Pricing

Pay for proof, not noise. Every on-demand plan is backed by our guarantee — no high or critical finding, you don't pay.

Xora On-Demand
On-Demand Autonomous Pentest
Xora Continuous
Automated Continuous Pentesting at Scale
Standard Pentest
$4,000
per assessment

Time-boxed, fixed-scope exploit validation for a single application and its primary APIs. Best for lightweight apps with a modest set of CRUD resources, simple workflows, and low integration complexity.


Output
Compliance-ready report — SOC 2, ISO 27001, HIPAA, GDPR & 40+ frameworks
Depth of Test
One application, one set of APIs — depth of a 2-week manual penetration test
  • Detailed proof-of-concept exploits
  • Real-world attack simulation
  • Blackbox, Whitebox, or Greybox testing
  • End-to-end application scanning
  • Enterprise-grade accuracy
  • Auditor-accepted reports
  • Actionable remediation guidance
  • Autofix findings
  • Free, instant re-testing with automated verification
  • Same-day results
  • Deploy on-demand
  • Role-based access testing
  • Frictionless auth testing (2FA, Magic Link, Email)
Start test ›
No High or Critical Finding = Don't Pay
✦ Most popular
Rightsized Pentest
$960 – $30,000+
scoped to your application (how we calculate)

Priced to match your app. Xora analyzes your repos, endpoints, and roles, then sets the right scope automatically. Best for platforms with multiple modules, integrations, and multi-step workflows.


Output
Compliance-ready report — SOC 2, ISO 27001, HIPAA, GDPR & 40+ frameworks
Depth of Test
Coverage scales with your application — depth of a 4-week manual penetration test
  • Everything in Standard, plus:
  • Scope set automatically from your repos
  • Multi-service & multi-repo applications
  • Deeper coverage for complex applications
  • Ideal for complex or large platforms
Start test ›
No High or Critical Finding = Don't Pay
Continuous Testing
Custom
tailored to your org

Ongoing offensive security that tests every release automatically. New code ships, new tests run. Best for organizations running continuous delivery at scale.


Output
Continuous reports & real-time findings, plus continuous security hardening
Scope
Always-on, scales with your releases
  • Everything in Rightsized, plus:
  • Pentest on every deploy
  • Continuous offensive coverage
  • Broker support for internal applications
  • Early access to new vulnerability coverage
  • Enterprise SLA & support
  • Training & onboarding
  • Dedicated success manager
Request a Quote ›