Home Features ArmoTunnel ArmoMCP Server ArmoFuzzer Pricing Contact Sign In
Simple, Transparent Pricing

Choose Your Plan

Start with a 7-day trial — no credit card required. Each plan includes ArmoTunnel for local application scanning, matching your FQDN allowance.

Monthly Annual Save 20%
7-day trial

Starter

Essential DAST scanning for a single domain

£499/mo

billed monthly

  • 1 FQDN (domain) + 1 ArmoTunnel
  • All 474+ security plugins
  • 1 concurrent scan
  • HTML + JSON reports
  • OWASP Top 10 mapping
  • Email notifications
  • REST API access
  • No recurring scans
  • No monitoring
Start 7-Day Trial
7-day trial

MSSP

Multi-tenant enterprise DAST platform

£3,599/mo

multi-tenant, billed monthly

  • 10 FQDNs (domains) + 10 ArmoTunnels
  • Multi-tenant (custom subdomain)
  • All 474+ plugins + custom
  • 10 concurrent scans
  • White-label reports + SLA compliance
  • Advanced monitoring + threat detection
  • 176+ YARA malware rules
  • Infrastructure security grade (A+ to F)
  • Asset discovery + file mapping
  • Signed audit logs + export
  • Full API + SDK + MCP Server access
  • 100 users per tenant
  • Priority support (4h SLA)
Contact Sales

Feature Comparison

Detailed breakdown of what's included in each plan.

Feature Starter Professional MSSP
FQDNs (Domains)1510
ArmoTunnel1 tunnel5 tunnels10 tunnels
TenantsSingleSingleMulti-tenant
Concurrent Scans1310
Security PluginsAll 474+All 474+All + Custom
Recurring Scans
Report FormatsHTML, JSONPDF, HTML, JSON, CSVAll + White-label
ComplianceOWASP Top 10+ PCI-DSS+ Custom Frameworks
NotificationsEmailEmail + Webhook+ Slack/Teams
Cross-Scan Dedup
Scan Comparison
API AccessREST APIREST APIFull + SDK
MCP Server Access
Audit LoggingBasicSigned chainSigned + Export
Basic Monitoring
Advanced MonitoringFull + Threats
YARA Malware Scanning176+ built-in + Custom
Custom Subdomain
SupportCommunityEmail (48h)Priority (4h SLA)

Frequently Asked Questions

Dynamic Application Security Testing (DAST) analyzes running web applications to find security vulnerabilities. Unlike SAST which examines source code, DAST tests applications as an attacker would, sending requests and analyzing responses to identify vulnerabilities like SQL injection, XSS, authentication bypasses, and more.
Tunnel scanning uses ArmoTunnel to test applications running on localhost or your internal network — the app is never exposed to the internet. FQDN scanning tests publicly accessible domains (e.g., app.example.com). All plans include both FQDN scanning and ArmoTunnel — the number of tunnels matches your FQDN allowance (Starter: 1, Professional: 5, MSSP: 10).
ArmoTunnel is a lightweight CLI tool (~25MB) that creates a secure reverse tunnel from your machine to ArmoScan's scanning infrastructure. It allows you to security-test local, staging, and intranet applications without exposing them to the internet. Download it from the Developers page.
Sign up and get full access to all Professional plan features for 7 days — no credit card required. Run unlimited scans with all 474+ plugins, generate compliance reports, and evaluate the platform with your own applications. When your trial ends, choose a plan to continue or your account will be paused.
Yes, annual billing saves 20% compared to monthly billing. Toggle "Annual" above to see discounted pricing.
Payments are processed securely by Paddle, our merchant of record. Paddle handles payment processing, tax calculation, invoicing, and subscription management. You can pay with credit card, PayPal, Apple Pay, or Google Pay.
Yes, you can upgrade at any time and the prorated difference is charged immediately. Downgrades take effect at the end of the current billing period. Your scan history, findings, and reports are preserved across plan changes.

Ready to Secure Your Applications?

Start your 7-day trial today — no credit card required. All Professional features included.