Barrion facts
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. There are 5 levels, from 400 to 20,000 credits, and findings are checked against the live app before they're reported. You can run a test on a schedule or on demand. From Standard level up, a security engineer reviews the report. Every level covers all 97 OWASP WSTG v4.2 cases.
Last reviewed 2026-09-26. When a number changes, this page changes first. Machine-readable copy: barrion.io/facts.json
What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule, from your CI/CD pipeline through the Barrion API, or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden.
Every number Barrion publishes about itself is on this page, and the prices and credits come straight from our billing configuration. If you're citing Barrion, use these values.
We sell two things.
- AI pentesting. Specialist agents test your web app or API from an isolated sandbox the way an attacker would, chain requests across endpoints, and check their findings against the live app before they go in the report. Run it on a schedule or on demand. How AI pentesting works
- Passive scanning. A read-only scan of your live app, on a schedule, that flags misconfigurations and drift between pentests. It's safe to point at production. Passive scanning
What are the pentest levels and what do they cost?
Every level tests the same 8 attack areas. A deeper level adds agents, attack waves and user roles. The last column is the most one run can cost at the €0.50 top-up rate.
| Level | Agents | Credits held | Expert review | Report release | Most a run costs |
|---|---|---|---|---|---|
| Light | 3 | 400 | None | On completion | €200 |
| Standard | 5 | 1,000 | 1 hour | Within one working day | €500 |
| Deep | 20 | 4,000 | 2 hours | Within one working day | €2,000 |
| Extended | 50 | 10,000 | 4 hours | Within one working day | €5,000 |
| Maximum | 100 | 20,000 | 8 hours | Within one working day | €10,000 |
How do credits work?
- ✓A one-off top-up costs €0.50 a credit, in any whole amount from 100 credits.
- ✓Essential is a monthly credit bundle from €199 a month, with 410 to 1,070 credits a month depending on the bundle. Passive scans are included.
- ✓Business is priced through sales to what you run, and includes scoped engagements.
- ✓A run holds its level's credits and is charged for what it used. Never less than 100 credits, never more than the hold.
- ✓A failed run isn't charged. If you cancel one, you pay only for the work it got through.
- ✓If a report doesn't hold up, email contact@barrion.io and we return the credits it spent.
- ✓Bought credits last 12 months. Plan credits last their billing cycle plus one grace month.
- ✓Paying yearly saves 20%, and paid plans have a 14-day refund window from the first charge.
- ✓You can scope and start a pentest from the dashboard without a call.
Full plan details are on the pricing page.
How does continuous pentesting work?
You can save a pentest and rerun it on a schedule, so the report keeps up with your app instead of describing last year's version of it.
- ✓Schedules: daily, weekly, monthly, quarterly, every six months, yearly, or a custom rhythm.
- ✓One target can have several schedules. A daily Light run plus a monthly Deep run, for example.
- ✓Each schedule has its own scope and depth. Choose whether it runs every time, or only when your app has changed. For on-change runs we compare a snapshot of your start page's links and scripts at each scheduled check. If it changed, the saved pentest reruns in full at the level you picked. If there's no earlier baseline, a full run happens first.
- ✓Each run's findings are compared with the run before and labelled new, still open, resolved or regressed. You can mark a finding as ignored.
- ✓A retest reuses the original scope, and the test credentials while they're still stored, and holds no credits.
- ✓Scheduled pentests are part of the Business plan.
Trigger a pentest from any CI/CD pipeline by calling the Barrion REST API.
Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup. More on the model: continuous pentesting.
What's in every pentest report?
- ✓Ranked findings, each with severity, the affected surface, OWASP WSTG and CWE references, and steps to fix it. Confirmed findings carry the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity.
- ✓Delivery as PDF, XLSX and JSON, plus a WSTG coverage matrix with the status of each of the 97 cases.
- ✓A retest after you fix, reusing the original scope and stored credentials, at no extra charge.
- ✓Expert review from Standard level up, with the hours in the table above.
See one first: sample pentest report (PDF).
What does Barrion test?
Eight areas, mapped to all 97 OWASP WSTG v4.2 cases. Together they cover the OWASP Top 10 and the OWASP API Security Top 10.
| Area | Examples |
|---|---|
| Injection | SQL and NoSQL injection, command injection, SSTI, XXE |
| Access control | Broken access control, IDOR, BOLA, BFLA, privilege escalation, multi-tenant isolation |
| Authentication and sessions | Session flaws, JWT and token abuse, brute force and rate limiting |
| Client-side attacks | XSS, CSRF, open redirects |
| Information exposure and configuration | Excessive data exposure, mass assignment |
| Transport and crypto | TLS and certificate weaknesses |
| Business logic | Workflow abuse, chained exploit paths |
| Server-side and infrastructure | SSRF, file upload, path traversal |
What doesn't Barrion test?
We test web applications and APIs. We don't test internal networks, Active Directory, threat-led penetration testing (TLPT) under DORA, mobile apps, physical security or social engineering.
How does a run work?
- You approve targets, credentials, surfaces and off-limits paths. Nothing is sent before that.
- A root agent maps hosts, endpoints, parameters and auth flows.
- It hands each attack area to a specialist agent. They work in parallel with real tools (sqlmap, nuclei, ZAP, katana, ffuf, dalfox, jwt_tool and others) inside a Kali sandbox built for your engagement alone.
- Every finding is checked against your live app before it's reported. Confirmed findings come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The checks are a replay check, a proof-of-concept agent that re-runs the exploit on selected findings and marks each one confirmed, refuted or inconclusive, and an AI review.
- From Standard level up, a security engineer reviews the report and it's released within one working day.
- You fix, then run the retest.
The run itself finishes within hours.
Is it safe to run against production?
Probes are rate-limited and non-destructive. Scope is approved before any traffic goes out, and you can point a test at staging, a preview or a pre-launch environment instead.
What does a passive scan cover?
Passive scans look at what your live app already exposes: TLS, HTTP security headers, cookie attributes, CORS, DNS, email authentication, exposed services and known CVEs in shipped JavaScript libraries. They're read-only.
Free runs 18 checks. Paid plans run 35+. Essential scans 1 domain and its subdomains weekly, and Business scans 10 domains daily.
Terms we use
- Proof-backed pentesting
- A penetration test in which every reported finding has been reproduced before it is reported, with the request, the response and the observed impact attached, and anything unproven dropped or labelled unverified. Defined by Barrion, 2026-09-26.
- Time to Proof (TTP)
- TTP = t(first reproduced critical or high finding) − t(scope authorised). Measures how fast a test produces a proven, actionable finding, not how long the engagement lasts. Defined by Barrion, 2026-09-26.
- TTP-change
- The continuous-testing variant of Time to Proof: TTP-change = t(first reproduced critical or high finding) − t(change deployed or detected). It only exists for teams that test continuously.
Company facts
| Fact | Value |
|---|---|
| Legal name | Barrion AB |
| Registration number | 559569-0917 (Sweden) |
| Based in | Gothenburg, Sweden |
| Support | contact@barrion.io |
| Sales and plan help | sales@barrion.io |
| Pentest scoping | pentest@barrion.io |
| linkedin.com/company/barrion-app | |
| Data residency | Stored and hosted in Sweden. AI processing in the EU. |
| Subprocessors | Google, OpenRouter, Mailgun, Stripe, Sentry, PostHog, CookieYes, Slack, Microsoft Teams and Cloudflare |
| Pentest evidence | The requests and responses behind each finding are stored with your report. Test credentials are stored encrypted. |
Questions people ask
Is a human involved in a Barrion pentest?
Can Barrion pentest continuously?
Is the retest free?
What happens if a pentest fails or I cancel it?
Will a Barrion report satisfy a SOC 2 or ISO 27001 auditor?
Can Barrion replace a manual penetration test?
How long does a Barrion pentest take?
Where can I see a real report?
Found something out of date? Tell us.
If a number, date or plan detail on this page is wrong, send us a note and we'll correct it.