Clear, transparent pricing trusted by 1000+ businesses
Offensive DAST vulnerability scanner that scans behind login for 10,000+ test cases like OWASP Top 10, ports, CVEs & more
$69/m
Here's how the target is defined
Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.
If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.
- 3 monthly vulnerability scans with 15,000+ tests (OWASP, SANS, CVEs)
- Run authenticated scans for full coverage
- 1 Integration (CI/CD, Slack, Jira etc.)
- AI powered conversational vulnerability fixing assistance
$199/m
Here's how the target is defined
Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.
If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.
- Unlimited vulnerability scans with 15,000+ tests (OWASP, SANS, CVEs)
- Run authenticated scans for full coverage
- Unlimited integrations
- AI-powered conversational vulnerability fixing assistance
- Four expert Vetted Scans to ensure zero false positives (on annual billing)
$499/m
- Unlimited vulnerability scans with 15,000+ tests (OWASP, SANS, CVEs)
- Run authenticated scans for full coverage
- AI-powered conversational vulnerability fixing assistance
- Flexibly change URLs from 5 target pool (30 day cooling period)
- Four expert Vetted Scans to ensure zero false positives
- Account Manager
$699/yr
Here's how the target is defined
Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.
If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.
- 3 monthly vulnerability scans with 15,000+ tests (OWASP, SANS, CVEs)
- Run authenticated scans for full coverage
- 1 Integration (CI/CD, Slack, Jira etc.)
- AI powered conversational vulnerability fixing assistance
$1999/yr
Here's how the target is defined
Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.
If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.
- Unlimited vulnerability scans with 15,000+ tests (OWASP, SANS, CVEs)
- Run authenticated scans for full coverage
- Unlimited integrations
- AI-powered conversational vulnerability fixing assistance
- Four expert Vetted Scans to ensure zero false positives (on annual billing)
- Compliance view for SOC2, ISO27001, PCI-DSS, HIPAA etc.
$4999/yr
- Unlimited vulnerability scans with 15,000+ tests (OWASP, SANS, CVEs)
- Run authenticated scans for full coverage
- AI-powered conversational vulnerability fixing assistance
- Flexibly change URLs from 5 target pool (30 day cooling period)
- Four expert Vetted Scans to ensure zero false positives
- Compliance view for SOC2, ISO27001, PCI-DSS, HIPAA etc.
- Account Manager
Compare plans & FIND the right one for you
Hacker-style pentest by Autonomous AI & certified experts at dev speed, built to meet & exceed
SOC2, ISO, & HIPAA requirement
One web or SaaS app counts as one target, including all APIs consumed.
Mobile is per platform, so an Android app and an iOS app are two targets
Networks, cloud, IPs and standalone APIs are 1 target each
$2999/yr
$199/mo
If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.
Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.
Click the 🛈 icon to know more.

One web or SaaS app counts as one target, including all APIs consumed.
Mobile is per platform, so an Android app and an iOS app are two targets
Networks, cloud, IPs and standalone APIs are 1 target each
$5999/yr

$9999/yr onwards

$999/yr
If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.
Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.
Know More
Weekly vulnerability scans with 3000+ tests (OWASP, SANS etc.)
Essential features like pentest dashboard, PDF reports and scan behind login
Continuously discover & scan every API in your infrastructure for broken access control, authorization flaws, OWASP Top 10 & more
$199/m
$199/mo
If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.
Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.
Click the 🛈 icon to know more.
- 20 API DAST scans/month with 15,000+ authenticated test cases
- CI/CD, JIRA and Slack integrations
- Auto re-scan of selective vulnerabilities after fixes
- Full and management PDF reports
$499/m
- 60 API DAST scans per month with 15,000+ authenticated test cases
- CI/CD, JIRA and Slack integrations
- Auto re-scan of selective vulnerabilities after fixes
- Full and management PDF, CSV & JSON reports
- Capture live API traffic via 10+ integrations (Kong, Postman, AWS, GCP, Azure, Nginx etc.)
- Continuous observability & auto-inventory (10M+ API requests/m)
- Detects orphan, shadow & zombie APIs to reduce exposure
Contact us
- 1000+ API DAST scans annually with 15,000+ authenticated test cases
- CI/CD, JIRA and Slack integrations
- Auto re-scan of selective vulnerabilities after fixes
- Full and management PDF, CSV & JSON reports
- Capture live API traffic via 10+ integrations (Kong, Postman, AWS, GCP, Azure, Nginx etc.)
- Continuous observability & auto-inventory (15M+ API requests/m)
- Detects orphan, shadow & zombie APIs to reduce exposure
$1999/yr
$199/mo
If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.
Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.
Click the 🛈 icon to know more.
- 200+ API DAST scans/year with 15,000+ authenticated test cases
- CI/CD, JIRA and Slack integrations
- Auto re-scan of selective vulnerabilities after fixes
- Full and management PDF reports
$4999/yr
- 700+ API DAST scans per year with 15,000+ authenticated test cases
- CI/CD, JIRA and Slack integrations
- Auto re-scan of selective vulnerabilities after fixes
- Full and management PDF, CSV & JSON reports
- Capture live API traffic via 10+ integrations (Kong, Postman, AWS, GCP, Azure, Nginx etc.)
- Continuous observability & auto-inventory (10M+ API requests/m)
- Detects orphan, shadow & zombie APIs to reduce exposure
Contact us
- 1000+ API DAST scans annually with manual pentests by certified experts
- CI/CD, JIRA and Slack integrations
- Auto re-scan of selective vulnerabilities after fixes
- Full and management PDF, CSV & JSON reports
- Capture live API traffic via 10+ integrations (Kong, Postman, AWS, GCP, Azure, Nginx etc.)
- Continuous observability & auto-inventory (15M+ API requests/m)
- Detects orphan, shadow & zombie APIs to reduce exposure
Compare plans & FIND the right one for you
Astra continuously scans AWS, Azure, and GCP for misconfigs, IAM risks, and vulnerabilities, validating every finding before it reaches you
$99/m
$199/mo
If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.
Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.
Click the 🛈 icon to know more.
- Scan 1 cloud target
- Unlimited automated security scans
- PDF reports
- Scan up to 250 resources per account
- Email support
$199/m
- Scan 3 cloud targets of your choice
- Unlimited automated security scans
- PDF, JSON & Management Reports
- Scan up to 1000 resources per account
- Priority ticket & email support
- Schedule weekly, monthly etc. scans
- Slack, JIRA integration along with compliance mapping of issues
Contact us
- Scan multi cloud setups seamlessly
- Unlimited automated security scans
- PDF, JSON & Management Reports
- Scan high volume of resources & cloud services
- Dedicated account manager
- Schedule weekly, monthly etc. scans
- Manual pentest & cloud security review by cloud security experts
$999/yr
$199/mo
If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.
Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.
Click the 🛈 icon to know more.
- Scan 1 cloud target
- Unlimited automated security scans
- PDF reports
- Scan up to 250 resources per account
- Email support
$1999/yr
- Scan 3 cloud targets of your choice
- Unlimited automated security scans
- PDF, JSON & Management Reports
- Scan up to 1000 resources per account
- Priority ticket & email support
- Schedule weekly, monthly etc. scans
- Slack, JIRA integration along with compliance mapping of issues
Contact us
- Scan multi cloud setups seamlessly
- Unlimited automated security scans
- PDF, JSON & Management Reports
- Scan high volume of resources & cloud services
- Dedicated account manager
- Schedule weekly, monthly etc. scans
- Manual pentest & cloud security review by cloud security experts
Compare plans & FIND the right one for you
Loved by leading security conscious companies around the world

.avif)



































.webp)









Trusted by 1000+ engineering teams








.webp)


FAQs
Frequently asked questions
How do you define a target for DAST Scanner?
Do you offer discounts on multi-year commitments or bundled services?
Does Pentest (PTaaS) cover specific compliance requirements (e.g., SOC 2, PCI, ISO 27001)?
What is the timeline for manual and automated testing, including rescans?
How do you define a target for Pentest (PTaaS)?
- If you have a SaaS app, the entire app with all its APIs and underlying cloud is 1 target.
- If you have a mobile app, one Android app is considered as one target and one iOS app is considered another target. If they share code base, we offer a tailored pricing starting from $2200/app depending on the scope
- In case of networks, cloud, IPs and APIs - multiple clouds, IPs, APIs etc. can be clubbed into one target. Please schedule a call for tailored pricing.
What is covered in automated vs manual pentesting/VAPT?
How can I validate the fixed vulnerabilities?
Do you work with our developer in patching the vulnerabilities?
Find & fix every vulnerability with Astra
Astra's continuous pentest platform: PTaaS for expert led pentesting, DAST Scanner for continuous vulnerability detection & API Security Platform for API observability &
vulnerability scanning - all working together to secure your applications.










