Pricing

Productized security assessments with AI speed and human validation.

Pentoma is priced per assessment because web pentesting, source-code review, and AI red teaming have different scopes, risks, and deliverables.

Three offensive-security products

Choose a product to see scope-tiered pricing.

Launch pricing is for early customers and is locked for the term of your engagement. Regular is the standard rate after the launch period. Tiers marked Custom scope are quoted to fit the actual application, codebase, or AI system surface.

Offensive runtime testing for web applications and APIs.

Pentoma Web Essential

$5,000 launch

$6,000 regular

One web app or API with limited roles

  • - AI-assisted web and API testing
  • - Human validation before confirmation
  • - Compliance-ready report
Request assessment

Pentoma Web Standard

$8,000 launch

$10,000 regular

Authenticated SaaS apps, APIs, and multiple roles

  • - Business-logic and authorization review
  • - Retest window for remediated findings
  • - Executive and engineering report
Request assessment

Pentoma Web Complex Scope

$15,000+

Custom scope

Complex SaaS, multi-tenant authorization, broad APIs

  • - Multi-role and admin workflow coverage
  • - Deep authorization and API testing
  • - Custom delivery timeline
Request assessment

Bundles

Bundle products when evidence needs to connect across runtime, source, and AI behavior.

Launch pricing is scoped by application size, repository count, roles, environments, and AI system complexity.

$12,000-$15,000 launch range

Web + Code Readiness

Runtime exploit evidence connected to source-level remediation.

$14,000-$18,000 launch range

Web + AI Readiness

Application and AI behavior coverage for AI-enabled SaaS products.

$20,000-$25,000 launch range

Full Pentoma Assessment

Pentoma Web, Pentoma Code, and Pentoma AI Red Teaming in one evidence package.

Every assessment

The price is tied to a deliverable, not seats.

Pentoma assessments include the coverage, validation, reporting, and evidence handoff needed for engineering and audit use.

AI-assisted coverage with deterministic and human validation
Reproducible evidence, remediation guidance, and severity rationale
Executive, engineering, and compliance-ready report views
SOC 2, ISO 27001, OWASP, and CWE mappings where applicable