Pricing
Launch realistic attacker simulations that show exactly how your web app could be broken.
Choose a plan based on volume and depth of proof. Every run is operator-launched and scope-controlled.
Starter
For quick, single-target simulations on one critical flow
Free forever · 3 simulations/month · No credit card
Professional
For teams fixing real exploit paths in critical flows
Business
For full-domain simulations, deeper proof, and compliance-aligned security testing
Frequently asked questions
What this simulates
- Unauthorized access attempts (IDOR, role bypass, missing checks)
- Account takeover attempts (credential abuse, auth flow probing)
- Session abuse attempts (token misuse, fixation patterns)
- Business logic manipulation (workflow abuse and edge cases)
- API discovery and exploit paths (REST and GraphQL)
- Input manipulation attacks (safe payloads; proof of impact capture)
What this does not simulate
- Internal network lateral movement and Active Directory attacks
- Endpoint malware execution, persistence, or ransomware behavior
- Phishing, social engineering, or employee impersonation
- Physical security testing
- Source code review, SAST, or dependency auditing
- Cloud posture reviews and infrastructure misconfiguration audits
Can I change plans anytime?
Yes, you can change your subscription at any time.
Upgrading (Starter to paid): Changes apply immediately.
Switching paid plans: Changes apply at the end of the billing period.
Downgrading to Starter: Your paid plan is set to cancel at the end of the billing period. Team members are removed immediately and switched to individual Starter accounts (no team data access), while the owner keeps paid access until the period ends.
What payment methods do you accept?
We process payments securely through Stripe, accepting all major credit and debit cards (Visa, Mastercard, American Express, and more).
Is there a free trial?
Absolutely. Our Starter plan is free — no credit card required. You can launch simulations right away and upgrade when you need more volume or deeper proof.
Do you offer custom pricing?
Yes. We provide custom pricing for large teams, agencies, and organizations with specific security or compliance needs. Contact our sales team to discuss a plan tailored to your environment.
Does this satisfy my SOC 2, PCI DSS, or ISO 27001 audit requirements?
Partially. Nautillo Pro generates the security testing evidence auditors require — HTTP-level proof of exploitation, findings mapped to specific framework controls, and a repeatable testing cadence. This is accepted as supporting evidence across SOC 2, PCI DSS, GDPR, and ISO 27001 audit processes.
It does not replace mandatory human-led assessments: PCI DSS Req 11.3 requires a Qualified Security Assessor, SOC 2 Type II requires a licensed CPA firm, and ISO 27001 certification requires an accredited audit body. Nautillo Pro prepares you for those assessments — it does not substitute for them, and it does not issue compliance certificates or attestations.
Related content
Documentation
Learn how to run simulations and interpret results.
Security
Understand how we protect data and enforce access controls.
Support
Get help with onboarding, billing, or verification.