SaaSFort

Pricing

Pricing: external security evidence, from €49/mo

Priced per measured perimeter. 14-day free trial, no credit card. An automated external-surface analysis, complementary to a manual penetration test.

Free, 60 seconds, no account. A-F grade across 66 controls in 25 categories, each finding with its raw evidence and timestamp.

66
controls, every tier
25
categories
4
frameworks mapped
One-time, no subscription

€39 one-time. The NIS2 Audit Pack.

Full NIS2 and ISO 27001 control-mapped PDF, 90-day scan history, and a dated attestation. Delivered immediately. No recurring charge.

Get the Audit Pack
14-day free trial No credit card required Cancel anytime

Free

Evaluate the engine — no credit card, no time limit.

Free
No credit card required
  • 1 domain
  • 1 scan per week
  • OWASP Top 10 (2021) mapping
  • Raw evidence and timestamp per finding
  • Email alerts
Get Started Free

Starter

A single perimeter, measured daily, with evidence retained.

€49 /month
or €490/year (Save 17%)
  • 3 domains monitored
  • Daily external-surface scans
  • 5 Evidence Reports / month
  • NIS2 Article 21(2) control mapping
  • Email alerts

No credit card required

Most Popular

Growth

For organisations answering a security department on a schedule.

€149 /month
or €1490/year (Save 17%)
  • 10 domains monitored
  • Continuous external-surface measurement
  • Unlimited Evidence Reports
  • NIS2, ISO 27001 and DORA control mapping
  • CI/CD integration
  • Email alerts
  • Remediation guidance (AI) Soon

No credit card required

Scale

For multi-entity perimeters under recurring third-party review.

€399 /month
or €3990/year (Save 17%)
  • 25 domains monitored
  • Custom-branded Evidence Reports
  • SSO + team roles Soon
  • NIS2, ISO 27001 and DORA control mapping
  • Exposure confirmed by content signature (no soft-404)
  • Priority support (<2h SLA)
  • Full API access

No credit card required

Risk-free

14 days free. No credit card. Cancel anytime.

Test the full Growth tier -- multi-domain scans, NIS2 export, Evidence Reports -- before paying a cent. We never charge you automatically. Cancel from your dashboard in one click.

Maps findings to:NIS2 Article 21ISO 27001 Annex AOWASP Top 10GDPR-ready

Built for SaaS, fintech, healthtech, and MSPs across the EU

Enterprise

Unlimited domains, custom SLA, dedicated CSM, bulk VC portfolio licensing, custom integrations.

Talk to Sales
Maps findings to NIS2 & ISO 27001 256-bit encryption Powered by Stripe Cancel anytime, no lock-in

Evidence standard

What a security department gets, check by check

  • 66 controls across 25 categories

    A fixed, published control set. The same domain measured twice yields the same result, so a finding can be contested, re-run and compared.

  • Raw evidence and a timestamp on every finding

    Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.

  • Mapped to OWASP Top 10 (2021), NIS2 Article 21(2), ISO/IEC 27001:2022 Annex A and DORA

    Mapping happens in the engine, so the export goes to the auditor without re-formatting.

  • Exposure confirmed by content signature

    Any exposed file or sensitive path is confirmed by signing the content and comparing it with a reference response, which rules out catch-all handlers and soft-404s.

SaaSFort performs automated external-surface analysis. It is complementary to a manual penetration test, not a replacement for one, and it does not detect business-logic flaws.

Price comparison

Entry prices in this market, with sources

Published entry prices, each linked to the vendor page it came from. Scopes differ, so these are prices, not equivalences.

Tool Entry price
SaaSFort Growth You're here €149/mo
HostedScan Basic $49/mo
Detectify App €90/mo
Intruder Essential $149/mo
Aikido Basic $300/mo

All prices verified on competitor public pricing pages. SaaSFort Growth includes multi-domain scans, NIS2 export, ISO 27001 mapping, Evidence Reports, and continuous monitoring.

Why teams trust the result

No magic. Just three things competitors don't do.

Deterministic

66 controls, 25 categories, reproducible

Same domain, same result. No AI heuristics -- RFC validation, header presence, certificate chains, DNS records. A finding can be contested, re-run and compared.

Evidence

Raw evidence and a timestamp on every finding

Observed headers, certificate chain, negotiated cipher suites, DKIM selectors tested, response excerpts. A reviewer verifies the observation instead of trusting a score.

Auditor-ready

Every finding tagged with its OWASP / NIS2 / ISO 27001 / DORA control

Mapping happens at the engine layer. Hand the JSON / CSV / PDF export to a reviewer without re-formatting anything.

Pricing FAQ

Is there a free trial?
Yes — 14 days of full Growth access, no credit card required. Plus a free one-time scan on any plan.
Can I switch plans?
Yes, upgrade or downgrade anytime. Billing is prorated automatically via Stripe.
What payment methods are accepted?
All major credit cards and SEPA debit via Stripe. Annual invoicing available for Enterprise plans.
Is annual billing required?
No — monthly billing is available on all plans. Annual saves up to 17% and is preferred for enterprise procurement.
Can I cancel at any time?
Yes. Cancel your subscription from your dashboard at any time. You keep access until the end of your billing period. No cancellation fees, no questions asked.
What security checks does SaaSFort run?
SaaSFort performs 66 automated checks across 25+ categories: SSL/TLS, HTTP security headers, DNS, DKIM, DNSSEC, CVE-linked JS library detection, WAF detection, cipher suites, Certificate Transparency, cookie security, source map exposure, and more.
Does SaaSFort help with NIS2 compliance?
Yes. All paid plans include NIS2 compliance mapping. Our scans map findings to NIS2 requirements so you can demonstrate third-party vendor due diligence to auditors.
Is SaaSFort compliant with ISO 27001?
Our Scale plan includes NIS2 / ISO 27001 compliance mapping, allowing you to map scan results to these frameworks and answer vendor security questionnaires faster.
Where is my data stored?
Scan results are stored encrypted on EU infrastructure (AWS eu-west-3, Paris). We never share or sell your security data. You can request deletion at any time. Full GDPR compliance.
Do you access our source code or internal systems?
No. SaaSFort performs external, non-intrusive OSINT-style scans only. We check what is publicly visible — exactly what an attacker or an enterprise buyer would see. No agent to install.
How fast is a scan?
First results in under 60 seconds. A full 66-check scan completes in under 2 minutes. Evidence Reports are generated instantly from scan results.
What is a Evidence Report?
A branded, multi-page PDF report formatted for procurement and legal teams. It maps scan findings to business risk, includes pass/fail per check, compliance mappings (NIS2, OWASP, ISO 27001), and remediation guidance. Enterprise buyers can attach it directly to vendor onboarding.
What if I need more domains than my plan allows?
Contact us for custom domain add-ons, or upgrade to Scale/Enterprise for higher limits.
What kind of support is included?
Free and Starter plans include email support. Growth includes priority email. Scale includes priority support with a <2h SLA. Enterprise gets a dedicated CSM.
How long does onboarding take?
Under 2 minutes. Enter your domain, run a scan, get results. No onboarding call needed, no agent to install, no configuration required.
How is SaaSFort different from SecurityScorecard or Intruder?
SecurityScorecard starts at €500+/mo and targets large enterprises with raw API data. Intruder starts at €149/mo for developer-focused vulnerability scanning. SaaSFort starts at €49/mo, focuses on SMB procurement workflows, and produces PDF Evidence Reports non-technical teams can act on immediately.