Pricing you can work out without a call
Every paid plan includes everything we scan — code, applications and the perimeter — and the Free plan keeps one host under a weekly scan for $0. Plans differ in how much you point them at. You pay for what you monitor: not per user, not per scan, not per finding.
Free
$0/ month
For a small project with one host — regular security monitoring at no cost, no card, no time limit.
- 1 infrastructure host — a full infrastructure scan, every week
- 1 repository for code and dependency scanning
- Attack Surface and Discovery for your whole footprint
- Security Score, statuses, snooze and false positives
- 1 user · email when new CRITICAL or HIGH findings appear
Basic
$129/ month
For small teams without cloud infrastructure — one DevOps or CTO who owns security among other things.
- 3 infrastructure hosts — an IP, a hostname or a subdomain
- 1 web application tested while it’s running
- 10 repositories for code and dependency scanning
- Everything we scan, on an unlimited schedule
- Unlimited users, free read-only seats for auditors
Advanced
14-day free trialBest value$269/ month
For companies of 20–60 with cloud infrastructure and active CI/CD.
- 8 infrastructure hosts, 2 web applications, 20 repositories
- AWS — EC2 and Route 53 discovered and rescanned when they change
- Slack, Microsoft Teams and Jira routing
- Everything in Basic
Pro
$449/ month
For companies of 30–100 with mature DevOps, first enterprise customers and audit requirements.
- 15 infrastructure hosts, 4 web applications, 40 repositories
- Custom SLA by severity and per target
- Severity Override with an audit trail
- Two-way CI/CD webhook — trigger and status callback
- Attack Surface change tracking and alerts
- Everything in Advanced
Need more than your plan includes?
Add licences at the same rate on any paid plan. Nothing to negotiate, and no minimum. The Free plan can’t add licences — Basic is the next step.
$4
per infrastructure host — one IP, hostname or subdomain
$45
per web application tested while it’s running
$9
per repository for code and dependency scanning
Compare the plans line by line
Every paid plan includes everything we scan; Free covers one host with a weekly scan. Plans differ in how much you point them at, and in where findings are delivered.
| Feature | Free | Basic | Advanced | Pro |
|---|---|---|---|---|
| Plan & licences | ||||
| Infrastructure licences included | 1 | 3 | 8 | 15 |
| Web application licences included | — | 1 | 2 | 4 |
| Repository licences included | 1 | 10 | 20 | 40 |
| Users | 1 | Unlimited | Unlimited | Unlimited |
| Read-only seats for auditors | — | Free | Free | Free |
| Scheduled and on-demand scans | 1 automatic scan a week | Unlimited | Unlimited | Unlimited |
| External security | ||||
| Asset discovery — hosts, subdomains, services | ||||
| External infrastructure scanning | ||||
| Web application scanning (DAST) | — | |||
| TLS/SSL certificate expiry monitoring | ||||
| Attack Surface monitoring | Included: without change history | Included: with change history | ||
| Attack Surface change tracking & alerts | — | — | — | |
| Security Score | ||||
| Code | ||||
| Static code analysis, all supported languages | ||||
| Dependency scanning (SCA) | ||||
| PR checks — commit status on every push | — | |||
| Auto-fix | — | sooncoming soon | sooncoming soon | sooncoming soon |
| PR review | — | sooncoming soon | sooncoming soon | sooncoming soon |
| Workflow | ||||
| Vulnerability management — statuses, SLA and snooze | statuses and snooze, no SLA | Included: custom SLA | ||
| Severity Override with audit trail | — | — | — | |
| Remediation history with dates | ||||
| Role-based access control | — | |||
| Integrations | ||||
| Email alerts | ||||
| CI/CD webhook | — | trigger | trigger | two-way |
| GitHub / GitLab repositories | ||||
| Slack, Microsoft Teams and Jira routing | — | — | ||
| AWS — EC2 and Route 53 discovered and rescanned on change | — | — | ||
Discovery never consumes a licence: it maps your whole footprint, and you decide which assets go under monitoring. On paid plans scans are not billed, so the schedule costs the same whether it runs weekly or monthly. Free has a fixed weekly scan.
Questions people ask before paying
Topscan builds on the best in class scanning engines
Still have questions?
Contact usThree kinds, and they are counted separately. An infrastructure host is one IP, hostname or subdomain. A web application is one running app tested from the outside. A repository is one repo for code scanning. Discovery is free and maps your whole footprint — a licence is used only when you put an asset under monitoring, so the hosts you dismiss cost nothing.
Add licences at $4 per infrastructure host, $45 per web application and $9 per repository. The rate is the same on every paid plan — there is no volume pricing to negotiate and no sales call in the way.
No to all three. Users are unlimited on every paid plan (Free has one). On paid plans scans are never billed — a weekly schedule costs exactly what a monthly one does — and a busy month with many findings costs the same as a quiet one. Free has a fixed weekly scan.
Yes, and it costs nothing. Read-only seats are free on every paid plan, so an auditor or a customer’s security reviewer can read findings and remediation history without taking a paid seat.
Regular security monitoring for a small project, free: a full infrastructure scan of one host every week, Discovery and Attack Surface for everything around it, one repository, one user, findings with a fix and a Security Score. Add more only when the project needs it — paid features stay visible and marked with the plan that opens them. It is limited by size, not by the depth of the scan.
At the end of the paid period the workspace moves to the Free plan instead of being closed: the first target you added stays under weekly monitoring, the rest and any repositories over the limit stay visible read-only, one user keeps access. Nothing is deleted, and choosing a plan again restores everything. A workspace blocked for non-payment can also be moved to Free by hand, by accepting the Free plan terms.
The trial is 14 days of the full Advanced plan and needs no card, so nothing is charged automatically. If you don’t subscribe when it ends, the workspace moves to the Free plan: the first host you added stays under a weekly scan, one repository stays connected, one user keeps access, and everything above that stays visible read-only. Nothing is deleted — pick a plan any time and the full workspace is back.
Start with one domain
14 days of the full Advanced plan, no credit card, and you decide which assets get scanned. Nothing is charged when the trial ends — the workspace moves to the Free plan, one host stays under a weekly scan, and picking a plan brings the rest back.
Unlimited scans and users on every paid plan · Free plan for one host