01 / SUBSCRIPTION PLANS

Flexible Security Subscriptions

Choose the subscription that fits your security needs. Each plan offers tiered limits you can scale as your program grows. Mix and match across categories for full-spectrum coverage.

External Pentest & ASM

Everything an attacker can see from the outside. Continuous external penetration testing combined with always-on attack surface management — discover and test your internet-facing infrastructure around the clock.

Every tier includes
  • External penetration testing
  • Continuous attack surface monitoring
  • Multi-engine reconnaissance & scanning
  • Dark web exposure monitoring
  • Real-time alerting on new exposures
  • Validated findings with proof-of-concept
  • Compliance-ready reporting (PCI DSS, SOC 2)
  • On-premise deployment available
Choose your scope
Scope is measured in root domains monitored and live assets (IPs or subdomains) tested. Every external subscription includes continuous monitoring of your domains — new exposures are discovered and tested as they appear, not at the next scheduled scan.
01 / Tier

Starter

  • Up to 2 TLDs
  • Up to 10 IPs/Subdomains
Best for

A focused internet footprint — a website, mail, VPN, and a handful of cloud services under one or two domains.

2 domains 10 assets
02 / Tier

Growth

  • Up to 3 TLDs
  • Up to 20 IPs/Subdomains
Best for

Growing perimeters — several products or brands, staging environments, and cloud infrastructure that changes month to month.

3 domains 20 assets
03 / Tier

Scale

  • Up to 4 TLDs
  • Up to 50 IPs/Subdomains
Best for

Established estates across teams and acquisitions — including the infrastructure nobody remembers deploying.

4 domains 50 assets
Limits reset on the 1st of each month. Retesting previous findings is always free.
Free retesting on all subscriptions
SSO included at every tier

Internal Penetration Testing

What an attacker does once they're inside. Simulate insider threats and test your internal network defenses — from Active Directory attacks to lateral movement and privilege escalation.

Every tier includes
  • Internal network penetration testing
  • Active Directory attack simulation
  • Lateral movement & privilege escalation
  • Network segmentation assessment
  • Validated findings with proof-of-concept
  • Compliance-ready reporting
  • Detailed remediation guidance
  • On-premise deployment available
Choose your scope
Scope is the number of live internal IPs tested each month. No minimum asset count — start as small as your network actually is.
01 / Tier

Starter

  • Up to 100 IPs
Best for

A single site or small segmented network — one Active Directory domain, a server room or a small cloud VPC.

100 IPs
02 / Tier

Growth

  • Up to 250 IPs
Best for

Multi-site or hybrid networks — branch offices, VPN users, and a growing Active Directory forest.

250 IPs
03 / Tier

Scale

  • Up to 500 IPs
Best for

Complex estates — multiple domains and forests, data centers, and segmented environments that need regular lateral-movement testing.

500 IPs
Limits reset on the 1st of each month. Retesting previous findings is always free.
Free retesting on all subscriptions
SSO included at every tier

Web Application Testing

Deep security testing for your web applications, APIs, and modern frameworks — metered by logical application, not by hostname. Each application is tested continuously all year long, with unlimited free retests. Go beyond scanners with AI-driven exploitation.

Every tier includes
  • Web application penetration testing
  • Metered by logical application, not per hostname
  • Continuous testing — 12 assessments/year per app
  • Full OWASP Top 10 coverage & beyond
  • REST API, GraphQL & WebSocket testing
  • Authentication & authorization testing
  • MFA, magic-link & 2FA login flows handled
  • Black-box, grey-box or white-box — your choice
  • SPA & modern framework support
  • CI/CD pipeline integration
  • Validated findings with proof-of-concept
  • Compliance-ready reports: SOC 2, ISO 27001, PCI DSS, HIPAA
  • On-premise deployment available
Choose your scope
One application means one authentication boundary and one codebase — no matter how many hostnames it runs on. app.example.com, admin.example.com, and api.example.com sharing a single codebase count as one application. A Complex application — 4 or more roles, cross-tenant isolation testing, or cardholder/PHI data in scope — uses two slots.
01 / Tier

Standard App

  • 1 application slot
Best for

Single-tenant applications with straightforward workflows — dashboards, customer portals, and CRUD-style SaaS with up to 3 user roles behind one authentication boundary.

Includes
  • + One auth boundary, one codebase — any number of hostnames
  • + Every role authenticated & tested (up to 3)
  • + 12 assessments across the year — continuous, not point-in-time
  • + Unlimited free retests with automated verification
Uses 1 slot Up to 3 roles
02 / Tier

Complex App

  • 2 application slots
Best for

Applications where authorization is the attack surface — multi-tenant SaaS, 4 or more user roles, or cardholder data / PHI in scope.

Everything in Standard, plus
  • + Full role-matrix authorization testing — every role pair
  • + Cross-tenant isolation testing
  • + Cardholder data & PHI handling in scope (PCI DSS / HIPAA)
  • + Deeper business-logic & workflow-abuse coverage
Uses 2 slots 4–6 roles
Each application slot is tested continuously across the year — 12 assessments plus unlimited free retests. Complex applications use two slots.
Add-on test packs

Need extra capacity? One-off test packs don't count against your continuous application slots — use them as a flexible buffer when demand spikes.

Single
1 web app test
Contact Sales →
3-Pack
3 web app tests
Contact Sales →
5-Pack
5 web app tests
Contact Sales →
10-Pack
10 web app tests
Contact Sales →
Free retesting on all subscriptions
SSO included at every tier
FAQ

Frequently asked questions

Each subscription category (External & ASM, Internal, Web Application) offers multiple tiers based on scope. Pick the tier that matches your current environment size. You can upgrade tiers at any time as your testing needs grow.

For External and Internal subscriptions, your testing limits reset on the 1st of each month. For example, if you subscribe to the 100 IP internal tier, you can test up to 100 IPs each month. The following month, your limit resets and you can test another 100 IPs.

Your Web Application subscription is a number of application slots. A Standard application uses one slot; a Complex application uses two. Each covered application is tested continuously across the whole year — 12 assessments per app, plus unlimited free retests. Stack as many slots as you need to cover your portfolio, or contact us for a custom Enterprise scope.

One application is one authentication boundary and one codebase — regardless of how many hostnames it runs on. If app.example.com, admin.example.com, and api.example.com all share a single codebase, that is one application, not three. Most vendors meter per hostname; we meter per logical application, so you are not charged multiple times for the same code.

An application is Complex if any of the following apply: it has 4 or more distinct user roles, it is multi-tenant and requires cross-tenant isolation testing, or it handles cardholder data or PHI. Complex applications use two slots rather than one, because authorization testing scales with the square of the number of roles and multi-tenant isolation testing doubles the matrix again. Applications beyond roughly 6 roles, or that need a bespoke test design, are scoped as Enterprise.

One-Off Test Packs are point-in-time web application tests, purchased separately from your continuous application slots. They are a flexible buffer for when demand spikes — for example, if you cover 5 applications on your annual subscription but need to test 2 extra apps before a product launch, you can purchase a pack without changing your annual commitment.

Yes. Retesting previous findings is free across all subscription categories and tiers. Once a vulnerability is identified, you can retest it as many times as needed without consuming your monthly limits or application slots.

Absolutely. Each subscription covers a specific testing domain. You can subscribe to one, two, or all three depending on your security needs. Each subscription has its own independent limits.

Yes. Canima uses safe exploitation techniques designed for production environments. Our AI agents understand the difference between demonstrating a vulnerability and causing disruption. You can configure risk tolerance levels per engagement.

02 / GET STARTED

Ready to get started? Let's talk.

Schedule a demo to see Canima in action and find the right subscription for your security needs.

  • Free security consultation
  • Custom tier recommendations for your environment
  • 7-day demo environment access
  • Flexible annual subscriptions