Astra Security publishes real prices on a public page. Reaching a total is the harder part, because the spend spreads across five products, four pricing tabs, and a per-target unit, with the pentest line sold annually only.
Every number below comes from Astra’s own pages, checked in July 2026, with a screenshot of each pricing tab. What needs explaining is how the pieces combine into your actual total.
Each section sets Astra’s numbers against CodeAnt AI, which prices per user and bills its pentest only when a working exploit is proven.
Short answer: Astra’s pentest costs $1,999 per target per year (Pentest Auto, autonomous) or $5,999 per target per year (Pentest Expert, manual plus autonomous), with Enterprise custom. The DAST scanner runs $69 to $499 per month, cloud scanning $99 to $199 per month, and a one-week trial costs $7. There is no free tier, no monthly pentest billing, and no published price for the new waitlisted Autonomous Pentest product.

Astra Security Pricing Plans at a Glance
Here is the full current price list in USD, as of July 2026. Monthly figures use the page’s monthly billing view.
Product line | Plan | Price | Unit and key limits |
|---|---|---|---|
Pentest (PTaaS) | Pentest Auto | $1,999/yr | 1 target, autonomous pentest, 1 human re-scan, annual only |
Pentest (PTaaS) | Pentest Expert | $5,999/yr | 1 target, manual + autonomous pentest, 2 expert re-scans, sales call to buy |
Pentest (PTaaS) | Enterprise | Custom | Multi-target, on-prem deployment, continuous autonomous pentesting |
DAST Scanner | Scanner Lite | $69/mo | 1 target, 3 scans per month, 1 integration |
DAST Scanner | Scanner | $199/mo | 1 target, unlimited scans and integrations |
DAST Scanner | Scanner Agency | $499/mo | 5-target pool with a 30-day cooling period |
Cloud Security | Cloud Starter | $99/mo | 1 cloud target, up to 250 resources per account |
Cloud Security | Cloud Growth | $199/mo | 3 cloud targets, up to 1,000 resources per account |
Cloud Security | Cloud Enterprise | Custom | Multi-cloud, expert-led cloud pentest and review |
API Security | All tiers | Not purchasable | Pricing tab not selectable on the live page |
Autonomous Pentest | Waitlist | TBA | Credit-based model, rates unpublished |
Count carefully and that is five products with four pricing tabs, three of which print real numbers. Annual billing carries a 15% saving on the DAST and cloud lines, and the pentest line has no monthly option to discount.
How Much Does an Astra Pentest Cost?
Astra sells three pentest tiers, all priced per target and billed annually. Here is what each includes, straight from the plan cards on the live pricing page.
What you get | Pentest Auto ($1,999/yr) | Pentest Expert ($5,999/yr) | Enterprise (custom) |
|---|---|---|---|
Autonomous pentest, depth of a 2-week human pentest | Yes | Yes | Yes |
Manual pentest by certified experts (OWASP, APTS, SANS, PTES) | No | Yes | Yes |
Compliance reports (SOC 2, ISO 27001, HIPAA) | Yes | Yes | Yes |
First report on the same day | Yes | Not listed | Not listed |
Human re-scans to verify fixes | 1 | 2 | Not stated |
Cloud security config review (AWS, GCP, Azure) | No | Yes | Yes |
Pentest of consumed APIs and AI components in scope | No | Yes | Yes |
CREST, PCI-ASV, CERT-In compliant reports | No | Yes | Yes |
Named account manager | No | Yes | Yes |
Private cloud and on-premise deployment | No | No | Yes |
Centralized workspace management | No | No | Yes |
Internal application scanning | No | No | Yes |
Continuous autonomous pentesting | No | No | Yes |
Custom SLA and payment options | No | No | Yes |
How you buy | Self-serve checkout | Schedule a call | Contact us |
The Enterprise card starts from “Everything in Pentest Expert” and adds the deployment and scale rows above. Astra’s pricing FAQ puts manual pentests at 10 to 15 working days.
The table settles two decisions before you pick. Pentest Expert is not self-serve, so treat the $5,999 list price as the opening number in a negotiation, and if your auditor requires CREST, PCI-ASV, or CERT-In recognized reports, the $1,999 tier will not satisfy them.
Whichever tier you pick, every pentest plan includes a shared Slack channel, AI auto fixes delivered into your IDE via MCP, and a public Trust Center page. Our penetration testing cost guide shows how these figures sit against the wider market.
How Much Does the DAST Scanner Cost?
Scanner Lite runs $69 per month for one target with 3 vulnerability scans a month, authenticated scanning, and a single integration. Scanner, the popular tier at $199 per month, lifts scans and integrations to unlimited and adds four expert-vetted scans a year on annual billing.
Agencies managing client sites get their own tier, with Scanner Agency at $499 per month swapping the single target for a 5-target pool you can rotate on a 30-day cooling period. Annual billing brings the three tiers to $699, $1,999, and $4,999 per year, per the page’s 15% saving toggle.

How Much Does Cloud Security Scanning Cost?
Cloud Starter costs $99 per month and scans one AWS, Azure, or GCP target up to 250 resources per account. Cloud Growth at $199 per month covers three cloud targets of your choice, 1,000 resources per account, scheduled scans, JSON and management reports, and Slack plus Jira integrations.
A custom-priced Cloud Enterprise tier covers multi-cloud estates and adds a manual pentest and cloud security review performed by cloud security experts. The $7 one-week trial covers this line too.

What Counts as a Target?
Astra bills nearly everything per target, so the target definition drives your entire quote. Per the pricing FAQ, a target is a domain with all its site-tree URLs, and a URL, IP, website, or API each qualifies.
Astra’s own FAQ adds two clarifications that matter for budgeting:
SaaS apps consolidate. A SaaS application with all its APIs and underlying cloud counts as one pentest target, and extra hosts your site calls (like api.example.com) can be added during setup without buying another target.
Mobile apps split. iOS and Android builds of the same product count as one target each, so a mobile pentest is usually a two-target line item.
Read your own architecture against that definition before comparing Astra to per-user tools. A five-microsite marketing estate is five DAST targets, while one consolidated app is one pentest target.
Where Does the Bill Grow?
Your Astra invoice grows along four levers, all documented on Astra’s own pages.
Product-line stacking. DAST, pentest, and cloud each bill separately, so covering one app and its cloud account on paid tiers means at least two subscriptions, and three once a compliance pentest enters.
Target count. Every additional domain, IP, or mobile build multiplies the per-target price across whichever lines cover it.
Re-scan ceilings. Fix verification by humans caps at one re-scan on Auto and two on Expert, and a slow remediation cycle can outrun them. Our retest guide covers why that cap matters more than it looks.
The sales gates. Expert requires a call and Enterprise is custom, so the self-serve numbers stop at $1,999.
Stack the lines for one SaaS app and the shape becomes concrete. Scanner at $1,999, Cloud Starter at $999, and Pentest Expert at $5,999 total $8,997 per year for a single target on annual billing, before any enterprise gate.
A 10-developer team covering code security on CodeAnt AI pays $2,400 a year at $20 per user per month, with the pentest billed only on proven findings. Where your estate sits between those two shapes decides which meter is cheaper for you.
Multi-year commitments and bundles earn what Astra calls favorable pricing, per its FAQ. The 15% annual toggle is the only discount printed on the page.
Does Astra Security Have a Free Trial?
Astra has no free tier, and the entry offer is a $7 one-week trial of the DAST Scanner or Cloud Starter with platform access and no credit card commitment.
The pentest line has no trial at all, so you cannot sample the autonomous pentest that anchors Pentest Auto before the $1,999 annual commitment. Your options before paying are the scanner trial or a demo call.
CodeAnt AI approaches the same moment differently, with a free first black-box pentest scan that reports exploit-verified findings within 48 hours, before any payment details exist.
What Astra Gets Right on Pricing
Several of Astra’s pricing choices work in your favor.
Published numbers. Real prices are printed for three of its five products, including the flagship pentest tiers.
A cheap first taste. A $7 week of the scanner beats a demo call for judging finding quality on your own app.
MCP auto-fix on every plan. Fix prompts delivered into Cursor, VS Code, Claude Code, Claude Desktop, or ChatGPT ship with every pentest plan, including the cheapest.
A predictable unit. Per-target pricing is easy to forecast for a stable estate, and Astra’s target definition is generous about consolidating a SaaS app’s APIs and cloud.
Auditor-ready deliverables included. Compliance-mapped reports and the public Trust Center come with every pentest tier, which matters when the pentest exists to satisfy SOC 2 requirements.
What to Watch Before You Sign Up
A few details deserve a close look before you commit.
Annual-only pentests. No pentest tier bills monthly, so the minimum pentest commitment is $1,999 for a year, not a one-off engagement.
The $5,999 tier needs a call. Expert’s CTA is “Schedule a call”, so budget for a conversation, not a checkout.
The API tab cannot be selected. API Security pricing exists in the page markup, but the tab does not respond on the live pricing page and the line cannot be bought there.
Autonomous Pentest is waitlisted. The new agentic product is priced on credits, with rates still to be announced.
What those subscriptions actually buy, engine by engine, is covered in our Astra Security features breakdown.
How Does Astra Pricing Compare to CodeAnt AI?
The two platforms meter different things, with Astra pricing targets per year and CodeAnt AI pricing seats and findings.
Dimension | Astra Security | CodeAnt AI |
|---|---|---|
Billing unit | Per target, per product line | Per user per module, findings-based for pentests |
Pentest cost | $1,999 to $5,999 per target per year, annual only | $0 engagement fee, pay when a working exploit is proven |
Entry point | $7 one-week scanner trial, no pentest trial | Free black-box pentest scan plus a 14-day trial with unlimited seats |
Platform pricing | $69 to $499 per month per line | $20 to $24 per user per module per month |
Re-scans | 1 on Auto, 2 on Expert | Free and unlimited after fixes |
Code-layer coverage | None, runtime products only | SAST, secrets, and AI code review in the same platform |
Buying motion | Self-serve up to $1,999, sales call beyond | Self-serve signup |
Which surfaces you need tested matters more than the plan math. Astra’s spend covers runtime testing of deployed targets, and if you also need code review and static analysis, the full CodeAnt AI vs Astra Security comparison shows how the code side changes the numbers.
Where This Leaves You
Astra’s prices are public, and the total still takes work to assemble. Budget per target, per product line, and per year, and treat $1,999 as your real entry price if a compliance pentest brought you here.
Astra fits when your estate is a stable set of targets, your driver is an auditor-recognized pentest report, and separate line items for DAST, cloud, and pentesting suit how you buy. The broader field, including tools that bill differently, is mapped in our Astra Security alternatives guide.
CodeAnt AI is the pick when spend should follow people and proof instead of targets, with $20 to $24 per user per module per month, a free exploit-verified first scan, and pentest billing that starts only when a working exploit is proven.


