AI Pentesting

Hadrian Pricing 2026: Nova and Atlas Costs Explained

 Ninad Pathak - Tech Author
Ninad Pathak

Professional Code Breaker

Hadrian Nova starts at €3,000 per penetration test. Each test covers one external web application identified by one target URL, while Atlas has no published list price because Hadrian quotes it by total asset count.

CodeAnt AI’s agentic pentesting uses a different commercial model. Payment unlocks verified high- or critical-severity findings instead of buying a prepaid test entitlement.

TL;DR

Hadrian package

Published price as of July 31, 2026

Billing unit

Best fit

Main budget constraint

Nova

Starts at €3,000 per test; bundles available

One entitlement for one external web app identified by one URL

On-demand, scoped application pentests

Entitlements expire after the contractual year and do not roll over

Atlas

Custom quote

Total external asset count

Continuous external exposure discovery and validation

No public per-asset rate, bands, minimum, or add-on price

Free external scan

Free for eligible organizations

One introductory exposure report

Early attack-surface snapshot

Eligibility is reviewed on an introductory call; it is not a free Atlas or Nova tier

A usable quote needs five inputs that the headline price does not settle:

  • The target URLs covered by Nova

  • The asset-count rule used for Atlas

  • The number of Nova entitlements and the retest terms

  • The add-on charges and applicable taxes

  • The renewal notice date and the first renewal’s price basis

Normalize them with a penetration-testing cost benchmark. Use the procurement guide for commercial models and testing categories to separate application assessments from continuous exposure coverage.

How much does Hadrian cost in 2026?

Only Nova has a published starting price. One test starts at €3,000.

Bundles require a custom quote based on scope and frequency.

Atlas is quote-only and scales with the total asset count across the external attack surface. M&A assessment and infostealer credential-leak detection are named as extra-cost add-ons, but Hadrian does not publish their prices.

Hadrian pricing page showing Atlas asset-count pricing and Nova at 3,000 euros per test

Nova therefore gives procurement a starting unit, while Atlas requires an agreed asset inventory before a total can be calculated. The order form should define how Hadrian discovers assets and counts them for billing.

Hadrian pricing and packaging at a glance

Question

Nova

Atlas

What are you buying?

An on-demand agentic pentest

Continuous external exposure management

What sets price?

Number of pentest entitlements

Total asset count

Is a numeric price public?

Yes: starts at €3,000 per test

No

What is the stated scope?

One external web application per target URL

The organization’s external attack surface

Are bundles available?

Yes; discount schedule is not public

No public bundle schedule

Are add-ons named?

No priced add-on list on the pricing card

M&A assessment and infostealer credential-leak detection

Is a free version published?

No free Nova tier; a separate eligibility-gated exposure scan exists

No free Atlas tier

Nova is a scoped assessment that fits an external penetration-testing methodology. Atlas buys ongoing discovery and validation, so compare it through continuous versus annual pentesting instead of multiplying Nova’s €3,000 starting unit.

What the Nova €3,000 starting price includes

Hadrian describes Nova as discovering and fingerprinting a target before identifying and validating vulnerabilities. The test ends with a report for that target, and the FAQ gives a 24–48-hour completion window depending on scope.

This AI penetration-testing guide explains the agent workflow without expanding Nova’s contractual scope.

The report provides proof of exploitability with reproduction steps, then adds risk context and remediation guidance. Hadrian maps results against SOC 2 and ISO 27001 before adding NIS2 regulatory context.

Those deliverables support the evidence stages in a penetration-testing process. Use reproducible findings as the standard when comparing automated penetration testing.

Framework mapping is not certification. Hadrian’s terms say the references describe controls that Nova helps evidence rather than frameworks under which Nova is certified.

Audit buyers should first identify the applicable compliance penetration-testing requirement, then map the delivered fields to their AI pentesting compliance plan. A SOC 2 engagement should also be checked against the evidence described in these SOC 2 penetration-testing requirements.

One test means one target URL

The Nova terms define a target as one external web application identified by a single target URL. One entitlement covers one target, even when Nova follows redirects or authentication flows to a different URL during the test.

Hadrian counts each external web application by URL, so a separate API may add another entitlement.

A separate administration interface can do the same. The quote should map every hostname to an entitlement and name the authenticated role used for that target.

Nova can be configured for black-box or gray-box testing. It also supports the white-box approach described in this testing-mode guide, although the chosen mode does not change the contract’s target-URL definition.

Entitlements expire and do not roll over

Nova entitlements are issued for the contractual year and expire unused at year-end. They do not roll over, including under a multi-year order.

Starting a test consumes the entitlement. Once consumed, it is nonrefundable unless Hadrian suspended or aborted the test for reasons unrelated to the customer’s configuration or use.

Build the annual quantity from the release calendar and expected audit windows, then reserve capacity for remediation verification. Teams with irregular demand should include unused entitlement exposure when comparing Nova with a PTaaS buying model.

Retests need a written answer

Hadrian’s public terms say retests follow its documentation, but the public contract does not state an included quantity or a retest price. It also does not say whether each retest consumes another entitlement.

The order form should define the retest scope and completion window. It should also state the number included and how each one affects the entitlement balance.

How Atlas pricing works

Atlas pricing scales with the total asset count. Hadrian describes the service as continuous discovery and validation across the external attack surface, with event-driven testing when it detects change.

The public page does not define an asset or explain duplicate handling. It shows neither pricing bands nor minimum commitments, and it leaves the billing period and overage treatment undefined.

Ask Hadrian how its count treats domains and IP addresses before signing. The contract should address cloud resources and APIs, then explain how short-lived infrastructure affects the total.

The contract also needs a measurement date and a procedure for removing duplicate or retired assets. An AI pentesting provider evaluation should treat this counting method as a commercial term rather than a dashboard detail.

Atlas offers M&A assessment and infostealer credential-leak detection as paid add-ons. Request separate line items for the base subscription and each selected add-on because none has a public price.

Does Hadrian offer a free trial or free tier?

Hadrian publishes a free external exposure scan rather than a free Atlas or Nova tier. Its report maps the internet-facing footprint and assigns a passive score, then flags exploitable vulnerabilities and misconfigurations.

Eligibility is discussed on an introductory call. Hadrian reserves the right to decline organizations that do not meet its criteria.

Use the report to evaluate the sales claim, not as proof of paid-product depth. Ask Hadrian to distinguish passive checks from validated findings.

A vulnerability database can add technical context to disclosed identifiers. CISA’s Known Exploited Vulnerabilities catalog separately records vulnerabilities exploited in the wild, while a detailed entry such as CVE-2026-28292 illustrates the vulnerability-level evidence needed before prioritization.

Hadrian cost examples

The calculations below use Nova’s €3,000 entry price and are not Hadrian quotes. They exclude tax and bundle discounts, and the final amount can change with scope or annual price adjustments.

Planned Nova targets in one contractual year

Entry-unit calculation

Planning baseline

1

1 × €3,000

€3,000

5

5 × €3,000

€15,000

12

12 × €3,000

€36,000

One application with three nominated target URLs tested after four major releases would require 12 entitlements. At the published starting unit, the planning baseline is €36,000.

Hadrian offers bundles and prices by scope and frequency, so a negotiated quote may be lower or higher. Calculate demand from the URL inventory rather than the number of products.

Atlas cannot be modeled from Hadrian’s public figures. Request a price at the current asset count, then ask for another calculation using the expected 12-month count and a plausible acquisition scenario.

Cost drivers and contract terms to check

The Nova terms introduce six commercial constraints that do not appear in the €3,000 headline:

  1. Annual commitment behavior: The subscription renews for successive 12-month periods unless either party gives at least 30 days’ notice, unless the order form says otherwise.

  2. Unused-credit risk: Entitlements expire after the contractual year with no rollover.

  3. Annual adjustment: Hadrian may increase fees in line with Eurostat’s Harmonised Index of Consumer Prices.

  4. Taxes: Published fees exclude applicable taxes.

  5. Payment timing: Invoices default to net 30, and late balances accrue 1% interest per month.

  6. Scope and authorization: The customer must have authority to test each target, including a relevant third-party or multi-tenant system.

Authorization needs technical review before approval. Use the multi-tenant SaaS pentesting guide to find shared-service boundaries and common testing mistakes to identify invalid pilot conditions.

Record the authorization and test handling in a written plan. NIST SP 800-115 provides a primary-source framework for planning technical security tests.

What Hadrian pricing gets right

Nova publishes its entry unit and expected 24–48-hour turnaround before a sales call. The pricing page also describes the report and confirms that volume bundles are available.

Hadrian separates on-demand application testing from Atlas’s continuous exposure work. During a pilot, measure the turnaround and inspect the validated evidence rather than assigning value to the product label.

This guide explains the measurable benefits of AI pentesting.

The contract defines the target unit and the entitlement lifecycle. A buyer can use that baseline to negotiate annual volume and retest handling before stating how unused entitlements expire in the order form.

What to watch before signing

Do not treat one product as one Nova target. Build a URL inventory that distinguishes the primary application from separate APIs and administration surfaces, then map authenticated roles to each target.

Do not buy a bundle without a release calendar because unused entitlements expire. Retest language should specify the included quantity and state whether remediation verification consumes another entitlement.

Atlas needs an equally explicit asset definition. The contract should describe discovery and deduplication, then explain how transient assets affect recounts and overages.

Set the renewal reminder well before the default 30-day notice deadline. Price the M&A and infostealer add-ons separately so their cost remains visible at renewal.

Hadrian’s terms do not warrant that Nova identifies every vulnerability. Map the pilot to the OWASP Web Security Testing Guide and document which parts of the organization’s risk model remain outside the test.

Hadrian pricing vs CodeAnt AI

Hadrian sells Nova through prepaid annual entitlements, each scoped to one external web application by URL. As of July 31, 2026, CodeAnt’s AI pentesting intake page says low- and medium-severity findings are free, while payment unlocks high- and critical-severity findings.

CodeAnt requires a working proof-of-concept exploit before payment and charges nothing when a run finds no exploitable issue. Its product page states that the report arrives within 48 hours and that rescans after fixes are free and unlimited.

CodeAnt AI pentesting page showing the start-a-pentest form and 48-hour report message

Hadrian Nova’s public contract centers one external web application and target URL. CodeAnt supports black-box and white-box testing, while its gray-box mode adds code memory.

A commercial comparison should follow the technical evaluation described in AI pentesting versus traditional DAST.

Start by confirming that each service validates attack paths and completes the required authentication flow. Inspect the report evidence before agreeing to the retesting cadence.

Choose Hadrian when the team wants on-demand Nova tests alongside Atlas’s continuous external exposure program and can forecast annual entitlement demand. Evaluate CodeAnt when payment tied to verified serious findings and free rescans fit the application’s release pattern.

For a wider market view, use this AI pentesting platform comparison.

Hadrian pricing buyer checklist

Use the automated-pentesting checklist to prepare the technical scope. Adapt these automated-pentesting questions to the order form, then require written answers to the following points:

  • Map every Nova entitlement to its exact URL and authenticated role.

  • State the included test and retest quantities.

  • Define when an entitlement is consumed, restored, or forfeited.

  • Confirm the treatment of unused entitlements at year-end.

  • Define how Atlas discovers, deduplicates, and recounts assets.

  • Price every selected Atlas add-on separately.

  • Specify the delivered report fields and compare them with a sample pentest report.

  • Name the AI penetration-testing methodology that controls testing depth and safety.

  • Record the renewal date, notice deadline, HICP adjustment basis, taxes, and payment terms.

  • Document the customer data and credentials required for testing, including where Hadrian processes them.

Those answers convert Nova’s €3,000 starting unit into a defined annual scope. They also make an Atlas quote comparable when another provider uses a different asset-count model.

FAQs

How much does Hadrian Nova cost?

How much does Hadrian Atlas cost?

Does Hadrian have a free trial?

Do unused Nova tests roll over?

Is a Nova retest included in the €3,000 starting price?

Start Your 14-Day Free Trial

AI code reviews, security and quality trusted by modern engineering teams.

Table of Content
No headings found on page
Ship clean & secure code faster

Get Pentest Report

NO CC REQUIRED