Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

Pen Test Scoping Calculator

Estimate the effort and price range for a penetration test before you ever get on a call. Choose your target type, scale, authentication, and environments to see a tester-day estimate and a budget band.

Estimated effort
0 days
Estimated price range
$0
What a test at this scope typically includes:
    How we estimate, and why this is not a quote. Penetration tests are scoped by effort in tester-days. We derive days from the target type, its scale, the number of authenticated roles to test, and the number of environments, then apply a typical day-rate range of roughly $1,400 to $2,200 to produce a price band. These are reasonable industry-range estimates, not a fixed price. The real number depends on the actual complexity of your application, the methodology, whether retesting and a formal report are included, and timeline. We confirm scope on a short call before any engagement. Tests are delivered with our offensive-security partner.

    Questions

    How is pen test pricing estimated?

    Most penetration tests are scoped by effort, measured in tester-days. We estimate days from the type of target, its scale, the number of authenticated roles, and how many environments are in scope, then apply a typical daily rate range to produce a price band.

    Why does authentication increase the cost?

    Every distinct user role is its own attack surface. A tester has to exercise the app as each role and test for privilege escalation between them, so more roles mean more days of testing.

    Is this a quote?

    No. It is a planning estimate to help you budget and prepare for a scoping call. Final pricing depends on the real complexity of the target, the testing methodology, retesting needs, and reporting requirements. We confirm scope before any engagement.

    What is the difference between a vulnerability scan and a pen test?

    A scan is automated and finds known issues. A penetration test is performed by people who chain weaknesses together, exploit business logic, and validate real impact. Auditors and enterprise buyers usually want a manual pen test, not just a scan.

    Is this calculator free?

    Yes, it is free with no signup. When you are ready, we scope and deliver penetration tests with our offensive-security partner.

    Not ready for a call yet?

    Get the security playbook

    A few short notes from Jacob on locking down your startup without a big security team. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    Compliance Penetration Testing

    We run the test end to end and hand you an auditor-ready report.

    Explore Compliance Penetration Testing →

    Ready to scope a real test?

    Our penetration testing services are delivered with our offensive-security partner and pair well with ongoing vulnerability management so findings don't just get a one-time fix. We deliver a report your auditors and customers will accept. Bring this estimate to a scoping call.

    About our pen testing Book a call

    Want the full picture on SOC 2?

    This gives you the shape of the problem. The full picture is all 61 SOC 2 criteria, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free SOC 2 assessment See what is in the platform

    No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the workspace.