Skip to content
Pricing

Flat pricing. Everything included.

Unlimited targets and scans, hosted AI and up to five devices. Nothing is held back for a higher tier, because there is no higher tier.

One plan · everything includedLaunch price

SelfSec DAST

$250 / month excl. VAT

  • Unlimited target hosts
  • Unlimited scans per month
  • All 21 vuln + 10 passive modules, deep recon & CVE matching
  • Aggressive WAF evasion + adaptive memory
  • OpenAI + Anthropic + Ollama
  • Up to 5 devices · no per-user fees
Launch price: Nothing is charged during pre-release. The published price is the launch price. Up to 5 devices: A device is one install of the SelfSec app signed in with your account; release one from your dashboard any time. Checkout: Checkout runs against a simulated provider until public downloads open; a real provider slots in behind the same flow. Local data: Targets, responses and the findings database stay on the scanner host.
Plan context
Launch price
Nothing is charged during pre-release. The published price is the launch price.
Up to 5 devices
A device is one install of the SelfSec app signed in with your account; release one from your dashboard any time.
Checkout
Checkout runs against a simulated provider until public downloads open; a real provider slots in behind the same flow.
Local data
Targets, responses and the findings database stay on the scanner host.

Prices are in USD, exclude VAT and are billed monthly. SelfSec is sold to businesses and self-employed professionals only.

Who it is for

Cost, confidentiality and compliance decide the tool long before the feature list does. These are the situations the plan is shaped around.

You pay for your own tools

Solo engineers and bug-bounty hunters carry the license cost themselves. There is one plan and it keeps the full module set rather than crippling detection at the low end, and core scan processing stays on your machine.

You test other people's applications

Consultants work under NDA, and client URLs, evidence and reports are exactly what an assessment agreement says cannot be shared. Scanning runs locally, and flat pricing means one more client is not one more license to buy.

You have to know exactly where data goes

When a contract, a regulator or an internal policy governs where application data may travel, the deployment model decides the purchase. Core scan processing and findings stay on the host you run the scanner on.

Finding lifecycle

Confirmation is a stage, not an adjective

Finding lifecycle: a finding starts as Possible, passes a verification gate to Confirmed when independent evidence agrees, and a second gate to Exploited when the engine demonstrates impact. Refuted findings are kept with their evidence.

The confirmation pass actively disagreed. The finding is kept with its evidence rather than silently dropped, so you can see what the engine decided and why.

How SelfSec compares

Product model, deployment and buying path, in each vendor's own words

Acunetix is now sold as Invicti Web + API; the two right-hand columns describe one vendor's two products.

How SelfSec compares: product model, deployment and buying path, in each vendor's own published words. Checked 2026-10-03.
Axis SelfSecBurp Suite ProInvictiInvicti Web + APIformerly Acunetix
Buying basisOne flat plan at a published launch price, up to five devices. Nothing is charged during pre-release. Sold to businesses and self-employed professionals only.S$4991 · Licensed for individual users.Start a quote2 · on every tier; the only published figure is "$500 max per pentest"Get a quote3 · A target is defined in Invicti as a fully qualified domain name (FQDN).
DeploymentRuns on 127.0.0.1 on a Windows or Linux host you control.SLocal installation only.4SaaS, on-prem, and hybrid options5 · the pricing page lists "On-Premises (coming soon)" for Web + APIdeploy Invicti on premises or as a SaaS solution6 · the pricing page lists "On-Premises (coming soon)"
Validation approachA finding stays Possible until independent evidence promotes it to Confirmed; Exploited only when impact is demonstrated; Refuted findings are kept with their evidence.SNot stated on page7Proven exploitability. Zero guesswork.5automated proof of exploit for many findings6
AI roleOptional and off by default. The agent proposes the next experiment; the engine runs it and decides. Your own Anthropic or OpenAI key, Ollama on your host, or the plan's hosted AI.SAI assistance that helps you move faster through validation, exploration, and repetitive tasks, while keeping you in control.8Meet Octo, the hybrid agentic pentester combining scanners and AI9World's best DAST, even better with AI10
Trial pathJoin the launch list. Today the app runs only with an active plan. Launch evaluation terms are being decided and will be stated on this row before public downloads open.STry Burp Suite Professional for free8proof-of-concept licenses so you can evaluate the platform2no-risk Proof of Concept licenses3
Exports and CIHTML, JSON, Markdown, SARIF 2.1.0 and a MITRE ATT&CK Navigator layer, driven by a local HTTP API. A packaged command-line runner is on the roadmap.SSimple reporting with automated report generation7 · formats: not stated on page110+ out-of-the-box integrations plus a powerful API and open-source CLI5 · formats: not stated on pageIntegration with CI/CD pipelines6 · formats: not stated on page
Data boundaryTargets, responses and the findings database stay on the scanner host. Activation sends only the device identifier and your plan; the product reports no diagnostics; a configured AI service receives the scan context the work needs.SAutomatically keep a persistent log of all your testing activities using project files7 · where data is processed: not stated on pageNot stated on page2 · hosting regions are published; which data leaves your environment is notNot stated on page6
Team modelUp to five devices under one flat price, no per-user fees. Unlimited targets and scans.SDesigned for use by individual testers.4Unlimited users and scans5supports both small teams and enterprise security programs6
Product modelHybrid agentic vulnerability scanner (DAST) that runs as a self-hosted local service. Pre-release.SThe world's #1 web penetration testing toolkit.8Complete AppSec in one platform.11Acunetix is now Invicti Web + API.10
Sources · checked

“S” markers link to the SelfSec page that states the fact. This compares product models and buying paths, not detection results. Quoted text is copied from the linked page as it read on the checked date. “Not stated on page” means the linked page does not say; it does not mean the product lacks it. Vendor offerings and prices change; follow each source before purchasing.

Sources (11)
  1. https://portswigger.net/buy/pro (opens in a new tab)
  2. https://www.invicti.com/pricing (opens in a new tab)
  3. https://www.acunetix.com/pricing/ (opens in a new tab)
  4. https://portswigger.net/burp/dast/resources/dast-vs-professional (opens in a new tab)
  5. https://www.invicti.com/product/dast (opens in a new tab)
  6. https://www.acunetix.com/vulnerability-scanner/ (opens in a new tab)
  7. https://portswigger.net/burp/pro/features (opens in a new tab)
  8. https://portswigger.net/burp/pro (opens in a new tab)
  9. https://www.invicti.com/ (opens in a new tab)
  10. https://www.acunetix.com/ (opens in a new tab)
  11. https://www.invicti.com/platform-overview (opens in a new tab)

Questions before you join

How is SelfSec different from Burp Pro or Invicti?
It is a different product model, not a claim to out-detect them. Burp Suite Professional is a hands-on toolkit: its buy page lists "$499" per user, and PortSwigger describes it as "Licensed for individual users." Invicti is an enterprise platform bought through a quote. SelfSec is automated, self-hosted and flat-priced, and its classical engine has to confirm a finding before it is reported. The comparison above sets each difference against the vendor's own published page — it compares product models and buying paths, not detection results.
Does my AI key or scan data leave my machine?
Core scan processing and the findings database stay on the scanner host. Configured AI services may receive the scan context needed for the work you request. Account activation is a separate data flow, and the product reports no diagnostics.
Is my data sent to the cloud?
The scanner runs on your host; this site handles your account, subscription and activation. A configured external AI service is a distinct connection. Finding evidence remains in local scan history.
What do I need to run it?
SelfSec is a local agent that runs on a Windows or Linux host you already control. You point it at a target you are authorized to test — a web application or an Android application — and watch findings stream into a live dashboard. Host sizing and supported operating-system versions are published together with each installer.
Which platforms does the scanner run on?
Windows and Linux. Both are built and tested today and both ship at first release — an installer for Windows and a self-extracting package for Linux, each with the browser engine bundled so there is nothing else to install. macOS is not supported and no other host platform is announced. Which of the two you install on changes nothing about what the scanner can test: web and Android targets behave the same from either platform.
Can it scan a mobile app?
Android, yes; iOS is not supported. You give it an APK or an installed package, and the scanner drives the app on an emulator or a connected device while a local capture proxy turns the app's own requests into scan targets for the same engine that tests a website. It is not a one-click path: the Android SDK platform tools have to be on the scanner host, and intercepting HTTPS needs either a rooted device or the APK repackaging option. When neither is available the scan still runs and reports that its HTTPS coverage degraded, rather than quietly covering less.
What do I get without a subscription?
An account, and nothing more. Registering gives you a profile, support tickets and the newsletter — it does not unlock the scanner. The SelfSec app signs in with that account and refuses to run without an active plan, so there is no free usage tier to evaluate on. There is a single plan, and it carries the full 21 vulnerability and 10 passive modules, hosted AI, aggressive evasion, unlimited targets and scans. Nothing is held back for a higher tier, because there is no higher tier.
How do devices work for a team?
The plan includes up to five devices under one flat price, with no per-user fees. A device is one install of the SelfSec app signed in with your account; release one from your dashboard and it is free for someone else.
How does the SelfSec app connect to my plan?
Sign in to the SelfSec app with the same account you use here — there is no key to generate or paste. The app reports your active plan and limits, and you can release any device from your dashboard.
Who can buy SelfSec?
Businesses only — companies, other organizations and self-employed professionals buying for their trade, business or profession. SelfSec is a professional security tool and is not sold to consumers. When you create an account you confirm that you act for a business and give the company or trading name, address and country your invoices are issued to; a VAT or tax ID is optional. Prices are shown excluding VAT.
How does payment work here?
Nothing is charged during pre-release. The prices listed are the launch prices, checkout runs against a simulated provider so the account and subscription flow can be exercised end to end, and a real payment provider slots in behind the same flow before public downloads open.
Can I run SelfSec in CI?
Partly today, and we would rather be exact than sell you a step that does not exist. Scans and report exports are driven by a local HTTP API on 127.0.0.1, so a pipeline job on the scanner host can start a scan and pull the result. Reports export as SARIF 2.1.0, which GitHub code scanning ingests directly, alongside HTML, JSON, Markdown and a MITRE ATT&CK Navigator layer. What is not shipping yet is a packaged command-line runner with a build-failing exit code — it is on the roadmap and this answer will change when it lands.
Launch list

One plan, everything in it.

Join the launch list to hear when public downloads open, with deployment guidance and the first production-ready release. Nothing is charged during pre-release.