🚀 Acunetix is now Invicti Web + API. Read the announcement.

Invicti Pricing and Packages

Revolutionary Pricing.
Blazing Speed. Zero Noise.

  • Flexible Scanning
    Choose your starting point and scale without disruption
  • Unlimited Coverage
    Secure all apps: first-party, open-source, internal, external, dev or production
  • Transparent Pricing
    Pay based on your security needs, not arbitrary constraints

Legacy Models Hold You Back…
But Not Us!

  • Engine-Based Pricing
    Lock you into rigid licensing with scale limitations
  • Charge Per Environment
    Force choice between early testing or redundant licenses
  • Cap Concurrent Scans
    Create bottlenecks and slow down your remediation

Get a quote

loading the form...

Your information will be kept private

Flexible Packages, Transparent Pricing

Unlimited coverage. Pay for security, not arbitrary limits.

Agentic Pentest

Rapid, high-precision agentic pentesting for a single application and its API suite.

Start a quote

  • $500 max per pentest
  • Audit-ready PDF reports
  • Delivery within 24 hours
  • Hybrid DAST / Agentic prioritization
  • Blackbox, whitebox, or graybox testing
  • Business logic detection
  • Validated findings
  • Reproduction steps
  • Remediation guidance

Web + API

Find exploitable vulnerabilities across web apps and APIs with proof-based scanning.

Start a quote

  • Industry’s Best DAST
  • Multilayer API Discovery
  • Stateful API Security
  • LLM Security
  • Proof-Based Scanning
  • Runtime Validation
  • CI/CD Automation
  • SSO
  • Cloud Hosting
  • On-Premises (coming soon)
5,000+ companies of all sizes automate application security testing with Invicti
avg-dark
americanexpress-dark
cognizant-gray
aws-dark
airforce-dark
GARTNER REVIEWS

Superior service

“[The support team is] extremely approachable as a group and also highly responsive.”

– InfoSec Analyst, Communications

“The most helpful support team I have ever experienced.”

– Application Developer, Technology

“Good product with best support overall.”

– Application Developer, Technology

Frequently Asked Questions

Yes! Experience Invicti firsthand with our no-risk Proof of Concept licenses. Test the complete solution in your actual environment to ensure it perfectly addresses your organization’s specific security needs before making any commitment.

A target is defined in Invicti as a fully qualified domain name (FQDN). An FQDN is the complete domain name for a specific target and consists of two parts; the hostname and the domain name.
The below examples are considered to be 1 target, as they share the same FQDN.
http://example.com
https://example.com
http://www.example.com
http://www.example.com/test

Subdomains and ports share the same FQDN, but are considered to be different targets. For example:
http://example.com
http://test.example.com
http://example.com:81

Invicti integrates with 3rd party applications, making it easier to track and protect against identified vulnerabilities. Check out this page to see all our integrations.

Invicti employs advanced heuristic scanning technology rather than traditional signature databases, enabling it to detect zero-day vulnerabilities in even the most customized web applications.

Your Invicti subscription includes weekly Vulnerability Database Updates, covering known security issues in popular platforms like WordPress, Joomla, jQuery, Apache, and numerous others.

Beyond these regular updates, you’ll receive innovative security checks designed to identify emerging zero-day threats, along with continuous improvements and new features. We deliver major platform updates approximately every two months, ensuring you stay ahead of evolving security challenges.

For critical vulnerabilities like Heartbleed, our dedicated security research team works diligently to release protective updates within days of discovery. This specialized team continuously enhances both our vulnerability database and develops new security detection methods, providing you with industry-leading protection.

Invicti delivers comprehensive vulnerability detection capabilities, identifying thousands of security threat variants without being constrained by specific compliance frameworks or checklists. It thoroughly scans for all web security issues—whether they appear in regulatory requirements or not—providing protection that extends beyond standard compliance measures. Many of the vulnerabilities Invicti identifies are included in the OWASP Top 10 list of critical security risks, but its protection reaches far beyond these common threats to safeguard your applications against the full spectrum of potential exploits.

Customer satisfaction is a top priority at Invicti, which is why all of our subscriptions include world-class standard support with rapid response times, service excellence, and convenient access. Check out our support plans here.

If you have any other questions, don’t hesitate to reach out to us. You can also reach out to your Invicti representative if you are already in touch with one.

Secure Your Applications with Confidence Get the best coverage, speed, scale and accuracy in application security

Bottom Arrow