Pricing

Transparent pricing

Every number on this page is public, fixed, and the same one you’ll see on the product pages.

Fixed prices, no hidden fees, no scope creep. Start free with a Ghost Scan, book the $4,000 fixed-price penetration test, or run Wyrm free on your own machine.

Cost

What a penetration test costs

The honest answer to the penetration testing cost question is that the market is wide. 2026 cost guides from DeepStrike, Blaze Infosec, Intruder, and Astra put a typical web-and-API engagement from a traditional firm at roughly $5,000 to $35,000+ once scoping, hours, and change orders are added up. The AI-led platforms have set a new floor underneath that: Cobalt and Intruder list autonomous pentests from $3,500 per test, and Astra’s manual tier is $5,999 per target per year. That range is why penetration testing pricing is so hard to compare; you rarely know the number until the invoice arrives. Ours is $4,000, fixed, with a named engineer, a free re-test and a signed attestation, and you know it before you talk to anyone.

We price the penetration test at a flat $4,000 for the whole engagement: no hourly billing, no scope creep, one number quoted and held. Expedited 72-hour delivery is $500 extra. For teams that ship every week, the $899/month retainer turns the one-off engagement into continuous penetration testing: a fresh pentest every quarter with a monthly scan in between, for less than the pieces cost separately.

We priced for one market; we now price for two. The engagement is the same.

Free

no signup

Ghost Scan

PhantomDragon runs a surface scan of your site.

  • Surface scan across 9 categories
  • No sales call, no card, see what an attacker sees first
  • Real-time. Nothing stored.

$299

one-time

Security Scan

AI-powered deep scan of your site or app · Best for: small businesses launching a site or app

  • PhantomDragon AI runs 75+ scanner modules against your surface
  • Covers the OWASP Top 10: the most common web security gaps
  • An engineer reads the output and removes the obvious false positives
  • Executive PDF report readable without a security background + CSV export for your developers
  • Delivered in 48 hours

$4,000

per project

Penetration Test

A named engineer attempts to break into your system · One web app + its API, 3 hostnames, 2 roles · Best for: startups before a launch, fundraise or audit

  • Everything in Security Scan: the AI sweep runs first, so engineer hours go where tools can’t
  • Manual exploitation: auth bypass, session flaws, chained attacks
  • Business-logic testing (can someone skip payment? see another user’s data?)
  • Fix-it guidance + a free re-test after you patch

$899

per month, 6-month minimum

Security Retainer

Ongoing protection for your team · Best for: growing companies with regular code changes

  • Penetration test every quarter
  • Re-test on every fix, so closed findings stay closed
  • Priority triage when something breaks
  • Named engineer, monthly scan with delta report, quarterly summary, same-business-day response

From

$8,000

quoted per scope

Regulated / Enterprise

Scope specification, board-format reporting · Best for: CBSL-regulated finance and their vendors, multi-app estates, mergers

  • Audits across multiple connected systems
  • SOC 2 / ISO 27001 evidence packs and CBSL scope specifications
  • Named engineer + contractual SLAs; internal-network testing scoped separately

Products

Free / $29+

Wyrm

Free for local use, no account. Paid plans from $29/mo add cloud sync. Arranged by email.

Custom

DragonScale

Self-hosted commerce. Zero commission. Contact for a quote.

Flexible billing // PO-readyQuotes on WhatsApp · +94 71 055 5055De-brief session

Listed in USD. Companies registered in Sri Lanka have a local rate card, on the penetration testing in Sri Lanka page.

Questions

Pricing questions

Straight answers on what costs what, what’s free, and what’s included.

Ghost Protocol’s penetration test is a fixed $4,000, the whole web-and-API VAPT engagement, not an hourly estimate. For comparison, published 2026 cost guides (DeepStrike, Blaze Infosec, Intruder, Astra) put an equivalent engagement from a traditional firm at $5,000 to $35,000 once scoping, hours, and change orders are counted, and the AI-only platforms list from $3,500 per test. We quote one number and hold it: no hourly billing, no scope creep. Expedited 72-hour delivery is $500 extra, and the ongoing security retainer is $899/month. Companies registered in Sri Lanka have a local rate card. Read the full penetration testing cost guide for the market math and how to compare quotes.

A fixed-price engagement where a named engineer plus 75 AI-powered scanners try to break into your web app or API: one application plus its API, up to three hostnames, grey-box with two user roles. You get an executive-readable PDF report, developer JSON + SARIF, reproducible proof-of-concept for each high-severity finding, a free re-test after you patch, a 30-day Q&A inbox, and a signed attestation letter for auditors. Delivery is 5 to 7 days. No hourly billing and no scope creep.

The Ghost Scan at ghosts.lk/scan is free forever, no signup, no credit card. It’s an automated surface-level check of publicly visible configuration, results are generated in real time and not stored on our servers. Wyrm is also free to use locally with no limits, and a free 15-minute consult is available before any paid engagement.

The free Ghost Scan is an automated check of publicly visible configuration. The $4,000 penetration test is a manual deep-dive: a named engineer actively tries to exploit your application logic, authentication, and infrastructure, then hands you a report an auditor will accept. The free scan tells you if anything obvious is exposed; the pentest tells you whether someone can actually break in.

Yes. The security retainer is $899/month on a six-month minimum and works as continuous penetration testing: a fresh pentest every quarter, a monthly deep scan with a delta report between engagements, re-tests on every fix, priority triage when something breaks, a named engineer who knows your codebase, and a quarterly summary you can file with a board or auditor. It costs less than the four pentests and twelve scans bought separately. It is not a 24/7 service; the response commitment is same business day, in writing.

Yes. Standard delivery is 5 to 7 calendar days. Expedited 72-hour delivery is available for an extra $500. Most engagements don’t need it: SOC 2 auditors are comfortable with the standard 5 to 7 day turnaround.

Yes. Companies registered in Sri Lanka are invoiced in LKR at a local rate card, a separate price for the local market rather than a conversion. The figures are on the penetration testing in Sri Lanka page.

The free tier is free to use with no usage limits, install it via npm (wyrm-mcp), run wyrm-setup, and add it to your MCP config; no account is needed for local use. Wyrm is proprietary software (the Wyrm Terms of Service apply); your memory stays local on your machine. Paid plans add cloud and team features: Pro is $29/month (cloud sync, AES-256 encryption), Team is $199/month (shared memory, up to 25 seats), and Enterprise is $499/month (SSO/SAML, custom SLA, on-premise option). They are arranged by email, not a checkout: write to support@ghosts.lk.

DragonScale is a self-hosted commerce platform with no monthly fees and no per-order commissions, you own your data and infrastructure. It’s deployed in Starter, Business, and Enterprise tiers scoped to your needs, so pricing depends on locations, customization, and support level. Contact us for a tailored quote.

Four structural reasons. About four engineer-days go into each engagement, billed at a Colombo rate rather than a US one. PhantomDragon, our own 75-scanner engine, does the coverage work, so those days go to exploitation and chaining instead of enumeration. The scope is fixed (one web app plus its API), so there is no scoping overhead. And there is no platform fee and no sales team between you and the engineer. The method is OWASP / NIST, the report is built for auditors, and a named engineer signs the attestation; only the overhead is lower.

Those lines are drawn by firms selling $5,000+ tests, and the platforms themselves now sell $1,999 to $3,500 AI-only products under the word pentest. Ours is $4,000, so it sits above that line, but what makes it a pentest is not the price. A named engineer runs the manual phase, every high-severity finding ships with a reproducible proof of concept, a free re-test follows your fixes, and the attestation letter carries that engineer’s signature. The sample report shows all four.

Yes. Every report follows OWASP / NIST methodology and includes a scope statement, severity-ranked findings, an executive summary, remediation guidance, and a signed-and-dated attestation letter. The Pentest tier covers the technical-testing requirement for SOC 2, ISO 27001, and PCI-DSS. Anonymized sample reports are available under NDA before you commit.

Start free. Pay a fixed price when you’re ready.

Run a free Ghost Scan in seconds, or book the fixed-price penetration test: one price, five to seven days, a report you can hand to an auditor.