Pricing & Credits
The Credit-Based Model
TurboPentest uses a credit-based pricing model. You buy credits and spend them on pentests. This pay-as-you-go approach means you only pay for what you use - no per-seat charges that penalize large teams.
A credit is tier-specific: one credit unlocks one pentest at the tier it was purchased for. A Standard credit runs one Standard pentest, a Deep credit runs one Deep pentest, and so on. Credits are not a generic currency that different tiers consume in different multiples.
Pentest Tiers and Prices
Each tier costs a flat per-pentest price, reflecting the depth of analysis and the number of agent-hours involved.
Recon ($49)
- Phase 1 only - reconnaissance tools run across the attack surface
- No Phase 2 - no AI agent analysis
- Agent budget: 0.5 agent-hours, 1 agent
- Use case: quick surface-level assessment, pre-pentest reconnaissance, CI/CD on every PR
- Duration: approximately 30 minutes
- Output: raw tool results organized by category, no agent-validated findings
Audit-Ready ($99)
- Phase 1 + Phase 2 - full reconnaissance plus specialist AI agents
- Agent budget: 4 agent-hours, 4 agents
- Use case: regular security testing for web applications, CI/CD on merges to main, the report your auditor needs
- Duration: approximately 60 minutes
- Output: agent-validated findings with PoC exploits, severity ratings, and remediation steps
Threat-Hunt ($299)
- Phase 1 + Extended Phase 2 - full reconnaissance plus a larger specialist agent fleet
- Agent budget: 20 agent-hours, 10 agents
- Use case: thorough testing before major releases, monthly deep dives, hunting threats an audit checklist will not catch
- Duration: approximately 120 minutes
- Output: comprehensive findings including business logic flaws, authentication weaknesses, and cryptographic issues
Adversarial-Depth ($699)
- Phase 1 + Maximum Phase 2 - full reconnaissance plus the full agent fleet, depth agents, and exploit-chaining
- Agent budget: 80 agent-hours, 20 agents
- Use case: pre-launch security assessment, post-incident analysis, mimicking a determined attacker
- Duration: approximately 240 minutes
- Output: maximum-depth findings with validated exploit chains and comprehensive attack surface coverage
The canonical tier slugs remain recon, standard, deep, and blitz in URLs and the API; the outcome-named labels above (Audit-Ready, Threat-Hunt, Adversarial-Depth) are the display names for Standard, Deep, and Blitz.
Volume Discounts
Buying multiple credits of the same tier earns an automatic volume discount, applied at checkout:
| Quantity | Discount |
|---|---|
| 10+ | 10% |
| 50+ | 20% |
| 100+ | 30% |
The discount applies to the per-credit price of the tier you are buying. For example, 50 Audit-Ready credits are priced at $99 less 20% per credit.
Annual Subscriptions
If you pentest regularly, an annual subscription is cheaper than buying credits one at a time. Subscriptions are billed annually upfront, and all of the year's credits are granted to your account immediately:
- Audit-Ready: 12 Audit-Ready credits per year, 10% off
- Threat-Hunt: 12 Threat-Hunt credits per year, 15% off
- Pro: 8 Threat-Hunt + 4 Adversarial-Depth credits per year, 20% off
For organizations that want unlimited pentests in their own cloud, the Enterprise plan runs a dedicated TurboPentest instance in your environment for $4,999/month or $49,990/year. Contact [email protected].
Maximizing Credit Value
Choose the Right Tier
Not every target needs an Adversarial-Depth pentest. Match the tier to the situation:
- New feature on staging? Recon or Audit-Ready
- Sprint release to production? Audit-Ready
- Major version release? Threat-Hunt
- Pre-launch or incident response? Adversarial-Depth
Over-testing with Adversarial-Depth when Audit-Ready would suffice wastes money. Under-testing with Recon when Threat-Hunt is warranted misses vulnerabilities.
Use Recon for Triage
Run a Recon pentest first to understand the attack surface. If Phase 1 reveals a complex application with many endpoints, step up to Threat-Hunt or Adversarial-Depth. If the surface is minimal, Audit-Ready may suffice.
Earn Free Pentests Through Referrals
Refer other teams to TurboPentest. The person you refer gets 15% off their first purchase, and you earn a free Audit-Ready pentest credit for each conversion, up to 50 per year.
Credit Management
Balance and History
View your credit balance and transaction history in your account billing area. Each transaction shows the type (purchase, subscription grant, pentest consumption, referral reward), the tier, and the date and associated pentest where applicable.
Refund Policy
If a pentest fails due to a TurboPentest system error (not a target connectivity issue), the credit is returned to your account so you can re-run the pentest.
Bug Bounty Program
Learn how to report vulnerabilities in TurboPentest itself, understand severity tiers and rewards, and follow responsible disclosure practices.
CAPO Final Exam
The comprehensive Certified Agentic Pentesting Operator final exam covering all 7 courses. Pass with 90% to earn your CAPO certification.