Pricing 2026

Priced per developer. Not per scan, not per finding.

You pay for your team - one developer, one price. Dynamic testing and AI Pentest, which scale with your external surface, are metered by target URL. Self-hosted, air-gapped-capable, annual. No free tier; a full 30-day proof-of-concept in your own environment.

TL;DR

Three editions, priced per developer

Every edition is priced per developer / month, billed annually. Pick by the coverage you need; DAST and AI Pentest scale separately by target URL (below).

EssentialsPlatformEnterprise
Price$35 / dev · mo$70 / dev · mo$90 / dev · mo
Best forCode-security teams shifting leftA full AppSec program on one platformRegulated, air-gapped, proof-of-exploit
CoverageSAST · SCA · Secrets · IaC · Container+ DAST · Cloud posture · ASPM · API+ AI Pentest · Threat Modeling
DASTAdd-on / URLUnlimitedUnlimited
AI PentestAdd-on / URLAdd-on / URLUnlimited
ComplianceOWASP Top 10+ PCI · ISO 27001 · SOC 2+ NIST · HIPAA · GDPR + evidence vault
Air-gappedOptional (+15%)Optional (+15%)Included
SupportCommunity8×5 priority24×7 + SLA + CSM

Prices are illustrative list (local market, on-prem annual licence). Minimum $3,000 / $5,000 / $9,000 per year by edition. For a written quote, contact us.

The unit

What counts as “a developer”?

The platform is priced per developer - the bill tracks your team, not how many repositories or findings you have. Dynamic testing scales by the surface it reaches, so DAST and AI Pentest meter by target URL.

One developer is…

  • a human with platform access, or
  • a distinct code committer in the last 90 days
  • CI bots and service accounts do not count
  • inactive / archived contributors do not count

DAST & AI Pentest by URL

DAST is unlimited on Platform; AI Pentest is unlimited on Enterprise. Below those tiers each is an add-on per target URL - one registered scan target (a base host or application), not every crawled page.

Why per developer? A 2-developer team with 100 repositories pays for 2 developers - the bill tracks your team, and you can verify it against your source control.

Editions

Pick your coverage

All three are per developer / month, billed annually (local-market list). Subject to the per-edition minimum.

Essentials

$35 /dev · mo
  • SAST + SCA + Secrets
  • IaC + Container scanning
  • AI fix PRs
  • CI/CD gate - Monitor
  • OWASP Top 10 compliance
  • DAST - add-on per URL
  • AI Pentest - add-on per URL
  • Self-hosted · community support
  • Min $3,000 / yr
Get a quote

Enterprise

$90 /dev · mo
  • Everything in Platform
  • + AI Pentest unlimited (proven exploitation)
  • Threat Modeling (STRIDE)
  • RBAC + multi-tenant
  • Fail-closed gate + webhook + queue
  • + NIST / HIPAA / GDPR + evidence vault
  • Air-gapped included · white-label option
  • 24×7 + SLA + dedicated CSM
  • Min $9,000 / yr
Contact us
DAST & AI Pentest

Dynamic testing scales by target URL

DAST is unlimited on Platform; AI Pentest is unlimited on Enterprise. Where they are add-ons, they bill per registered target URL with volume bands.

Target URLsPer URL · yrvs list
1 - 10 URLs$1,200list
11 - 25$950≈ 20% off
26 - 50$750≈ 37% off
51+Customtalk to us

AI Pentest add-on: $1,000 / URL · yr continuous, or $1,500 for a one-off assessment. Developers bill at a flat per-seat rate; 100+ seats and multi-year terms earn 15-25% off. Minimum $3,000 / $5,000 / $9,000 / year by edition.

What's included

Edition feature matrix

Grounded in what the platform does today - not a roadmap.

CapabilityEssentialsPlatformEnterprise
SAST · SCA · Secrets · IaC · Container
AI assistant + verified fix PRs
DAST - proof-of-exploit dynamic testingadd-on✓ unlimited✓ unlimited
API security - OWASP API Top 10-
Cloud posture (CSPM)-
ASPM correlation + attack-chain graph-
Risk-weighted posture (0-100, A-F, trend)partial
AI Pentest - agentic, proven exploitationadd-onadd-on✓ unlimited
Evidence-based threat modeling (STRIDE)--
CI/CD gateMonitorBlock + PRFail-closed
SSO (OIDC / SAML / LDAP) + SCIM-
RBAC + multi-tenant-partial
Compliance frameworksOWASPPCI · ISO · SOC 2+ NIST · HIPAA · GDPR
Tamper-evident evidence vault + auditor portals-partial
Air-gapped deployment+15%+15%Included
SupportCommunity8×5 priority24×7 + SLA
Add-ons

Optional modules & services

DAST - proof-of-exploit dynamic testing, per target URL (included unlimited on Platform+)$1,200 / URL · yr
AI Pentest - agentic proven exploitation, per target URL (included unlimited on Enterprise)$1,000 / URL · yr · or $1,500 one-off
Air-gapped deployment - offline CVE / threat-intel cache+15%
24×7 SLA support - dedicated CSM, 99.9%+18%
White-label / MSSP - multi-tenant, OEM, revenue-shareCustom
Onboarding + migration - import from your current toolsQuoted

DAST is included unlimited on Platform; AI Pentest, air-gapped and 24×7 SLA are included on Enterprise. On lower tiers they are optional add-ons. All reports (audit PDF, SOC 2 / ISO / PCI mapping, evidence vault) are included - only white-label branding is paid.

Worked examples

What you would actually pay

# Startup - 8 devs, code security Essentials $35 /dev · mo 8 devs × $420/yr = $3,360 /yr # just above the $3,000 floor
# AI company - 2 devs, 100 repos Essentials $35 /dev · mo 2 devs × $420/yr = $840 repos don't add cost → $3,000 /yr # per-developer, not per-repo
# Mid team - 25 devs, full program Platform $70 /dev · mo 25 devs × $840/yr = $21,000 /yr # unlimited DAST + cloud + ASPM included
# Large enterprise - 150 devs, air-gap Enterprise $90 /dev · mo 150 devs × $1,080/yr = $162,000 /yr # unlimited DAST + AI Pentest + air-gap

Need DAST on Essentials? Add target URLs at $1,200/URL/yr - or move to Platform, where DAST is unlimited (cheaper past ~3 URLs for a 10-developer team).

FAQ

Frequently asked

Why per developer, and not per scan or per finding?

Developer count is something you already know and can verify against your source control. Per-scan or per-finding pricing punishes you for the two things a security tool should encourage - scanning more often and finding more. Dynamic testing and AI Pentest, the parts that scale with external surface rather than team size, are metered separately by target URL.

What exactly counts as one developer?

A distinct human with platform access, or a distinct code committer seen in the last 90 days - whichever is higher. CI service accounts, bots and inactive or archived contributors do not count. A 2-developer team with 100 repositories pays for 2 developers, not 100 repositories.

How are DAST and AI Pentest priced?

Platform includes unlimited DAST; Enterprise includes unlimited AI Pentest. Below those tiers each is an add-on priced per target URL - $1,200/URL/yr for DAST, $1,000/URL/yr for AI Pentest (or $1,500 for a one-off assessment). A URL means one registered scan target - a base host or application - not every page the crawler visits.

Is there a free tier?

No. apPosture is a self-hosted, licensed platform - there is no free or metered SaaS tier. Instead you get a full 30-day proof-of-concept in your own environment before you commit.

Is there a minimum?

Yes - $3,000 (Essentials), $5,000 (Platform) or $9,000 (Enterprise) per year. The floor covers the on-prem support and onboarding every deployment needs; small teams bill at the floor until seat count grows past it.

Are these annual prices?

The per-developer rate is shown per month but billed annually and paid upfront. Multi-year commitments and 100+ seats earn a 15-25% discount. A perpetual licence plus maintenance is available for government buyers.

Do the prices change by region?

These are illustrative list prices for the local market. Regional pricing and local-currency invoicing are available - contact us for a written quote for your scope.

An exact quote for your scope

Tell us your developer count, edition and whether you need air-gap - you get an exact price and a 30-day PoC in your own environment.