Four products, two ways to pay.
Pick a card below. Ryvx Compliance is a monthly or annual subscription for continuous monitoring of one website. Ryvx Strike and Ryvx Agent are pay-as-you-go: buy credits, spend them on a hosted run, no subscription required. Ryvx Forge (reverse engineering) is free forever, desktop app and CLI only.
- The twice-monthly automated check: re-runs on a schedule, not just once at signup, so the board below reflects your site as it is now, not as it was when you subscribed.
- A PCI DSS / Cyber Essentials status board: one place tracking every row: the parts our engine tests directly, and the parts only you can answer, side by side rather than in two separate places.
- A plain-English certificate: states exactly what was tested and what you declared. It never claims your business is compliant, certified, or accredited; nobody's certificate does that.
- Payment-page change detection: your checkout page's scripts and security headers are watched on a schedule, and an unauthorized-looking change gets flagged for you to confirm rather than missed silently, the ongoing monitoring PCI DSS v4.0 requirement 11.6.1 asks for.
- Three written policy documents: built from your own answers to a handful of short questions: an Information Security Policy, an Access Control Statement, and an Incident Response Plan, the paperwork PCI DSS requirement 12 and Cyber Essentials expect. Where you haven't got a control in place yet, the document says so plainly and leaves a placeholder, not a comfortable guess.
Buy credits and spend them on a hosted run whenever you need one; unused credits never expire. Ryvx Agent isn't a second purchase: it spends this exact same balance, on this exact same ladder, whether the target is a web app or an AI agent endpoint.
Or buy in bulk: 100 credits for £90 (save 10%) or 250 credits for £200 (save 20%). Same credits, same ladder, same no-expiry rule.
Strength alone sets the price above, fixed before the scan starts. Other hosted job types are quoted in credits before they start, capped the same way. See every attack category and the coverage report →
Desktop app and CLI only. Never sold hosted.
Point Ryvx at an AI agent endpoint you own, not a web app. Eleven attack categories run against it live, from a blunt override typed straight into a user message to an indirect injection smuggled inside content the agent retrieves for itself, each one probing whether the agent can be talked past the tool boundary you declared for it. Start from a built-in preset, a tool-less support chatbot, a coding agent with file and shell access, or a RAG assistant limited to one retrieval tool, or hand-write your own.
A run hands back a coverage report, not a plain findings list: every one of the ten OWASP LLM Top 10 risks gets a stated verdict, a finding filed, an attack attempted with nothing found, or not tested with the reason given (two of the ten aren't reachable by any live probe at all), mapped to a MITRE ATLAS technique id where one exists. Nothing files as a finding without a working proof of concept: a canary you plant coming back verbatim, a measured amplification against a baseline turn, or a false statement you declare being asserted back as fact.
- Scoping, and a written rules-of-engagement document
- Your first red-team run, done for you, with a walkthrough of the coverage report and its framework mapping
- Re-tested on your cadence, so a boundary that held last quarter is checked again after the prompt, the tools, or the model changes
- An evidence bundle per run: the cover, the raw artifacts it was written from, and a sha256 for each, so your auditor re-checks it rather than taking our word
- Your whole fleet on file, each agent with its own boundary policy, so a new model or a new tool gets re-tested against the policy it was signed off under
- Priced per registered agent, invoiced annually
What this does not include: SOC 2, an uptime SLA, SSO or role-based access. Ryvx is a UK sole trader and holds no security certification. If your procurement process requires one, tell us before you buy, not after.
Work with us- Reports under your own brand: your name, your logo, your accent colour, your footer. No mention of Ryvx on the deliverable.
- Everything in Enterprise, included.
- Priced on volume across your whole client book, not per agent, and the overage rate above is already below the self-serve top-up price for exactly that reason.
- You keep the client relationship. Ryvx is the engine behind it.
What this does not include: professional indemnity insurance or SOC 2. Ryvx is a UK sole trader. You are responsible for holding your clients' authorisation to test their systems, the same as if it were your own target; see the Terms page for the full obligations this plan carries.
Talk to us about reselling| CLI & desktop app | Every capability on the features page runs free through the CLI, for anyone, on any plan. Buying Strike/Agent credits or subscribing to Compliance unlocks the hosted dashboard; neither gates what you can run yourself. |
| Web scans & AI/LLM red-teaming | Hosted execution, where Ryvx runs the scan for you and bills it in credits, covers web-application scans and AI/LLM agent red-teaming today, using the same built-in policy presets the hosted form offers. |
| GitHub remediation-PR bot | Built, and not something any plan includes or you turn on yourself: it's arranged directly with us. We still won't call it live: no customer PR has been reviewed end to end through the hosted path yet. Email us if you want to be the first one we set up by hand. |
| Hash & IOC lookups | No hosted path. Run them through the free CLI instead. |
| Queue depth | Hosted scans run on our own hardware, one at a time, no matter what you pay. A plan doesn't make your scan run faster. A free account can have 1 scan queued or running at once; a Ryvx Compliance subscription raises that to 2. What a plan actually gates, full stop, is queue depth, never whether you can run a scan at all. |
| PR bot queue | Once a repository is connected, the GitHub PR bot shares the same queue and the same limit as web scans above; it is not a separate, stricter gate. Reverse engineering doesn't touch this queue at all; it runs locally, on your own machine, not on ours. |
| PR bot metering | No plan includes the PR bot; it's arranged directly with us. Once connected, what limits it is metering, not plan tier: 3 connected repos and 150 reviews a month. |
What we commit to. And what we don't, yet.
A guarantee about the service, not about what a scan will find. We withdrew a detection claim in August and aren't making a new one. Everything below is checked against what the code and the team actually do today, not what we'd like to promise.
Every finding a Ryvx agent files has to carry a working proof-of-concept (a script or request that reproduces the issue) or create_finding rejects it. That's not a review policy, it's a hard gate in the code: a finding missing its PoC, or any other required field, never becomes a line in your report. This applies to every run, every mode, every target, not a subset.
Ask within 14 days of buying a subscription or credits and you get a full refund, no questions asked, even if scans have already run in that time. Offered to every customer, not only consumers in the UK, on top of any statutory right you have. Cancelling a subscription is separate and self-serve, any time, from the account page. See Refunds for how to ask.
Ryvx is one person, with no ticketing system and no on-call rotation behind it. We're not publishing a response-time promise, because there's no support infrastructure yet to make one true. A message gets read by a human; it just doesn't come with a guaranteed turnaround.
There's no discount for re-scanning after a fix. A hosted scan is billed by its strength (quick, standard, or deep) every time, a re-run to confirm a fix included; there's no cheaper "just checking" rate. What's free: verifying a fix yourself with ryvx fix-check <before-run> <after-run>, which diffs two runs' findings locally, no account or charge, to show what's fixed, still present, or new. It doesn't run the second scan for you. You still pay for that the normal way if it's hosted, free if it's the CLI.
Flat by scan type. No metering to guess at.
Every hosted web-application scan is a category plus a strength. The strength sets a fixed price in credits, not a per-target estimate, and not a bill that arrives after the run finishes. Any category can be run at any strength.
Reverse engineering works differently again: it's a local capability, not a hosted one. It runs free, in the CLI and the desktop app, inside an isolated hardware-backed microVM on your own machine, and the sample never leaves that hardware. For malware analysis specifically that's a real advantage, not just a fallback: many security teams simply aren't permitted to upload a sample to a third party at all. Tier 1 static triage has completed real runs, nine of them on 2026-08-18, and Tier 3 one, on 2026-08-27. Tier 2 has never run outside development. The GitHub remediation-PR bot is real too, but it isn't something any plan includes or you switch on yourself: it's arranged directly with us, then capped at 3 connected repos and 150 reviews a month once it's connected. Email us and we'll set it up by hand. Hash and IOC lookups still have no hosted path. Run them yourself through the free CLI instead, no plan or account required.
You pick two things: a category (what the scan looks for) and a strength (how hard it goes). Only the strength sets the price, and it is fixed before the scan starts, so that is what it costs whether the run finishes in ten minutes or ninety.
What a scan costs to run is turns times model, and strength is exactly the turn budget: quick gives each agent 15 turns, standard 40, deep 80. The category changes what the agent is told to look for, not how much work it is allowed to do, so an OSINT run and a pentest run at the same strength cost the same. A bigger target takes the agent longer to work through; it doesn't change what you're charged.
Every run still carries a hard ceiling underneath the flat price: your credit balance divided by the 4× markup, or the product's own price divided by the same markup, whichever is lower. A scan can never push your balance negative, and it can never quietly cost more than the product you bought.
It still finishes and still delivers a report, not a partial file you have to guess about: the report itself states plainly, up front, that it was stopped early and coverage is incomplete, and it is billed at the full price you were quoted, the same as a scan that runs to completion. That's deliberate: a refund for a capped scan would let someone point it at a huge target, spend to the ceiling, and keep the partial result free. A scan that instead fails outright for a reason on our side (a crash, a timeout) is different: that one is marked failed, and you are not charged for it.
Our first cloud-model measurement was a standard-mode scan of OWASP Juice Shop. It came to $4.4723 in LLM spend. Two quick-mode runs against a second target followed: $2.98, then $1.68 on the next run. Those numbers, plus everything measured since, point the same way: token spend is small and keeps shrinking, while the box slot a scan holds for the better part of an hour doesn't. The three prices above actually charge for the slot, not the tokens, which is also why the price doesn't move with target size.