Pricing
Simple, transparent
pricing.
Free to start. Pay only when you need more. No subscriptions unless they add ongoing value.
- TLS & HTTPS check
- Security headers analysis
- Cookie flag audit
- CORS policy check
- AI key detection
- Shareable report link
Additional scanner capabilities may come later — nothing is scoped or priced yet.
- Full Nessus CSV analysis
- CISA KEV enrichment
- FIRST EPSS enrichment
- Composite risk scoring
- SLA compliance tracking
- Exception register
- SOC 2 audit evidence
- ISO 27001 audit evidence
- HTML report export
- JSON output + CI gate
- Local scan history
- Unlimited scans
Team/workflow capabilities are being explored for later — not decided or priced yet. Follow along on the Early Access page →
Common questions
Is the free Web Scanner really unlimited?
The free surface scan is rate-limited per IP to prevent abuse, but there is no daily cap for normal usage.
Will there be paid tiers later?
Possibly, for capabilities that need ongoing infrastructure or team/organization features. Nothing beyond what's listed above is built or priced yet — see Early Access for where that stands.
Can I self-host VulnPilot?
Yes. VulnPilot is MIT licensed. Install it anywhere, run it air-gapped, modify it — no restrictions.
What data do you store?
The Web Scanner stores scan results briefly for sharing. VulnPilot stores nothing on our servers — all data lives on your machine.