Choose the coverage that fits your needs

SCOPED ASSESSMENT

Agentic Pentest

Get a scoped, agentic assessment of an application or connected ecosystem, with a working exploit for each finding the AI agents confirm.

For teams running focused deep agentic scans.

Risks Covered
50
Tokens Included
50
Pentest Equivalent
1 week of pentest

Pentest equivalent is the time one pentester needs to assess the same number of risks.

Core package: $499 one-time assessment
Get started
CONTINUOUS APPLICATION SECURITY

AppSec

Most Popular

Continuously secure one connected mobile or web/API application ecosystem.

Coverage
WHAT'S INCLUDED
  • 1 Mobile App
  • Up to 3 Web/API targets
  • Up to 3 source code repositories
  • Static, dynamic, runtime, and behavioral analysis
  • Authenticated login, SSO, and 2FA/OTP workflows

Tested together as one attack surface

Billing
AppSec Mobile: $599 per application / month, billed annually
Get started
ORGANIZATION-WIDE

Enterprise

Secure multiple applications with configurable coverage, governance, automation, and support.

  • Configurable application coverage
  • Annual pooled AI Security Credits
  • Governance, integrations, and support
  • Attack Surface and App Vetting included
How we protect your data
  • SSO/SAML, RBAC, and audit logs
  • Bring your own AI key (BYOK)
  • Data residency in the US, EU, GCC, or APAC
  • On-premises deployment (add-on)
Built for your portfolioCustomannual agreement
Book a demo
Trusted By
GoogleRolexCiscoPanasonicEdenredDeloitteTelmedIQTikTokBMWOoredoo

What security teams say about Ostorlab

Gartner Logo

4.8/5

Read the reviews
Very efficient team, the support engineers are very good and knowledgeable. The product is always evolving and they take customer input very seriously.
Senior Appsec Engineer - Banking

Gartner® and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose

APPSEC / MOBILE

Secure the mobile app and everything behind it

Continuously test the app and its connected APIs, backends, source code, dependencies, containers, secrets, configurations, and runtime workflows.

Mobile app
APIs Source Runtime Dependencies CI/CD Secrets

Continuous discovery

New builds, dependencies, and exposed services are automatically pulled into coverage.

Runtime intelligence

Static, dynamic, behavioral, and authenticated workflow testing in one workspace.

From finding to fix

Investigate deeply, generate secure patches, and validate remediation without context switching.

BEST FOR

Teams shipping mobile products

  • Mobile engineering and AppSec teams
  • Teams shipping Android, iOS, or HarmonyOS apps
  • Continuous security and privacy testing
  • CI/CD-integrated investigation and remediation
WHAT'S INCLUDED

One connected security workspace

A single Workspace covers your complete application ecosystem:

1 Mobile AppApp Store, Google Play, TestFlight + binary files (.apk, .ipa, .aab)
+
Up to 3 Web/API targetsREST, GraphQL & backend endpoints
+
Up to 3 source code repositoriesGitHub, GitLab, Bitbucket & Azure DevOps
  • Static, dynamic, runtime, and behavioral analysis
  • Authenticated login, SSO, and 2FA/OTP workflows
  • 20 AI Security Credits/month
  • One-click Autofix and Ticket Agent triage
  • Unlimited collaboration seats
INTEGRATIONS INCLUDED

Security belongs in the tools your teams already use

AI SECURITY CREDITS

How AI Security Credits work

Routine workspace testing is included. Credits power advanced AI actions.

20credits / month
Dig deeper
Autofix
Agentic testing
Fix validation
CREDITS POWER
  • Agentic mobile, web, and API testing
  • Single Vulnerability Assessment & Dig Deeper
  • AI Autofix code patches & configuration fixes
  • Ticket Agent triage & Pull-request drafting
  • Fix validation & pentest-grade assessments
WHAT HAPPENS WHEN YOU RUN OUT?

Routine workspace testing continues. Advanced AI actions require additional credits or, for Enterprise, credits from the annual pool.

COMPARE COVERAGE

Compare plans

See how each plan supports application testing, AI-powered remediation, reporting, continuous security, and governance. Click category headers to expand or collapse.

Not sure which testing mode you need? Compare testing modes

Capability
Agentic PentestScopedGet started
AppSec MobileContinuousGet started
AppSec Web/APIContinuousGet started
EnterprisePortfolioBook a demo
Primary use case
Validated assessment
Continuous mobile ecosystem security
Continuous web/API/backend security
Organization-wide AppSec
Pricing basis
Assessment Credits
Workspace + AI Security Credits
Workspace + AI Security Credits
Custom annual plan
Mobile application support
Supports mobile ecosystems
Application/workspace allowance
Scoped assessment
1 Mobile Workspace (1 Mobile App + Up to 3 Web/API + Up to 3 Repos)
1 Web/API Workspace (Up to 3 Web/API + Up to 3 Repos)
Configurable
Monthly AI Security Credits
Estimate-based
20 AI Security Credits/month
20 AI Security Credits/month
Annual credit pool
Multi-asset Security Runs
Mobile app testing (Android, iOS, HarmonyOS)
Add-on
Configurable
Web app & API/backend testing
Configurable
Source repository scanning
Configurable
Container scanning
Configurable
SBOM scanning
Configurable
SAST, DAST, SCA & API Security
Runtime & Behavioral analysis
Configurable
Authenticated workflow testing (SSO/2FA)
Configurable
Agentic AI testing
AI Bring Your Own Key (BYOK)
Single Vulnerability Assessment & Dig Deeper
With credits
With credits
With credits
With credits
AI Autofix & Ticket Agents
Add-on
Configurable
PR drafting & Fix validation
Add-on
Available on request
Available on request
Configurable
Human validation
Add-on
Add-on
Configurable
Continuous monitoring & rescanning
Configurable
CI/CD, Source code & Ticketing integrations
Available on request
Asset Attack Surface
Available on request
Included
App Vetting
Available on request
Included
SSO/SAML, RBAC & Audit logs
Available on request
Add-on
Add-on
Support & SLA Tiers
Standard
Standard / Priority
Standard / Priority
Choice of Standard, 24/5 Priority, or Dedicated TAM & 24/7 SLA
QUESTIONS, ANSWERED

Frequently asked questions

Learn how plans, workspaces, credits, assessments, integrations, and additional coverage work.

Book a demo

An application is identified by its package name (Android) or bundle identifier (iOS). All builds sharing the same identifier within the same platform are counted as a single application. Each license is a monthly slot that you can rotate over your applications each month. If for instance you have 6 applications (3 Android and 3 iOS) and you opt in for 2 licenses. You can scan 2 applications the first month as many times as needed and then switch to 2 different applications next month, etc.

READY WHEN YOU ARE

Ready to secure your applications?

Start with Agentic Pentesting or build your complete Application Security program.