Pricing
Pricing: external security evidence, from €49/mo
Priced per measured perimeter. 14-day free trial, no credit card. An automated external-surface analysis, complementary to a manual penetration test.
Free, 60 seconds, no account. A-F grade across 66 controls in 25 categories, each finding with its raw evidence and timestamp.
€39 one-time. The NIS2 Audit Pack.
Full NIS2 and ISO 27001 control-mapped PDF, 90-day scan history, and a dated attestation. Delivered immediately. No recurring charge.
Free
Evaluate the engine — no credit card, no time limit.
- 1 domain
- 1 scan per week
- OWASP Top 10 (2021) mapping
- Raw evidence and timestamp per finding
- Email alerts
Starter
A single perimeter, measured daily, with evidence retained.
- 3 domains monitored
- Daily external-surface scans
- 5 Evidence Reports / month
- NIS2 Article 21(2) control mapping
- Email alerts
No credit card required
Growth
For organisations answering a security department on a schedule.
- 10 domains monitored
- Continuous external-surface measurement
- Unlimited Evidence Reports
- NIS2, ISO 27001 and DORA control mapping
- CI/CD integration
- Email alerts
- Remediation guidance (AI) Soon
No credit card required
Scale
For multi-entity perimeters under recurring third-party review.
- 25 domains monitored
- Custom-branded Evidence Reports
- SSO + team roles Soon
- NIS2, ISO 27001 and DORA control mapping
- Exposure confirmed by content signature (no soft-404)
- Priority support (<2h SLA)
- Full API access
No credit card required
Risk-free
14 days free. No credit card. Cancel anytime.
Test the full Growth tier -- multi-domain scans, NIS2 export, Evidence Reports -- before paying a cent. We never charge you automatically. Cancel from your dashboard in one click.
Built for SaaS, fintech, healthtech, and MSPs across the EU
Enterprise
Unlimited domains, custom SLA, dedicated CSM, bulk VC portfolio licensing, custom integrations.
Not sure yet?
Try a free scan first -- no account neededEvidence standard
What a security department gets, check by check
66 controls across 25 categories
A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.
Raw evidence and a timestamp on every finding
Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.
Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA
Mapping happens in the engine, so the export goes to the auditor without re-formatting.
Exposure confirmed by content signature
Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.
SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.
Price comparison
Entry prices in this market, with sources
Published entry prices, each linked to the vendor page it came from. Scopes differ, so these are prices, not equivalences.
| Tool | Entry price |
|---|---|
| SaaSFort Growth You're here | €149/mo |
| HostedScan Basic | $49/mo |
| Detectify App | €90/mo |
| Intruder Essential | $149/mo |
| Aikido Basic | $300/mo |
All prices verified on competitor public pricing pages. SaaSFort Growth includes multi-domain scans, NIS2 export, ISO 27001 mapping, Evidence Reports, and continuous monitoring.
Why teams trust the result
No magic. Just three things competitors don't do.
66 controls, 25 categories, reproducible
Same domain, same result. No AI heuristics -- RFC validation, header presence, certificate chains, DNS records. A finding can be contested, re-run and compared.
Raw evidence and a timestamp on every finding
Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.
Every finding tagged with its OWASP / NIS2 / ISO 27001 / DORA control
Mapping happens at the engine layer. Hand the JSON / CSV / PDF export to a reviewer without re-formatting anything.
Pricing FAQ
Is there a free trial?
Can I switch plans?
What payment methods are accepted?
Is annual billing required?
Can I cancel at any time?
What security checks does SaaSFort run?
Does SaaSFort help with NIS2 compliance?
Is SaaSFort compliant with ISO 27001?
Where is my data stored?
Do you access our source code or internal systems?
How fast is a scan?
What is a Evidence Report?
What if I need more domains than my plan allows?
What kind of support is included?
How long does onboarding take?
How is SaaSFort different from SecurityScorecard or Intruder?
Buyer guides: SaaS Security Leaderboard: public NIS2 grades ·Security scan by use case ·NIS2 supplier questionnaire ·Prove SaaS security to enterprise buyers ·NIS2 audit evidence requirements ·NIS2 supply chain Article 21 ·How to answer a security questionnaire fast ·Vendor security assessment guide ·What a NIS2 audit costs