Rates & ServiceSection H · Subscriptions

The
Rate Card.

Four standing engagement tiers, priced on the record. Every engagement includes a detailed report and expert recommendations. Custom engagements available for non-standard situations.

Standing Engagements

Choose Your Dispatch

Dispatch 01

The Vibe Check

$1,500per engagement

For the founder who shipped fast with AI tools and needs to know what they actually shipped.

  • Authentication & session management
  • Secret exposure in client bundles
  • IDOR on auto-generated CRUD endpoints
  • File upload handling
  • Rate limiting on auth-critical endpoints
  • Findings memo + remediation recs
  • 14-day re-test window

Delivery

1 week from kickoff

Best for

Pre-launch SaaS, recently-shipped MVPs, vibecoded apps

Editor's Pick
Dispatch 02

The Field Report

$5,000 – $8,000per engagement (scope-dependent)

The full adversarial assessment. What a serious buyer expects when they ask "have you been pentested?"

  • Everything in The Vibe Check, plus:
  • Full OWASP Top 10 coverage
  • Business logic abuse testing
  • API security (REST + GraphQL)
  • Server-side validation review
  • Access control matrix testing
  • Secure code review of critical paths
  • Internal & external attack simulation
  • Executive summary + technical report
  • Reproducible PoCs for every finding
  • 30-day re-test + 60-min readout call

Delivery

2-3 weeks from kickoff

Best for

SaaS preparing for SOC 2, pre-fundraise due diligence, investor security review

Dispatch 03

The Standing Beat

$4,000per month (6-month minimum)

A standing security desk for teams that ship continuously and need coverage that ships with them.

  • Monthly attack-surface scan
  • Quarterly full Vibe Check on production
  • Slack channel access (24-hour response)
  • Pre-deployment review of major releases (2/month)
  • Annual full Field Report (included)
  • Incident response triage (first 4 hours free)
  • Direct line to senior correspondent
  • Quarterly business reviews

Delivery

Ongoing commitment

Best for

$20K+ MRR SaaS, continuous shipping velocity, regulated industries

Dispatch 04

The Bureau Engagement

Customtypically $10K-$30K+

For engagements that don't fit a template: multi-system assessments, due diligence, regulatory response.

  • Pre-acquisition technical due diligence
  • Multi-application portfolio assessment
  • Post-incident independent review
  • Regulatory response security assessment
  • Custom security program design
  • Senior correspondent dedicated to engagement
  • Weekly status briefings
  • Executive + technical reporting layers

Delivery

Custom timeline

Best for

Situations where standard tiers don't fit. Contact us to scope.

Frequently Asked

Questions & Answers

I just need a quick automated scan. Can I get that?

+

No. We don't sell automated scanning as a standalone service. Every Cyber Pantheon engagement includes automated scanning as part of the methodology, but our value is in the manual review and exploitation validation that scanners can't do. If you only want a scan, we recommend running nuclei (free, open-source) or a SaaS tool like Snyk.

Why does The Vibe Check cost $1,500 when other firms offer scans for $200?

+

Because The Vibe Check isn't a scan. It's 5-8 hours of senior correspondent time manually reviewing your highest-risk surfaces. A $200 scan finds CVEs in dependencies. The Vibe Check finds the IDOR that lets User A read User B's data — which is what actually causes breaches.

My budget is $1,000. Can we work together?

+

Probably not directly. Our floor is $1,500 because below that we can't deliver the quality we stand behind. If budget is the constraint, we recommend a freelancer on Toptal or Codementor — happy to refer. If you want to wait until you can afford the $1,500 Vibe Check, we'll be here.

What's the difference between The Field Report and a full SOC 2 pentest?

+

Nothing — The Field Report is what you submit to your SOC 2 auditor as your annual penetration test. Same methodology (OWASP WSTG v4.2), same report format, same re-test window. We've delivered this for SOC 2, HIPAA, ISO 27001, and PCI-DSS compliance contexts.

Do you offer refunds if you find nothing?

+

No. A clean report is the most valuable deliverable we provide — it means your engineering team did the work up front. We don't discount "no findings" engagements because the work to validate that nothing is wrong is identical to the work to find that something is wrong.

How fast can you start?

+

For The Vibe Check: typically within 5 business days of signed SOW + deposit. For The Field Report: within 10 business days. For The Standing Beat: within 2 weeks of signed agreement. For Bureau Engagements: depends on scope.

Do you sign NDAs?

+

Yes, standard mutual NDA before any technical discussion. We can use yours or ours.

Do you work with Web3 / smart contracts?

+

Not currently. We specialize in web application security for SaaS and small-team products. If you need smart contract auditing, we recommend Trail of Bits, OpenZeppelin, or Spearbit.

Still Unsure?

Let's talk through
your situation.

Schedule a 30-minute briefing with our team. We'll walk through your specific needs and recommend the right engagement.

Built with v0