Skip to main content
PRICING

Continuous AI pentesting. Honest pricing.

Two offerings, two models: the KAI Platform is a subscription from €1,200/month with a 14-day free trial. Expert services — pentests, red team, audits — are scoped and quoted per engagement. Every finding ships with reproducible proof of exploitation, so your team only triages what matters.

No credit card requiredAnnual or monthlyCancel anytime
KAI PLATFORM

Fixed pricing. Predictable bills.

AI-powered continuous security testing — published pricing, 14-day free trial, no per-finding charges.

These tiers cover the KAI platform subscription only. Human-led work — pentests, red team, compliance audits — is scoped per client under KAOS Services.

STARTER

For startups & small teams

1,200/month
Billed annually · €14,400/yr · save 20%
Up to 10 assets · 1 concurrent scan · unlimited scans in queue

Continuous AI pentesting for a single product or a small estate. Self-serve onboarding — same-day scans on common stacks.

  • All 127 attack techniques
  • Weekly scheduled scans + on-demand
  • PDF + JSON report exports
  • Slack / Teams / GitHub integrations
  • MITRE ATT&CK mapping
  • 3 users · email support
  • 14-day free trial
Start Free Trial
MOST POPULAR

PRO

Most teams pick this

3,200/month
Billed annually · €38,400/yr · save 20%
Up to 50 assets · 1 concurrent scan · unlimited scans in queue

Continuous AI pentesting across your full estate. Compliance-ready evidence, full API and CI/CD gating included.

  • Everything in STARTER
  • Daily scheduled scans + on-demand
  • Compliance evidence: PCI 4.0 · ISO 27001 · SOC 2 · HIPAA · NIS2 · DORA · ENS
  • All export formats (PDF · DOCX · JSON · SARIF · CSV · XLSX)
  • REST + GraphQL API · webhooks · Terraform
  • Risk acceptance + retest workflow
  • SLA tracking + analytics dashboards
  • 15 users · SAML SSO + SCIM
  • 4-hour SLA · business hours
Start Free Trial

ENTERPRISE

For regulated environments

Custom
Annual contract · scoped to your estate
Unlimited assets · 1 concurrent scan (more on request) · continuous rotation

Single-tenant, on-prem or air-gapped deployments. Custom techniques, BYOK encryption and dedicated solutions support.

  • Everything in PRO
  • Continuous scan rotation across full estate
  • Additional concurrent scan workers on request
  • On-prem · air-gapped · single-tenant managed VPC
  • BYOK (AWS KMS / Azure Key Vault / HSM)
  • Custom MITRE techniques + custom MCP servers
  • Audit log streaming (Splunk / Datadog / Elastic)
  • 1-hour SLA · 24/7 emergency · dedicated CSM
  • White-label reporting · auditor portal
Talk to Sales

Pricing context: KAI STARTER undercuts comparable AI pentest platforms (Pentera, NodeZero) by ~60%. KAI PRO sits at ~50% of Cobalt PtaaS Professional. Same autonomous AI agent across all tiers — only limits and integrations differ.

Compare KAI tiers

Same autonomous AI agent across all tiers. The differences are limits, integrations, deployment, and SLA.

KAI platform tier feature comparison: STARTER, PRO and ENTERPRISE
Feature
STARTER
€1,200/mo
PRO
€3,200/mo
ENTERPRISE
Custom
Limits & scope
Assets included1050Unlimited
Projects / workspaces1UnlimitedUnlimited
Concurrent scans (workers)111 (more on request)
Scans in queueUnlimitedUnlimitedUnlimited
Scheduled scan cadenceWeekly + on-demandDaily + on-demandContinuous rotation
User seats315Unlimited
Manual review by OSCE3 operatorVia KAOS ServicesVia KAOS ServicesVia KAOS Services
Engine & coverage
All 127 attack techniquesIncludedIncludedIncluded
RAG-driven technique selectionIncludedIncludedIncluded
6 MCP servers (code analysis, browser, OOB, …)IncludedIncludedIncluded
Custom MITRE techniques + custom MCP serversNot includedNot includedIncluded
Findings validated with proof of exploitIncludedIncludedIncluded
Reporting & compliance
PDF + JSON exportsIncludedIncludedIncluded
DOCX / SARIF / CSV / XLSX exportsNot includedIncludedIncluded
MITRE ATT&CK coverage matrixIncludedIncludedIncluded
Compliance evidence (PCI 4.0, ISO 27001, SOC 2, HIPAA, NIS2, DORA, ENS)Mapping onlyFull evidence packFull evidence pack
White-label / custom brandingNot includedNot includedIncluded
Auditor portal (read-only watermarked access)Not includedIncludedIncluded
Triage & lifecycle
Risk acceptance workflowNot includedIncludedIncluded
Re-test management + PoC replayNot includedIncludedIncluded
Field-level change history (audit trail)IncludedIncludedIncluded
SLA tracking + MTTR analyticsNot includedIncludedIncluded
Integrations & API
Slack / Teams / GitHub notificationsIncludedIncludedIncluded
JIRA / Linear / ServiceNow / GitHub IssuesNot includedIncludedIncluded
CI/CD: GitHub Actions / GitLab / Jenkins / Azure DevOpsManual APIIncludedIncluded
REST + GraphQL APIRead-onlyFullFull
Webhooks (HMAC signed) + delivery logNot includedIncludedIncluded
Terraform providerNot includedIncludedIncluded
Audit log streaming (Splunk / Datadog / Elastic)Not includedNot includedIncluded
Identity & security
Email + passwordIncludedIncludedIncluded
SAML SSO + OIDCNot includedIncludedIncluded
SCIM 2.0 user provisioningNot includedIncludedIncluded
Custom RBAC rolesNot includedNot includedIncluded
BYOK encryption (AWS KMS / Azure KV / HSM)Not includedNot includedIncluded
Deployment & data
Multi-tenant SaaS (EU / US)IncludedIncludedIncluded
Single-tenant managed VPCNot includedNot includedIncluded
On-prem Kubernetes (Helm chart)Not includedNot includedIncluded
Air-gapped operatorNot includedNot includedIncluded
Configurable data retention (30d–7y)12 months24 monthsConfigurable
Support & SLA
Email supportIncludedIncludedIncluded
Business-hours response SLA24h4h1h
24/7 emergency responseNot includedNot includedIncluded
Dedicated Customer Success ManagerNot includedNot includedIncluded
Solutions Engineer / onboardingSelf-serveGuidedDedicated
Production SLA uptime99.5%99.9%99.95%
Quarterly business reviewNot includedIncludedIncluded

Need a tier between PRO and ENTERPRISE? Talk to us— we'll size it to your estate.

What KAI ships with every finding

Quality you can act on immediately

We can't promise a number of findings — that depends entirely on your environment's exposure. What we can promise is the format and rigor of every finding KAI surfaces.

Reproducible PoC

Step-by-step instructions to reproduce the issue, including captured request / response pairs.

CVSS 4.0 + business impact

Severity scoring with environmental modifiers plus a plain-language business-impact summary.

MITRE ATT&CK + CWE mapping

Every finding tagged with the MITRE technique it abuses and the CWE class it belongs to.

Compliance cross-walk

Linked control families across PCI-DSS, ISO 27001, SOC 2, HIPAA, NIS2, DORA and ENS.

Captured artifacts

Screenshots, OOB callbacks, tokens, payloads — everything your engineering team needs to act.

Remediation guidance

Concrete fix recommendations, code-level when applicable, with verification steps after the patch.

SERVICES

KAOS Services

Human + AI engagements led by our offensive security team — pentests, red team operations, compliance audits, advisory.

Custom engagement pricing

Every engagement is scoped to you

Compliance audits, full pentests, red team operations and advisory hours are tailored to your scope, target environment, and regulatory requirements. We send a fixed-fee proposal after a 30-minute scoping call.

  • Pentest (web, API, mobile, network, cloud, infrastructure)
  • Red team & adversary emulation engagements
  • Compliance-driven audits (PCI-DSS, ISO 27001, SOC 2, NIS2, DORA, ENS)
  • Source code review and threat modelling
  • Continuous advisory retainer

Get a quote

30-min scoping call →
Fixed-fee proposal in 48h

Request Pricing

No obligation, no upfront fees.

HOW WE COMPARE

KAOS vs the alternatives

Why teams pick KAOS over a traditional pentest agency or a self-hosted scanner.

DimensionKAOS
Platform + Services
Traditional pentest agencyDIY scanner
Time to first scanSame day — self-serve4–8 weeks per engagementMinutes — output unverified
CostFrom €1.2k/mo (Platform) · custom (Services)€25k–€80k+ per project€3k–€10k/yr (hidden infra cost)
Coverage cadence24/7 continuous + deep manualPoint-in-time snapshotLimited to known CVE signatures
Finding formatEvery finding ships with PoCManual write-up, varies by analystCVE matches — high noise rate
Continuous testingBuilt-inNo — re-scope each timeScheduled scans only

All prices in EUR, exclude VAT. Andorran entity (KAOS S.L.U) for commercial contracting; EU customers contracted via KAOS AI SECURITY, S.L. on request.

Frequently Asked Questions

Still Have Questions?

Our team is happy to answer any questions and help you find the right plan.

Start Free TrialContact Us