Start free. Add the AI engineer for ₹24,999 / month.
The scanning engine is free forever. Bring your own AI key and both agents run on it at your cost, with no upgrade — or let us run them.
A taste of the scanning engine — 30+ scanners, cross-surface correlation, threat-intel, SOC 2 readiness. Free forever (no AI/LLM cost to run). No card.
Start free- Bring your own LLM key → both AI agents (Security Engineer + Pentester), at your model cost
- 2 scan targets
- All 5 categories — code · cloud · attack surface · identity · compliance
- 30+ OSS scanners (on-demand)
- Findings dashboard + all 27 frameworks mapped
- Human-in-the-loop approvals — you approve every fix
- Signed decision ledger
- Community support
Your AI Security Engineer, on top of the full scanning engine. It triages what actually matters, explains each issue in plain English, and proposes the fix for you to approve — it never changes anything on its own.
Talk to us to start- ★ AI Security Engineer — triages, explains in plain English, proposes fixes you approve
- Up to 25 scan targets
- Full full detection — correlation, threat-intel, attack paths
- Continuous monitoring + incidents
- All 27 frameworks — SOC 2 · ISO · GDPR · PCI · HIPAA · NIST · …
- Signed evidence packs + Trust Center
- Human-in-the-loop approvals + remediation
- Self-serve, managed, or MSP delivery — your service model
- Slack · Jira · email alerts
For when a customer's security review is holding up a deal. Your AI Pentester proves which issues are actually exploitable — with the request to replay — and re-tests after the fix to show the hole is really closed. One artifact instead of three purchases: the report, the evidence, and the proof it got fixed.
Talk to us to start- Everything in Core, plus:
- ★ AI Pentester — exploitation-proven, not just flagged
- VAPT report with a named human sign-off — what the reviewer is checking for
- Re-tests after every fix — proof the hole is closed
- Continuous testing, not once a year
For when the constraint is scale or delivery rather than capability: unlimited targets, a managed or MSP partner desk, and a named human accountable for the calls that matter.
Contact sales- Everything in Core + Pentest, plus:
- Unlimited scan targets
- Managed service + MSP / partner desk
- Role-based access (owner / member) — SSO / SAML on request, not yet shipped
- Custom / bring-your-own frameworks
- Dedicated success engineer + SLAs · on-prem option
Prices in INR, exclusive of 18% GST. Free is genuinely free — it runs only the open-source scanners (no AI cost on our side), so we never have to take it away. Annual billing on Core saves ~2 months. The signed decision ledger is on every plan.
Per application — the Safe-to-Host audit
One application, one price, one certificate. The full scan, the AI Pentester’s exploitation proof, a reviewer’s desk where a named auditor decides every finding, the re-test after remediation, and the signed Safe-to-Host certificate a data centre accepts before go-live.
- Assessed against OWASP Top 10 (2021), mapped to ISO 27001 and CERT-In
- Re-test included — the certificate issues only when nothing serious remains open
- Invoiced only when the buyer accepts the certificate. No advance.
- Your firm's name on the certificate; the engine named as provenance
CERT-In empanelment belongs to the auditing firm. Empanelled firms run this per client.
Pick your service model
Any paid tier runs three ways — you run it, we run it (managed), or your MSP runs it for clients. The product is identical; only who makes the human-in-the-loop calls changes.
Compare plans
| Free | Core | Core + Pentest | Enterprise | |
|---|---|---|---|---|
| Deterministic + ML-based scanning | ||||
| Scan targets | 2 | Up to 25 | Up to 25 | Unlimited |
| Categories — code · cloud · attack · identity · compliance | All 5 | All 5 | All 5 | All 5 |
| OSS scanners wrapped | 30+ | 30+ | 30+ | 30+ |
| Cross-surface correlation + attack paths + threat-intel | ||||
| Continuous monitoring + incidents | ||||
| Compliance & evidence | ||||
| Frameworks mapped | All 27 | All 27 | All 27 | All 27 + custom |
| Signed evidence packs + Trust Center | ||||
| Questionnaire automation | ||||
| Human-in-the-loop approvals + apply | ||||
| Signed decision ledger | ||||
| AI agents — self-serve, no sales call | ||||
| AI Security Engineer — prioritize · chain · fix · explain | ||||
| AI Pentester — exploitation-proven VAPT | ||||
| Plain-English findings — what broke, why it matters, what to do | ||||
| Or: bring your own LLM key — AI on any plan, at your cost | ||||
| Delivery & platform | ||||
| Service model — self-serve · managed · MSP | Self-serve | Any | Any | Any |
| Integrations (Slack · Jira · email) | ||||
| Role-based access (owner / member) | ||||
| SSO / SAML | on request — not yet shipped | |||
| Support | Community | Standard | Standard | Dedicated + SLA |
Frequently asked
Is the Free plan really free — for me and for you?
Yes, both ways. Free runs only the open-source scanners across all five categories, so there's no AI/LLM cost on our side — which is exactly why we can keep it free forever. You connect up to 2 targets, see your real posture and SOC 2 readiness, with no credit card. The AI security engineer turns on when you upgrade.
What do I get on Core that Free doesn't have?
Your AI Security Engineer — it triages what actually matters, explains each issue in plain English, and proposes the fix for you to approve. Plus the full scanning engine: every scanner with cross-surface correlation, continuous monitoring with incidents, all 27 frameworks with signed evidence packs, and the human-in-the-loop apply loop that actually closes findings. ₹24,999/mo (or ₹2,49,990/yr), up to 25 targets.
How are the tiers structured?
Free to see your real posture with the scanning engine — and if you paste in your own LLM key, both AI agents run on Free at your model cost, no upgrade and no sales call. Core adds your AI Security Engineer (defense) on our side. Core + Pentest adds your AI Pentester (attack) — the one that proves which findings are actually exploitable, re-tests after each fix, and produces the VAPT report a customer's security review asks for. Enterprise is for when the constraint is scale or delivery rather than capability: unlimited targets, managed/MSP. SSO / SAML is not shipped yet — ask, and we will tell you where it is on the roadmap.
Can I run the AI on my own LLM key?
Yes, on any plan including Free. Connect your own key in Settings → AI engine — any OpenAI-compatible provider, or a local Ollama — and the agents run at your model cost instead of ours. Useful if you already have credits, or if your policy is that your code only goes to a model you control.
Are there API rate limits?
Yes — generous per-plan fair-use limits on the API, so one customer's automation can never slow the platform down for everyone else. Normal interactive use and CI never come close; paid plans get more headroom, and Enterprise is unmetered. If you hit a limit you get a clear 429 with a retry hint, never a hard lockout. AI spend is capped separately by the monthly budget you set.
Do I need a security engineer to use it?
No — that's the point. TensorShield does the security engineer's and the compliance manager's work, and only pulls you in to approve anything consequential. Built for a non-technical founder or ops lead.
What does "human in the loop" mean?
Low-risk fixes apply automatically. Anything consequential (a config change, an identity action) waits for one tap of your approval — and every decision, automated or human, is signed into a tamper-evident ledger.
What if I'd rather not run it at all?
Have it fully managed. Our security expert — or your MSP / consultancy partner — operates TensorShield for you: they triage, approve, and sign off, and you get the outcome plus named accountability. Same engine and signed evidence, priced per engagement.
Is there a per-application price for a government portal audit?
Yes. The Safe-to-Host audit is ₹49,999 per application + GST: the full scan, exploitation proof from the AI Pentester, a reviewer's desk where a named auditor decides every finding, the re-test after remediation, and the signed certificate. It is invoiced only when the buyer accepts the certificate — no advance — which is the term public-sector tenders set. CERT-In empanelment is the auditing firm's credential, not the product's; empanelled firms run it per client and their auditor's name goes on the certificate.
Can auditors trust the evidence?
Every finding cites the tool that proves it, and every compliance pack is cryptographically signed and pinned to the exact state it was assessed against — reproducible proof, not screenshots.
Start with the free plan today.
See your posture and first findings in minutes. Upgrade when you're ready.
Start free