Pricing

Flat per-company tiers. No per-asset bill shock.

Per-asset pricing is the #1 SMB complaint about Qualys, Tenable and Rapid7. Perimeter charges a flat price with generous caps, so your bill is predictable. Annual billing saves 15%.

Free

$0

DIY / single small org

  • External ASM for 1 root domain
  • Internal scan, 1 agent / 25 assets
  • Nuclei + Trivy + OpenVAS engines
  • Exploit-first ranking (EPSS + KEV over CVSS)
  • False-positive suppression + FP feedback loop
  • Signed per-finding evidence records
  • Email alerts, CSV/JSON export · 1 user

Starter

$142/mo

Small org, light surface

  • 3 domains, 100 assets
  • Weekly continuous scans + drift alerts
  • Slack / Teams / webhook alerts
  • Remediation + suppression workflow
  • PDF reports · cert-expiry monitoring
  • 3 users · basic RBAC

Pro

$285/mo

Growing, compliance-driven SMB

  • 10 domains, 500 assets · daily scans
  • Container / IaC / SBOM scanning
  • Scheduled daily EPSS/KEV refresh + drift alerts
  • Signed evidence packs · PCI / HIPAA / SOC 2 reports
  • Sightline RA + Bastion mapping
  • Jira / ServiceNow / GitHub ticketing · 10 users

MSP

$399/mo

+ ~$8 / managed client

  • Per-client workspaces + isolation
  • Bulk reporting & audit binders
  • White-label reports
  • Cross-client dashboards
  • Unlimited internal users
  • BYO custom templates
Us vs the named leaders

The full triad — for less than they charge for half of it

Every price below is the vendor's own published or widely-cited figure. The pattern is consistent: the SMB-friendly tools (Intruder, Detectify) leave out internal authenticated scanning or container/SBOM, and the enterprise tools (Nessus, Qualys, Rapid7) charge per-asset or per-scanner and sell ASM, prioritization and compliance as separate line items. Perimeter ships all of it in one flat per-company price.

Capability Perimeter Intruder.io Nessus (Tenable) Qualys VMDR Rapid7 InsightVM Detectify
External attack-surface managementYesYesExpert tier onlyAdd-onSeparate productYes
Internal authenticated network scanFree tier$499 Pro gateYesYes (appliance)YesNo
Container / SBOM / dependency CVEsIncludedNoNoSeparate moduleSeparate moduleNo
IaC misconfiguration scanningIncludedNoNoAdd-onAdd-onNo
Exploit-first ranking (EPSS + KEV over CVSS)FreeYesVPR (Pro+)TruRisk (paid)YesPartial
Transparent FP suppression + reasonsYesNoNoNoNoNo
FP feedback loop (remembered across rescans)YesNoNoManual muteManual muteNo
Multi-engine corroborationYesNoNoNoNoNo
Findings = signed compliance evidencePCI/HIPAA/SOC2/ISO/CMMCThinReports onlySeparate moduleReports onlyNo
Cross-product evidence graphSightline + BastionNoNoNoNoNo
No scanner-appliance feeRuns on Lookout agentSaaSPer scanner~$8–9k/yr eachSaaSSaaS
No per-asset bill / asset minimumFlat + capsPer-targetPer scanner~$199–250/asset≥512-asset minPer-subdomain
Genuinely useful free tierFull engine, signed evidenceTrial onlyNoNoNoNo
Entry price$0 / $142$149/mo$4,390/yr~$199–250/asset~$23/asset (≥512)~€82/mo
Full-triad price$285/mo$499/mo$6,390/yr*$5-figure + modules$5-figure + ASM~€275/mo (ext only)
Yes = included Partial = gated, paid add-on, or higher tier No = not offered * Nessus Expert adds basic EASM but still no internal+container+compliance in one SKU.

Sources: Intruder pricing, Tenable buy, Qualys pricing (CyCognito), Rapid7 InsightVM pricing, Detectify pricing. Figures as published / widely cited at time of writing; we update as vendors change. See the full breakdowns: vs Intruder · vs Tenable / Nessus · vs Qualys.

Comparison · Perimeter vs Intruder.io

The Intruder.io alternative with internal scanning on the free tier

Intruder has the cleanest SMB UX in the category — and we respect it. But it gates internal authenticated scanning to its $499/mo Pro tier, has no container or SBOM scanning, and its compliance-evidence mapping is thin. Perimeter ships the full triad and native control mapping starting at $0.

CapabilityPerimeterIntruder.io
External attack-surface managementYesYes
Internal authenticated scanningFree tier (Lookout agent)Gated to $499 Pro
Container image scanningYes (Trivy)No
SBOM / dependency CVE scanningYes (Trivy)No
IaC misconfiguration scanningYes (Trivy)No
Exploit-first ranking (EPSS + KEV over CVSS)FreeYes
FP suppression + reasons + feedback loopYesNo
Subdomain-takeover detectionYesYes
Emerging-threat / rapid-response runsYes (free tier)Yes
Findings = signed compliance evidencePCI/HIPAA/SOC2/ISO/CMMCThin
Cross-product evidence graphSightline + Bastion + WardNo (single product)
No scanner-appliance feeRuns on Lookout agentSaaS
Starting price$0$149/mo

Intruder pricing and feature gating per intruder.io/pricing at time of writing. We update comparisons as vendors change.

Where Intruder is still a fine choice

If you only need clean external scanning and never want to deploy an agent, Intruder's onboarding is excellent. Perimeter's edge shows up the moment you need internal authenticated scans, container/SBOM coverage, or you have a compliance auditor asking for control-level evidence — that's where the $499 gate and the missing scan types bite.

More, for less — concretely

Internal scanning without the gate

Intruder reserves internal authenticated scanning for its $499/mo Pro plan. Perimeter includes it on the free tier via the Lookout agent.

vs Intruder: $499/mo → $0

Container + SBOM, not a separate SKU

Intruder, Nessus and Detectify don't scan container images or dependency/SBOM CVEs at all; Qualys and Rapid7 sell them as extra modules. Perimeter bundles Trivy in Pro.

vs Qualys/Rapid7: +modules → included

No per-asset bill shock

Qualys runs ~$199–250 per asset/yr plus ~$8–9k scanner appliances; Rapid7 forces a ≥512-asset minimum. Perimeter is flat per-company with generous caps.

vs Qualys: ~$199–250/asset → flat

Signed evidence built in

Where the enterprise tools sell compliance reporting as another module and the SMB tools skip it, every Perimeter finding auto-maps to PCI / HIPAA / SOC 2 / ISO / CMMC and exports as an HMAC-signed evidence record.

vs all: extra module → native + signed

De-noised, not "mostly false positives"

The common complaint about Qualys and Nessus is the false-positive flood. Perimeter ranks exploit-first and suppresses likely FPs with a reason — and remembers when you mark one, free on every tier.

vs incumbents: ~30% FP noise → suppressed

What you don't pay for

No $8–9k/yr scanner appliance fees (Qualys) — internal scans run on your existing Lookout agent box. No ≥512-asset minimum commit (Rapid7). No paywall on the exploit-prioritization layer (Tenable VPR / Qualys TruRisk). And AI remediation guidance is bring-your-own-key — we never charge you for inference.