Quote-confirmed. Scope-locked. No fine print.
Every engagement is anchored to a written authorization. Limits enforced at the database layer.
See exactly what you use.
Subscription tier, invoices, and plan management in one place — with live meters for SOC signals, SMS notifications, and AI tokens. Soft caps warn you; hard caps protect you.

Three plans. All quote-confirmed.
Custom and per-audit scoping available — every engagement is anchored to a written authorization.
7-day free trial on every plan · Card required · No charge for 7 days · Cancel anytime
Every commit gets an autonomous security pass — proven findings only, before code hits review or production.
Card required · No charge for 7 days · Cancel anytime
- 1 repository · runs on every push and pull request
- Covers web apps, APIs, backend services and Web3/DeFi math
- Working PoC attached to every finding (no theoretical alerts)
- Slack + GitHub PR annotations, ticket-ready
Scheduled staging-network exploit sweeps across binary, web, crypto and live-LLM.
Card required · No charge for 7 days · Cancel anytime
- Web2, Web3 and AI-agent surfaces
- Allowlisted staging targets
- Working exploit script per finding
- Realtime PoC logs
Firms license blind initial passes that auto-generate compiled, passing PoCs — now with Live SOC for real-time attack detection.
Card required · No charge for 7 days · Cancel anytime
- All surfaces · multi-engagement workspace
- AI narrative drafting
- Full audit trail of model calls
- Custom range integrations
- Live SOC: real-time SIEM/EDR ingest + MITRE-tagged incidents
- Recommend-and-defend playbooks · email / Slack / Teams / PagerDuty
Custom and per-audit scoping available. All plans are scope-locked to your written authorization.

Audit-grade pentests at a price designed to undercut the market.
One-off engagements priced $1 below the leading autonomous-pentest vendor — or bundled at no extra cost into any Range Assessment / Audit Co-Pilot contract over $2,000/month.
Pentests included on every contract over $2,000/month.
Annual contracts: pentests scheduled per release. Talk to sales for a custom cadence.
Comprehensive pentest for a single application.
Lightweight apps with few interconnected features, a modest set of CRUD resources, simple workflows, low integration complexity.
Equivalent depth of a 2-week manual penetration test.
- Compliance-ready report: SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, NIST CSF, NIS2, ISO 42001, TS 50701 + 40 more frameworks
- Audit-ready report within 5 business days
- Free re-test with automated verification after fix
- Frictionless authenticated testing (2FA, magic link, email)
- Detailed proof-of-concept exploits
- Actionable remediation guidance
- Black-box, white-box, or grey-box
- Every finding human-reviewed before it ships
Deeper coverage for more complex applications.
Apps or platforms with multiple modules, integrations, multi-step workflows, deeper access-control patterns and data models.
Equivalent depth of a 4-week manual penetration test.
- Everything in Single Target
- Authenticated multi-role testing across tenants
- Web2 + Web3 / smart-contract + AI-agent surface coverage
- IDOR, SSRF, deserialization, auth-bypass, prompt-injection, tool-abuse probes
- Realtime streaming of findings into your Console
- Vulnerability coverage map + reasoning trace per finding
- Request/response and endpoint-level trace detail
- Two free re-tests after fixes ship
Continuous coverage for organisations at scale.
Mature application portfolios — multi-module SaaS, admin tools, extensive resource relationships, regulated environments.
Continuous security hardening across every release.
- Everything in Full Surface
- Continuous offensive coverage — re-runs on every release
- Early access to new vulnerability coverage as we ship detections
- Multi-member access, shared assessment knowledge, human-directed operatives
- Single Sign-On (SSO) + API access for workflow integration
- Quarterly executive readout + framework-mapped board pack
- Dedicated detection-engineering channel for your stack
Prices are per application, per test. Re-tests after fix are free. Every finding is human-reviewed before it ships — we never push automated changes to your environment.
Single Target and Full Surface: submit scope, pay securely on the next step, work starts the same day.
Free for 7 days. Card required. Cancel anytime before day 8.
- Sign up with your company email and pick a plan. We collect a valid payment method up front, but nothing is charged for 7 days.
- Run the platform end-to-end — authorize a target, launch audits, review C4 findings, export framework-mapped reports. Limits enforced by your plan.
- On day 8 your card is charged the monthly plan fee and your subscription continues month-to-month at the published price.
- Cancel anytime from /billing → Manage (Stripe customer portal). Cancel before day 8 and you pay nothing.
Billing is handled by Stripe with full tax, fraud, and dispute handling. Bank statements show LINK.COM* SMERT.AI. See Terms and Privacy.
Stop chasing false positives.
Start shipping proof.
Bring us a repo, a commit, or an authorized staging target. We'll come back with compiled, passing exploits — or nothing at all.
Trial requires a card. No charge for 7 days. Cancel anytime.

