Pentest Pricing
Understand Aikido Pentest pricing options, fixed tiers, and credit costs.
Aikido Pentest uses Aikido Credits, where 1 credit equals $1 USD.
Standard Pentests have a fixed cost; Rightsized Pentests are estimated from your application's scope and complexity, with the total confirmed before testing starts. Continuous Pentesting is usage-based and is focussed on the changes.
Get an estimate for your project on the Pricing page.
1,000 credits gives you roughly the equivalent security coverage of one week of a traditional human-led pentest.
Pricing options
Every Standard and Rightsized Pentest, including all fixed tiers and coverage levels, includes a compliance-ready report and retesting.
Standard Pentest
A Standard Pentest costs 4,000 credits. It's the entry tier in the traditional pricing model shown in the Pricing guide: a time-boxed assessment of one application and its primary APIs, with a fixed cost known upfront.
Rightsized Pentest
A Rightsized Pentest is Aikido's recommendation when you can connect your repositories and want coverage tailored to the security-relevant parts of your application. Aikido analyzes your connected repositories, maps the possible attack vectors, ranks them by risk and likelihood, and uses that analysis to define the testing scope needed for meaningful security coverage.
This means the price reflects the security-relevant parts of your application, rather than simply its size. The Pricing page shows a recommended credit amount for the selected project, and Aikido confirms your exact cost before you start.
Fine-tune your coverage
Use the coverage slider to fine-tune the depth of your Rightsized Pentest before you confirm it. The slider is continuous; the labels below are reference points, not separate packages. Move toward high-risk coverage to focus your budget on the most serious risks only, or toward deeper coverage to test more of your application:
High risk only – Prioritizes the areas most likely to expose serious vulnerabilities. Some areas may receive less or no coverage.
Recommended coverage – Covers the security-sensitive parts of your application and APIs identified through Aikido's analysis of your repositories.
Deeper coverage – Builds on recommended coverage with additional testing of complex workflows and less common attack paths.
The credit estimate includes a breakdown by repository, so you can see how each repository contributes to the total cost.

Continuous Pentesting
Continuous Pentesting provides ongoing offensive security testing for every release. As your code changes, Aikido runs focused tests against the new changes.
Continuous Pentesting is usage-based: each agent that runs costs 10 credits. The Pricing page shows an annualized estimate based on your Git activity from the last 30 days. Aikido checks each configured deploy or scheduled run, but only launches agents for security-relevant changes. Your actual cost depends on the agents Aikido launches for each run. Learn more in Continuous Pentesting.
Pricing guide
If you can't connect your repositories, Aikido can run a black-box assessment, which tests your application externally without access to its source code. Use these reference tiers to estimate a black-box assessment or compare them with your Rightsized estimate:
Standard Pentest
One application and its primary APIs
4,000
Large app
Multiple user roles and significant business logic
8,000
Complex app
A large attack surface, many endpoints, or a complex microservice architecture
16,000
Enterprise app
Large-scale platforms or interconnected systems
32,000
These are reference prices. Aikido confirms your exact cost before the assessment starts. If you can't connect your repositories and want advice on the right coverage, open the Intercom chat in the bottom right corner. Our team is here to help.
Paying with credits
You can check your balance, buy credits, and review transactions in your Aikido Wallet. See Wallet & Credits.
Run now, pay later
Start your pentest now and pay with credits later. If your assessment meets the conditions below and finishes without any High or Critical findings, Aikido waives the pending credits.
This offer is available for your first full assessment and lets you start without purchasing credits upfront.
How it works
Start instantly: Aikido creates pending credits to cover your initial run.
Limited results: High and Critical findings stay blurred until you pay for the pending credits. For larger assessments, Aikido reveals at least one High or Critical finding so you can preview the depth of the results before paying.
Report and retesting unavailable: The compliance-ready report and retesting become available after the pending credits are settled or waived.
No High or Critical findings: If your assessment meets the no-pay conditions and completes with no High or Critical findings, Aikido waives the pending credits.
One at a time: You must pay your balance before using Run now, pay later again.
Requirements
You can use Run now, pay later if you:
Have no outstanding unpaid credits.
Run a pentest that costs 8,000 credits or less. Most applications fall within this limit.
Link at least one active repository. Demo repositories don't qualify.
Provide at least two valid test user accounts.
Use a work email, or have a workspace admin who uses one. Personal email addresses, such as Gmail, don't qualify.
When the no-pay condition applies
The no-pay condition applies when all of the following are true:
This is your first full assessment in your workspace.
You used Run now, pay later for that assessment.
The assessment completed with no High or Critical findings.
Your pentest was set up correctly so Aikido could test the application thoroughly.
When the no-pay condition does not apply
The no-pay condition does not apply in these cases:
Second runs and retests: Any follow-up assessment on the same application, including re-runs after you fixed findings from a previous test.
Continuous Pentesting: Automated follow-up runs triggered by deploys or schedules. See Continuous Pentesting.
Scoped or feature-focused tests: Assessments limited to a narrow part of your app (for example, a single feature or endpoint). These scopes are often too small to surface High or Critical findings reliably.
Incomplete setup: Common examples include missing test users, API-only tests without sufficient application context, or targets that blocked meaningful authenticated testing.
Unexplored escalation potential: Medium or Low findings where Exploit Further was available but not used. Aikido may not waive credits if a finding could reasonably have been escalated to High or Critical severity. See Human in the Loop.
Last updated
Was this helpful?