Honest security & compliance for SaaS

Three honest services. One report your auditor accepts.

Automated assessment at $1,999/yr. Real human pen test at $4,999 flat. SOC 2 readiness in 90 days from $5,999. Every deliverable says exactly what we did — and what we didn't. So your auditor, prospect, and procurement team all get the same straight answer.

PDF in your inbox in 3 min No sales call Upgrade only if you want more

An automated scan when that's what you need. A real pen test when that's what you need. SOC 2 readiness when the audit deadline is what you need. We're explicit about which is which — and we charge accordingly.

Automated
Security Assessment

Toolchain-based scan against your application. Headers, TLS, known CVEs, exposed surfaces. Annual artifact for vendor questionnaires.

$1,999 / year · learn more →
Most teams pick this
Continuous · bundle
Continuous Security

Automated + 1 pen test + 1 retest per year. Predictable monthly, save vs à la carte.

$999 / mo · $9,999 / yr · learn more →
Penetration test
Penetration Testing

Senior engineer + engine probe for IDOR, business logic, auth bypass, chained exploits. Sequential-ID fuzzing, user-enum probing, narrative report with Burp-style evidence, signed Remediation Report after retest.

$4,999 / engagement · learn more →
Need a SOC 2 Type I report? 90-day SOC 2 readiness from $5,999 →

The risk isn't theoretical. The numbers say so.

Independent industry data on the vulnerability and breach landscape. These are the facts your customers and auditors are already reading.

38,000+
CVEs published in 2024
$4.88M
Average cost of a data breach (2024)
277d
Median time to identify + contain
10,000+
Vulnerability templates in our toolchain

Three documents. The same format serious firms use.

01 / ASSESSMENT

Findings Report

Executive summary, findings by severity, evidence captures, remediation steps. Modeled on the structure established pen testing firms use. PDF, ready to forward to your team.

View sample
02 / ATTESTATION

Verification Document

One-page PDF you can share with prospects. Public verification URL with QR code. Scope and methodology stated honestly so nobody is misled.

View sample
03 / REMEDIATION

Re-scan Confirmation

After you fix the findings, request a re-scan. Get a follow-up report showing what's now clean. Included in every plan, no surcharge.

Learn more

This is the part nobody else shows you.

A clear table of what automated scanning can — and can't — detect. Use it to decide what level of testing you actually need.

Vulnerability class CyberGrid finds it Needs manual pen test
Missing security headers
CSP, HSTS, X-Frame-Options, cookie flags
✓ Yes — optional
TLS / cipher misconfiguration
Weak ciphers, expired certs, deprecated protocols
✓ Yes — optional
Exposed admin panels & secrets
.env files, .git folders, debug endpoints
✓ Yes — optional
Known CVEs in your stack
Outdated libraries, vulnerable plugins, dependency CVEs
✓ Yes — optional
Verbose error / stack trace disclosure
Information leakage in error responses
✓ Yes — optional
IDOR / broken access control
User A reading User B's data
✗ No ! Required
Business logic flaws
Coupon abuse, race conditions, workflow bypasses
✗ No ! Required
Authenticated session attacks
Privilege escalation, complex auth bypasses
✗ No ! Required
→ Compare honestly

What should your pen test actually cost?

Same scope can come back at $2,999 from a boutique and $45,000 from a Big-4. Use our calculator: tell it your app type, scope, and compliance driver, see the real industry range — and where our $4,999 flat fee fits.

Open the calculator

We name the actual tools we run. So can you.

Every report lists each tool used by name and version. No black-box claims. If a customer asks "what did you actually run?", we have a clear answer.

Web application surface

Template-driven vulnerability scanning

Detects exposed paths, known CVEs, common misconfigurations, header issues, and information disclosure across your application's public surface.

nuclei v3.3 httpx v1.6 OWASP ZAP
Transport security

TLS configuration audit

Cipher suites, certificate chain, protocol versions, HSTS configuration, and known TLS vulnerabilities. Catches deprecated protocols still enabled.

testssl.sh v3.2 tls-scan
External perimeter

Subdomain & port discovery

Subdomain enumeration, exposed services, port-level fingerprinting. Identifies forgotten endpoints, shadow infrastructure, and orphaned hosts.

nmap v7 subfinder dnsx
Reporting & attestation

Standardized output

Findings normalized to a common severity scale (Critical / High / Medium / Low / Informational). PDF report with evidence, remediation, and a verifiable attestation page.

Puppeteer OWASP severity CVSS v3
Read the full methodology

Sign-up to attestation in under 24 hours.

01  /  Verify

Verify your domain

Add a DNS TXT record we generate. Confirms you own what we're about to scan.

~5 minutes
02  /  Schedule

Schedule your scan

Pick an immediate or off-hours window. We respect your traffic and rate-limit.

instant
03  /  Scan

Scan runs

Our worker runs the toolchain against your target. Live progress in your dashboard.

30–90 minutes
04  /  Receive

Report & attestation

PDF report in your inbox. Attestation with verification URL ready to share.

within 24 hours

Look at exactly what you'd actually receive.

From founders who needed an answer to "do you pen test?"

"

We were six months in, a $50k ARR contract on the line, and the buyer asked for a security testing artifact. CyberGrid had a real attestation in our prospect's inbox the next morning. Closed the deal.

M
Mara Holloway
Founder · ledgerfox.io
"

The honest framing is the whole reason we picked them. I'm not going to pretend a $1,999 scan is a pen test, and my customers respect that I don't. Other vendors made me uncomfortable with what they were claiming.

J
Jules Park
CTO · stratum (Series A)
"

Caught a misconfigured S3 CORS policy and a stack trace leak our team missed for a year. Two real findings on the first scan. Both fixed before the report PDF generated.

D
Devi Annamalai
Eng Lead · plinth.app
"

SOC 2 auditor asked for our most recent pen test on a Tuesday. We had a kickoff call Wednesday, scoped Thursday, and the engagement was running Monday. Report a week later. The compliance-mapping appendix dropped straight into our auditor's evidence file.

R
Reuben Castillo
Head of Eng · helix-ops.io
"

Found a real IDOR in our billing endpoint — cross-tenant data access — that our own QA had missed for eighteen months. PoC was reproducible in five steps. Patched same-day. Worth the $4,999 a hundred times over.

A
Aoife Brennan
CTO · clemenza.tech
"

The procurement package — NDA, MSA, DPA, SoW, pre-filled security questionnaire — saved us literal weeks. Our legal team signed the templates as-is. First time that's happened with a vendor.

S
Sven Kowalski
VP Engineering · northbridge-data.io
"

SOC 2 readiness in eight weeks instead of six months. They scoped exactly what we needed, did the gap analysis, ran the pen test, and handed our auditor a binder. The CPA they referred us to closed Type I without a single follow-up question.

P
Priya Ramaswamy
COO · meridian-billing.io
"

Continuous caught a regression three days after we shipped a new auth flow — an unauthenticated endpoint exposed by a stale rewrite rule. We'd never have found it before our next annual pen test. Worth $999 a month on that incident alone.

T
Tomás Vega
Head of Platform · ravenstack.io
"

Did our iOS + Android pen test for one fixed price. Found a hardcoded API token in the Android binary and a TLS pinning bypass via Frida. Both report-ready, both reproducible. We patched and shipped in the same sprint.

N
Naomi Iqbal
Mobile Eng Lead · finchpay.app

Three ways to buy. Same honest testing.

Automated Assessment
$1,999
per year · all-in

Quarterly scans + public attestation. The right floor for any team that needs an audit-ready artifact.

  • Up to 3 web targets · 4 scans/yr
  • All scan profiles · unlimited re-scans
  • PDF report + public attestation
  • Compliance-mapped (SOC 2 / ISO / PCI / HIPAA)
Start a scan — $1,999/yr
Penetration Test
$4,999
per engagement · $1,999 retest

One-off pen test. A senior engineer, manually, methodology-based. The real thing.

  • Single web app or API in scope
  • Manual exploitation + chained exploits
  • IDOR, authz, business logic, auth bypass
  • NDA + SoW at kickoff · 5–10 day turn
Request a pen test — $4,999
See the full comparison
Service 04 · Compliance program

Need a SOC 2 report, not just a scan?

Our SOC 2 readiness service is a full 90-day program: policy library, control implementation, evidence collection, GRC tooling setup, and a referred CPA audit firm to issue your Type I report. Bundle with the pen test below for a complete compliance posture.

$5,999 · Starter (≤25 staff)
$9,999 · Standard (25-100)
90 days · to audit-ready
See the SOC 2 program
CPA audit fees billed separately

Things buyers ask before they sign up.

Is this really a penetration test?

The $1,999 automated assessment isn't one, and we'd never call it one — it runs scanners (nuclei, httpx, testssl.sh) and finds a defined subset of issues. We also offer a separate penetration testing service ($4,999 flat) for the things scanners genuinely can't find: IDORs, business logic, authentication bypass, chained exploits. See /penetration-testing. Both are useful, clearly labeled, and we never call one the other.

Will this satisfy a SOC 2 audit?

For some auditors and some risk classifications, an automated assessment is acceptable. For others — especially anything customer-data-adjacent — you'll need a real pen test. We don't promise SOC 2 acceptance because that decision is between you and your auditor. We do give you a clear, documented artifact you can show them.

What if you find a critical vulnerability?

We email you immediately — we don't wait for the report. You get the finding details, remediation steps, and free re-scans until it's fixed. We never publish or share findings; they're yours alone.

Will the scan break my application?

Our default profile is non-destructive — no fuzzing of inputs that could cause data corruption, no DoS-style traffic spikes. We rate-limit to 50 requests per second and you can schedule scans for off-hours. That said, any active scanning carries some risk of triggering rate limiters, WAFs, or unusual error paths, which is why our Service Agreement includes the same disclaimer every reputable scanner uses.

What's the difference between you and Astra / Intruder / Detectify?

Those are continuous monitoring products at $150–300/month. CyberGrid is quarterly point-in-time at $1,999/year — flat, no tiers. Better fit if you want clean dated artifacts and a real pen-test option from the same vendor; worse fit if you want continuous monitoring. We're also more direct about scope limitations — we publish a public "what we catch / what we miss" table on the homepage, which the bigger players don't do.

Can I share the attestation publicly?

Yes. Every attestation has a public verification URL anyone can visit to confirm it's real, see what scope was tested, and read the methodology. The verification page is plain about what was and wasn't included — that protects everyone involved.

What happens if I want to cancel?

Cancel anytime from your dashboard. Plans don't auto-renew unless you choose. If you cancel mid-year, you keep access to your reports and attestations indefinitely — they're yours.

→ Ready when you are

An honest scan beats a vague promise.

Get your application assessed, your report in 24 hours, and an attestation you can hand to anyone asking about your security posture.