KAI Platform from €1,200/month — fixed pricing, 14-day free trial. Human-led services scoped per client. Every finding KAI reports ships with reproducible proof of exploitation, so your team only triages what matters.
AI-powered continuous security testing — published pricing, 14-day free trial, no per-finding charges.
These tiers cover the KAI platform subscription only. Human-led work — pentests, red team, compliance audits — is scoped per client under KAOS Services.
For startups & small teams
Continuous AI pentesting for a single product or a small estate. Self-serve onboarding — same-day scans on common stacks.
Most teams pick this
Continuous AI pentesting across your full estate. Compliance-ready evidence, full API and CI/CD gating included.
For regulated environments
Single-tenant, on-prem or air-gapped deployments. Custom techniques, BYOK encryption and dedicated solutions support.
Pricing context: KAI STARTER undercuts comparable AI pentest platforms (Pentera, NodeZero) by ~60%. KAI PRO sits at ~50% of Cobalt PtaaS Professional. Same autonomous AI agent across all tiers — only limits and integrations differ.
Same autonomous AI agent across all tiers. The differences are limits, integrations, deployment, and SLA.
| Feature | STARTER €1,200/mo | PRO €3,200/mo | ENTERPRISE Custom |
|---|---|---|---|
| Limits & scope | |||
| Assets included | 10 | 50 | Unlimited |
| Projects / workspaces | 1 | Unlimited | Unlimited |
| Concurrent scans (workers) | 1 | 1 | 1 (more on request) |
| Scans in queue | Unlimited | Unlimited | Unlimited |
| Scheduled scan cadence | Weekly + on-demand | Daily + on-demand | Continuous rotation |
| User seats | 3 | 15 | Unlimited |
| Manual review by OSCE3 operator | Via KAOS Services | Via KAOS Services | Via KAOS Services |
| Engine & coverage | |||
| All 127 attack techniques | |||
| RAG-driven technique selection | |||
| 6 MCP servers (code analysis, browser, OOB, …) | |||
| Custom MITRE techniques + custom MCP servers | — | — | |
| Findings validated with proof of exploit | |||
| Reporting & compliance | |||
| PDF + JSON exports | |||
| DOCX / SARIF / CSV / XLSX exports | — | ||
| MITRE ATT&CK coverage matrix | |||
| Compliance evidence (PCI 4.0, ISO 27001, SOC 2, HIPAA, NIS2, DORA, ENS) | Mapping only | Full evidence pack | Full evidence pack |
| White-label / custom branding | — | — | |
| Auditor portal (read-only watermarked access) | — | ||
| Triage & lifecycle | |||
| Risk acceptance workflow | — | ||
| Re-test management + PoC replay | — | ||
| Field-level change history (audit trail) | |||
| SLA tracking + MTTR analytics | — | ||
| Integrations & API | |||
| Slack / Teams / GitHub notifications | |||
| JIRA / Linear / ServiceNow / GitHub Issues | — | ||
| CI/CD: GitHub Actions / GitLab / Jenkins / Azure DevOps | Manual API | ||
| REST + GraphQL API | Read-only | Full | Full |
| Webhooks (HMAC signed) + delivery log | — | ||
| Terraform provider | — | ||
| Audit log streaming (Splunk / Datadog / Elastic) | — | — | |
| Identity & security | |||
| Email + password | |||
| SAML SSO + OIDC | — | ||
| SCIM 2.0 user provisioning | — | ||
| Custom RBAC roles | — | — | |
| BYOK encryption (AWS KMS / Azure KV / HSM) | — | — | |
| Deployment & data | |||
| Multi-tenant SaaS (EU / US) | |||
| Single-tenant managed VPC | — | — | |
| On-prem Kubernetes (Helm chart) | — | — | |
| Air-gapped operator | — | — | |
| Configurable data retention (30d–7y) | 12 months | 24 months | Configurable |
| Support & SLA | |||
| Email support | |||
| Business-hours response SLA | 24h | 4h | 1h |
| 24/7 emergency response | — | — | |
| Dedicated Customer Success Manager | — | — | |
| Solutions Engineer / onboarding | Self-serve | Guided | Dedicated |
| Production SLA uptime | 99.5% | 99.9% | 99.95% |
| Quarterly business review | — | ||
Need a tier between PRO and ENTERPRISE? Talk to us— we'll size it to your estate.
We can't promise a number of findings — that depends entirely on your environment's exposure. What we can promise is the format and rigor of every finding KAI surfaces.
Step-by-step instructions to reproduce the issue, including captured request / response pairs.
Severity scoring with environmental modifiers plus a plain-language business-impact summary.
Every finding tagged with the MITRE technique it abuses and the CWE class it belongs to.
Linked control families across PCI-DSS, ISO 27001, SOC 2, HIPAA, NIS2, DORA and ENS.
Screenshots, OOB callbacks, tokens, payloads — everything your engineering team needs to act.
Concrete fix recommendations, code-level when applicable, with verification steps after the patch.
Human + AI engagements led by our offensive security team — pentests, red team operations, compliance audits, advisory.
Why teams pick KAOS over a traditional pentest agency or a self-hosted scanner.
| Dimension | KAOS Platform + Services | Traditional pentest agency | DIY scanner |
|---|---|---|---|
| Time to first scan | Same day — self-serve | 4–8 weeks per engagement | Minutes — output unverified |
| Cost | From €1.2k/mo (Platform) · custom (Services) | €25k–€80k+ per project | €3k–€10k/yr (hidden infra cost) |
| Coverage cadence | 24/7 continuous + deep manual | Point-in-time snapshot | Limited to known CVE signatures |
| Finding format | Every finding ships with PoC | Manual write-up, varies by analyst | CVE matches — high noise rate |
| Continuous testing | Built-in | No — re-scope each time | Scheduled scans only |
All prices in EUR, exclude VAT. Andorran entity (KAOS S.L.U) for commercial contracting; EU customers contracted via KAOS AI SECURITY, S.L. on request.
Our team is happy to answer any questions and help you find the right plan.