Engagement Pricing
We charge for results, not for time.
20% upfront setup fee covers environment configuration and codebase ingestion. You pay the balance only when Vorthix AI delivers a proven, attacker-confirmed finding. If we find nothing, you pay only the setup fee. Nothing more. Zero false positives shipped.
Starter
< 50k LOC
$1,500 setup + per finding
Small to medium codebases. Full autonomous analysis with sanitizer-confirmed findings and complete disclosure package.
- $1,500 upfront setup fee
- Pays balance on proven CVE
- Low/Medium: $500–$1,500
- High: $2,000–$4,000
- Critical: $5,000–$10,000
- Minimized reproducers
- Network exploit confirmation
- Patch suggestions
Professional
50k–200k LOC
$3,000 setup + per finding
Medium codebases. Continuous autonomous coverage with CI/CD integration, diff-aware analysis, and priority coordination.
- $3,000 upfront setup fee
- Pays balance on proven CVE
- Low/Medium: $500–$1,500
- High: $2,000–$4,000
- Critical: $5,000–$10,000
- CI/CD integration
- Diff-aware re-analysis
- Priority coordination
- Dedicated researcher contact
Enterprise
200k+ LOC
$5,000 setup + per finding
Large codebases and portfolios. Multi-target coverage with custom infrastructure, dedicated researcher, and executive reporting.
- $5,000 upfront setup fee
- Pays balance on proven CVE
- Low/Medium: $500–$1,500
- High: $2,000–$4,000
- Critical: $5,000–$10,000
- Multi-target coverage
- Custom sandboxing
- Dedicated researcher
- Executive reporting
- SLA guarantees
Zero False Positives, Guaranteed
If a finding cannot be reproduced deterministically under sanitizer, it is not reported. No noise. No maybes.
Compare plans.
| Feature | Focused | Continuous | Enterprise |
|---|---|---|---|
| Sanitizer-confirmed findings | |||
| Minimized reproducers | |||
| CI/CD integration | — | ||
| Diff-aware re-analysis | — | ||
| Multi-target coverage | — | — | |
| Dedicated researcher | — | — |
Frequently asked.
- How does Vorthix actually work?
- Vorthix clones your repository, compiles with AddressSanitizer and coverage instrumentation, maps every entry point and trust boundary, then runs adversarial hypothesis cycles — prioritizing parsers, decoders, and auth paths. A candidate becomes a finding only when it crashes under sanitizer. Every finding ships with a minimized reproducer, sanitizer trace, suggested patch, and regression test.
- Is Vorthix just a scanner?
- No. Scanners pattern-match against known signatures and produce false positives. Vorthix reasons adversarially — it forms hypotheses, writes targeted harnesses, and proves each finding by crashing the program under runtime sanitizers. Nothing is reported until it reproduces deterministically. Zero false positives are shipped.
- What languages and target types does Vorthix support?
- Full source code auditing across C, C++, Rust, Go, Python, TypeScript, JavaScript, Java, Kotlin, Ruby, PHP, and Swift. Binary and reverse engineering capabilities cover compiled binaries, stripped firmware, and protocol analysis without source code.
- How long does an engagement take?
- Focused single-target engagements run continuously until the analysis is complete, typically producing initial findings in 24–48 hours. The pymonocypher finding was confirmed in under 2 hours. Continuous engagements integrate with CI/CD and re-analyze on every commit.
- How is the sandbox isolated?
- Vorthix runs all analysis in isolated sandboxes. Target code executes in a controlled environment with no outbound network access, and no data persists after task completion. Proof-of-concept execution is sandboxed to prevent any lateral effect on infrastructure.
- Do you do web application security testing?
- Yes. Vorthix applies the same proof-based approach to web surfaces — SSRF, XSS/DOM, path traversal, SQL/NoSQL injection, authentication bypass, IDOR, JWT flaws, and request smuggling. Every web finding requires a working demonstrator before it is reported.
Point it at a target. Leave with proof.
Private access open to security teams and researchers.