Invicti pricing

What middleBrick covers

  • Fixed monthly tiers with clear per-API scaling
  • Authenticated scanning with domain ownership verification
  • Findings mapped to PCI-DSS 4.0, SOC 2 Type II, OWASP API Top 10
  • Read-only scanning with strict network safety controls
  • GitHub Action integration as a CI/CD quality gate
  • Data deletion on demand with 30-day purge policy

Public pricing tiers and included capabilities

Published tiers provide a fixed monthly price and a defined set of APIs, scans, and features. The Free tier is zero cost and includes CLI access with 3 scans per month. The Starter tier is billed at a fixed monthly rate and supports up to 15 APIs, monthly recurring scans, a web dashboard for reports and trends, email alerts, and the MCP Server for AI coding assistants. The Pro tier is billed monthly with a base subscription for 100 APIs and incremental pricing per additional API; it adds continuous monitoring, diff detection between scans, compliance report downloads, GitHub Action integration as a CI/CD gate, Slack and Teams alerts, and signed webhooks. The Enterprise tier is quote based and aimed at large scale programs, offering unlimited APIs, custom rules, SSO, detailed audit logs, an SLA, and dedicated support.

Authentication options and domain verification

Authenticated scanning is available from the Starter tier upward and supports Bearer tokens, API keys, Basic authentication, and cookies. Before credentials are accepted, a domain verification gate requires proof of ownership through a DNS TXT record or an HTTP well-known file so that only the domain owner can enable authenticated scans. When authenticated scanning is active, the scanner forwards a restricted set of headers: Authorization, X-API-Key, Cookie, and X-Custom-*, ensuring that credentials are not exposed to unrelated services.

Coverage aligned to compliance frameworks

The scanner maps findings to three frameworks: PCI-DSS 4.0, SOC 2 Type II, and OWASP API Top 10 (2023). For other regulations, the product helps you prepare for audits and aligns with security controls described in relevant standards, supporting audit evidence without asserting certification or compliance guarantees. This approach keeps the tool focused on detection while clarifying its role in broader assessment programs.

Feature limitations and responsible disclosure scope

middleBrick is a scanner that detects and reports; it does not fix, patch, block, or remediate. Specific attack categories are out of scope, including active SQL injection or command injection testing, business logic validation, blind SSRF detection, and full web application pentesting. The tool also does not replace a human pentester for high-stakes audits, and findings such as sensitive data exposure or unsafe consumption patterns are provided with remediation guidance rather than automated correction.

Data handling, privacy, and deployment safety

Scan data is deletable on demand and purged within 30 days of cancellation; customer data is never sold and is not used for model training. The scanner enforces a strict safety posture by using only read-only methods, blocking private IPs, localhost, and cloud metadata endpoints at multiple layers, and never sending destructive payloads. This design reduces risk to the target environment while maintaining transparency about what the scanner does and does not test.

Frequently Asked Questions

Is pricing per user, per scan, or per API?
Pricing is structured around monthly subscriptions per team. The Free tier is per account, Starter and Pro are fixed monthly tiers with defined API counts, and Enterprise is quote based for unlimited APIs.
Can I scan more than the included number of APIs?
Yes. You can add additional APIs to your subscription, with incremental pricing for the Pro tier. Contact sales for Enterprise arrangements to scale beyond the published limits.
Are compliance reports included in every paid tier?
Compliance reports and branded downloads are included in the Pro tier. Starter provides dashboard reports and email alerts; Enterprise includes custom reporting options.
How often are scans scheduled in continuous monitoring?
Continuous monitoring supports schedules of every 6 hours, daily, weekly, or monthly. These settings apply per monitored API and generate diff notifications when findings or scores change.