Request access

Continuous penetration testing.

We continuously test your web apps, APIs, and infrastructure, and our security engineers verify every finding by hand. You get real, exploitable vulnerabilities you can hand to engineering, with no false positives.

Request access

Scope your targets.

Add the domains, APIs, and hosts you control and prove ownership. You set what is in scope. Nothing else is touched.

The engine runs the tests.

Recon, TLS, and the full web and API tests run against your login sessions and your schema. Continuously, and on every release through CI.

Every finding verified by hand.

A security engineer reproduces and rates each finding before it reaches you. No false positives, nothing to triage twice.

Coverage

Everything a manual pentest covers.

Our methodology from manual engagements, automated so every scan runs it in full.

  • Network

    Infrastructure and ports

    Port and service discovery, TLS and certificate grading, and authenticated host-level vulnerability scanning across every asset you expose.

  • Web

    Web applications

    Every page crawled and fuzzed: hidden files and debug endpoints, dangerous HTTP methods, HTTP/2 request smuggling, and vulnerable or outdated components.

  • API

    APIs and GraphQL

    Object- and function-level authorization on every ID, introspection, alias and batch overload, mass assignment, and method fuzzing across REST and GraphQL.

  • Access

    Authentication and sessions

    Horizontal and vertical access control, OAuth and SSO flows, CSRF, 2FA bypass, session fixation and rotation, and every cookie flag and prefix.

  • Injection

    Injection

    SQL, cross-site scripting including blind, command, SSRF, template and expression-language, XML external entities, and prompt injection on AI-backed endpoints.

  • Crypto

    Files and crypto

    Upload execution and path traversal, JWT algorithm and key confusion, token entropy, and weak, reused, or leaked secrets.

  • Transport

    Transport and headers

    HSTS, CSP, clickjacking, CORS, cache directives, content sniffing, and sensitive data carried in the clear.

  • Logic

    Rate limiting and logic

    Brute force on login, OTP, and reset flows, race conditions, invalid state transitions, and business-logic and excessive-agency abuse.

Why Huci

Built to replace the annual pentest.

  1. Automated, so continuous

    Testing runs continuously and on every release, so you find issues as they ship, not once a year.

  2. Verified, so no false positives

    A security engineer reproduces every finding by hand. You never chase a false alarm or read a report full of scanner noise.

  3. Deeper than a scanner

    Access control, multi-step flows, and business logic are tested as real flows using your sessions and schema, not matched against a CVE list.

  4. One predictable fee

    A manual pentest in the Netherlands costs €2,500 to €12,000 for one day. Huci runs continuously all year for a fixed monthly fee.

The panel

Findings, tracked and reported.

Every verified finding, with the request that proves it and its current status.

  • Each finding with its request, response, and steps to reproduce, rated by CVSS.

  • A status on every finding: open, fixed, retested, or accepted with a reason.

  • A signed PDF report every month for your records and your auditors.

  • A webhook to Slack, Jira, GitHub, or GitLab the moment a finding is confirmed.

Articles

How we test.

What we look for, and how we prove it.

All articles
Pricing

One price per target.

A target is one application, API, or domain, tested in full. Prices in euros, excluding VAT. Pay yearly and get two months free.

  • Starter

    99per month

    1 target

    One application, API, or domain, tested every week.

    • Authenticated and unauthenticated testing
    • The full test suite on every run
    • Every finding verified by hand
    • Findings in the panel with reproduction
    • Email on every new finding
    Request access
  • TeamMost teams

    299per month

    5 targets

    Tested on every release and wired into your CI and tooling.

    • Everything in Starter
    • Triggered on every release via CI or webhook
    • OpenAPI and GraphQL schema import
    • Monthly signed PDF report
    • Alerts to Slack, Jira, GitHub, and GitLab
    Request access
  • Scale

    799per month

    20 targets

    Nightly testing with retests and a named tester.

    • Everything in Team
    • Nightly testing and retest on fix
    • SSO and audit log
    • Quarterly review with your tester
    • Priority support with a named contact
    Request access

A target covers an app, API, or domain of ordinary size, up to around 500 routes or endpoints, tested in full. Larger or more complex apps, many thousands of routes or dozens of roles, are scoped to their real surface and priced for the work they take, so a small app never subsidises a giant one. Extra targets are €40 per month, and every plan starts with a 14-day trial. Running more than 20 targets, or need private runners and a scoped audit report? Talk to us about Enterprise.

FAQ

Common questions.

The tests a pentester runs, automated and repeated on a schedule instead of once a year. Huci covers your infrastructure, web apps, and APIs, and a security engineer verifies every finding by hand.

A scanner flags anything that looks off, and most of it is noise. Huci runs a full penetration test and a security engineer verifies every finding, so you never get a false positive.

A manual web-application pentest in the Netherlands costs €2,500 to €12,000 for one day. Huci starts at €99 per month per target and runs all year.

One application, API, or domain of ordinary size, up to around 500 routes or endpoints, tested in full. Larger or more complex apps are scoped and priced individually. Extra targets are €40 per month.

Yes. Huci scans with and without login, using the sessions and roles you provide to test access control between accounts.

Scans run only against assets you have proven you control, inside the scope you set. You can pause or stop any run, and every request is logged.

A panel of verified findings, each with the request, a CVSS rating, and steps to reproduce. A signed PDF report every month, and a webhook to Slack, Jira, GitHub, or GitLab on anything new.

Weekly, nightly, or on every deploy through CI or a webhook. You choose the cadence for each target.

Authorization

Authorized targets only.

Scans run only against assets you have proven you control, inside the scope you set, under a signed agreement. You can pause or stop any run, and every request the engine sends is logged and available to you.