AI Pentesting

StackHawk Pricing in 2026: Plans, Limits, and Total Cost

 Ninad Pathak - Tech Author
Ninad Pathak

Professional Code Breaker

StackHawk pricing starts at $10 per user per month for Wingman, with unlimited apps and 50 agentic scans per user each month. Scale has no public list price; sales scopes it by team, with unlimited apps and unlimited agentic scans under the public terms available on July 31, 2026.

The $10 figure covers a Wingman seat, not an entire application-security program. Compare the agent subscription with the scope of AI penetration testing and the CodeAnt AI pricing model before treating the deliverables as substitutes.

TL;DR

Plan

Published price

Included usage

Best fit

Main pricing unknown

Wingman

$10/user/month

Unlimited apps; 50 scans/user/month

Developers running security tests inside an AI coding agent

Additional-scan unit price

Scale

Custom quote

Unlimited apps; unlimited agentic scans

Security programs that need discovery, governance, and reporting

Contract price, minimum team size, and term

StackHawk pricing page showing Wingman at $10 per user per month and Scale as a sales-scoped plan

Wingman has a 14-day trial with no credit card, while Scale trials are arranged through sales. At full quota use, Wingman’s list price works out to $0.20 per scan; that arithmetic says nothing about scan depth or coverage.

StackHawk tests a running application. If the evaluation includes source analysis, separate that work using the distinction between SAST and DAST before comparing prices.

How Much Does StackHawk Cost?

StackHawk Wingman costs $10 monthly for each person who runs it alongside a coding agent. One paid user receives 50 scans per billing month and can use them across an unlimited number of applications.

Scale is quote-only. StackHawk says its price is team-based rather than usage-based, and its public comparison table removes the agentic-scan ceiling.

The public page gives no minimum team size or annual commitment. It also omits a volume schedule.

No onboarding fee or dollar price for Scale is published.

Use the Wingman list price when you can identify each person who will scan from an agent. Request a normalized Scale quote when the purchase extends to organization-wide discovery or access control.

Coverage reporting and enterprise support also move the purchase into Scale. If the purchase requires an assessment with an audit-facing deliverable, separate it from day-to-day scanning using this comparison of AI pentesting versus traditional DAST.

StackHawk Pricing Plans at a Glance

Pricing dimension

Wingman

Scale

Public price

$10/user/month

Contact sales

Billing basis

Each person who runs Wingman

Team-based; exact unit not public

Applications

Unlimited

Unlimited

Agentic scans

50/user/month

Unlimited

Coding-agent workflow

Included

Included

Attack-surface discovery

Not listed

Included

Sensitive-data detection

Not listed

Included

Program reporting

Not listed

Included

Teams, roles, and SSO

Not listed

Included

Support

Standard

Enterprise

Trial

14 days; no card

Separate 14-day sales trial

The table describes published packaging, not feature equivalence with another security product. Map the required security layer with a SAST and DAST tool comparison, then price the smallest package that covers it.

What Each StackHawk Plan Includes

Wingman: agent-based testing for individual developers

Wingman runs inside AI coding agents and is presented as a find-fix-verify workflow. The current pricing page names Claude Code and Cursor as supported agents.

GitHub Copilot and Codex are also listed. The fifth supported agent is Antigravity.

Inside those environments, the agent configures a reachable application and executes the dynamic scan.

It then interprets findings against the code before applying a fix and running the scan again. This workflow depends on an active StackHawk account and Hawk CLI 6.0.0 or later.

The setup also requires authentication and a running application that the scanner can reach. Source code must be available when the agent is expected to remediate a finding.

Include those prerequisites in the pilot; purchasing a seat does not create a reachable test target. Use the automated pentesting checklist to document the first run.

StackHawk Agent Skills documentation showing the supported agents, Hawk CLI version, authentication, running-application, and source-code prerequisites

Scale: visibility and governance around the testing program

Scale includes Wingman’s agent workflow, then adds attack-surface discovery and sensitive-data detection. It also expands scan coverage and provides program reporting.

Teams and roles bring access control into the plan, while SSO supports centralized identity. Enterprise support completes the published Scale package.

StackHawk describes reporting through scan coverage and fix rates by team. Program owners can use those measures to see what entered testing before checking whether the team fixed the reported issues.

Compare its program view with a dedicated code-security dashboard. If audit evidence drives the purchase, compare the promised output with a pentest sample report.

How the StackHawk Free Trial Works

Wingman includes a 14-day trial with no credit card. After the trial, the account can convert to $10 per user per month.

StackHawk says cancellation does not require a sales conversation.

Scale also has a 14-day trial arranged through sales. StackHawk’s cloud-deployment quick start gives a trial account 10 hours of cloud-deployed scanning, a separate unit from Wingman’s paid monthly scan count.

Record elapsed cloud-scan hours and completed scans during the pilot.

StackHawk cloud deployment documentation showing the 14-day trial, 10 cloud-scan hours, and public-target or allowlisting requirement

Use the trial on a representative authenticated workflow, not a landing page. OWASP’s Web Security Testing Guide supplies test categories, while the OWASP API Security Project covers API authorization and business-flow cases.

A pilot that skips authentication can leave protected routes untouched. The evaluation framework for an AI pentest platform for B2B SaaS provides a concrete application context.

What Makes the StackHawk Bill Grow?

Five variables can move the price or the surrounding delivery cost:

  • Active users: Wingman spend rises by $10 for each person who runs the agent workflow.

  • Scan volume: each Wingman user gets 50 scans per month. StackHawk says extra scans can be purchased after the ceiling, but it does not publish the add-on price.

  • Program requirements: the capabilities listed in the Scale section require the quote-only plan.

  • Environment preparation: cloud scanning needs a reachable target or network allowlisting. Authenticated testing also needs stable test accounts and data.

  • Operational ownership: a continuous pentesting toolchain needs an owner for failed runs and expired credentials.

These cost drivers separate the subscription from the work required to keep scans running. Release-by-release testing incurs a different operating cost from a point-in-time assessment.

Use the continuous versus annual pentesting breakdown to decide whether the tool supports a calendar event or a deployment gate. Treat an assurance deliverable as a separate job with its own acceptance criteria.

StackHawk Pricing Examples

These examples apply the published Wingman price and quota. They exclude taxes and extra scans.

Scale pricing and services are also outside the calculation. Any negotiated discount would change the result.

Active Wingman users

Monthly list price

Included scans/month

Effective price per included scan at full use

1

$10

50

$0.20

5

$50

250

$0.20

10

$100

500

$0.20

25

$250

1,250

$0.20

The calculation supports capacity planning, but “scan” is not a standardized unit of security assurance. Start by naming the target and the authenticated routes that the scanner must reach.

Then define the test policy and the evidence the team must retain. Specify how rescans work so that each quoted scan count describes the same process.

For a finding mapped to a known CVE, the vulnerability database identifies the affected package and its severity. It also provides remediation context for the engineering team.

NIST’s Secure Software Development Framework can place verification within the development lifecycle.

What StackHawk Gets Right on Pricing

The visible Wingman price lets a developer calculate seat spend without a sales call. Its quota of 50 scans per user also supports a basic capacity model.

The pricing card does not impose an application-count penalty, and the no-card trial lets a team validate setup before entering billing details. Scale creates a clear enterprise boundary by adding the program capabilities described earlier and removing the agentic-scan ceiling.

Wingman prices developer-loop testing; Scale prices organization-level oversight. The benefits of AI pentesting and the division between defensive and offensive security help define which work belongs in each budget.

What to Watch Before Signing

The public page and documentation use different plan names

The current pricing page shows Wingman and Scale. StackHawk documentation also uses Secure and Enterprise for some subscriptions or entitlements, and an older pricing URL remains crawlable.

Do not import an old plan price from a directory into the 2026 budget. Ask the seller for the order-form SKU and a feature map for that SKU.

The seller should also identify the online terms that govern the order.

Overage pricing is not public

Wingman users can buy additional scans after reaching 50, but the public page omits the price and bundle size. It does not explain when purchased scans expire or whether unused scans roll over.

If the team may cross the quota, compare a written overage schedule with Scale rather than extrapolating $0.20 per scan.

“Unlimited” does not define the test

Scale removes the agentic-scan count, but the contract still needs to define concurrent runs and scan duration. The support response and target restrictions should also be written into the order.

Review the fair-use language before accepting an unlimited label. The data-retention clause should state what StackHawk stores and for how long.

Use the same fields when reviewing questions for an automated pentesting vendor.

Coverage and evidence need acceptance criteria

Ask the vendor to identify which authenticated flows and API protocols are in scope. The pilot should also name the business-logic tests and the remediation evidence required for acceptance.

OWASP ASVS supplies verifiable application-security requirements for a testable pilot scorecard.

StackHawk Pricing vs CodeAnt AI

StackHawk Wingman sells developer access to an agentic dynamic-testing loop. CodeAnt AI includes one full scan and keeps low- or medium-severity findings free.

Payment unlocks findings rated high or critical. CodeAnt ties that payment to a working proof-of-concept exploit, so nothing is owed when the test finds nothing exploitable.

CodeAnt states that rescans are free and unlimited. Buyers can scope the work as black-box testing or use the white-box option when the tester should have implementation context.

Gray-box testing provides an intermediate level of access. The product page states that an audit-grade PDF report is delivered within 48 hours.

Validate the output against your acceptance criteria and inspect a sample security report before approval.

Buyer question

StackHawk Wingman

StackHawk Scale

CodeAnt AI pentesting

Public entry model

$10/user/month

Custom team quote

One full scan included; pay to unlock high/critical findings

Usage boundary

50 scans/user/month

Unlimited agentic scans

Free unlimited rescans stated on product page

Primary workflow

Test and remediate inside a coding agent

Program discovery, coverage, governance, and reporting

Exploit validation and pentest reporting

Public application scope

Unlimited apps

Unlimited apps

Scope the target and depth during the engagement

Best evaluation artifact

A successful authenticated find-fix-rescan flow

Coverage and governance proof across teams

Reproducible PoC and audit-facing report

CodeAnt also provides a code security platform that runs SAST and software composition analysis. The same platform detects secrets and scans infrastructure-as-code.

SBOM support covers the software inventory requirement. Price that layer separately when the program needs source and dependency analysis.

The code review versus penetration testing guide maps the overlap and boundaries.

StackHawk Pricing Buyer Checklist

If scan results will block a release, define the fail conditions and name the person who can approve an override. Every exception should carry an expiry rule.

A code-security gating workflow shows where those controls fit.

Send these questions before approving a plan:

  1. Which SKU will appear on the order form: Wingman, Scale, Secure, or Enterprise?

  2. What counts as a billable user, and how are seats added or removed mid-cycle?

  3. What does an additional Wingman scan cost, how is it packaged, and do unused scans expire?

  4. Does the quote require an annual term, minimum team size, onboarding fee, or support package?

  5. Which targets, protocols, authenticated flows, and business-logic tests are included?

  6. What concurrency, duration, fair-use, retention, and data-residency terms apply?

  7. Which reports, attestations, APIs, and audit artifacts are included?

  8. What happens to data and access at cancellation or non-renewal?

Run the pilot against a written acceptance plan. The guide to choosing an AI pentesting provider provides an evaluation framework, while automated pentesting mistakes identifies gaps that a low-friction scan can hide.

Frequently Asked Questions About StackHawk Pricing

Is StackHawk free?

StackHawk offers a 14-day Wingman trial with no credit card, not a public free-forever Wingman plan; the cloud quick start also gives trial accounts 10 cloud-deployed scan hours. Use this DevSecOps pentesting workflow to define what the trial must run in CI/CD.

How much is StackHawk Wingman?

Wingman is $10 per user per month as of July 31, 2026. Each user receives 50 scans per month and unlimited applications.

How much is StackHawk Scale?

StackHawk does not publish a Scale price. It describes team-based rather than usage-based pricing, with unlimited applications and unlimited agentic scans.

Request the price unit and any minimum purchase in writing. The quote should also state the contract term and included support.

Ask for the overage language before comparing Scale with Wingman. For broader market scoping, use a current pentesting vendor evaluation rather than stale directory prices.

What happens after 50 Wingman scans?

StackHawk says the user receives a notification and can buy additional scans or upgrade to Scale. The public page does not state the additional-scan price.

Is StackHawk pricing enough for a compliance budget?

Not by itself. A compliance budget must specify test scope and the evidence format that the assessor will receive.

The budget also needs a testing cadence and a process for verifying remediation. Confirm the assessor’s expectations before choosing the plan.

CodeAnt’s guide to AI pentesting for compliance translates those requirements into evaluation questions. An enterprise pentesting and code-security plan separates recurring scanning from code controls and audit deliverables.

FAQs

Start Your 14-Day Free Trial

AI code reviews, security and quality trusted by modern engineering teams.

Table of Content
No headings found on page
Ship clean & secure code faster

Get Pentest Report

NO CC REQUIRED