Packages & pricing
Pricing that scales with your security programme
Every SecScope customer gets a portal built around their engagements. Plans are set up with the SecScope team and apply to your whole organisation — pick the capabilities your team needs, and we configure the rest. There's no self-service checkout: tell us where you're headed and we'll get you on the right plan.
Core
See and act on your results.
Included with your engagement
Up to 5 portal users
- Findings inventory with full vulnerability detail, evidence & CVSS
- Branded PDF reports and the Excel vulnerability tracker
- Update remediation status, comment with the testers & request retests
- Saved views and CSV export of your findings
- Mandatory 2FA and role-based access for your team
Professional
Run your security programme from the portal.
Contact sales for pricing
Up to 25 portal users
- Everything in Core, for up to 25 users
- Self-service engagement & retest requests
- Advanced dashboards, trends and the Remediation Planner
- Risk-acceptance workflow and a tested-asset inventory
- Jira & ServiceNow connectors, webhooks and a document workspace
- Contract usage & quota reporting
- Team management with an admin audit log
Enterprise
Scale it across the whole org, your way.
Contact sales for pricing
Unlimited seats
- Everything in Professional, with unlimited seats
- API access plus an MCP server for your own tools & AI agents
- Custom ticketing and workflow integrations
- Built for org-wide, programmatic and automated use
- The highest assurance and integration flexibility
Why teams upgrade
The capabilities that earn their keep
A closer look at the premium features organisations rely on day to day.
Remediation Planner
Model your remediation before you commit resources. Toggle which severities you'd resolve and watch projected posture recompute live, so you fix what moves the needle first.
Risk acceptance
When a finding won't be fixed, accept the risk on the record — a customer-initiated request, a provider approval, and an expiry date, kept audit-ready.
Jira & ServiceNow integrations
Push findings into the tools your engineers already use, with per-engagement routing and severity-to-priority mapping — auto-created or pushed on your terms.
Usage & quota reporting
See your contracted pentest and retest allowances, track what you've consumed, and export branded usage reports for finance and stakeholders.
Asset inventory
Keep a living inventory of everything that's been tested, with risk and findings linked per asset — so coverage and exposure are never a guess.
API & agent access
On Enterprise, tenant-scoped API tokens and an MCP server let your own tools and AI agents query your findings and posture — consent-gated and isolated to your tenant.
Full comparison
Every feature, side by side
Professional unlocks analytics, planning, collaboration, standard integrations and team management. Enterprise adds custom integrations, API and agent/MCP access, and unlimited seats. Seat limits and consent-based items are shown inline.
| Feature | Core | Professional Most popular | Enterprise |
|---|---|---|---|
| Essentials & baseline | |||
| Findings inventory — filter by severity, status, target date & CVSS | |||
| Full vulnerability detail — impact, steps to reproduce, PoC & evidence, remediation, references | |||
| Branded PDF reports + Excel vulnerability tracker | |||
| Password-protected reports (reveal in-portal) | |||
| Remediation status updates with attributed history | |||
| Finding comments & Q&A threads with the testing team | |||
| Retest requests on fixed findings | |||
| Saved views + CSV export | |||
| Email notifications | |||
| Mandatory two-factor authentication (2FA / TOTP) | |||
| Role-based access control (RBAC) | |||
| User profiles & avatars | |||
| Security-posture dashboard (open & critical at a glance) | |||
| Light & dark themes, mobile-responsive portal | |||
| Portal seats | 5 | 25 | Unlimited |
| Analytics & planning | |||
| Advanced dashboard metrics — trends, sparklines, SLA & remediation-rate roll-ups | |||
| Finding history timeline (full audit trail) | |||
| Remediation Planner — what-if posture simulator | |||
| Contract usage & quota reporting (PDF / Excel usage reports) | |||
| Asset inventory with per-asset risk & finding linkage | |||
| Collaboration & workflow | |||
| Self-service engagement & retest requests | |||
| Risk-acceptance workflow (approval step + expiry tracking) | |||
| Global search across findings, engagements & reports | |||
| Notification centre — in-app inbox + per-event email preferences | |||
| Document workspace for engagement files | |||
| Integrations & automation | |||
| Standard integrations — Jira & ServiceNow connectors | |||
| Signed webhooks — stream portal events to your systems | |||
| Custom integrations — bespoke ticketing / workflow connectors | |||
| Administration | |||
| Team management — invite, manage roles & admin audit log | |||
| Tamper-evident reports — verify downloaded report integrity | |||
| Methodology summary & coverage appendix in reports | |||
| Programmatic & AI | |||
| API access — tenant-scoped tokens | |||
| Agent / MCP access — let your tools & AI agents query your data | |||
| AI-assisted authoring | By arrangement | By arrangement | By arrangement |
Plans & billing FAQ
The practical questions
How do I choose or change a plan?
Plans are set up with the SecScope team and apply to your whole organisation — there's no self-service checkout or in-app upgrade. Tell us what your team needs and we'll configure the right plan for your tenant. To move up a tier, just contact sales.
Is there a trial?
Yes. We offer a time-boxed trial with Professional-level capabilities. When it ends, it either converts to a paid plan or reverts to the standard baseline — and either way, none of your data is removed.
What happens to my data if my plan changes or a trial ends?
Nothing is deleted. Your findings, reports, history and comments are always retained. Changing plans only changes which premium features you can access — never your underlying data.
How many people can I add to the portal?
Core includes up to 5 portal users, Professional up to 25, and Enterprise is unlimited (or a high negotiated limit). Every account uses role-based access, so you control who can see and do what.
Can my team sign in with SSO / SAML?
Not yet. Portal users sign in with email and password, with mandatory two-factor authentication (TOTP) on every account. Federated single sign-on is on our roadmap.
How do I upgrade?
Contact sales. Upgrades are handled with the SecScope team rather than in-app, so we can map the plan to your contract and switch on the right capabilities for your tenant.
Not sure which plan fits?
Tell us about your environment and how your team works, and we'll set you up on the right plan — including a trial if you'd like to try Professional first.
Talk to sales