Don't let security
slow you down.

Choose your pen test tier.

Startup

$4,000/test

Up to 500k billable lines of code. Ideal for a single primary surface — a web app or API with a focused attack surface.

Get started

Comparable to a focused 2-week manual pentest.

Scale

$12,000/test

500k to 2M billable lines of code. Ideal for a product spanning multiple surfaces — web, large APIs, mobile, desktop apps, CLI, and MCP servers. Includes PCI compliance coverage.

Get started

Comparable to a broader 4-week manual pentest.

Enterprise

Custom

2M+ billable lines of code. Everything in Scale, including desktop apps and PCI, for organizations with many applications, internal tooling, and custom compliance needs.

Schedule a call

Comparable to ongoing coverage from a larger security testing team.

Add-on

Managed Remediation

Your findings, remediated and verified by Trace.

Our security engineers understand your CI/CD, scope the work, ship the fixes as reviewed pull requests, and re-test every finding on your pre-production stack to confirm the exploit is gone.

Get a quote
My team stayed focused on the product. Trace's engineers remediated the findings end to end and confirmed nothing was still exploitable.
Madhu G Nadig
Madhu G Nadig
Co-Founder & CTO
Flagright

Frequently asked questions

A whitebox pen test means we test with full visibility into your systems, including source code, cloud configuration, and architecture, instead of probing from the outside like a traditional "blackbox" test. That access lets Trace find real, high-impact vulnerabilities and pinpoint the exact code behind each one.

Trace tests your web applications, APIs, authentication flows, desktop apps, CLIs, MCP servers, AI chat, webhooks, and third-party integrations for real vulnerabilities like SQL injection, broken auth, SSRF, XSS, and more. Every finding includes proof of exploitation.

Have a different surface? Let us know and we’ll work with you to ensure coverage.

Tiers are sized by billable source lines of code (SLOC): first-party application code that contains something other than whitespace or a comment. We don’t count test code, configuration and data files, documentation, or generated and vendored code — only the handwritten code we actually test for vulnerabilities. It’s the same way Sonar counts LOC for licensing, and you can reproduce the number in seconds with an open-source counter like scc.

Yes. Trace pen test reports can be used to satisfy SOC 2, ISO 27001, or HIPAA requirements. Scale and Enterprise tiers also include PCI compliance coverage.

No. AI handles the testing at scale, but a certified security engineer reviews every finding before the report reaches you, so you get automated speed with human-verified accuracy.

Most pen tests are completed within a few days depending on scope. For teams that want ongoing coverage, we offer continuous testing options that re-test your applications as they evolve.

Trace performs whitebox testing, so we ask for as much access as possible. At a minimum, your GitHub repos and a staging URL or production environment.