Security coverage
without the enterprise bill.
Startups shouldn't need five tools or a $25k contract to know whether their PRs and live app are exposed. Start free, upgrade when you ship.
PR review coverage for solo developers. No live battletests, strictly dev-time security.
- 15 advanced PR reviews/hour
- Up to 300 advanced reviews/month
- No live battletests
- Basic fallback when limit hit
- Full historical findings memory
PR review + live prod defence. Covers your code and your running infrastructure.
- 30 advanced PR reviews/hour
- On-demand live battletests · unlimited targets
- Up to 30 battletests/month (4-hour cooldown)
- Emergency $49 on-demand battletest
- Cross-PR open-finding tracking
Continuous posture across multiple environments. The full security infrastructure layer.
- 50 advanced PR reviews/hour
- Automated schedules, 3 concurrent · unlimited targets
- Up to 45 battletests/month (2-hour cooldown)
- +$50/mo per extra schedule
- Knowledge-graph pattern matching
Multi-org billing, on-prem deployment, custom compliance reporting, and dedicated SLAs.
- Unlimited battletests, schedules & targets
- Multi-organisation billing orchestration
- Self-hosted / on-prem deployment
- SOC 2 / ISO 27001 evidence packages
- Dedicated SLA and onboarding
- SSO / SAML
Estimate your monthly cost
One run = one battletest, whatever its depth. Targets are unlimited.
Automated recurring battletests require Observability.
Sizes peak PR-review load (~15/hour at busy times)
One flat price.
Not five tools, not per-seat, not a pentest invoice.
| Product | Category | Price |
|---|---|---|
| BattleTest Startup | PR review + pentesting | $60/mo |
| CodeRabbit Pro | PR review (code quality + security) | $24–30/dev/mo |
| Snyk Team | Dependency + SAST scanning | $25/dev/mo (min 5 devs) |
| TurboPentest | Per-test pentesting | $99/domain per test |
| Equixly | Autonomous API pentesting | €4,999/test |
| Aikido Security | AppSec scanning + automated pentesting | $350–8,000/mo flat |
| NodeZero | Autonomous pentesting | $25,000–42,500/year |
| HackerOne + HAI | Bug bounty platform + AI triage | Enterprise (custom) |
| Penligent Pro | AI-assisted penetration testing | $39.92/mo (manual, no CI/CD) |
Common questions
Do I need a credit card to start?
No. The Free plan requires no payment info. Upgrade when you're ready.
What counts as a battletest?
One run against one verified target is one battletest, whatever depth you choose (Discover, Probe, or Full Exploit) and however much attack surface it covers. You're billed per run, not per target: registering and DNS-verifying domains is free and unlimited. Run battletests on demand (Startup and up) or automatically on a schedule (Observability and up).
What happens when I hit the PR review limit?
Nothing is billed. You choose in Settings: queue (PRs wait for the rolling hour to reset, just like a CI runner) or fallback (immediate basic scan that catches secrets and CVEs). No surprise invoices, ever.
What's the on-demand battletest?
Startup and Observability users can trigger an out-of-band battletest at any time for $49. It funds one immediate run, skipping whatever's blocking it: the standard cooldown timer or a reached monthly battletest limit. Useful when you've just deployed an emergency hotfix and need an immediate green light before going to sleep.
Can I cancel anytime?
Yes. Monthly plans cancel end-of-period with no penalty. Annual plans follow our refund policy.
Do you offer a refund?
Yes. Your first paid monthly or annual subscription has a 14-day money-back guarantee. See our Refund Policy for eligibility and statutory rights.
What's the difference between basic and advanced reviews?
Basic reviews are fast single-pass scans, great for secrets, CVEs, and common issues. Advanced reviews run a multi-turn agentic loop across your full codebase with a verifier pass on critical findings. Free plan gets advanced on public repos (5/hr) and 10 advanced reviews per month on private repos; all paid plans get advanced on everything with no monthly cap.
When does Enterprise make sense?
Enterprise is for teams that need multi-organisation billing orchestration, self-hosted or on-prem deployment, or custom SOC 2 / ISO 27001 compliance reporting. Standard teams should stay on the self-serve tiers as long as possible, we deliberately keep the self-serve ceiling high.
Not ready to pay?
Start free.
No credit card. No expiry. Advanced reviews on public repos, basic reviews plus 10 advanced per month on private repos.
Get started free →- Public repos: 5 advanced + 5 basic reviews/hour
- Private repos: 5 basic reviews/hour + 10 advanced reviews/month
- Secrets and CVE detection
- No credit card · no time limit
Ship fast.
Don't get breached.
Start with the free plan. Zero credit card, zero config files. Your next PR could be the one that catches the issue that would've cost you everything.