Pricing

Start with the assessment.
Upgrade for the workflow you need.

Free gives you the complete on-premises AD findings set for one domain, including the risk posture score, Quick Wins, and the executive summary export. Standard adds account risk scores, hybrid identity checks, scheduled scanning, history, and trends. Auditor adds the portable Linux scanner, multi-domain scale, and commercial rights to assess authorized third-party environments. Enterprise is scoped around your deployment, scale, and integration requirements.

Free
Free
Run the complete on-premises AD findings set against one domain. No finding cap or preview.
$0
No paid subscription required
1 domain · 1 user
The full AD assessment
All on-prem AD findings, no cap or preview
Attacker insight + remediation steps
MITRE & compliance mappings
Risk posture score + Quick Wins
Executive summary export
Account risk scores
Hybrid identity (Entra) checks
Platform
Portable Windows scanner — no agent install
2FA included
Latest scan only, no history or trends
Community support only
Standard
Standard
Track posture over time. For an internal team hardening a single AD environment.
$3,000 / year
Billed annually
1 unique domain / term · 3 users
Everything in Free, plus
Account risk scores
Hybrid identity (Entra) checks
Scheduled & recurring scans via Windows agent
Full scan history & report history
Trend tracking + scan-to-scan diff
Custom logo on reports
Access & Support
3 users included
Standard support
Enterprise
Enterprise
For requirements outside the standard plans. Deployment, scale, support, and custom capabilities are scoped and priced around what you actually need.
Custom
Tailored quote · contact our team
Custom domain, user & deployment scope
Auditor capabilities, with custom scope for
Domain and user scale beyond Auditor
SSO / SAML
Air-gapped / fully offline deployment custom scope
Support & Deployment
Onboarding and support matched to your requirements
Custom contract & procurement
API & integrations available to scope
Custom engineering available when needed additional fees may apply
No credit card to start Read-only AD assessment · no changes to Active Directory Annual subscription Portable Windows scanner on every plan Linux scanner on Auditor+ Built by offensive security practitioners
Full feature comparison
Feature Free Standard Auditor ★ Enterprise
Pricing
Annual price $0 $3,000 Custom
Billing motion Self-serve Self-serve Sales-assisted
Findings & assessment content
All findings (no cap)
Attacker insight per finding
Step-by-step remediation guidance
MITRE ATT&CK + compliance mapping
Risk posture score + quick wins
Account risk scores
Scanning & scope
Active Directory checks
Hybrid identity checks (Entra)
Unique domains per subscription term 1 1 Custom
On-demand scans A few per day Unlimited Unlimited
Scheduled / recurring scans
Read-only assessment, no AD changes
Portable Windows scanner
No agent install; run assessments on demand
Windows agent for scheduled scanning
Portable Linux scanner
Air-gapped / fully offline deployment
Enterprise custom scope; engineering fees may apply
Available to scope*
History & trends
Retained scan history Latest only Full Full
Trend tracking (posture over time)
Scan-to-scan comparison (diff)
Reporting & exports
HTML report
Executive summary export
Custom logo on reports
White-label reports
Access & users
Users included 1 3 Unlimited
Two-factor authentication
Role-based access control (RBAC)
SSO / SAML Available to scope*
Licensing & use rights
Internal-use rights
Commercial / MSSP / consulting rights
Authorized third-party assessments
Written client authorization required for each environment
Integrations & API
API access Available to scope*
Ticketing / SIEM / webhooks Available to scope*
Support & services
Support level Community Standard White glove
Remediation assistance (add-on) Base rate 15% off 40% off
Dedicated onboarding / CSM Available to scope*

* Enterprise capabilities marked “Available to scope” are not automatically included. They are quoted based on your requirements, and custom engineering or implementation fees may apply.

Optional Add-On

Remediation Assistance

Hands-on remediation and expert advisory from Breach Point practitioners. Separate from the software subscription, available on every plan.

On-demand remediation assistance from Breach Point practitioners
Finding interpretation, remediation planning, hands-on implementation, assessment support, executive readouts, and architecture review. Billed hourly and purchased as you need it with no long-term commitment. Your plan tier earns a discount off the base hourly rate.
Hands-On + Advisory
Free plan
Base rate
Standard plan
15% off
Auditor plan
25% off
Enterprise plan
40% off
Enterprise & Custom

Need a deployment that doesn't fit the standard plans?

Enterprise starts with the Auditor capabilities and is scoped around your requirements. That can mean more domains, SSO, a fully offline deployment, custom onboarding, or other implementation work. Those options are quoted as part of the engagement rather than assumed to be included.

Custom domain scale Air-gapped deployment SSO / SAML Custom onboarding Support options Custom engineering Custom procurement

Common Questions

Pricing FAQ

Is the Free plan really the full assessment?
Yes, for the on-premises findings themselves. Free scans one domain and surfaces every on-prem AD finding, with Hacker Insight, remediation guidance, MITRE/compliance mappings, the risk posture score, Quick Wins, and the executive summary export. It keeps your latest scan only. Standard adds account risk scores, hybrid identity checks, scheduled scanning, history, and trends.
What scanner options are available?
Every plan can use the portable Windows scanner for on-demand assessments. Standard and above can install the Windows agent for automated scheduled scans. Auditor and Enterprise also include the portable Linux scanner. A fully offline, air-gapped deployment is an Enterprise option that must be scoped separately and may require additional engineering work.
What's the difference between Standard and Auditor?
Standard is for an internal team hardening one domain. It adds account risk scores, hybrid identity checks, scheduled Windows scanning, history, trends, and scan-to-scan comparison. Auditor is built for consultants, MSSPs, and auditors: it adds the portable Linux scanner, up to 50 unique domains per subscription term, unlimited users, white-label reports, RBAC, and, critically, the commercial license to assess authorized third-party environments. Client work requires Auditor or above.
How does the Auditor 50-domain limit work?
Auditor includes up to 50 unique Active Directory domains during each subscription term. A domain counts when it is first assessed or registered under the subscription and stays counted for the rest of that term. Removing the domain, deleting its scan data, or finishing the engagement does not free the slot for another domain during the same term. Repeated assessments of the same domain do not use additional slots, and the count resets at the start of a new term. Full detail is in the Plan Entitlement Schedule.
Can Auditor be used for client work?
Yes. Auditor includes commercial rights for authorized consulting, MSSP, auditing, and third-party assessments. You can work with any number of client organizations, but every domain assessed during the subscription term counts toward the 50 unique-domain limit. You need written client authorization for each environment you assess, from its owner or operator, as set out in the EULA.
Do you offer monthly billing?
All plans are annual. Annual billing is standard for security software and lets us keep pricing lower than monthly equivalents would allow. If monthly matters for your situation, contact us and we can discuss options.
How is Enterprise priced?
Enterprise is quoted around the capabilities and deployment you actually need. It starts from the Auditor feature set, then we can scope options such as additional domain scale, SSO/SAML, air-gapped operation, custom onboarding, or other implementation work. Those options are not automatically included in every Enterprise subscription, and features that require custom engineering may carry additional development or implementation fees. Talk to our team and we'll scope it with you.
What does "remediation assistance" include?
Both advisory and hands-on help from Breach Point practitioners: finding interpretation, remediation planning, executive readouts, and hands-on implementation when you want us to do the fixes alongside your team. It's billed hourly, and active subscribers earn a discount off the base rate: 15% on Standard, 25% on Auditor, and 40% on Enterprise. Your exact rate is included in your quote.
Does running a scan impact my production environment?
Insight Recon performs read-only assessment activity. It does not modify Active Directory objects, extract credentials, perform exploitation, or deploy software to your domain controllers or endpoints as part of its standard assessment workflow. Like any directory assessment tool, scanning does generate queries, authentication activity, and logs, and your environment's configuration or security controls may raise alerts. You'll need a domain account with the appropriate read permissions.
What happens to my data and reports?
Scan data and reports are retained for active subscribers. Free keeps your latest scan; history and trend tracking are on Standard and above. You can delete your data at any time from your account. Retention and deletion timelines are in our Privacy Policy, and the contractual terms are in the EULA.

Get Started

Run the assessment before you buy anything.

No credit card required. Run the on-prem AD findings set against one domain, review the report, and upgrade when you need account scoring, automation, history, Linux, multi-domain use, or commercial rights.