Free
no signup
Ghost Scan
PhantomDragon runs a surface scan of your site.
- Surface scan across 9 categories
- No sales call, no card, see what an attacker sees first
- Real-time. Nothing stored.
Pricing
Every number on this page is public, fixed, and the same one you’ll see on the product pages.
Fixed prices, no hidden fees, no scope creep. Start free with a Ghost Scan, book the $4,000 fixed-price penetration test, or run Wyrm free on your own machine.
The honest answer to the penetration testing cost question is that the market is wide. 2026 cost guides from DeepStrike, Blaze Infosec, Intruder, and Astra put a typical web-and-API engagement from a traditional firm at roughly $5,000 to $35,000+ once scoping, hours, and change orders are added up. The AI-led platforms have set a new floor underneath that: Cobalt and Intruder list autonomous pentests from $3,500 per test, and Astra’s manual tier is $5,999 per target per year. That range is why penetration testing pricing is so hard to compare; you rarely know the number until the invoice arrives. Ours is $4,000, fixed, with a named engineer, a free re-test and a signed attestation, and you know it before you talk to anyone.
We price the penetration test at a flat $4,000 for the whole engagement: no hourly billing, no scope creep, one number quoted and held. Expedited 72-hour delivery is $500 extra. For teams that ship every week, the $899/month retainer turns the one-off engagement into continuous penetration testing: a fresh pentest every quarter with a monthly scan in between, for less than the pieces cost separately.
We priced for one market; we now price for two. The engagement is the same.
Free
no signup
PhantomDragon runs a surface scan of your site.
$299
one-time
AI-powered deep scan of your site or app · Best for: small businesses launching a site or app
$4,000
per project
A named engineer attempts to break into your system · One web app + its API, 3 hostnames, 2 roles · Best for: startups before a launch, fundraise or audit
$899
per month, 6-month minimum
Ongoing protection for your team · Best for: growing companies with regular code changes
From
$8,000
quoted per scope
Scope specification, board-format reporting · Best for: CBSL-regulated finance and their vendors, multi-app estates, mergers
Free / $29+
Free for local use, no account. Paid plans from $29/mo add cloud sync. Arranged by email.
Custom
Self-hosted commerce. Zero commission. Contact for a quote.
Listed in USD. Companies registered in Sri Lanka have a local rate card, on the penetration testing in Sri Lanka page.
Straight answers on what costs what, what’s free, and what’s included.
Ghost Protocol’s penetration test is a fixed $4,000, the whole web-and-API VAPT engagement, not an hourly estimate. For comparison, published 2026 cost guides (DeepStrike, Blaze Infosec, Intruder, Astra) put an equivalent engagement from a traditional firm at $5,000 to $35,000 once scoping, hours, and change orders are counted, and the AI-only platforms list from $3,500 per test. We quote one number and hold it: no hourly billing, no scope creep. Expedited 72-hour delivery is $500 extra, and the ongoing security retainer is $899/month. Companies registered in Sri Lanka have a local rate card. Read the full penetration testing cost guide for the market math and how to compare quotes.
A fixed-price engagement where a named engineer plus 75 AI-powered scanners try to break into your web app or API: one application plus its API, up to three hostnames, grey-box with two user roles. You get an executive-readable PDF report, developer JSON + SARIF, reproducible proof-of-concept for each high-severity finding, a free re-test after you patch, a 30-day Q&A inbox, and a signed attestation letter for auditors. Delivery is 5 to 7 days. No hourly billing and no scope creep.
The Ghost Scan at ghosts.lk/scan is free forever, no signup, no credit card. It’s an automated surface-level check of publicly visible configuration, results are generated in real time and not stored on our servers. Wyrm is also free to use locally with no limits, and a free 15-minute consult is available before any paid engagement.
The free Ghost Scan is an automated check of publicly visible configuration. The $4,000 penetration test is a manual deep-dive: a named engineer actively tries to exploit your application logic, authentication, and infrastructure, then hands you a report an auditor will accept. The free scan tells you if anything obvious is exposed; the pentest tells you whether someone can actually break in.
Yes. The security retainer is $899/month on a six-month minimum and works as continuous penetration testing: a fresh pentest every quarter, a monthly deep scan with a delta report between engagements, re-tests on every fix, priority triage when something breaks, a named engineer who knows your codebase, and a quarterly summary you can file with a board or auditor. It costs less than the four pentests and twelve scans bought separately. It is not a 24/7 service; the response commitment is same business day, in writing.
Yes. Standard delivery is 5 to 7 calendar days. Expedited 72-hour delivery is available for an extra $500. Most engagements don’t need it: SOC 2 auditors are comfortable with the standard 5 to 7 day turnaround.
Yes. Companies registered in Sri Lanka are invoiced in LKR at a local rate card, a separate price for the local market rather than a conversion. The figures are on the penetration testing in Sri Lanka page.
The free tier is free to use with no usage limits, install it via npm (wyrm-mcp), run wyrm-setup, and add it to your MCP config; no account is needed for local use. Wyrm is proprietary software (the Wyrm Terms of Service apply); your memory stays local on your machine. Paid plans add cloud and team features: Pro is $29/month (cloud sync, AES-256 encryption), Team is $199/month (shared memory, up to 25 seats), and Enterprise is $499/month (SSO/SAML, custom SLA, on-premise option). They are arranged by email, not a checkout: write to support@ghosts.lk.
DragonScale is a self-hosted commerce platform with no monthly fees and no per-order commissions, you own your data and infrastructure. It’s deployed in Starter, Business, and Enterprise tiers scoped to your needs, so pricing depends on locations, customization, and support level. Contact us for a tailored quote.
Four structural reasons. About four engineer-days go into each engagement, billed at a Colombo rate rather than a US one. PhantomDragon, our own 75-scanner engine, does the coverage work, so those days go to exploitation and chaining instead of enumeration. The scope is fixed (one web app plus its API), so there is no scoping overhead. And there is no platform fee and no sales team between you and the engineer. The method is OWASP / NIST, the report is built for auditors, and a named engineer signs the attestation; only the overhead is lower.
Those lines are drawn by firms selling $5,000+ tests, and the platforms themselves now sell $1,999 to $3,500 AI-only products under the word pentest. Ours is $4,000, so it sits above that line, but what makes it a pentest is not the price. A named engineer runs the manual phase, every high-severity finding ships with a reproducible proof of concept, a free re-test follows your fixes, and the attestation letter carries that engineer’s signature. The sample report shows all four.
Yes. Every report follows OWASP / NIST methodology and includes a scope statement, severity-ranked findings, an executive summary, remediation guidance, and a signed-and-dated attestation letter. The Pentest tier covers the technical-testing requirement for SOC 2, ISO 27001, and PCI-DSS. Anonymized sample reports are available under NDA before you commit.
Run a free Ghost Scan in seconds, or book the fixed-price penetration test: one price, five to seven days, a report you can hand to an auditor.
Sol here. Ask about a pentest, the free scan, Wyrm, or anything on the site.