sheet 01 pricing 3 tiers · 1 attack cycle

predictable security spend. real results.

  • every tier runs the full ai attack cycle — recon, exploitation, WAF bypass, chaining
  • tiers scale on human hours, report depth, and support level — not on what gets tested
  • bug hunters on retainer, backed by ai — without the overhead of a full red team
tier 1

sentinel

full ai attack cycle with expert oversight.

£600 /mo +VAT
billed quarterly. £7,200/year +VAT.
  • secure local infrastructure — zero SaaS, SSH-only
  • full attack cycle — recon, exploitation, WAF bypass, chaining
  • continuous attack surface monitoring & change detection
  • technology fingerprinting & CVE/CWE correlation
  • 4 hours expert exploitation per month
  • proof-of-concept for every finding
  • findings summary report
  • monthly intelligence summary
get started
tier01 / 03
price£600 /mo
billedquarterly
checkedoffensive team
tier 3

adversary

maximum human hours, formal reporting, priority support.

£2,800 /mo +VAT
billed quarterly. £33,600/year +VAT.
  • everything in strike
  • 12 hours expert exploitation per month
  • formal red team report (executive + technical)
  • priority support
get started
tier03 / 03
price£2,800 /mo
billedquarterly
checkedoffensive team
note · outside the tier set

one-off engagement

not ready for a subscription? we run a focused offensive assessment against your agreed scope and deliver a full exploitation report with working proof-of-concept for every finding. 2-week turnaround.

  • fixed scope, agreed up front
  • £3,000–8,000 +VAT depending on scope and complexity
  • full report with PoC. no subscription required
projectmastermind
sheet01 / 04
drawntrace37
checkedoffensive team
sheet 02 compare 12 rows · 3 tiers

what's included at every tier

feature
sentinel
strike
adversary
01secure local infrastructure (zero SaaS)
02full AI attack cycle (recon, exploitation, WAF bypass, chaining)
03continuous attack surface monitoring
04CVE/CWE correlation
05monthly intelligence summary
06expert exploitation hours
4 hrs/mo
8 hrs/mo
12 hrs/mo
07PoC for every finding
08findings summary
09written findings report
10formal red team report
11retest verification
12priority support

all plans run on secure local infrastructure — zero SaaS platforms storing your data. no hidden extras. billed quarterly with a 3-month minimum commitment. annual contracts receive a 5% discount.

projectmastermind
sheet02 / 04
drawntrace37
checkedoffensive team
sheet 03 faq notes 01–08

common questions

how is this different from a pen test?
a pen test is a point-in-time assessment — typically 5–10 days of testing, once a year. mastermind runs continuously. your attack surface is monitored daily and the system re-tests it as it changes; you get the depth of a pen test with the coverage of continuous monitoring — plus proprietary ai-driven exploitation tooling and seasoned offensive researchers validating every finding.
how is our data handled?
all tooling runs locally on a hardened server — zero SaaS platforms processing or storing your data. your findings, scan results, and credentials never leave the environment. encrypted mesh network, SSH-only access. when you offboard, all engagement data is securely destroyed.
do we need to give you access to source code?
no. mastermind operates as a black-box red team by default — we test from the outside, exactly as a real attacker would. we only need the agreed scope (domains, IPs, applications) and signed rules of engagement. if you provide test credentials, we can go deeper — testing role-based access control, authorization boundaries, IDOR, and privilege escalation across your authenticated surfaces. if you want white-box coverage, we can review source code directly — identifying vulnerabilities that are invisible from the outside. API documentation and architecture context can also accelerate findings.
what happens if you find a critical vulnerability?
critical findings (P1/P2) are reported immediately via your preferred channel — typically within hours of validation. every finding includes a proof-of-concept demonstrating real impact, not theoretical risk. we don't report noise. if we report it, it's real and it matters.
how quickly can we start?
from signed agreement to first scan: typically 48 hours. we configure your scope and begin reconnaissance immediately. you'll receive your first intelligence summary within the first week.
is this legal?
yes. all testing is conducted under a formal rules of engagement agreement that defines exact scope, permitted testing windows, and exclusions. we hold explicit written authorisation before any testing begins and comply with applicable computer misuse and data protection legislation in your jurisdiction — including the Computer Misuse Act 1990 (UK), CFAA (US), and equivalent laws across the EU and APAC. we carry professional indemnity insurance and can work within your existing compliance requirements.
can we upgrade or downgrade our tier?
yes. tier changes take effect at the start of the next billing quarter. upgrades can be arranged mid-quarter with pro-rated billing. all historical data and findings are preserved across tier changes.
what if we need more exploitation hours?
if you consistently need more hours than your tier includes, upgrading is usually the best option. we'll advise based on your actual usage patterns.
projectmastermind
sheet03 / 04
drawntrace37
checkedoffensive team
sheet 04 get started end of set

ready to see what we'd find?

send us your scope. we'll probe it and walk you through the findings on a 30-minute teams call.

projectmastermind
sheet04 / 04
drawntrace37
checkedoffensive team