Detectify
Stockholm attack-surface and application scanner built with payloads from 400+ ethical hackers
Quick Overview
| Company | Detectify AB |
|---|---|
| Category | Web Security |
| Headquarters | Stockholm, Sweden |
| Founded | 2013 |
| EU Presence | EU (Sweden) |
| Open Source | No |
| Compliance | ISO 27001, GDPR |
| Pricing | Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year |
| Free Option | Free Starter tier; tailored trials for paid plans |
| Replaces | Tenable, Qualys, Invicti |
Detailed Review
Detectify combines external attack surface management with dynamic application security testing, continuously mapping what an organisation exposes to the internet and then testing each asset for exploitable vulnerabilities. The payloads come partly from Detectify's own research and partly from Crowdsource, a network of more than 400 ethical hackers who submit real attack techniques rather than generic signatures, which is the company's clearest point of difference from a conventional scanner.
Coverage extends to REST and GraphQL APIs from the Standard tier up, and CI/CD integration on Professional lets scanning run inside a deployment pipeline rather than as a separate quarterly exercise. Detectify AB is based in Stockholm, so the reports generated from scanning a customer's infrastructure — which can include internal URLs, parameters and, occasionally, exposed credentials — are processed under Swedish and EU law.
Pricing is published rather than quote-only, down to a point: a free Starter tier covers up to five users and 100 assets, Standard is €2,500 a year, Professional €5,000, and Enterprise €15,000 for unlimited users and assets. That transparency stops where most vendors hide it — mid-market — which is unusual in application security. The honest limit: it is a scanner and attack-surface tool, not a WAF or CDN, so it finds exposure rather than blocking it.
What Detectify does well
- External attack surface management plus DAST in one platform
- Crowdsource payloads from 400+ ethical hackers
- REST and GraphQL API scanning
- Published pricing from a free tier to €15,000/year
- Swedish company, EU jurisdiction
Where Detectify falls short
- Finds vulnerabilities rather than blocking attacks — not a WAF or CDN
- Standard tier caps at 750 assets and 10 users
- CI/CD integration reserved for Professional and above
- Enterprise pricing jumps sharply to €15,000/year
Standout feature. Published pricing from a free tier to €15,000 a year — rare transparency in enterprise application security.
Pros and Cons
Pros
- External attack surface management plus DAST in one platform
- Crowdsource payloads from 400+ ethical hackers
- REST and GraphQL API scanning
- Published pricing from a free tier to €15,000/year
- Swedish company, EU jurisdiction
Cons
- Finds vulnerabilities rather than blocking attacks — not a WAF or CDN
- Standard tier caps at 750 assets and 10 users
- CI/CD integration reserved for Professional and above
- Enterprise pricing jumps sharply to €15,000/year
Alternatives to Detectify
Frequently Asked Questions
What is Detectify?
Detectify combines external attack surface management with dynamic application security testing, continuously mapping what an organisation exposes to the internet and then testing each asset for exploitable vulnerabilities. The payloads come partly from Detectify's own research and partly from Crowdsource, a network of more than 400 ethical hackers who submit real attack techniques rather than generic signatures, which is the company's clearest point of difference from a conventional scanner.
Where is Detectify based?
Detectify operates from Stockholm, Sweden, which places it under EU (Sweden). Compliance: ISO 27001, GDPR.
What does Detectify cost?
Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year. Free Starter tier; tailored trials for paid plans.
Who is Detectify best for?
Security teams that want continuous external attack-surface and app testing. Published pricing from a free tier to €15,000 a year — rare transparency in enterprise application security.
What are the drawbacks of Detectify?
Finds vulnerabilities rather than blocking attacks — not a WAF or CDN. Standard tier caps at 750 assets and 10 users. CI/CD integration reserved for Professional and above. Enterprise pricing jumps sharply to €15,000/year.