Detectify

Stockholm attack-surface and application scanner built with payloads from 400+ ethical hackers

Quick Overview

Company Detectify AB
Category Web Security
Headquarters Stockholm, Sweden
Founded 2013
EU Presence EU (Sweden)
Open Source No
Compliance ISO 27001, GDPR
Pricing Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year
Free Option Free Starter tier; tailored trials for paid plans
Replaces Tenable, Qualys, Invicti

Detailed Review

Pros and Cons

Pros

  • External attack surface management plus DAST in one platform
  • Crowdsource payloads from 400+ ethical hackers
  • REST and GraphQL API scanning
  • Published pricing from a free tier to €15,000/year
  • Swedish company, EU jurisdiction

Cons

  • Finds vulnerabilities rather than blocking attacks — not a WAF or CDN
  • Standard tier caps at 750 assets and 10 users
  • CI/CD integration reserved for Professional and above
  • Enterprise pricing jumps sharply to €15,000/year

Alternatives to Detectify

See all web security →

Frequently Asked Questions

What is Detectify?

Detectify combines external attack surface management with dynamic application security testing, continuously mapping what an organisation exposes to the internet and then testing each asset for exploitable vulnerabilities. The payloads come partly from Detectify's own research and partly from Crowdsource, a network of more than 400 ethical hackers who submit real attack techniques rather than generic signatures, which is the company's clearest point of difference from a conventional scanner.

Where is Detectify based?

Detectify operates from Stockholm, Sweden, which places it under EU (Sweden). Compliance: ISO 27001, GDPR.

What does Detectify cost?

Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year. Free Starter tier; tailored trials for paid plans.

Who is Detectify best for?

Security teams that want continuous external attack-surface and app testing. Published pricing from a free tier to €15,000 a year — rare transparency in enterprise application security.

What are the drawbacks of Detectify?

Finds vulnerabilities rather than blocking attacks — not a WAF or CDN. Standard tier caps at 750 assets and 10 users. CI/CD integration reserved for Professional and above. Enterprise pricing jumps sharply to €15,000/year.

Who worked on this review

Three people touch every tool page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Marta Kowalczyk
Written by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Ingrid Halvorsen
Edited by

Ingrid Halvorsen

Managing Editor · Oslo, Norway

Runs the review process and decides when a page is ready to publish or needs another pass.

Daniel Brandt
Fact-checked by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Go to Detectify