Skip to main content
Detectify AB logo
Risk & ComplianceFounded 2013 · 13 yrs

Detectify

Continuous attack surface discovery plus payload-based application and API security testing that proves what is actually exploitable.

By Detectify AB · HQ Stockholm, Sweden · 4.2/5 Value-Position score (estimate)

Positioning guardrails

Best for

  • Security teams that must continuously map and test their full external attack surface
  • DevSecOps teams automating AppSec, API and internal scanning inside CI/CD pipelines
  • Organizations that want exploitability proof to cut vulnerability noise and false positives
  • Teams building agentic AI workflows that need deterministic security testing via MCP
  • Mid-market and enterprise security programmes that need PCI ASV scanning for PCI DSS

Ideal size: Security team of 2-20 in a 50-2,000 person org people · Scale-up or enterprise with a DevSecOps practice and a named security owner

Not for

  • Teams looking for source-code review (SAST) or IDE-level secure coding tooling
  • Buyers seeking endpoint, email or cloud-workload protection rather than external AppSec
  • Procurement teams that require vendor-published SOC 2 or ISO 27001 evidence (none found on its trust pages)
  • Organizations with no one available to triage and remediate findings
  • Very small teams that want a single all-in-one security platform

Value metrics scorecard

Time-to-Value

Under a week to first scan

~3 days to first production value

Total Cost of Ownership

$5,400/yr

Starts at $0 · Annual platform fee per tier, billed annually (Starter free, then from EUR 2,500 / 5,000 / 15,000), plus additional cost per asset, domain, target and IP range

Implementation Friction

2/5

Engineering + admin effort required

Value-Position score

4.2

out of 5 · model estimate

Full cost breakdown

Mandatory implementation fee

None

Seat tiers

Starter up to 5 users / 1 team; Standard up to 10 users / 1 team; Professional unlimited users across 2 teams; Enterprise unlimited users and teams

Add-on costs

  • PCI ASV Scanning: additional EUR 500 per year
  • Surface Monitoring, Application Scanning and API Scanning: additional cost per domain or target
  • Additional onboarding: 5 hours for EUR 2,500
  • Extra internal scanning environments charged separately
  • Additional assets, apex domains, subdomains and IP ranges billed on top of the platform fee

Company & support

Who is behind Detectify, and how your team gets help once it is live.

Company

Founded
2013 · 13 yrs in business
Headquarters
Stockholm, Sweden

How you get support

  • PhoneNot listed
  • EmailAll plans
  • Live chatNot listed
  • Support portal / ticketsNot listed
  • Community forumNot listed
  • Help centre / docsAll plans
  • Dedicated account managerEnterprise only
  • In person / on-siteNot listed
Hours
Not recorded
Response time
Not stated

Starter includes email support; Standard adds professional support from security specialists; Professional adds a dedicated customer success manager; Enterprise adds a solutions engineer, enterprise support and an SLA.

“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.

Market position

Where Detectify sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.

Quadrant view

Typical annual cost × Time-to-value

$2k/yr$5k/yr$11k/yr$26k/yr$64k/yr1d2d3d4dAnnual TCO ← betterDays to value better →Quick & CheapQuick & PriceySlow & CheapSlow & PriceyDetectifyDescopeInfisicalRemoteRemoFirstStackHawk

The lines cross at the median of the solutions shown, so about half sit on each side of each line. A dashed ring marks an outlier pinned to the edge; hover for its value.

Detectify is outlined. Click any dot to open its dossier.

Companies on the chart 6 / 10

  • Detectify
  • Descope
  • Infisical
  • Remote
  • RemoFirst
  • StackHawk
Add or change companies

Up to 10 companies including Detectify. Listed closest first.

Stack fit signal

Compatibility with standard B2B ecosystems.

MCPNative

Ships an official MCP server. Connects to Claude Code, Claude Desktop, ChatGPT connectors and Cursor out of the box.

SalesforceNot supported
AWSIntegration
SnowflakeNot supported
HubSpotNot supported
Google WorkspaceNot supported
Microsoft 365Not supported
SAPNot supported
SlackNot supported

AI & MCP readiness

What Detectify ships in AI, and what it asks of your ecosystem.

AI features shipped

Agentic workflows

Sources describe Alfred AI, an internal LLM agent chain that turns new CVE research into live scanner tests, plus agentic tooling and an MCP server so AI coding agents can call the same deterministic, payload-based tests as human engineers. No customer-facing model key or audit-export details are stated.

In your ecosystem

AI connection
Official MCP server
Model key
Not recorded
AI usage audit
Not recorded

Compliance attestations

SOC 2 — not heldISO 27001 — not heldGDPR — not heldHIPAA — not heldFedRAMP — not heldISO 42001 — not heldIAPP AIGP* — not held

* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.

Bottom line

Detectify is a Stockholm application security platform founded in 2013 by ethical hackers. It pairs continuous external attack surface discovery with payload-based DAST, API scanning (REST and GraphQL) and internal scanning, and says 99% of the vulnerabilities it finds carry no CVE. Pricing runs from a free Starter tier to Standard (EUR 2,500), Professional (EUR 5,000) and Enterprise (EUR 15,000) annual platform fees, plus extra charges per asset. An MCP server lets AI agents call the same tests.

Frequently asked questions

What does Detectify actually scan?

Detectify continuously discovers and maps your external attack surface - domains, subdomains, IPs, technologies, ports and protocols - and runs payload-based vulnerability testing on every asset, scanning new assets as they appear. Add-on products cover authenticated DAST application scanning, REST and GraphQL API scanning with a dynamic fuzzing engine, internal systems and CI/CD, and PCI ASV scanning for PCI DSS programmes.

How is Detectify priced?

An annual platform fee by tier: Starter from EUR 0 for up to 5 users, Standard from EUR 2,500 for up to 10 users, Professional from EUR 5,000 for unlimited users across 2 teams, and Enterprise from EUR 15,000 for unlimited users and teams. Additional assets, domains, targets, IP ranges and extra internal scanning environments cost extra, and PCI ASV Scanning adds EUR 500 per year.

Can AI coding agents call Detectify directly?

Yes. Detectify publishes an MCP server and agentic tooling that give AI agents deterministic, payload-based access to the platform, so agents can check their own output against your live attack surface rather than assuming a security posture. This is listed alongside integrations in the plan comparison, and Detectify also runs Alfred AI, an LLM agent chain that turns new CVE research into live scanner tests.

What onboarding and support is included?

Onboarding is bundled with paid plans: 2 hours of expert onboarding on Standard, 5 hours on Professional and 15 hours on Enterprise, with extra onboarding available at EUR 2,500 for 5 hours. Support is email on Starter, professional support on Standard, and a dedicated customer success manager on Professional and Enterprise, where an SLA and solutions engineer are also included.

How does Detectify reduce false positives?

Rather than matching static signatures, Detectify uses 100% payload-based testing and a dynamic fuzzing engine that rotates proprietary payloads across scans, with machine learning prioritising which payloads to fire based on past findings. The vendor says real-world hacker research is used to prove what is actually exploitable, and that 99% of the vulnerabilities it finds over the past three years have no CVE assigned.

What certifications does Detectify hold?

The vendor's trust, compliance and security pages reviewed here do not state SOC 2, ISO 27001, HIPAA, FedRAMP or ISO 42001 certifications. The security page instead documents a responsible disclosure programme ([email protected]) covering *.detectify.com, and PCI ASV Scanning is offered to support customers' PCI DSS compliance work.