fSecurity AI+

Plans

Sized to your company, not to a checklist.

Every service is dimensioned for three company sizes: what is included, how fast we respond and how deep the compliance package goes. Quotes are scoped to your surfaces after a 30-minute call.

Company size

Small

1–50 employees

  • Standard report: executive + technical
  • 1 retest included
  • Email support, business hours
Get a scoped quote

Mid-size

50–250 employees

  • Dedicated senior tester
  • SOC 2-ready compliance documentation
  • 2 retests included
  • 48-hour response SLA
  • Quarterly executive summary
Get a scoped quote

Enterprise

250+ or regulated

  • OSCP / CISSP certified team
  • Full compliance package: PCI DSS, ISO 27001 and regulator mapping, audit-ready format
  • Unlimited retesting within the window
  • Dedicated Slack / Teams channel
  • 24-hour response SLA
  • Board-level executive report and presentation
Get a scoped quote

Included in every plan

  • Rules of Engagement and NDA
  • AI-driven testing with senior validation
  • Proof of exploitation on every finding
  • Executive and technical report
  • Re-test after the fix
  • Live walkthrough

Pentest as a Service

One-time or continuous

One-time

  • One full engagement on the chosen surfaces
  • Findings delivered in days, not weeks
  • Retest of critical findings per your plan

Continuous

  • Recon and targeted tests re-run every month
  • Regression checks after each release
  • Evidence kept current for auditors and customers
  • New critical CVEs checked against your assets
  • Support-hour pool for remediation guidance
  • Cancel any time after the first 3 months
Pentest typesCadence
Web applicationsPortals, online banking, e-commerce and internal apps.One-time or continuous
APIsREST, GraphQL and partner integrations.One-time or continuous
Mobile applicationsAndroid, iOS and HarmonyOS, with their backend APIs.One-time or continuous
Aerospace infrastructureGround segments, data links and mission systems.One-time or continuous
External networkEverything reachable from the internet.One-time or continuous
Internal networkWhat happens once someone is already inside.One-time or continuous
Identity and Active DirectoryDirectory, credentials and privilege escalation.One-time or continuous
Cloud and KubernetesAWS, Azure, GCP and container platforms.One-time or continuous
WirelessCorporate and guest networks at every site.One-time or continuous
IoT and OTDevices, industrial control and field equipment.One-time or continuous
Social engineeringPhishing, vishing and pretexting with real impact.One-time or continuous
AI systems and LLMsChatbots, assistants and models wired into your systems.One-time or continuous

Multiple surfaces

Most programs combine three or more surfaces, typically external + internal + API, or web + API + mobile. Coverage is scoped on the call.

Get a scoped quote

Training

Same subscription for every company size. Group terms for teams.

  • Offensive AI Fundamentals8 weeks, 2 hrs/week
  • Defensive AI Fundamentals8 weeks, 2 hrs/week
  • Offensive + Defensive Advanced12 weeks, 3 hrs/week

Consulting

Maturity & attack-surface assessment

  • SmallUp to 3 systems, 1 interview round, CMMI checklist10 business days
  • Mid-sizeUp to 10 systems, SOC 2 / ISO 27001 gap analysis, 3 rounds15 business days
  • EnterpriseUnlimited scope, SUGEF / PCI-DSS mapping, board presentation, 18–24 month roadmap25 business days

Targeted AI automation

  • Small1–2 use cases: AI alerting, automated scanning
  • Mid-size3–5 use cases: threat hunting, behavioral IAM, anomalies
  • EnterpriseAI SOC-lite, compliance automation, SIEM integration

Quotes in USD, scoped to your surfaces. Local taxes apply where required.