Plans
Self-serve
The 30-day subscription trial does not include any credits — top up credits first to run operations.
$189
/mo
175 credits/mo
+ buy more credits any time
44–87 findings triaged, or up to 3 web app tests
About 3,000 assets (5,000 Cybergraph nodes)RealmsAn isolated workspace with its own Tentacles, knowledge and graph. One per environment or per client.Documentation
- 3
Seats
- 2
TentaclesA worker that runs tooling next to the target, inside your network. More Tentacles means more work in parallel.Documentation
- 3
Cybergraph nodesAssets and their findings, kept between operations. The graph is what makes the next run start where the last one stopped.Documentation
- 5,000
PlaybooksYour own saved methodology, authored and versioned by you. Our system playbooks do not count against the limit.Documentation
- 1
SkillsKnowledge you add to the agent — a technique, a target quirk, an internal convention it should apply.Documentation
- 1
External API
- Not included
Deployment
- SaaS
Your data trains our models
- Yes
Cracken Red
- Unavailable
$1,490
/mo
1,400 credits/mo
+ buy more credits any time
6–28 web app tests on Smart
About 12,000 assets (20,000 Cybergraph nodes)RealmsAn isolated workspace with its own Tentacles, knowledge and graph. One per environment or per client.Documentation
- 3, same as Starter
Seats
- 5
TentaclesA worker that runs tooling next to the target, inside your network. More Tentacles means more work in parallel.Documentation
- 5
Cybergraph nodesAssets and their findings, kept between operations. The graph is what makes the next run start where the last one stopped.Documentation
- 20,000
PlaybooksYour own saved methodology, authored and versioned by you. Our system playbooks do not count against the limit.Documentation
- 5
SkillsKnowledge you add to the agent — a technique, a target quirk, an internal convention it should apply.Documentation
- 15
External API
- Included
Deployment
- SaaS, same as Starter
Your data trains our models
- Your choice
Cracken Red
- Unavailable, same as Starter
$9,490
/mo
9,000 credits/mo
+ buy more credits any time
40–180 web app tests on Smart
About 20,000 assets (30,000 Cybergraph nodes)RealmsAn isolated workspace with its own Tentacles, knowledge and graph. One per environment or per client.Documentation
- 10
Seats
- 10
TentaclesA worker that runs tooling next to the target, inside your network. More Tentacles means more work in parallel.Documentation
- 10
Cybergraph nodesAssets and their findings, kept between operations. The graph is what makes the next run start where the last one stopped.Documentation
- 30,000
PlaybooksYour own saved methodology, authored and versioned by you. Our system playbooks do not count against the limit.Documentation
- Unlimited
SkillsKnowledge you add to the agent — a technique, a target quirk, an internal convention it should apply.Documentation
- Unlimited
External API
- Included, same as Pro
Deployment
- SaaS, same as Pro
Your data trains our models
- Your choice, same as Pro
Cracken Red
- Unavailable, same as Pro
Corporate
Quoted
annually
Credits agreed in your contract
Cracken Red
- Available
RealmsAn isolated workspace with its own Tentacles, knowledge and graph. One per environment or per client.Documentation
- Unlimited
Seats
- Unlimited
TentaclesA worker that runs tooling next to the target, inside your network. More Tentacles means more work in parallel.Documentation
- 50
Cybergraph nodesAssets and their findings, kept between operations. The graph is what makes the next run start where the last one stopped.Documentation
- 50,000
PlaybooksYour own saved methodology, authored and versioned by you. Our system playbooks do not count against the limit.Documentation
- Unlimited
SkillsKnowledge you add to the agent — a technique, a target quirk, an internal convention it should apply.Documentation
- Unlimited
External API
- Included
Deployment
- SaaS
Support
- Standard
Training
- Onboarding
Your data trains our models
- No — by contract
Quoted
annually
Credits agreed in your contract
Cracken Red
- Available, same as Business
RealmsAn isolated workspace with its own Tentacles, knowledge and graph. One per environment or per client.Documentation
- Unlimited, same as Business
Seats
- Unlimited, same as Business
TentaclesA worker that runs tooling next to the target, inside your network. More Tentacles means more work in parallel.Documentation
- 100
Cybergraph nodesAssets and their findings, kept between operations. The graph is what makes the next run start where the last one stopped.Documentation
- Unlimited
PlaybooksYour own saved methodology, authored and versioned by you. Our system playbooks do not count against the limit.Documentation
- Unlimited, same as Business
SkillsKnowledge you add to the agent — a technique, a target quirk, an internal convention it should apply.Documentation
- Unlimited, same as Business
External API
- Included, same as Business
Deployment
- Private cloud
Support
- Premium
Training
- Continuous
Your data trains our models
- No — by contract, same as Business
Quoted
annually
Credits agreed in your contract
Cracken Red
- Available, same as Enterprise
RealmsAn isolated workspace with its own Tentacles, knowledge and graph. One per environment or per client.Documentation
- Unlimited, same as Enterprise
Seats
- Unlimited, same as Enterprise
TentaclesA worker that runs tooling next to the target, inside your network. More Tentacles means more work in parallel.Documentation
- Unlimited
Cybergraph nodesAssets and their findings, kept between operations. The graph is what makes the next run start where the last one stopped.Documentation
- Unlimited, same as Enterprise
PlaybooksYour own saved methodology, authored and versioned by you. Our system playbooks do not count against the limit.Documentation
- Unlimited, same as Enterprise
SkillsKnowledge you add to the agent — a technique, a target quirk, an internal convention it should apply.Documentation
- Unlimited, same as Enterprise
External API
- Included, same as Enterprise
Deployment
- Your choice
Support
- Premium, same as Enterprise
Training
- Continuous, same as Enterprise
Your data trains our models
- No — by contract, same as Enterprise
Credits calculator
Credits are what model work draws on.
By activity, on Smart
Vulnerability triage
2–4per findingExploit development
through to a working proof of concept15–90per CVEWeb app test
full kill chain50–220per appNetwork penetration test
220–1,100per /24Red team engagement
many hosts, over weeks1,100–3,500per engagementContinuous monitoring
re-run on a schedule2,000–7,700per month
By model
Multiply any range above by the model's factor.
Each model, except our proprietary Cracken Red, resolves to the Pareto frontier model for offensive security. Read more in docs
| Model | Resolves to | Relative credit use | One web app test | What it is for |
|---|---|---|---|---|
Red | Cracken Red | 0.29× | 14–64 credits | Security-specialised operations. Unlocked by sales, on any plan. |
Max | GPT Sol · Fable · Gemini Pro | 1.67× | 84–367 credits | Deepest reasoning per step, for targets the others stall on. |
Smart | GPT Terra · Sonnet | 1.00× | 50–220 credits | General offensive work: recon, exploitation and reporting. |
Efficient | GPT Luna · Haiku · Gemini Flash | 0.33× | 16–73 credits | Fastest turnaround on bounded, well-scoped steps. |
Compare
Build on your own
| Cracken | LangGraph | CrewAI | Claude Agent SDK | |
|---|---|---|---|---|
Offensive toolkit preinstalled | Yes | No | No | No |
Scanner and EDR connectors | Yes | No | No | No |
Tenant isolation | Yes | No | No | No |
| The SDK warns tenants can leak into each other | ||||
No-refusal model On work you are authorised to do | Yes | Partial | Partial | No |
| LangGraph and CrewAI take any model; you align it | ||||
Distributed execution | Yes | Partial | Partial | No |
| Sold separately, or sized by hand | ||||
Operator UI | Yes | Partial | Partial | No |
| Studios for the builder, not the operator | ||||
Bi-temporal Cybergraph When we last saw it, and every change since | Yes | Partial | Partial | No |
| Checkpoints and key-value memory to build on | ||||
Stable upgrades | Yes | Yes | No | Partial |
| LangGraph publishes a policy; the SDK is pre-1.0 | ||||
Vibe coding tools
| Cracken | Claude Code | GitHub Copilot | Antigravity | |
|---|---|---|---|---|
Offensive toolkit preinstalled | Yes | No | No | No |
Air-gapped | YesOn Custom | Partial | Partial | No |
| Only Copilot's local BYOK claims air-gapped use | ||||
Scanner and EDR connectors | YesMCP or native integration | Partial | Partial | Partial |
| Only where an MCP server exists | ||||
Any model family | Yes | No | Yes | Yes |
| Claude Code routes to Claude models only | ||||
Bring your own model keys | YesEnterprise and Custom | Partial | Yes | Partial |
| Claude Code takes Claude keys; Antigravity none | ||||
Open-source hacking agents
Our lab took a shell on two of the agents we tested, through nothing but text they read on a target. Read Red-Teaming the Agentic Red-Teamer
| Cracken | CAI | PentestGPT | Shannon | |
|---|---|---|---|---|
Secure by design | Yes | No | No | No |
| CAI's own repo documents the shell it gives up | ||||
Human approval per action Before anything destructive | Yes | No | No | No |
| Interrupt or steer mid-run, never approve first | ||||
Scanner and EDR connectors | Yes | No | No | No |
| Offensive tools yes; Qualys, Wiz, Okta no | ||||
Scope enforced, not prompted | Yes | Partial | Partial | Partial |
| Only Shannon enforces it, and only in its proxy | ||||
Air-gapped | YesOn Custom | Partial | Partial | Yes |
| Only Shannon documents air-gapped deployment | ||||
Offensive toolkit preinstalled | Yes | Partial | No | Yes |
| Shannon ships a Kali image; CAI, utilities | ||||
Autonomous AI pentest
| Cracken | XBOW | Terra Security | Novee | |
|---|---|---|---|---|
Human approval per action Before anything destructive | Yes | No | Partial | No |
| Plans and guardrails approved before launch | ||||
Beyond web and API | Yes | No | Yes | No |
| Only Terra Security documents internal networks | ||||
Bring your own model keys | YesEnterprise and Custom | Partial | Yes | Partial |
| XBOW and Novee document no model of yours | ||||
Air-gapped | YesOn Custom | Partial | Yes | Partial |
| Novee says on-prem; XBOW says data residency | ||||
Operator shell | Yes | Partial | Partial | Partial |
| Terra's TORCH supervises; none hands you a shell | ||||
Old-school auto-pentest
| Cracken | Pentera | Horizon3 NodeZero | Picus | |
|---|---|---|---|---|
Operator shell | Yes | No | No | No |
Bring your own model keys | YesEnterprise and Custom | No | No | No |
| Their “your LLM” options are client-side | ||||
Calls your MCP servers mid-run | Yes | No | No | No |
| Their MCP servers point the other way | ||||
Air-gapped | YesOn Custom | Partial | No | Yes |
| Pentera does not document air-gapped operation | ||||
Human approval per action Before anything destructive | Yes | Partial | Partial | Partial |
| Guardrails set before launch, not per action | ||||
Manual pentest
Actively partnering with manual pentest companies. Reach out if you are one. See the partner program
| Cracken | Cobalt | NetSPI | HackerOne | |
|---|---|---|---|---|
Bring your own model keys | YesEnterprise and Custom | No | No | No |
| Cobalt Sage and NetSPI AI are theirs to run | ||||
Customer-hosted | Yes | No | Partial | No |
| NetSPI publishes no deployment model | ||||
You author the procedures | Yes | No | Partial | No |
| Methodology is fixed by test and asset type | ||||
Starts within a day | Yes | Partial | Partial | No |
| One business day on Cobalt's top tier only | ||||
Application security
| Cracken | Snyk | Codex Security | Claude Security | |
|---|---|---|---|---|
Runs tools against live hosts | Yes | No | No | No |
Runs on a model you host | YesEnterprise and Custom | No | No | No |
| Each runs its own model and only its own | ||||
Air-gapped | YesOn Custom | Partial | No | No |
| Snyk scans locally; the upload is what stops | ||||
Self-hosted | YesEnterprise and Custom | Yes | Partial | Partial |
| Neither agent documents a deployment you host | ||||
FAQ
What's in the trial?
Thirty days, no card: 1 realm, 1 seat, 1 Tentacle, 100 Cybergraph nodes, 1 playbook, 1 skill. No credits, so top up to run model work.
Do unused credits roll over?
Monthly credits reset at renewal. Top-up credits never expire.
Can I change plan?
In the billing portal. An upgrade is prorated and its credits land immediately; a downgrade waits for the cycle end. Cancel any time.
Do you train models on our data?
On Trial and Starter, yes — those tiers are cheaper because your prompts contribute. On Pro and Team it is a switch you own. On Business, Enterprise and Custom it is off by contract, and a self-hosted deployment sends us nothing.
What happens when I hit a limit?
You get an upgrade prompt, not dropped work. Archived realms stop counting and can be restored; stale Cybergraph nodes expire on their own.

