Pay per site, not per finding.
Priced per site, per month. Pay yearly and two months are free. Early customers keep launch pricing for a year. Every plan runs the same verification gate, you never pay for noise.
- Your site
- Authorize
- Live scan
- Verification gate
- Verified report
A letter grade in under a minute. Free with a Notra account.
- Passive scorecard: TLS, security headers, cookie flags, exposed files, email auth
- Letter grade and one-line plain-English summary
- Sign in free — no card, no domain ownership required
- Results in under a minute
- No verified findings or evidence pack (that starts at Deep Audit)
A full pentest, every finding proven. Once.
- Full active scan across every module (CVE xref, XSS, CORS, TLS, headers, exposed files, redirects)
- Every finding passes the verification gate before you see it
- Raw request/response evidence attached to each finding
- Branded PDF + shareable web report, findings explained like a human wrote them
- Unauthenticated deep budget: 360 requests · 60 min · 20-finding target
- Domain ownership required (DNS TXT or file upload)
The deep budget, plus your logged-in sessions.
- Everything in the Deep Audit, at the same verification standard
- Authenticated testing with your session cookie (member areas, dashboards, account flows)
- Extended ceiling ~480 requests · 90 min
- Raw request/response evidence attached to each finding
- Domain ownership required (DNS TXT or file upload)
One domain, watched. New criticals alert you.
- 1 monitored domain, deep-depth scans included
- Daily automated rescans
- Diff alerts: new, resolved and regressed findings between scans
- Findings cross-referenced against real NVD + CISA KEV data
- Email report on every rescan
Up to 5 domains, monitored and re-scanned.
- Up to 5 monitored domains
- 3 team seats
- Daily automated rescans
- REST API + CI/CD gate
- Everything in Monitor
White-label audits for your whole client roster.
- White-label PDF reports
- Client workspaces + 10 seats
- Up to 25 monitored domains
- REST API + CI/CD gate
- Everything in Pro, per domain
Pooled domains, SSO, and a named contact.
- Unlimited or pooled domain volume
- SSO/SAML, full audit log and role-based access control
- Custom modules and your own severity policy
- SLA plus named-engineer review of shipped reports
- On-prem / VPC scan runners for sensitive environments
Is the free scan really free?
Yes. It's free with a Notra account — no card, no domain ownership. It runs the passive scorecard (TLS, headers, cookies, exposed files, email auth) and returns a letter grade. Verified findings and evidence start at the Deep Audit.
One-time audit or a subscription, which do I need?
If you want a single honest answer before a launch or a handover, buy a one-time Deep Audit. If your site keeps changing and you want new or regressed issues caught automatically, Monitor or Pro re-runs the audit daily and emails you every result.
What's the difference between the Deep Audit and Deep+?
The Deep Audit ($149) runs the full unauthenticated deep budget: 360 requests · 60 min · 20-finding target. Deep+ ($299) adds testing with your authenticated session cookie and an extended ceiling (~480 requests · 90 min), so member areas, dashboards and account flows get covered too.
What do I need before a paid audit?
Domain ownership. You prove it with a DNS TXT record or an uploaded file token before any active probing runs, we don't touch a site you haven't authorized.
Is scanning my site safe?
Yes. Active probes use safe, non-destructive defaults with a per-target rate ceiling, and money-movement endpoints (cart, checkout, pay) stay untouched unless you agree to a sandboxed test. Every proof is a benign detection probe, never a weaponized exploit.
Do you need my passwords or source code?
No. Notra is black-box by default. It only sees what any visitor sees. Optional authenticated scans (Deep Audit) use a session cookie you paste in, encrypted immediately, used once for that run, deleted the moment it finishes, and called out plainly in the report.
How do you avoid false positives?
The verification gate. We throw out anything that can't attach evidence, re-run each candidate with a benign proof, de-duplicate, and hold everything to a 0.8 confidence floor before it reaches you.
Where do the CVEs come from?
We fingerprint your stack, then cross-reference NVD, CISA KEV, GHSA and OSV with version-range logic, and re-check continuously so a newly-published KEV on your stack raises an alert.
What stops someone scanning a domain they don't own?
A hard authorization gate. No active module runs until you prove control with a DNS TXT record or an uploaded file token, and every authorization is logged.
What if a scan fails?
It auto-retries once. If it still fails, it's automatically marked failed and refunded — no ticket to file. You never pay for a scan that didn't deliver.
Start with your grade.
Run the free scorecard first. Upgrade to a verified Deep Audit only if the grade worries you.