Pricing

Security Platform Plans

Basic

$99/mo

For small teams establishing their security foundation

Get started
  • Weekly scans of code, cloud, containers (e.g. SAST, DAST, SCA)
  • Automatic asset inventory & architecture visualization
  • Integrations with numerous cloud services
  • Up to 3 contributors

Essentials

$499/mo

For teams who need deeper coverage and compliance evidence

Get started
  • Everything in Basic
  • Daily scans of containers and infrastructure; Github PR scanning, ad-hoc scans
  • Automatic fixes via AI
  • Integrations with GRC tools
  • Contributors: 10 included (25 max)

Growth

$999/mo

For growing companies scaling security or pursuing HIPAA or CMMC

Get started
  • Everything in Essentials
  • Penetration test management (BYO tester)
  • External network scanning
  • Consulting services available
  • Contributors: 10 included (100 max)

Advanced

$1999/mo

For organizations with maturing security needs

Get started
  • Everything in Growth
  • Custom prioritization schemes
  • Annual penetration test
  • SAML + SCIM
  • Contributors: 10 included (unlimited available)
Open source

Maintaining a public open source project? Fencer is free for public repos.

Contact us to apply →

Compare features and plans

Basic
Essentials
Growth
Advanced

Add-ons

Additional contributors
$49 each | 25 max
$99 each | 100 max
$149 each | Unlimited
Extra security monitoring event data
10GB included
Additional $0.30/GB
20GB included
Additional $0.25/GB
40GB included
Additional $0.20 GB
Additional human-led penetration testing
$6,000
$6,000

Vulnerability Scanning & Management

One-Click Fixes
Remediate common vulnerabilities with a single action
Not included
Included
Included
Included
Custom Prioritization Schemes
Define risk scoring based on your environment
Not included
Not included
Not included
Included
Agent-Driven Codegen
Use AI agents to plan changes, create PRs and fix issues
Not included
Included
Included
Included
Vulnerability Prioritization
Identify the highest-impact issues to fix next
Included
Included
Included
Included
Vulnerability Consolidation
Unified view of findings across all scanners
Included
Included
Included
Included

Security Scanning

API Scanning
Not included
Not included
Included
Included
External Network Scanning
Not included
Not included
Included
Included
Web Application Scanning (DAST)
Identify runtime application vulnerabilities
Basic
Full
Full
Full
Scanning Frequency
Weekly
Daily
Daily
Daily
License Scanning
Gain visibility into & control open source software usage
Not included
Included
Included
Included

Penetration Testing

Annual Human-Led Penetration Test
Expert human-led penetration testing.
Not included
Not included
Not included
Included
Penetration Test Management
Centralized management of your penetration test findings, remediation, and documentation.
Not included
Included
Included
Included
AI Penetration Testing
Not included
Not included
1
2

Asset Visibility & Security Context

Architecture & Network Diagram
Auto-generate a current view of system & network architecture, make edits and export to other tools for deeper customization
Included
Included
Included
Included
SBOM Generation
Auto-generate a detailed inventory of software components in CycloneDX or SPDX formats
Not included
Included
Included
Included
Asset Inventory
Continuous inventory of infra, devices, repositories, dependencies and more
Included
Included
Included
Included

Security Monitoring

Security Event Data Ingestion
Not included
Included
Included
Included
Security Monitoring
Real-time visibility and alerting on security events
Not included
10 GB/month
20 GB/month
40 GB/month
Threat Intelligence (Coming Soon)
Ensure awareness of current industry-wide threats and actors
Not included
Not included
Not included
Included
Incident Management (Coming Soon)
Document incidents and track incident response
Not included
Not included
Not included
Included
Threat Hunting
Investigate threats with detailed, real-time event data
Not included
Included
Included
Included

Compliance Evidence & Audit Support

Evidence Export
Use findings, SBOMs, and diagrams as audit-ready evidence
Included
Included
Included
Included
GRC Integrations
Sync security evidence to Vanta or Drata
Not included
Included
Included
Included

Integrations

GRC
Vanta, Drata
Not included
Included
Included
Included
Cloud Infrastructure
AWS, Cloudflare, Render, Heroku, GCP, Digital Ocean
Included
Included
Included
Included
Data Platforms
Snowflake
Included
Included
Included
Included
Identity & Device Management
1Password, Iru (Kandji)
Included
Included
Included
Included
Code & CI/CD
GitHub
Included
Included
Included
Included

Account Features

SSO
Included
Included
Included
Included
SCIM
Not included
Not included
Not included
Included
SAML
Not included
Not included
Not included
Included

Support & Services

Slack
Receive support via a private Slack channel
Not included
Included
Included
Included
Email
Receive support via email
Included
Included
Included
Included
Support Coverage
Availability of support
24/5
24/5
24/7
24/7
Consulting
Expert advice on startup security
Not included
Not included
Contact Us
Contact Us
Chat
Live chat support
Included
Included
Included
Included

Penetration Testing Packages

AI-led

$3,000

Fully autonomous, on-demand testing with results in hours. Ideal for teams that want quality coverage with fast turnaround.

Get started
  • Tests OWASP Top 10, business logic, and APIs
  • Validated findings in hours
  • Audit-ready report for SOC 2 and ISO 27001
  • Unlimited retests, and pay only for high or critical findings

Human-led

$6,000

A hands-on engagement scoped to your app. Best when you need deep, manual review of complex business logic.

Contact us
  • Deep manual testing of business logic, auth, and complex flows
  • Full engagement, results in ~2 weeks
  • Audit-ready report for SOC 2 and ISO 27001
  • Includes a retest to verify your fixes

Continuous

Custom

A bespoke testing program tailored to your needs. Made for teams with mature security programs that want always-on coverage.

Contact us
  • Re-runs full coverage on every security-relevant change
  • Always-on; findings surface as you ship
  • Live dashboard plus audit-ready reports
  • Continuous verification as you remediate

Already on a Fencer platform plan?

Add penetration testing

How a pen testing engagement works

1

Scoping

Define the target application and rules of engagement.

2

Scheduled

Your engagement is queued and confirmed.

3

In progress

The app is probed and exploited, and attack paths are confirmed.

4

Reporting

You get findings, confirmed paths, and downloadable artifacts.

5

Completed

Fix the issues, then re-test to verify.

Frequently asked questions

Can one engagement cover multiple applications?

Yes. Scope several applications into a single engagement, or talk to us for larger environments.

Do I need a Fencer platform plan to run a penetration test?

No. Penetration testing is available on its own. If you are on a platform plan, you can add it as a one-time add-on in the same dashboard.

Does a penetration test help with SOC 2 and customer security reviews?

Yes. Testing hardens your application first, and the report and evidence also serve as proof for audits like SOC 2 and ISO 27001 and for buyer security questionnaires.

What do I get at the end of an engagement?

A report you can use for audits and attestations, with confirmed attack paths and exploit evidence, plus downloadable artifacts. AI-led includes unlimited retests; human-led includes a retest to verify your fixes.

What is continuous penetration testing?

Continuous is a bespoke program that keeps testing your application over time, re-running full coverage on every security-relevant change so new attack paths surface as you ship. It fits teams with more mature security programs that want always-on coverage. We scope the cadence, coverage, and price to your environment.

What is the guarantee?

The AI-led pen test comes with a guarantee: you only pay if we find a high or critical severity issue. If we do not find one, that engagement costs you nothing. The guarantee applies to the AI-led pen test only, not to continuous or human-led engagements.

How often can I run an AI-led penetration test?

As often as you ship. Each engagement is a one-time test, so you can run one whenever you push a meaningful change, and AI-led includes unlimited retests to verify your fixes.

What is the difference between AI-led and human-led penetration testing?

AI-led uses autonomous agents to test your application on demand, with results in hours and a report you can use for audits and attestations. Human-led brings human experts for deep, manual testing of complex business logic over a longer engagement. They complement each other, and many teams use both.

Take Fencer for a spin

See what security handled from code to cloud looks like.
Start a free trial in minutes, or book a demo for a guided tour.