Pricing

Launch realistic attacker simulations that show exactly how your web app could be broken.

Choose a plan based on volume and depth of proof. Every run is operator-launched and scope-controlled.

New users: 30% off for the first 6 months

Starter

For quick, single-target simulations on one critical flow

Free
Always Free · No credit card
3 single-target simulations per month
1 team seat
1 URL target per run
Multi-step attack chains toward account takeover and unauthorized access
Proof of impact with clear steps to reproduce
Safety-first defaults (rate limits and scope checks)
Basic evidence export (PDF)
30-day scan history retention (evidence 7 days)
Community support
CI/CD API access
Full-domain exploration
Credential stuffing simulation
Deeper proof-of-impact validation

Free forever · 3 simulations/month · No credit card

Most Popular

Professional

For teams fixing real exploit paths in critical flows

€69/month
€48.30/month
Save 30% for 6 months
200 single-target simulations per month
Team workspace (10 seats)
Multi-step attack chains with proof and decision trail
Protocol attacks: CORS, Host Header, HTTP Smuggling, WebSocket
JWT attack suite
Injection & XSS testing
Authentication bypass & session testing
Credential stuffing simulation
Business logic testing
File upload exploit testing
IDOR & unauthorized access testing (ID enumeration, privilege escalation)
CI/CD API access (5,000 triggers/day)
Evidence exports (PDF + JSON)
Up to 12 months scan history retention (evidence 30 days)
Priority email support (24h)
Full-domain exploration (4 per month)
AI-guided tests
Advanced injection chaining & executable upload probing
Best Value

Business

For full-domain simulations, deeper proof, and compliance-aligned security testing

€149/month
€104.30/month
Save 30% for 6 months
Unlimited single-target simulations per verified domain
30 full-domain simulations per month
Unlimited team seats
Deeper proof-of-impact validation
More technique depth and safer retries
Advanced API exploit paths
BOLA/BFLA & vertical privilege escalation chains (multi-user authorization)
Business logic manipulation scenarios
Login rate limit & lockout testing
Compliance presets: PCI DSS 4.0, HIPAA, GDPR, SOC 2, ISO 27001:2022, OWASP Top 10, NIST CSF
Findings mapped to compliance requirements with audit evidence
Detailed evidence and decision trails
Unlimited CI/CD API triggers
Evidence exports (PDF + JSON)
Up to 24 months scan history retention (evidence 60 days)
Priority email support (4-hour SLA)
Team workspace & roles

Frequently asked questions

What this simulates

  • Unauthorized access attempts (IDOR, role bypass, missing checks)
  • Account takeover attempts (credential abuse, auth flow probing)
  • Session abuse attempts (token misuse, fixation patterns)
  • Business logic manipulation (workflow abuse and edge cases)
  • API discovery and exploit paths (REST and GraphQL)
  • Input manipulation attacks (safe payloads; proof of impact capture)

What this does not simulate

  • Internal network lateral movement and Active Directory attacks
  • Endpoint malware execution, persistence, or ransomware behavior
  • Phishing, social engineering, or employee impersonation
  • Physical security testing
  • Source code review, SAST, or dependency auditing
  • Cloud posture reviews and infrastructure misconfiguration audits

Can I change plans anytime?

Yes, you can change your subscription at any time.
Upgrading (Starter to paid): Changes apply immediately.
Switching paid plans: Changes apply at the end of the billing period.
Downgrading to Starter: Your paid plan is set to cancel at the end of the billing period. Team members are removed immediately and switched to individual Starter accounts (no team data access), while the owner keeps paid access until the period ends.

What payment methods do you accept?

We process payments securely through Stripe, accepting all major credit and debit cards (Visa, Mastercard, American Express, and more).

Is there a free trial?

Absolutely. Our Starter plan is free — no credit card required. You can launch simulations right away and upgrade when you need more volume or deeper proof.

Do you offer custom pricing?

Yes. We provide custom pricing for large teams, agencies, and organizations with specific security or compliance needs. Contact our sales team to discuss a plan tailored to your environment.

Does this satisfy my SOC 2, PCI DSS, or ISO 27001 audit requirements?

Partially. Nautillo Pro generates the security testing evidence auditors require — HTTP-level proof of exploitation, findings mapped to specific framework controls, and a repeatable testing cadence. This is accepted as supporting evidence across SOC 2, PCI DSS, GDPR, and ISO 27001 audit processes.

It does not replace mandatory human-led assessments: PCI DSS Req 11.3 requires a Qualified Security Assessor, SOC 2 Type II requires a licensed CPA firm, and ISO 27001 certification requires an accredited audit body. Nautillo Pro prepares you for those assessments — it does not substitute for them, and it does not issue compliance certificates or attestations.

Related content

Documentation

Learn how to run simulations and interpret results.

Explore
Security

Understand how we protect data and enforce access controls.

Explore
Support

Get help with onboarding, billing, or verification.

Explore