Don't let security
slow you down.

Choose your pen test tier.

Startup

$4,000/test

Up to 500k billable lines of code. Ideal for a single primary surface — a web app or API with a focused attack surface.

Schedule a call

Comparable to a focused 2-week manual pentest.

Scale

$12,000/test

500k to 2M billable lines of code. Ideal for a product spanning multiple surfaces — web, large APIs, mobile, CLI, and MCP servers.

Schedule a call

Comparable to a broader 4-week manual pentest.

Enterprise

Custom

2M+ billable lines of code. Ideal for organizations with many applications spanning every surface — web, API, mobile, CLI, MCP, and internal tooling.

Schedule a call

Comparable to ongoing coverage from a larger security testing team.

Add-on

Managed Remediation

Your findings, remediated and verified by Trace.

Our security engineers understand your CI/CD, scope the work, ship the fixes as reviewed pull requests, and re-test every finding on your pre-production stack to confirm the exploit is gone.

Get a quote
My team stayed focused on the product. Trace's engineers remediated the findings end to end and confirmed nothing was still exploitable.
Madhu G Nadig
Madhu G Nadig
Co-Founder & CTO
Flagright

Frequently asked questions

A whitebox pen test means we test with full visibility into your systems, including source code, cloud configuration, and architecture, instead of probing from the outside like a traditional "blackbox" test. That access lets Trace find real, high-impact vulnerabilities and pinpoint the exact code behind each one.

Trace tests your web applications, APIs, authentication flows, CLIs, MCP servers, AI chat, webhooks, and third-party integrations for real vulnerabilities like SQL injection, broken auth, SSRF, XSS, and more. Every finding includes proof of exploitation.

Have a different surface? Let us know and we’ll work with you to ensure coverage.

Tiers are sized by billable source lines of code (SLOC): first-party application code that contains something other than whitespace or a comment. We don’t count test code, configuration and data files, documentation, or generated and vendored code — only the handwritten code we actually test for vulnerabilities. It’s the same way Sonar counts LOC for licensing, and you can reproduce the number in seconds with an open-source counter like scc.

Yes. Trace pen test reports can be used to satisfy SOC 2, ISO 27001, or HIPAA requirements.

No. AI handles the testing at scale, but a certified security engineer reviews every finding before the report reaches you, so you get automated speed with human-verified accuracy.

Most pen tests are completed within a few days depending on scope. For teams that want ongoing coverage, we offer continuous testing options that re-test your applications as they evolve.

Trace performs whitebox testing, so we ask for as much access as possible. At a minimum, your GitHub repos and a staging URL or production environment.