Services & pricing
Three depths of access, each priced up front. Pick by how much of the inside you're willing to show us — the more we see, the more we find, and the faster we find it.
We start with nothing but a domain name — no credentials, no documentation, no source. This is what an opportunistic outside attacker sees, and what they'd try first.
Dynamic Application Security Testing. You give us working logins for each role in the application, and we test it from the inside — the access level of a real user or a compromised account.
Static Application Security Testing. You give us read access to the source repository. We trace vulnerabilities to the exact function and line, not just the symptom.
| Onetime — short engagement | Blackbox | Graybox (DAST) | Whitebox (SAST) |
|---|---|---|---|
| 1 domain + all subdomains | ₱400,000 | ₱450,000 | ₱550,000 |
| Each additional domain | ₱40,000 | ₱40,000 | ₱40,000 |
| What's included | Scanning with customizations for your environment. | Credentials provided by you. Testing is thorough across every authenticated role. | Code repository access provided by you. Source code scanning included. |
| Timeline | 1 week | 1–2 weeks | 2 weeks |
| Applications covered | 1–30 | 1–20 | 1–10 |
| Retainer | Blackbox | Graybox (DAST) | Whitebox (SAST) |
| Monthly | ₱45,000 | ₱50,000 | ₱59,000 |
| Annual | ₱540,000 | ₱600,000 | ₱708,000 |
Retainers cover continuous testing on the same scope as the tier's onetime engagement. Larger scopes, additional applications beyond the ranges above, or combined tiers are quoted directly — email us the details.
Tell us how many applications you run and whether you can share credentials or source — we'll recommend a tier.
Book an assessment