Clear, transparent pricing trusted by 1000+ businesses

Offensive DAST vulnerability scanner that scans behind login for 15,000+ test cases like OWASP Top 10, ports, CVEs & more

LIMITED OFFER

Try DAST Scanner for a full week — just $7

Get platform access · No credit card commitment · Cancel anytime

Start $7 Trial

BEST FOR SMALL TEAMS
Scanner Lite
Schedule monthly vulnerability scans

$69/m

Astra
1 Target

Here's how the target is defined

Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.

If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.

Astra
Supported for
15,000+ test cases
3 vulnerability scans a month
Authenticated scanning
1 Integration (Slack, Jira, CI/CD etc.)
Vulnerability management console
Auto re-scan after fixes
AI fix assistance
Email support
⭐ Popular
BEST FOR SMALL TEAMS
Scanner
Unlimited security scans at dev speed

$199/m

1 Target

Here's how the target is defined

Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.

If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.

Supported for
All Scanner Lite features, plus
Unlimited vulnerability scans
4 vetted scans (annual billing)
Unlimited integrations
BEST FOR SMALL TEAMS
Scanner Agency
Unlimited scans on a rotating pool

$499/m

5 Target Pool

Target

You get 5 target slots, with the ability to change targets in those slots with a 30-day cooling period. Example: Scan 5 targets, after 30 days scan 5 new targets.

Target Explained: Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, website, API etc. If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.

Get Started
Supported for
All Scanner features, plus
5-target pool, swap every 30 days
4 expert vetted scans (any billing)
Customer success manager
LIMITED OFFER

Try DAST Scanner for a full week — just $7

Get platform access · No credit card commitment · Cancel anytime

Start $7 Trial

BEST FOR SMALL TEAMS
Scanner Lite
Schedule monthly vulnerability scans

$699/yr

Astra
1 Target

Here's how the target is defined

Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.

If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.

Astra
Supported for
15,000+ test cases
3 vulnerability scans a month
Authenticated scanning
1 Integration (Slack, Jira, CI/CD etc.)
Vulnerability management console
Auto re-scan after fixes
AI fix assistance
Email support
⭐ Popular
BEST FOR SMALL TEAMS
Scanner
Unlimited security scans at dev speed

$1999/yr

1 Target

Here's how the target is defined

Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, IP, website, API etc.

If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.

Supported for
All Scanner Lite features, plus
Unlimited vulnerability scans
4 vetted scans (annual billing)
Unlimited integrations
BEST FOR SMALL TEAMS
Scanner Agency
Unlimited scans on a rotating pool

$4999/yr

5 Target Pool

Target

You get 5 target slots, with the ability to change targets in those slots with a 30-day cooling period. Example: Scan 5 targets, after 30 days scan 5 new targets.

Target Explained: Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, website, API etc. If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned.

Get Started
Supported for
All Scanner features, plus
5-target pool, swap every 30 days
4 expert vetted scans (any billing)
Customer success manager
For Partners

Think your customers would love Astra too? Let's join forces.

Perfect for
Compliance platforms
MSSPs
Insurance providers
Auditors

Hacker-style pentest by Autonomous AI & certified experts at dev speed, built to meet & exceed
SOC2, ISO, & HIPAA requirement

BEST FOR SMALL TEAMS
Pentest Auto
1 Target

One web or SaaS app counts as one target, including all APIs consumed.
Mobile is per platform, so an Android app and an iOS app are two targets
Networks, cloud, IPs and standalone APIs are 1 target each

Hacker style autonomous pentest at machine speed

$2999/yr

$199/mo

Astra
1 Target
Astra
Astra
A target is a URL that will be tested by our vulnerability scanner. It can be the URL of a web application, website, API etc.

If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.

Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.

Click the 🛈 icon to know more.
Pentest for SOC2, ISO 27001, HIPPA etc.
Supported for
Real-world attack simulation
Vulnerability management console
Role based graybox pentest
AI auto-fixes
Trust Center
1 human re-scan
Email support
1 Integration
⭐ Popular
BEST FOR SMALL TEAMS
Pentest Expert
1 Target

One web or SaaS app counts as one target, including all APIs consumed.
Mobile is per platform, so an Android app and an iOS app are two targets
Networks, cloud, IPs and standalone APIs are 1 target each

Offensive pentests by certified pentesters & autonomous agents

$5999/yr

Pentest for SOC2, ISO 27001, HIPPA etc.
Supported for
All Pentest Auto features, plus
Manual pentest by certified experts
CREST, PCI-ASV, CERT-IN reports
Unlimited web DAST scans
AI component pentesting
2 human re-scans
Customer success manager
Unlimited integrations
BEST FOR SMALL TEAMS
Enterprise
Autonomous testing & certified pentesters, tailored to your infra

$9999/yr onwards

Run a world class continuous pentest program.
Supported for
All Pentest Expert features, plus
Security consulting
On-premise deployment
Private cloud instance
Custom SLA & payment terms
Voice on roadmap
Custom workspace management
ScannER

$999/yr

$75/mo effectively
Astra
1 Target
Astra
A target is a URL that will be tested by our vulnerability scanner. It can be the URL of a web application, website, API etc.

If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.

Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.

Know More
Get Started
tick

Weekly vulnerability scans with 3000+ tests (OWASP, SANS etc.)

tick

Essential features like pentest dashboard, PDF reports and scan behind login

For Partners

Think your customers would love Astra too? Let's join forces.

Perfect for
Compliance platforms
MSSPs
Insurance providers
Auditors

Continuously discover & scan every API in your infrastructure for broken access control, authorization flaws, OWASP Top 10 & more

BEST FOR SMALL TEAMS
API DAST Scanner
Scheduled DAST scans on your API spec file

$199/m

$199/mo

1 Target
A target is a URL that will be tested by our vulnerability scanner. It can be the URL of a web application, website, API etc.

If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.

Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.

Click the 🛈 icon to know more.
15,000+ authenticated test cases
20 scans a month
CI/CD, JIRA & Slack
Auto re-scan after fixes
Full & management PDF reports
Email support
Extra scans at $10
⭐ Popular
BEST FOR SMALL TEAMS
API Security Pro
Continuous API discovery and scans               

$499/m

All API DAST Scanner features, plus
60 scans a month
Live API traffic capture
Continuous observability & inventory
Adds CSV & JSON reports
Orphan, shadow, zombie APIs
BEST FOR SMALL TEAMS
API Enterprise
Discovery and scanning at enterprise scale

Custom

All API Security Pro features, plus
1000+ scans a year
15M+ API requests observed
Tailored test cases
Dedicated account manager
Volume-based scan pricing
BEST FOR SMALL TEAMS
API DAST Scanner
Scheduled DAST scans on your API spec file

$1999/yr

$199/mo

1 Target
A target is a URL that will be tested by our vulnerability scanner. It can be the URL of a web application, website, API etc.

If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.

Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.

Click the 🛈 icon to know more.
15,000+ authenticated test cases
20 scans a month
CI/CD, JIRA & Slack
Auto re-scan after fixes
Full & management PDF reports
Email support
Extra scans at $10
⭐ Popular
BEST FOR SMALL TEAMS
API Security Pro
Continuous API discovery and scans               

$4999/yr

All API DAST Scanner features, plus
60 scans a month
Live API traffic capture
Continuous observability & inventory
Adds CSV & JSON reports
Orphan, shadow, zombie APIs
BEST FOR SMALL TEAMS
API Enterprise
Discovery and scanning at enterprise scale

Custom

All API Security Pro features, plus
1000+ scans a year
15M+ API requests observed
Tailored test cases
Dedicated account manager
Volume-based scan pricing
For Partners

Think your customers would love Astra too? Let's join forces.

Perfect for
Compliance platforms
MSSPs
Insurance providers
Auditors

Astra continuously scans AWS, Azure, and GCP for misconfigs, IAM risks, and vulnerabilities, validating every finding before it reaches you

LIMITED OFFER

Try Cloud Starter for a full week — just $7

Full platform access · AWS, Azure & GCP · No credit card commitment · Cancel anytime

Start $7 Trial

BEST FOR SMALL TEAMS
Cloud Starter
Scan for cloud security misconfigurations across your cloud account

$99/m

$199/mo

1 Target
A target is a URL that will be tested by our vulnerability scanner. It can be the URL of a web application, website, API etc.

If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.

Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.

Click the 🛈 icon to know more.
Supported for
Security misconfigs & IAM checks
1 cloud account
Up to 250 resources
Unlimited automated scans
Auto re-scan after fixes
PDF reports
Validated findings
Unlimited Integrations
Email support
⭐ Popular
ENTERPRISE-READY (CUSTOM)
Cloud Growth
Scheduled multi-account scans with control mapping

$199/m

Supported for
All Cloud Starter features, plus
3 cloud accounts
Up to 1000 resources
Scheduled scans
Control mapping
JSON & management reports
BEST FOR LARGE TEAMS
Cloud Enterprise
Multi-cloud and hybrid scanning at enterprise scale

Custom

Supported for
All Cloud Growth features, plus
Multi-cloud & hybrid
Unlimited resources
Continuous scan scheduling
Custom dashboards
Customer Success Manager
LIMITED OFFER

Try Cloud Starter for a full week — just $7

Full platform access · AWS, Azure & GCP · No credit card commitment · Cancel anytime

Start $7 Trial

BEST FOR SMALL TEAMS
Cloud Starter
Automated configuration scans on your cloud account

$999/yr

$199/mo

1 Target
A target is a URL that will be tested by our vulnerability scanner. It can be the URL of a web application, website, API etc.

If your website makes API calls to different domains, you can add them as an extra host without having to purchase another domain.

Let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets.

Click the 🛈 icon to know more.
Supported for
Security misconfigs & IAM checks
1 cloud account
Unlimited automated scans
Up to 250 resources
Auto re-scan after fixes
PDF reports
Validated findings
Unlimited Integrations
Email support
⭐ Popular
Cloud Growth
ENTERPRISE-READY (CUSTOM)
Scheduled multi-account scans with control mapping

$1999/yr

Supported for
All Cloud Starter features, plus
3 cloud accounts
Up to 1000 resources
Scheduled scans
Control mapping
JSON & management reports
BEST FOR LARGE TEAMS
Cloud Enterprise
Multi-cloud and hybrid scanning at enterprise scale

Custom

Supported for
All Cloud Growth features, plus
Multi-cloud & hybrid
Unlimited resources
Continuous scan scheduling
Custom dashboards
Custom integrations & API
Customer Success Manager
For Partners

Think your customers would love Astra too? Let's join forces.

Perfect for
Compliance platforms
MSSPs
Insurance providers
Auditors

"Astra identified several moderate and high severity issues that our team never thought existed. We are working in the Mental Health space and data privacy and security are extremely critical to us. That being said, I am thankful for their service."

Georgi Atanasov, CTO, Sentur

“A key standout during our Astra Pentest was the solid support via Slack, making communication easy and efficient. The platform itself is user-friendly, and the Jira integration greatly streamlined issue resolution for our team, seamlessly fitting into our existing workflow”

Richard Ganpatsing

"Astra's exceptional manual penetration testing and efficient automated tools have provided invaluable insights into our application's security, making them our trusted partner for comprehensive and reliable security measures"

 Georgi Atanasov

"Astra plugs straight into our agent tooling. Findings come with enough context that my coding agents fix, test, and validate the patch with a human in the loop. For a lean KYC platform, that's the difference between a backlog and a same-day fix."

 Georgi Atanasov

"Astra's autonomous AI testing discovered two vulnerabilities that years of previous penetration tests had missed."

 Georgi Atanasov

"The MCP integration is where Astra pulled ahead of every other pen test vendor we've engaged with. Our engineers pulled findings, repro steps, and fixes straight into their IDE. Triage turned into a few queries in chat. Fixes landed faster because the agent already had full context. Every finding came with detailed repro steps and a real fix. We'd hire them again."

 Georgi Atanasov

Trusted by 1000+ engineering teams

G2 Leader Winter
G2 Most Implementable WInter
G2 Momentum Leader Winter
G2 Best Results Mid Market Winter
BetterDoc
Comptla
mamaearth
Prime Healthcare
coloplast
comptla
How do you define a target for DAST Scanner?
Simply put, a domain with all its site tree URLs is a target. Target can be the URL of a web application, website, API etc. If your website makes API calls to different domains (eg: api.example.com), you can add them as an extra host during setup without having to purchase another target for it, and all calls to api.examples.com from example.com will be scanned too without any additional license required.
However, let's say you have a customer dashboard at https://app.example.com/ and an admin dashboard at https://admin.example.com/ with different login pages, then you will need 2 targets as both will require deep scanning of their own. Learn more here.
Do you offer discounts on multi-year commitments or bundled services?
Yes, we offer favorable pricing on multi-year contracts and bundled offerings. Please feel free to schedule a call so that our sales engineers take a deep dive into your requirements and share a tailored pricing.
Does Pentest (PTaaS) cover specific compliance requirements (e.g., SOC 2, PCI, ISO 27001)?
Yes, our pentest (VAPT) covers requirements of all these compliances. Our pentest reports are recognized by all auditors.
What is the timeline for manual and automated testing, including rescans?
The manual pentest by security experts takes anywhere between 10-15 working days to complete. After you sign-up, you will have instant access to 'Engagement Letter' which certifies that the pentest is on-going. You can use the engagement letter while the pentest is underway.
The automated DAST scans and API vulnerability scans are available on-demand instantly. You can initiate or schedule scans per your convenience.
How do you define a target for Pentest (PTaaS)?
Think of it as bringing security engineers and dev teams together for continuous, agile pentests. It's pentesting that keeps up with your pace.
  • If you have a SaaS app, the entire app with all its APIs and underlying cloud is 1 target.
  • If you have a mobile app, one Android app is considered as one target and one iOS app is considered another target. If they share code base, we offer a tailored pricing starting from $2200/app depending on the scope
  • In case of networks, cloud, IPs and APIs - multiple clouds, IPs, APIs etc. can be clubbed into one target. Please schedule a call for tailored pricing.
What is covered in automated vs manual pentesting/VAPT?
The automated offensive vulnerability scans via our DAST scanner test for 10,000+ vulnerabilities in your application in an automated way by running authenticated automated vulnerability scans.
The manual penetration test by security pentesters goes beyond just automated scans. It covers business logic testing, price manipulation vulnerabilities, authentication and authorization attacks and much more surface area, which often is missed by automated scanners.
Automated scans are good for ongoing security, and maintaining compliance. Manual pentests test your defenses much deeper, and help you achieve compliances like SOC2, ISO27001, HIPAA etc.
How can I validate the fixed vulnerabilities?
If you are going for a Pentest (PTaaS) plan, it comes with 2 rescans by our pentesters to validate the fixes for the vulnerabilities uncovered during the pentest.
If you are considering our DAST Scanner, it comes with a feature to re-scan vulnerabilities individually which you can use to validate fixes instead of having to run in-depth scans again.
Do you work with our developer in patching the vulnerabilities?
Yes, for sure. While we do not fix the vulnerabilities for you, but we assist your developers in fixing the vulnerabilities reported. Your developer can comment under each vulnerability if they have any questions regarding the fixing process. We also have an AI-powered bot that helps with contextual remediation assistance.
Astra

Find & fix every vulnerability with Astra

Astra's continuous pentest platform: PTaaS for expert led pentesting, DAST Scanner for continuous vulnerability detection & API Security Platform for API observability &
vulnerability scanning - all working together to secure your applications.

2 Million+
Vulnerabilities Uncovered
3,000+
Pentests Completed
4.6/5
on G2
Astra
Click here to update your cookies settings