Pricing & Credits
The Credit-Based Model
TurboPentest uses a credit-based pricing model. You buy credits and spend them on pentests. This pay-as-you-go approach means you only pay for what you use - no per-seat charges that penalize large teams.
A credit is tier-specific: one credit unlocks one pentest at the tier it was purchased for. An Audit-Ready credit runs one Audit-Ready pentest, a Threat-Hunt credit runs one Threat-Hunt pentest, and so on. Credits are not a generic currency that different tiers consume in different multiples.
Pentest Tiers and Prices
Each tier costs a flat per-pentest price, reflecting the depth of analysis and the number of agent-hours involved.
Recon ($49)
- Phase 1 + Phase 2 - reconnaissance tools run across the attack surface, then a single generalist AI agent reasons over the results
- Phase 2 at the smallest scope - 1 generalist agent (no supervisor, no specialist swarm)
- Agent budget: up to 0.5 agent-hours, 1 agent
- Use case: quick surface-level assessment, pre-pentest reconnaissance, CI/CD on every PR
- Duration: in minutes
- Output: agent-validated findings at the smallest scope - the generalist agent still validates before reporting, just without the deeper specialist coverage of higher tiers
Audit-Ready ($99)
- Phase 1 + Phase 2 - full reconnaissance plus specialist AI agents
- Agent budget: up to 4 agent-hours, 4 agents
- Use case: regular security testing for web applications, CI/CD on merges to main, the report your auditor needs
- Duration: in hours
- Output: agent-validated findings with PoC exploits, severity ratings, and remediation steps
Threat-Hunt ($299)
- Phase 1 + Extended Phase 2 - full reconnaissance plus a larger specialist agent fleet
- Agent budget: up to 20 agent-hours, 10 agents
- Use case: thorough testing before major releases, monthly deep dives, hunting threats an audit checklist will not catch
- Duration: in hours
- Output: comprehensive findings including business logic flaws, authentication weaknesses, and cryptographic issues
Adversarial-Depth ($699)
- Phase 1 + Maximum Phase 2 - full reconnaissance plus the full agent fleet, depth agents, and exploit-chaining
- Agent budget: up to 80 agent-hours, 20 agents
- Use case: pre-launch security assessment, post-incident analysis, mimicking a determined attacker
- Duration: in hours
- Output: maximum-depth findings with validated exploit chains and comprehensive attack surface coverage
The canonical tier slugs remain recon, standard, deep, and blitz in URLs and the API; the outcome-named labels above (Audit-Ready, Threat-Hunt, Adversarial-Depth) are the display names for the standard, deep, and blitz tiers.
Volume Discounts
Buying multiple credits of the same tier earns an automatic volume discount, applied at checkout:
| Quantity | Discount |
|---|---|
| 10+ | 10% |
| 50+ | 20% |
| 100+ | 30% |
The discount applies to the per-credit price of the tier you are buying. For example, 50 Audit-Ready credits are priced at $99 less 20% per credit.
Annual Subscriptions
If you pentest regularly, an annual subscription is cheaper than buying credits one at a time. Subscriptions are billed annually upfront, and all of the year's credits are granted to your account immediately:
- Audit-Ready: 12 Audit-Ready credits per year, 10% off
- Threat-Hunt: 12 Threat-Hunt credits per year, 15% off
- Pro: 8 Threat-Hunt + 4 Adversarial-Depth credits per year, 20% off
For organizations that want unlimited pentests in their own cloud, the Enterprise plan runs a dedicated TurboPentest instance in your environment for $4,999/month or $49,990/year. Contact us through the support tool.
Maximizing Credit Value
Choose the Right Tier
Not every target needs an Adversarial-Depth pentest. Match the tier to the situation:
- New feature on staging? Recon or Audit-Ready
- Sprint release to production? Audit-Ready
- Major version release? Threat-Hunt
- Pre-launch or incident response? Adversarial-Depth
Over-testing with Adversarial-Depth when Audit-Ready would suffice wastes money. Under-testing with Recon when Threat-Hunt is warranted misses vulnerabilities.
Use Recon for Triage
Run a Recon pentest first to understand the attack surface. If Phase 1 reveals a complex application with many endpoints, step up to Threat-Hunt or Adversarial-Depth. If the surface is minimal, Audit-Ready may suffice.
Earn Free Pentests Through Referrals
Refer other teams to TurboPentest. The person you refer gets 15% off their first purchase, and you earn a free Audit-Ready pentest credit for each conversion, up to 50 per year.
Credit Management
Balance and History
View your credit balance and transaction history in your account billing area. Each transaction shows the type (purchase, subscription grant, pentest consumption, referral reward), the tier, and the date and associated pentest where applicable.
Refund Policy
If a pentest fails due to a TurboPentest system error (not a target connectivity issue), the credit is returned to your account so you can re-run the pentest.
Bug Bounty Program
Learn how to report vulnerabilities in TurboPentest itself, understand severity tiers and rewards, and follow responsible disclosure practices.
CAPO Final Exam
The comprehensive Certified Agentic Pentesting Operator final exam covering all 7 courses. Pass with 90% to earn your CAPO certification.