Engagement Pricing

We charge for results, not for time.

20% upfront setup fee covers environment configuration and codebase ingestion. You pay the balance only when Vorthix AI delivers a proven, attacker-confirmed finding. If we find nothing, you pay only the setup fee. Nothing more. Zero false positives shipped.

Starter

< 50k LOC

$1,500 setup + per finding

Small to medium codebases. Full autonomous analysis with sanitizer-confirmed findings and complete disclosure package.

  • $1,500 upfront setup fee
  • Pays balance on proven CVE
  • Low/Medium: $500–$1,500
  • High: $2,000–$4,000
  • Critical: $5,000–$10,000
  • Minimized reproducers
  • Network exploit confirmation
  • Patch suggestions
Talk to Our Team
Most Popular

Professional

50k–200k LOC

$3,000 setup + per finding

Medium codebases. Continuous autonomous coverage with CI/CD integration, diff-aware analysis, and priority coordination.

  • $3,000 upfront setup fee
  • Pays balance on proven CVE
  • Low/Medium: $500–$1,500
  • High: $2,000–$4,000
  • Critical: $5,000–$10,000
  • CI/CD integration
  • Diff-aware re-analysis
  • Priority coordination
  • Dedicated researcher contact
Talk to Our Team

Enterprise

200k+ LOC

$5,000 setup + per finding

Large codebases and portfolios. Multi-target coverage with custom infrastructure, dedicated researcher, and executive reporting.

  • $5,000 upfront setup fee
  • Pays balance on proven CVE
  • Low/Medium: $500–$1,500
  • High: $2,000–$4,000
  • Critical: $5,000–$10,000
  • Multi-target coverage
  • Custom sandboxing
  • Dedicated researcher
  • Executive reporting
  • SLA guarantees
Contact Us

Zero False Positives, Guaranteed

If a finding cannot be reproduced deterministically under sanitizer, it is not reported. No noise. No maybes.

Compare plans.

FeatureFocusedContinuousEnterprise
Sanitizer-confirmed findings
Minimized reproducers
CI/CD integration
Diff-aware re-analysis
Multi-target coverage
Dedicated researcher

Frequently asked.

How does Vorthix actually work?
Vorthix clones your repository, compiles with AddressSanitizer and coverage instrumentation, maps every entry point and trust boundary, then runs adversarial hypothesis cycles — prioritizing parsers, decoders, and auth paths. A candidate becomes a finding only when it crashes under sanitizer. Every finding ships with a minimized reproducer, sanitizer trace, suggested patch, and regression test.
Is Vorthix just a scanner?
No. Scanners pattern-match against known signatures and produce false positives. Vorthix reasons adversarially — it forms hypotheses, writes targeted harnesses, and proves each finding by crashing the program under runtime sanitizers. Nothing is reported until it reproduces deterministically. Zero false positives are shipped.
What languages and target types does Vorthix support?
Full source code auditing across C, C++, Rust, Go, Python, TypeScript, JavaScript, Java, Kotlin, Ruby, PHP, and Swift. Binary and reverse engineering capabilities cover compiled binaries, stripped firmware, and protocol analysis without source code.
How long does an engagement take?
Focused single-target engagements run continuously until the analysis is complete, typically producing initial findings in 24–48 hours. The pymonocypher finding was confirmed in under 2 hours. Continuous engagements integrate with CI/CD and re-analyze on every commit.
How is the sandbox isolated?
Vorthix runs all analysis in isolated sandboxes. Target code executes in a controlled environment with no outbound network access, and no data persists after task completion. Proof-of-concept execution is sandboxed to prevent any lateral effect on infrastructure.
Do you do web application security testing?
Yes. Vorthix applies the same proof-based approach to web surfaces — SSRF, XSS/DOM, path traversal, SQL/NoSQL injection, authentication bypass, IDOR, JWT flaws, and request smuggling. Every web finding requires a working demonstrator before it is reported.

Point it at a target. Leave with proof.

Private access open to security teams and researchers.