The model
Start free. Pay when it’s worth paying for.
We’re a new company and the pricing says so. Find out whether anything is wrong with your software before you spend a thing.
Pricing tiers
Scan
$0
one target
Scores and counts by severity, so you know whether there is anything worth acting on. No invoice, no commitment.
Start with a free scanFull report
Most useful$2,000
one target
Everything we found, how to reproduce it, and how to fix it.
Request a full report| What you get | Scan$0 | Full report$2,000 | Continuous$10,000 |
|---|---|---|---|
| Security scoresOverall posture, scored by severity. | Included | Included | Included |
| Vulnerability counts by severityHow many we found, and how bad they are. | Included | Included | Included |
| Interactive reportThe paid deliverable. The free scan returns the summary above, not the report. | Not included | Included | Included |
| Full finding detailCWE, CVSS 3.1, affected endpoint, evidence. | Not included | Included | Included |
| Reproduction script per findingRe-run it after your fix to prove the fix landed. | Not included | Included | Included |
| Proposed fix as a diffWhite-box engagements. Formatted for a pull request. | Not included | Included | Included |
| Scans at least twice a month | Not included | Not included | Included |
| Delta testing in your pipelineChanged code gets tested as it merges. Diff-scoped testing needs source access, so this part is white-box. | Not included | Not included | Included |
| Testing modeWhite-box needs source access and an hour of your engineers' time — at every tier, including the free one. | Black-box or white-box | Black-box or white-box | Black-box or white-box |
Prices in USD. One target is one application, repository or binary. Talk to us if you have several. How an engagement works →
Modes
Black-box or white-box
The tier decides what you get; the mode decides how much we find. Either mode is available at any tier, so a free scan can be white-box: you still get the summary and not the full report, but it will be a much better-informed summary.
Black-box
No access to your code.
We work from outside, the way an attacker does. It’s how demos run.
- Needs only a target and your written authorisation
- Coverage limited to what’s reachable from outside
White-box
We read your source, and we talk to you.
Source access plus a one-hour interview with your team.
- Static analysis and live testing correlated against each other
- Findings arrive with a fix as a diff
Questions
The ones worth asking
- What do you need from me to start?
- A signed agreement and authorisation, then the target address and test credentials. White-box adds source access and an hour of your engineers’ time. Nothing gets installed.
- What does the free scan actually tell me?
- Scores and a count of what we found, by severity: enough to know whether anything is worth acting on. Detail, reproduction scripts and fixes start at the paid tier.
- What if you find nothing?
- Then it cost you an email. We’d sooner say so than pad a report to justify an invoice.
- How long until the first report?
- A day for a contained application in black-box — several weeks for a large system where the findings chain into each other. You get a real estimate after the discovery call.
- What is not covered?
- Web findings are exploit-validated: we ran the exploit and watched what happened. Compiled binaries are analysed statically, pinned to the exact function but never executed, and labelled that way.
- Is my code retained or used for training?
- No. Your source is copied into a container that gets destroyed when the engagement ends, along with the traffic and the exploit code. The report is all that leaves.
- Why is this cheaper than a manual pentest?
- Most of the labour in a manual engagement is machine work a person was doing by hand.
Anything else: info@ria-labs.com
Start with the free one
Nominate a target. If nothing comes back, you’ve lost an email.