Shieldome offers two distinct ways to buy security scanning. Understanding the difference will save you money and make sure you are getting the right level of coverage for your situation.
Token Packs — buy scans, use them when you need them
Token packs are a one-time purchase. You buy a bundle of scan tokens and spend them on any target URL whenever you want — no schedule, no commitment, no recurring charge.
How they work
- Each completed scan costs 1 token, regardless of target, scan depth, or report format.
- Tokens are valid for 12 months from your last purchase. Buying again extends the clock on your entire balance.
- You can scan any URL on the internet — useful for auditing vendors, checking client sites, or one-off assessments.
- Full results — OWASP Top 10, PDF/SARIF/CSV reports, scan history — come with every token, every pack.
When token packs make sense
- Freelancers and consultants who run audits for different clients at irregular intervals.
- Developers who want to verify a site before launch or after a major change.
- Security teams with a defined list of assessments to run over a quarter — buy once, spread the scans.
- Anyone who does not need weekly monitoring and wants to pay only for what they use.
SaaS Monitoring — continuous, automatic, on a schedule
SaaS monitoring subscriptions run automated scans on a weekly schedule against URLs you register. You set it up once and Shieldome monitors continuously, alerting you when something changes.
What is monitored
- PCI DSS 4.0 Monitoring — weekly script inventory on checkout pages per Requirement 11.6.1. Alerts on new, changed, or removed scripts.
- GDPR Compliance Monitoring — consent banner detection, cookie hygiene, third-party tracker identification, sensitive data exposure.
- SOC 2 Readiness Monitoring — automated CC criteria checks plus a manual checklist your team fills in the dashboard.
- API Security Scanner — weekly OWASP API Top 10 checks against your REST API endpoints.
When SaaS monitoring makes sense
- Compliance requirements where you need documented continuous monitoring (PCI DSS 4.0, GDPR, SOC 2).
- Production environments where a script injection or configuration drift could go undetected for weeks.
- SaaS companies who need to demonstrate to enterprise customers that their platform is continuously monitored.
Can I use both?
Yes — and many customers do. The most common pattern is to use a SaaS monitoring subscription for continuous coverage of production URLs, and token packs for one-shot assessments of new features, client audits, or vendor due diligence. The two billing models are completely independent.
Which should I start with?
If you are not sure: start with a token pack. Run a scan on your main domain, review the findings, and see what Shieldome surfaces. If you then decide you want that level of visibility on a recurring basis — or if you have a compliance requirement that demands it — upgrade to the relevant monitoring subscription. Your token balance stays and can still be used for one-off scans alongside any subscription.