ApyGuard Pricing: API Security Testing Plans
Choose the API security testing plan that fits your team's workflow. Each option includes OWASP API Top 10 coverage, AI-powered vulnerability detection, behavior profiling, and the visibility needed to secure APIs as they evolve.
Billing cycle
Free Trial
Start free.
7 days, one lifetime scan, no card required.
Plan
Commitment
7-day free trial • no card required
Best for
Getting to first value
Upgrade
Anytime
Included
- Continue from your first scan
- No checkout step
- Upgrade anytime
Self-serve
Basic
For developers who want continuous API security without a dedicated security hire.
Choose endpoint tier
Per month
Endpoints
25
Scans
1
Included
- 25 API endpoints
- 1 monthly scans
- Behavior profiling
- OpenAPI blueprint
- API discovery
Advanced
Professional
For product teams shipping APIs regularly and security engineers who need full pipeline visibility.
Choose endpoint tier
Per month
Endpoints
50
Scans
4
Included
- 50 API endpoints
- 4 monthly scans
- Behavior profiling
- OpenAPI blueprint
- API discovery
Optional add-ons
Paid extension add-ons
One-time add-on
API Security Report
One-time security scan for your APIs. Endpoints are analyzed against the OWASP API Security Top 10, with findings prioritized by severity and delivered as a PDF report with remediation guidance.
Pay once
No monthly billing cycle
- One-time payment
- 100 API endpoints
- 1 scans
One-time add-on
API Security Report
One-time security scan for your APIs. Endpoints are analyzed against the OWASP API Security Top 10, with findings prioritized by severity and delivered as a PDF report with remediation guidance.
Pay once
No monthly billing cycle
- One-time payment
- 50 API endpoints
- 1 scans
What counts as an API endpoint?
In ApyGuard, one endpoint equals one unique combination of HTTP method and path. For example, GET /v1/users/{id} and POST /v1/users count as two separate endpoints. If you're unsure how many endpoints your API has, you can use the free trial to discover them for you.
What are Guardy Credits?
Guardy is ApyGuard's AI assistant, separate from the scanning engine. Use it to analyze vulnerability findings, kick off a scan, or pull a daily security snapshot without leaving the dashboard. Credits power these assistant interactions only — your scans always run on full AI regardless of credit balance. Credits refill each billing period.
Full comparison
Compare All ApyGuard API Security Testing Plans
See every included feature and plan level in one shared comparison table.
Free
Free 7 days trial
Basic
from $129/month
Professional
from $299/month
Enterprise
Custom contact us
Value
ApyGuard vs. Manual API Penetration Testing
Manual penetration testing provides valuable expert review at a point in time. Automated testing complements that work with repeatable checks during active development.
ApyGuard can run in release workflows and generate tests from an API definition, including checks for authorization, authentication, and business logic risks.
Manual testing still has a role in compliance-driven organizations. For teams building and shipping APIs continuously, automated scanning is faster, cheaper, and more thorough between annual assessments.
Repeatable
Testing model
for release workflows
Reviewable
Finding context
requests and responses
Continuous
Feedback
through development
Compatible
Manual reviews
as a complementary control
Industries
Who Uses ApyGuard?
Security teams use ApyGuard across six common API-heavy industries. Pick the one closest to your environment to see examples, risks, and deployment patterns.
Fintech & Banking
Payment APIs, open banking, PCI-DSS scope
Explore use caseHealthcare & Digital Health
Patient data APIs, HIPAA, FHIR endpoints
Explore use caseE-commerce & Retail
Order APIs, cart security, business logic abuse
Explore use caseSaaS & Developer Platforms
Multi-tenant isolation, API key scoping, CI/CD gates
Explore use caseInsurance
Claims APIs, underwriting data, partner integrations
Explore use caseGovernment & Public Sector
Citizen data APIs, compliance documentation
Explore use caseFAQ
Frequently Asked Questions About ApyGuard Pricing
What's included in the 7-day free trial?
The free trial gives you access to the ApyGuard scanning engine for one lifetime scan, including API discovery, OWASP API Top 10 coverage, behavior profiling, and a limited vulnerability report. No credit card is required to start. At the end of 7 days, you can upgrade to a paid plan or your account moves to read-only state. Your scan results stay accessible.
What happens when the trial ends?
When your trial ends, you can continue on a paid Basic or Professional plan with one click. Your connected APIs and first scan results carry over. If you don't upgrade, your account stays active in read-only mode. We don't delete your data or charge you automatically.
Can I cancel anytime?
Yes. Paid plans are month-to-month (or annual, if you choose that billing cycle). Cancel from your account dashboard at any time. You keep access until the end of your current billing period. We don't charge cancellation fees.
Is there an annual billing discount?
Yes. Annual billing saves you two months compared to monthly. Toggle to yearly billing above to see the annual price for each plan tier.
Can I upgrade between plans?
Yes. Upgrades take effect immediately and you're prorated for the remainder of your billing period.
What payment methods do you accept?
ApyGuard accepts all major credit and debit cards (Visa, Mastercard, American Express). Enterprise plans also support invoicing. Payments are processed securely via Paddle.
Do you offer startup or team discounts?
If you're an early-stage startup or need licenses for a large security team, contact us. We have options that aren't listed on the public pricing page.
Need a custom plan?
Talk to sales for custom limits, support, or deployment needs.
Sales-assisted setup
Share your needs and get a custom quote.