Don't let security
slow you down.
Choose your pen test tier.
Startup
Up to 500k billable lines of code. Ideal for a single primary surface — a web app or API with a focused attack surface.
Schedule a callComparable to a focused 2-week manual pentest.
Scale
500k to 2M billable lines of code. Ideal for a product spanning multiple surfaces — web, large APIs, mobile, CLI, and MCP servers.
Schedule a callComparable to a broader 4-week manual pentest.
Enterprise
2M+ billable lines of code. Ideal for organizations with many applications spanning every surface — web, API, mobile, CLI, MCP, and internal tooling.
Schedule a callComparable to ongoing coverage from a larger security testing team.
Managed Remediation
Your findings, remediated and verified by Trace.
Our security engineers understand your CI/CD, scope the work, ship the fixes as reviewed pull requests, and re-test every finding on your pre-production stack to confirm the exploit is gone.
Get a quoteMy team stayed focused on the product. Trace's engineers remediated the findings end to end and confirmed nothing was still exploitable.

Frequently asked questions
What is a whitebox pen test?
A whitebox pen test means we test with full visibility into your systems, including source code, cloud configuration, and architecture, instead of probing from the outside like a traditional "blackbox" test. That access lets Trace find real, high-impact vulnerabilities and pinpoint the exact code behind each one.
What does the pen test cover?
Trace tests your web applications, APIs, authentication flows, CLIs, MCP servers, AI chat, webhooks, and third-party integrations for real vulnerabilities like SQL injection, broken auth, SSRF, XSS, and more. Every finding includes proof of exploitation.
Have a different surface? Let us know and we’ll work with you to ensure coverage.
How do you decide which tier I need?
Tiers are sized by billable source lines of code (SLOC): first-party application code that contains something other than whitespace or a comment. We don’t count test code, configuration and data files, documentation, or generated and vendored code — only the handwritten code we actually test for vulnerabilities. It’s the same way Sonar counts LOC for licensing, and you can reproduce the number in seconds with an open-source counter like scc.
Is this suitable for SOC 2, ISO 27001, or HIPAA?
Yes. Trace pen test reports can be used to satisfy SOC 2, ISO 27001, or HIPAA requirements.
Is it fully automated?
No. AI handles the testing at scale, but a certified security engineer reviews every finding before the report reaches you, so you get automated speed with human-verified accuracy.
How fast do I get my report?
Most pen tests are completed within a few days depending on scope. For teams that want ongoing coverage, we offer continuous testing options that re-test your applications as they evolve.
What do I need to prepare?
Trace performs whitebox testing, so we ask for as much access as possible. At a minimum, your GitHub repos and a staging URL or production environment.