Cadence by Collabor8
Live demo Benchmark Get started →

Pricing

Priced for what you actually run.

Two pillars, two honest price models. Pillar 1 — pre-deployment static assessment — is priced by the size of your codebase, because a bigger app costs more to assess. Pillar 2 — external penetration testing — is priced by how deep you want to test (Level 1 or Level 2) and how many targets are in scope. Every price is stated here, before you ever sign up. No feature gates, no per-seat fees.

At a glance

Pillar 1 — static assessmentper assessment, by codebase size from R2000
Pillar 2 — external testingper testing window, by depth & targets from R1000
Crediteverything is bought in credits R250
Start free

The two pillars

What you're buying, and how it's priced.

Pillar 1

Pre-deployment static assessment

The full engine over your entire codebase, mapped to every framework. Priced once per assessment by the decompressed size of what you upload.

TierCodebase sizeCreditsPrice
Small 0 – 100 MB 8 R2000
Standard 100 MB – 500 MB 11 R2750
Large 500 MB – 1.2 GB 14 R3500
X-Large 1.2 GB – 2 GB 16 R4000
Custom / specialised over 2 GB Talk to us
Every tier runs the whole engine over the entire check set — the size only sets the price, never what gets assessed. Anything over the self-serve limit becomes a specialised engagement — get in touch.
Pillar 2

External penetration testing

A live, safety-enveloped test of your deployed application from the outside. Priced per testing window by how deep you go — Level 1 or Level 2 — and how many targets are in scope.

DepthLevelsCreditsPrice
Essential L0L1 4 R1000
Standard L0L1L2 8 R2000
Level 1 is passive observation plus GET-only forced browsing — non-intrusive, near-zero risk. Level 2 adds benign, detect-only active probes under the safety envelope. Prices are per testing window for a single target; each additional target in scope is +4 credits (R1000). Scope and rules of engagement are agreed and authorised before any run — talk to us to scope it.

All prices in South African Rand. Everything is bought as credits (1 credit = R250) — a tier simply bundles the credits that piece of work costs, so the price you see is the price you pay.

Every static assessment includes

The whole engine, every time.

  • Full static assessment across all mapped frameworks (ASVS, ISO 27001, PCI-DSS, POPIA, OWASP, SOC 2 and more)
  • Multi-pass, cross-validated verdicts with a confidence band
  • A downloadable report with file:line evidence for every finding
  • A publicly verifiable security badge when you clear the threshold
  • Continuous CVE watch against your dependencies between runs
  • Assessment cadence, windows and a remediation tracker
  • Contextual re-assessment with your supporting documents — bundled, no extra charge
  • Your code and documents are never stored — only the report is kept

See it on your own code first.

Run a free quick check on your application — a handful of our most common checks — before you spend a credit. Sign up, verify, and go.

Start free