enough” isn’t. Quoted to your real surface, measured, not guessed.

Features

  • Everything in the Medium Plan
  • Maximum agent depth & parallelism
  • Opus 4.8 on hard targets, with adaptive reasoning
  • Human triage review of every confirmed finding
  • Value-based scoping
  • Turnaround in 1–2 business days
  • One free re-test within 30 days
  • Results guarantee + a path to continuous coverage
Customizable to your needs
Get started

Scope factors

What changes the
assessment scope?

Hector pricing starts with a simple buying motion, then adjusts when the application requires deeper black-box coverage.

Number of applications or APIs
Number of user roles and privilege levels
Report audience: internal, customer, audit, or leadership
Number of reachable endpoints
Business logic depth
Retest volume after remediation
Number of authenticated areas
Required testing window
Review depth required from Hector's security team

Use cases

From release pressure to reviewed findings.

  1. 01

    Choose the buying motion

    Pick one feature test, one urgent assessment, recurring release coverage, or a continuous program.

  2. 02

    Confirm target and scope

    Define the application, credentials, user roles, allowed windows, and safety constraints.

  3. 03

    Run the assessment

    Hector crawls, analyzes, and runs autonomous workers against the approved black-box scope.

  4. 04

    Review and retest

    Hector reviews reported vulnerabilities, delivers the report, and validates remediation through the retest path.

FAQ

Got any questions?

Everything you need to know about Hector.

  • Because scope, not features, drives the real cost of testing. Every plan runs all 8 vulnerability agents and ships an audit-grade report. The tiers change how much surface we cover, how deep the agents go, how fast you get results, and how much human review sits on top.