// Pricing
Priced like an audit.
Not a toy.
Every scan is a real probe in an isolated box, ownership-proven and read-only by default. Your first scan is free; if it finds an exposure, activate a recurring plan for on-demand re-scanning.
Plans
Pro
$2,388/yr billed annually · or $299/mo month-to-month
- 3 apps
- Unlimited on-demand scans (fair-use rate limits apply)
- Full six-vector probe suite: broken reads, missing RLS & Firestore rules, exposed storage, leaked keys, auth misconfig
- Exact one-line fixes + reproduction
- Re-scan to verify the fix
- Email support
Agency
$5,988/yr billed annually · or $649/mo month-to-month
- 20 client apps
- Unlimited on-demand scans (fair-use rate limits apply)
- Everything in Pro
Enterprise
For platforms & portfolios
- Unlimited apps
- Everything in Agency
- SSO, audit logs, SLA
- CI/CD & API access
- Dedicated support
// annual billing is the best rate · month-to-month has no lock-in · cancel anytime
Your first scan is free. If it finds an exposure, checkout shows the full amount due and starts a recurring monthly or annual subscription. If it is clean, no subscription starts.
// Compare
Every plan, side by side.
| Feature | Pro | Agency | Enterprise |
|---|---|---|---|
| Apps | 3 | 20 | Unlimited |
| On-demand scanning | Included | Included | Included |
| Probe vectors | All six | All six | All six |
| Exact fixes + reproduction | Included | Included | Included |
| Re-scan to verify | Included | Included | Included |
| SSO · audit logs · SLA | Not included | Not included | Included |
| CI/CD & API access | Not included | Not included | Included |
| Support | Priority | Dedicated |
// FAQ
Straight answers.
Do you need access to my backend?
You connect via OAuth so we can confirm you own the Firebase or Supabase project. Scans are read-only by default and only ever run against apps you own.
What counts as one app?
One backend project: one Firebase project or one Supabase project.
Is there a free scan, and how does the charge work?
Your first scan is free: a real probe in an isolated box on a backend you've verified you own. If it reports an exposure, you can activate a recurring plan. Checkout shows the exact annual or monthly charge and renewal interval. If the free scan is clean, no subscription starts.
What if you don't find anything?
No subscription starts and your card is not charged. You keep the clean report from the free scan.
Can I cancel?
Yes. Month-to-month has no lock-in, so you can cancel anytime. Annual plans run for the year and renew yearly.
How is this different from a scanner?
Scanners guess from static rules and flood you with false positives. DenyFirst proves the issue by actually reaching the data as an anonymous or signed-in user, then hands you the exact rule to change.
Ship it locked.
Scan my app// read-only by default · proof before packets · your data never leaves the box