One-off · no subscription
A pentest report for your customer or auditor. $99, in hours.
One automated external penetration test of one asset you have proved you own, and the dated report that goes with it: every finding with the request that proved it, fixes, and an OWASP Top 10 and SOC 2 mapping that says what an external test can and cannot evidence. Bought once. No card kept on file.
₹9,900 in India via Razorpay · refunded once if the scan cannot run · automated, not human-led
A customer's security questionnaire asks for one
Date of last external test, open findings, cadence — the pack answers from a scan that actually ran, and the report is dated and shareable.
Your SOC 2 auditor wants evidence of testing
A dated external test with findings tracked to a fix, mapped to the SOC 2 criteria it evidences — and honest about the criteria an external test cannot.
An investor or enterprise deal needs it by Friday
A manual firm quotes weeks and five figures. This runs in hours on a domain you prove you own, and the report says exactly what it is and is not.
What is in the report
- 1
Executive summary
Exposure score, severity counts, and what changed since any earlier scan.
- 2
Every finding with evidence
The request that proved it, what we established (demonstrated, confirmed, likely, unconfirmed), impact in plain language.
- 3
Fix guidance
Step-by-step remediation with configuration for common servers and frameworks.
- 4
OWASP Top 10 & SOC 2 mapping
Which categories and criteria this test evidences — and which it cannot, named on the face of the report.
- 5
What was tested, and what was not
Each stage that ran, with the limits of an automated external test stated.
- 6
Questionnaire pack
The answers security questionnaires ask for, generated from this scan.

A real Deep-profile report on docqon.com, one of our own products — findings, evidence and fixes exactly as a customer receives them, with internal identifiers redacted. The one-off report runs the same Deep scan plus the penetration-test stage on top. Open the PDF.
From signup to PDF
Step 1· 5 min
Create an account and add the asset
The domain, subdomain, IP or API base URL you want tested. No card on file for the free account.
Step 2· 10 min
Prove you own it
A DNS TXT record, a hosted file or a meta tag. Nothing is sent to an asset you have not verified.
Step 3· hours
Buy the report and start the test
$99 once (₹9,900 in India). The full Deep + penetration-test scan runs in the background; a thorough test of a real site takes hours, not minutes.
Step 4
Download the PDF
The report and questionnaire pack appear in the app and are mailed to your confirmed address. Send them on.
What the test does
- Real attack payloads from a narrow allowlist: path traversal, file inclusion, OS-command injection, server-side template injection, XXE, XPath, open redirect, CRLF, SQL injection, reflected XSS
- Bounded proof where the class allows it: reflected markup injection rendered in Chromium, SQL injection by boolean differential, SSRF via an out-of-band collector
- API operations answering without the authentication their own schema declares; enumerable object references (the IDOR/BOLA precondition)
- Security headers, cookie flags, TLS and certificates, DNS and email spoofing (SPF, DMARC, CAA, DNSSEC), exposed services and ports, exposed version-control and build files, known-vulnerable software
- How much of a fixed set of attack signatures your WAF actually blocked
What it does not do — stated on the report too
- Automated, not human-led. It does not test business logic, race conditions or stored XSS, and does not chain findings into attack paths. If a contract specifies a human-led test, you need one.
- External only, on assets you have verified. Nothing inside your network; no subdomain you have not verified separately.
- Six OWASP Top 10 categories have purpose-built tests; A07 in part; A10 (SSRF) only where the out-of-band check ran. A04 and A09 cannot be assessed from outside — the report says so.
- SecQon is external testing evidence. It is not an audit and does not make you compliant with anything.
One-off pentest report — $99 once
- · One full penetration test of one asset — everything Business runs, once
- · The complete written report with evidence, proofs and fix guidance
- · The questionnaire pack and compliance mapping
- · No subscription, no renewal, no card kept on file
Need re-tests every day instead? Plans from $49 a month.
Questions people ask
Will an auditor or customer accept an automated report?
Many accept automated external testing as evidence of a testing programme; some requirements specify a human-led test. The report states plainly that it is automated and lists what it did and did not test, so whoever set the requirement can judge it. Ask them before you buy if you are unsure.
How long does it take?
Setup is about fifteen minutes. The test itself runs in the background for hours, depending on how much of the site the crawl finds — our own full sweep of docqon.com took about 4.2 hours. You are emailed when the report is ready.
Is it safe to run on production?
It is built not to break things: destructive and data-extraction actions are blocked, payloads are bounded, and traffic is limited to 10 requests per second per asset. We still recommend telling your team first.
What if the scan fails?
A one-off scan that fails, is cancelled, never starts, or is refused because the asset is not verified refunds its credit, once.
What does it cost in India?
₹9,900 for the same report, paid through Razorpay with a GST invoice where applicable.
Do I need a subscription?
No. The report is bought once, no card is kept on file, and the free account it sits on stays free. If you later want daily re-tests, the paid plans start at $49 a month.