// scope and pricing

Price the product boundary, not the endpoint count.

Each starting price assumes one defined product, complete intake and written authorisation. Roles, workflows, integrations and delivery requirements determine the final scope.

ARGUS / PricingReady
01Website Pentest€490
02Web Application PentestFrom €3,500
03Focused ValidationFrom €7,500
04Full Application PentestFrom €15,000
€490
Website Pentest
From €3,500
Web Application Pentest
From €7,500
AppSec Core
From €30,000
Argus Sentinel
// Website and web application pentesting

Website and web application pentesting

Start at €490 for a simple public website. Authentication, custom APIs, checkout, separate applications or material business logic move the engagement to the appropriate application scope. We price the product boundary, not an arbitrary endpoint count.

// 3 working days · fixed fee

Website Pentest

€490

A fixed-scope assessment for a public website on one technology stack. It covers the root domain, www and up to five owned subdomains that belong to the same website.

  • Root domain, www + up to 5 owned subdomains
  • Public, unauthenticated surface
  • Argus testing + expert review of material findings
  • Concise report with evidence and recommendations
  • One retest within 14 days
Start a Website Pentest
// 5–7 working days · fixed fee

Web Application Pentest

From €3,500

For a standard web application with one authenticated role, its directly consumed API and up to three critical workflows. Separate admin apps, complex SSO, multi-tenancy and additional roles require a larger scope.

  • One web application
  • One authenticated role
  • Primary API used by the application
  • Up to three critical workflows
  • Reviewed report + SARIF
  • One retest within 30 days
Scope a Web App Pentest
// 00 / start here

Discovery without the meeting cycle

Complete one structured intake, upload the evidence you already have, and receive an expert-validated security map and 90-day roadmap. Work starts when the required inputs are complete; clarification stays asynchronous.

// 10 working days · fixed fee

Discovery Sprint

From €5,000

One asynchronous intake for one product. We map architecture, data flows, access, security exposure and relevant regulatory risk, then deliver an expert-validated 90-day roadmap.

  • Secure structured intake
  • Architecture + data-flow map
  • Security, regulatory and AI risk register
  • Prioritised 90-day roadmap
  • Optional 45-minute handover
Start the Intake
// Application pentesting

Application pentesting

Choose the smallest application scope that covers the product boundary, authenticated roles, API surface and business logic under test. Focused Validation starts at €7,500; Full Application Pentest starts at €15,000.

// 7–10 working days · fixed fee

Focused Validation

From €7,500

A small web application or bounded API, up to two authenticated roles, with Argus-assisted testing and expert validation.

  • One bounded application or API
  • Up to two authenticated roles
  • Evidence-backed reviewed findings
  • Reviewed report + SARIF
  • One retest within 30 days
Scope Focused Validation
// 10–15 working days · fixed fee

Full Application Pentest

From €15,000

One web application and its primary API, including authentication, up to four roles, business logic and tenant isolation.

  • Web application + primary API
  • Up to four authenticated roles
  • Business-logic testing
  • Reviewed report + SARIF
  • One retest within 30 days
Scope a Full Pentest
// secure what you ship

Argus AppSec

Repository and pull-request assurance for teams that want security feedback where changes happen, without pretending every commit needs a full pentest.

// / year

AppSec Core

From €7,500

Continuous code assurance for a small product team.

  • 1 protected product
  • Up to 5 selected repositories
  • Up to 10 active contributors
  • Semgrep commit checks
  • SARIF and portal results
Discuss AppSec Core
// / year

AppSec Reviewed

From €15,000

Code assurance with specialist review and controlled pre-release validation.

  • 1 protected product
  • Up to 15 selected repositories
  • Up to 30 active contributors
  • Specialist review of material findings
  • Pre-release validation pilot
Discuss AppSec Reviewed
// 03 / argus sentinel

Argus Sentinel

Recurring evidence for one product without pretending that a pentester is permanently on call. Scheduled Argus runs surface change; human time is reserved for material findings and two focused testing windows each year.

// One product · 12-month scope

Argus Sentinel

From €30,000

Scheduled recurring validation for one product. Automation monitors change; bounded human review covers material findings, quarterly risk review and two focused manual windows.

  • Baseline Focused Validation
  • Monthly Argus validation
  • Quarterly risk review
  • Two manual testing windows per year
  • Two-business-day portal response
Scope Argus Sentinel
// per protected product / year

Complete Assurance

From €42,000

AppSec Reviewed and Argus Sentinel for one protected product, joined through a shared evidence and remediation record.

  • AppSec Reviewed
  • Argus Sentinel
Start Scoping

Not sure where to start?

Start with the smallest service that answers the decision in front of you. If the scope is already clear, go directly to Focused Validation or a Full Application Pentest.

Start Scoping
Plano de Recuperação e Resiliência, República Portuguesa e Financiado pela União Europeia — NextGenerationEU