Services & pricing

One rate card.
No quote request required.

Three depths of access, each priced up front. Pick by how much of the inside you're willing to show us — the more we see, the more we find, and the faster we find it.

Blackbox

We start with nothing but a domain name — no credentials, no documentation, no source. This is what an opportunistic outside attacker sees, and what they'd try first.

Graybox — DAST

Dynamic Application Security Testing. You give us working logins for each role in the application, and we test it from the inside — the access level of a real user or a compromised account.

Whitebox — SAST

Static Application Security Testing. You give us read access to the source repository. We trace vulnerabilities to the exact function and line, not just the symptom.

Rate card

All figures in PHP. One-time engagements are short, fixed-scope; monthly and annual are standing retainers.
Onetime — short engagement Blackbox Graybox (DAST) Whitebox (SAST)
1 domain + all subdomains ₱400,000 ₱550,000
Each additional domain ₱40,000 ₱40,000
What's included Scanning with customizations for your environment. Code repository access provided by you. Source code scanning included.
Timeline 1 week 2 weeks
Applications covered 1–30 1–10
Retainer Blackbox Graybox (DAST) Whitebox (SAST)
Monthly ₱45,000 ₱59,000
Annual ₱540,000 ₱708,000

Retainers cover continuous testing on the same scope as the tier's onetime engagement. Larger scopes, additional applications beyond the ranges above, or combined tiers are quoted directly — email us the details.

Not sure which tier fits?

Tell us how many applications you run and whether you can share credentials or source — we'll recommend a tier.

Book an assessment