Plans
Shieldome is a monthly SaaS subscription. Register your domains once - Shieldome scans them automatically on a fixed schedule and emails you when new vulnerabilities appear.
| Plan | Domains | Frequency | USD/mo | EUR/mo | RSD/mo | Highlights |
|---|---|---|---|---|---|---|
| Starter | 1 | Weekly | ~$19 | ~€18 | ~2,100 RSD | Email alerts, PDF reports, score trend |
| Pro | 5 | Daily | ~$49 | ~€46 | ~5,400 RSD | Everything in Starter + Slack/Jira, compliance posture |
| Agency | 20 | Daily | ~$179 | ~€166 | ~19,700 RSD | Everything in Pro + white-label reports, priority support |
| Enterprise | Unlimited | Daily | Custom | Custom | Custom | Custom SLA, dedicated support, SSO |
All plans include a 14-day free trial. No credit card required to start.
What every scan includes
- OWASP Top 10 (2021) - broken access control, injection, misconfigurations, auth failures, cryptographic failures, and more
- Port & service scan - TCP connect scan across top 20 ports; flags exposed databases, RDP, Redis, Telnet, and other dangerous services
- CVE detection - detects software versions from HTTP headers and page markup, cross-references NIST NVD for known vulnerabilities
- Subdomain & attack surface mapping - passive discovery via certificate transparency logs (crt.sh) and DNS resolution
- JS/SPA crawling - Playwright-powered dynamic crawl discovers hidden API endpoints, forms, and XHR calls invisible to static scanners
- API security testing - probes OpenAPI/Swagger endpoints and GraphQL introspection; detects public spec exposure and batch query abuse
- OAST blind vulnerability detection - Interactsh out-of-band probes confirm blind SSRF and XXE without relying on HTTP responses
- WAF/CDN detection - fingerprints 30+ WAF/CDN products by response headers and cookies
- Email security (SPF / DKIM / DMARC) - DNS checks for email spoofing protection gaps
- GDPR cookie consent - Playwright-powered detection of tracking cookies set before user consent
- Content Security Policy analysis - deep CSP header parsing: unsafe-inline, unsafe-eval, wildcard sources, missing directives
- Directory brute force - probes 60+ common hidden paths for exposed admin panels, config files, backups, and source leaks
- Rate limiting test - verifies login and auth endpoints enforce request throttling
- Screenshot evidence - captures a Playwright screenshot of the target homepage as scan evidence
- Data breach check - queries HaveIBeenPwned for domain exposure in known breach databases
- AI-powered remediation - Claude Haiku generates specific, actionable fix steps for every HIGH and CRITICAL finding
- Performance metrics - DNS lookup, TTFB, page size, caching, HTTP/2, compression
- PDF, DOCX, SARIF, CSV exports
- Compliance posture mapping - findings mapped to PCI DSS 4.0, GDPR articles, and ISO 27001:2022 controls
Monitored domains
- Only domains you own may be registered.
- Domains are stored without the scheme (e.g.
example.com). You supply the full URL when registering. - Each automatic scan updates the domain's last-scan date, security score, and trend graph.
Alerts and integrations
- All plans - email alert when a new HIGH or CRITICAL finding is detected, or when your score drops.
- Pro & Agency - Slack and Jira integrations.
- Agency - white-label PDF reports with your branding + priority support.
How to subscribe
- Go to Account → Subscription & Billing.
- Select a plan and complete payment.
- Your subscription activates immediately. Go to Account → Monitored Domains to register your first domain.
Cancellation
Cancel anytime from Account → Monitored Domains → Manage subscription. Your subscription stays active until the end of the current billing period.
Full feature comparison
| Feature | Starter | Pro | Agency | Enterprise |
|---|---|---|---|---|
| OWASP Top 10 checks | ✓ | ✓ | ✓ | ✓ |
| Port & service scan | ✓ | ✓ | ✓ | ✓ |
| CVE detection (NVD) | ✓ | ✓ | ✓ | ✓ |
| Subdomain discovery | ✓ | ✓ | ✓ | ✓ |
| JS/SPA dynamic crawl (Playwright) | ✓ | ✓ | ✓ | ✓ |
| API security (OpenAPI/GraphQL) | ✓ | ✓ | ✓ | ✓ |
| OAST blind vulnerability detection | ✓ | ✓ | ✓ | ✓ |
| WAF/CDN detection | ✓ | ✓ | ✓ | ✓ |
| Email security (SPF/DKIM/DMARC) | ✓ | ✓ | ✓ | ✓ |
| CSP deep analysis | ✓ | ✓ | ✓ | ✓ |
| GDPR cookie consent check | ✓ | ✓ | ✓ | ✓ |
| Directory brute force | ✓ | ✓ | ✓ | ✓ |
| Screenshot evidence | ✓ | ✓ | ✓ | ✓ |
| AI-powered remediation (Claude) | ✓ | ✓ | ✓ | ✓ |
| PDF / DOCX / SARIF / CSV | ✓ | ✓ | ✓ | ✓ |
| Scan history & trends | ✓ | ✓ | ✓ | ✓ |
| REST API & CLI tool | ✓ | ✓ | ✓ | ✓ |
| GitHub Actions YAML template | ✓ | ✓ | ✓ | ✓ |
| Automatic monitoring | ✓ | ✓ | ✓ | ✓ |
| Email alerts | ✓ | ✓ | ✓ | ✓ |
| Security score trends | ✓ | ✓ | ✓ | ✓ |
| Domains monitored | 1 | 5 | 20 | Unlimited |
| Scan frequency | Weekly | Daily | Daily | Daily |
| Authenticated scanning | - | ✓ | ✓ | ✓ |
| Slack & Jira integrations | - | ✓ | ✓ | ✓ |
| Compliance posture (PCI/GDPR/ISO) | - | ✓ | ✓ | ✓ |
| White-label PDF reports | - | - | ✓ | ✓ |
| Priority support | - | - | ✓ | ✓ |
| Custom SLA / SSO | - | - | - | ✓ |
Custom volume pricing
Need more than 20 monitored domains, a custom scan schedule, or a tailored arrangement for your team? Contact us for Enterprise pricing.
Payment history & invoices
Your full payment history and downloadable PDF invoices are available under Account → Subscription & Billing → Payment history.