Skip to main content
PRICING

Four products, two ways to pay.

Pick a card below. Ryvx Compliance is a monthly or annual subscription for continuous monitoring of one website. Ryvx Strike and Ryvx Agent are pay-as-you-go: buy credits, spend them on a hosted run, no subscription required. Ryvx Forge (reverse engineering) is free forever, desktop app and CLI only.

£100/mo
or £1,000/yr, billed annually (2 months free)
1 website. No credits included.
  • The twice-monthly automated check: re-runs on a schedule, not just once at signup, so the board below reflects your site as it is now, not as it was when you subscribed.
  • A PCI DSS / Cyber Essentials status board: one place tracking every row: the parts our engine tests directly, and the parts only you can answer, side by side rather than in two separate places.
  • A plain-English certificate: states exactly what was tested and what you declared. It never claims your business is compliant, certified, or accredited; nobody's certificate does that.
  • Payment-page change detection: your checkout page's scripts and security headers are watched on a schedule, and an unauthorized-looking change gets flagged for you to confirm rather than missed silently, the ongoing monitoring PCI DSS v4.0 requirement 11.6.1 asks for.
  • Three written policy documents: built from your own answers to a handful of short questions: an Information Security Policy, an Access Control Statement, and an Incident Response Plan, the paperwork PCI DSS requirement 12 and Cyber Essentials expect. Where you haven't got a control in place yet, the document says so plainly and leaves a placeholder, not a comfortable guess.
Billed in GBP. Strike/Agent credits are a separate purchase.
Ryvx Compliance is not a PCI Approved Scanning Vendor and does not issue compliance certification.
Get Compliance

Buy credits and spend them on a hosted run whenever you need one; unused credits never expire. Ryvx Agent isn't a second purchase: it spends this exact same balance, on this exact same ladder, whether the target is a web app or an AI agent endpoint.

quick
20 credits
standard
50 credits
deep
100 credits

Or buy in bulk: 100 credits for £90 (save 10%) or 250 credits for £200 (save 20%). Same credits, same ladder, same no-expiry rule.

Strength alone sets the price above, fixed before the scan starts. Other hosted job types are quoted in credits before they start, capped the same way. See every attack category and the coverage report →

Desktop app and CLI only. Never sold hosted.

PICK A CATEGORY, SAME PRICE AT EVERY STRENGTH
OSINT
Passive intelligence only: subdomains, technology fingerprints, exposed cloud assets, leaked credentials, certificate history. No active probing of any kind, safe to run against a target you are not yet authorized to actively test.
Compliance
Fills in your PCI DSS / Cyber Essentials compliance board: probes and confirms only, never exploits, so it's safe to run unattended on a schedule.
Pentest
A full assessment: maps the attack surface, then actively tests and exploits what it finds. Every finding ships with a working proof of concept.
WHAT A RYVX AGENT RUN IS

Point Ryvx at an AI agent endpoint you own, not a web app. Eleven attack categories run against it live, from a blunt override typed straight into a user message to an indirect injection smuggled inside content the agent retrieves for itself, each one probing whether the agent can be talked past the tool boundary you declared for it. Start from a built-in preset, a tool-less support chatbot, a coding agent with file and shell access, or a RAG assistant limited to one retrieval tool, or hand-write your own.

A run hands back a coverage report, not a plain findings list: every one of the ten OWASP LLM Top 10 risks gets a stated verdict, a finding filed, an attack attempted with nothing found, or not tested with the reason given (two of the ten aren't reachable by any live probe at all), mapped to a MITRE ATLAS technique id where one exists. Nothing files as a finding without a working proof of concept: a canary you plant coming back verbatim, a measured amplification against a baseline turn, or a false statement you declare being asserted back as fact.

11
attack categories against the live agent
8 / 10
OWASP LLM risks exercised, the other two stated as gaps
3
built-in boundary presets, or write your own
Enterprise
From $2,500
setup, plus the per-agent price
Annual invoicing · purchase orders accepted
  • Scoping, and a written rules-of-engagement document
  • Your first red-team run, done for you, with a walkthrough of the coverage report and its framework mapping
  • Re-tested on your cadence, so a boundary that held last quarter is checked again after the prompt, the tools, or the model changes
  • An evidence bundle per run: the cover, the raw artifacts it was written from, and a sha256 for each, so your auditor re-checks it rather than taking our word
  • Your whole fleet on file, each agent with its own boundary policy, so a new model or a new tool gets re-tested against the policy it was signed off under
  • Priced per registered agent, invoiced annually

What this does not include: SOC 2, an uptime SLA, SSO or role-based access. Ryvx is a UK sole trader and holds no security certification. If your procurement process requires one, tell us before you buy, not after.

Work with us
Partner
$7,500/yr
includes 3,000 credits, about 30 deep-strength scans a year
$0.25 / extra credit beyond that
  • Reports under your own brand: your name, your logo, your accent color, your footer. No mention of Ryvx on the deliverable.
  • Everything in Enterprise, included.
  • Priced on volume across your whole client book, not per agent, and the overage rate above is already below the self-serve top-up price for exactly that reason.
  • You keep the client relationship. Ryvx is the engine behind it.

What this does not include: professional indemnity insurance or SOC 2. Ryvx is a UK sole trader. You are responsible for holding your clients' authorization to test their systems, the same as if it were your own target; see the Terms page for the full obligations this plan carries.

Talk to us about reselling
WHAT HOSTED CREDITS BUY
CLI & desktop appEvery capability on the features page runs free through the CLI, for anyone, on any plan. Buying Strike/Agent credits or subscribing to Compliance unlocks the hosted dashboard; neither gates what you can run yourself.
Web scans & AI/LLM red-teamingHosted execution, where Ryvx runs the scan for you and bills it in credits, covers web-application scans and AI/LLM agent red-teaming today, using the same built-in policy presets the hosted form offers.
GitHub remediation-PR botBuilt, and not something any plan includes or you turn on yourself: it's arranged directly with us. We still won't call it live: no customer PR has been reviewed end to end through the hosted path yet. Email us if you want to be the first one we set up by hand.
Hash & IOC lookupsNo hosted path. Run them through the free CLI instead.
WHAT A PLAN GATES
Queue depthHosted scans run on our own hardware, one at a time, no matter what you pay. A plan doesn't make your scan run faster. A free account can have 1 scan queued or running at once; a Ryvx Compliance subscription raises that to 2. What a plan actually gates, full stop, is queue depth, never whether you can run a scan at all.
PR bot queueOnce a repository is connected, the GitHub PR bot shares the same queue and the same limit as web scans above; it is not a separate, stricter gate. Reverse engineering doesn't touch this queue at all; it runs locally, on your own machine, not on ours.
PR bot meteringNo plan includes the PR bot; it's arranged directly with us. Once connected, what limits it is metering, not plan tier: 3 connected repos and 150 reviews a month.
GUARANTEE

What we commit to. And what we don't, yet.

A guarantee about the service, not about what a scan will find. We withdrew a detection claim in August and aren't making a new one. Everything below is checked against what the code and the team actually do today, not what we'd like to promise.

✓
PoC or we don't report it

Every finding a Ryvx agent files has to carry a working proof-of-concept (a script or request that reproduces the issue) or create_finding rejects it. That's not a review policy, it's a hard gate in the code: a finding missing its PoC, or any other required field, never becomes a line in your report. This applies to every run, every mode, every target, not a subset.

✓
14-day refund, no questions

Ask within 14 days of buying a subscription or credits and you get a full refund, no questions asked, even if scans have already run in that time. Offered to every customer, not only consumers in the UK, on top of any statutory right you have. Canceling a subscription is separate and self-serve, any time, from the account page. See Refunds for how to ask.

○
Response time: best-effort, not an SLA

Ryvx is one person, with no ticketing system and no on-call rotation behind it. We're not publishing a response-time promise, because there's no support infrastructure yet to make one true. A message gets read by a human; it just doesn't come with a guaranteed turnaround.

○
Free re-scans after a fix: not yet

There's no discount for re-scanning after a fix. A hosted scan is billed by its strength (quick, standard, or deep) every time, a re-run to confirm a fix included; there's no cheaper "just checking" rate. What's free: verifying a fix yourself with ryvx fix-check <before-run> <after-run>, which diffs two runs' findings locally, no account or charge, to show what's fixed, still present, or new. It doesn't run the second scan for you. You still pay for that the normal way if it's hosted, free if it's the CLI.

✓ guaranteed today○ not guaranteed: real reason above
WHAT A CREDIT BUYS

Flat by scan type. No metering to guess at.

Every hosted web-application scan is a category plus a strength. The strength sets a fixed price in credits, not a per-target estimate, and not a bill that arrives after the run finishes. Any category can be run at any strength.

Reverse engineering works differently again: it's a local capability, not a hosted one. It runs free, in the CLI and the desktop app, inside an isolated hardware-backed microVM on your own machine, and the sample never leaves that hardware. For malware analysis specifically that's a real advantage, not just a fallback: many security teams simply aren't permitted to upload a sample to a third party at all. Tier 1 static triage has completed real runs, nine of them on 2026-08-18, and Tier 3 one, on 2026-08-27. Tier 2 has never run outside development. The GitHub remediation-PR bot is real too, but it isn't something any plan includes or you switch on yourself: it's arranged directly with us, then capped at 3 connected repos and 150 reviews a month once it's connected. Email us and we'll set it up by hand. Hash and IOC lookups still have no hosted path. Run them yourself through the free CLI instead, no plan or account required.

HOW A SCAN IS PRICED

You pick two things: a category (what the scan looks for) and a strength (how hard it goes). Only the strength sets the price, and it is fixed before the scan starts, so that is what it costs whether the run finishes in ten minutes or ninety.

WHY STRENGTH SETS THE PRICE

What a scan costs to run is turns times model, and strength is exactly the turn budget: quick gives each agent 15 turns, standard 40, deep 80. The category changes what the agent is told to look for, not how much work it is allowed to do, so an OSINT run and a pentest run at the same strength cost the same. A bigger target takes the agent longer to work through; it doesn't change what you're charged.

THE SPENDING CAP

Every run still carries a hard ceiling underneath the flat price: your credit balance divided by the 4× markup, or the product's own price divided by the same markup, whichever is lower. A scan can never push your balance negative, and it can never quietly cost more than the product you bought.

IF A SCAN HITS THE CEILING

It still finishes and still delivers a report, not a partial file you have to guess about: the report itself states plainly, up front, that it was stopped early and coverage is incomplete, and it is billed at the full price you were quoted, the same as a scan that runs to completion. That's deliberate: a refund for a capped scan would let someone point it at a huge target, spend to the ceiling, and keep the partial result free. A scan that instead fails outright for a reason on our side (a crash, a timeout) is different: that one is marked failed, and you are not charged for it.

WHY THE PRICE IS FLAT, NOT METERED

Our first cloud-model measurement was a standard-mode scan of OWASP Juice Shop. It came to $4.4723 in LLM spend. Two quick-mode runs against a second target followed: $2.98, then $1.68 on the next run. Those numbers, plus everything measured since, point the same way: token spend is small and keeps shrinking, while the box slot a scan holds for the better part of an hour doesn't. The three prices above actually charge for the slot, not the tokens, which is also why the price doesn't move with target size.

STAY IN THE LOOP

Release notes and product updates, by email.

We'll send a confirmation email; you're not on the list until you click the link in it. See our privacy policy.