Facts

Barrion facts

Barrion runs continuous, agentic AI penetration tests of web applications and APIs. There are 5 levels, from 400 to 20,000 credits, and findings are checked against the live app before they're reported. You can run a test on a schedule or on demand. From Standard level up, a security engineer reviews the report. Every level covers all 97 OWASP WSTG v4.2 cases.

Last reviewed 2026-09-26. When a number changes, this page changes first. Machine-readable copy: barrion.io/facts.json

Overview

What is Barrion?

Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule, from your CI/CD pipeline through the Barrion API, or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden.

Every number Barrion publishes about itself is on this page, and the prices and credits come straight from our billing configuration. If you're citing Barrion, use these values.

We sell two things.

  1. AI pentesting. Specialist agents test your web app or API from an isolated sandbox the way an attacker would, chain requests across endpoints, and check their findings against the live app before they go in the report. Run it on a schedule or on demand. How AI pentesting works
  2. Passive scanning. A read-only scan of your live app, on a schedule, that flags misconfigurations and drift between pentests. It's safe to point at production. Passive scanning
Levels

What are the pentest levels and what do they cost?

Every level tests the same 8 attack areas. A deeper level adds agents, attack waves and user roles. The last column is the most one run can cost at the €0.50 top-up rate.

LevelAgentsCredits heldExpert reviewReport releaseMost a run costs
Light3400NoneOn completion€200
Standard51,0001 hourWithin one working day€500
Deep204,0002 hoursWithin one working day€2,000
Extended5010,0004 hoursWithin one working day€5,000
Maximum10020,0008 hoursWithin one working day€10,000
Credits

How do credits work?

  • ✓A one-off top-up costs €0.50 a credit, in any whole amount from 100 credits.
  • ✓Essential is a monthly credit bundle from €199 a month, with 410 to 1,070 credits a month depending on the bundle. Passive scans are included.
  • ✓Business is priced through sales to what you run, and includes scoped engagements.
  • ✓A run holds its level's credits and is charged for what it used. Never less than 100 credits, never more than the hold.
  • ✓A failed run isn't charged. If you cancel one, you pay only for the work it got through.
  • ✓If a report doesn't hold up, email contact@barrion.io and we return the credits it spent.
  • ✓Bought credits last 12 months. Plan credits last their billing cycle plus one grace month.
  • ✓Paying yearly saves 20%, and paid plans have a 14-day refund window from the first charge.
  • ✓You can scope and start a pentest from the dashboard without a call.

Full plan details are on the pricing page.

Continuous

How does continuous pentesting work?

You can save a pentest and rerun it on a schedule, so the report keeps up with your app instead of describing last year's version of it.

  • ✓Schedules: daily, weekly, monthly, quarterly, every six months, yearly, or a custom rhythm.
  • ✓One target can have several schedules. A daily Light run plus a monthly Deep run, for example.
  • ✓Each schedule has its own scope and depth. Choose whether it runs every time, or only when your app has changed. For on-change runs we compare a snapshot of your start page's links and scripts at each scheduled check. If it changed, the saved pentest reruns in full at the level you picked. If there's no earlier baseline, a full run happens first.
  • ✓Each run's findings are compared with the run before and labelled new, still open, resolved or regressed. You can mark a finding as ignored.
  • ✓A retest reuses the original scope, and the test credentials while they're still stored, and holds no credits.
  • ✓Scheduled pentests are part of the Business plan.

Trigger a pentest from any CI/CD pipeline by calling the Barrion REST API.

Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup. More on the model: continuous pentesting.

Reports

What's in every pentest report?

  • ✓Ranked findings, each with severity, the affected surface, OWASP WSTG and CWE references, and steps to fix it. Confirmed findings carry the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity.
  • ✓Delivery as PDF, XLSX and JSON, plus a WSTG coverage matrix with the status of each of the 97 cases.
  • ✓A retest after you fix, reusing the original scope and stored credentials, at no extra charge.
  • ✓Expert review from Standard level up, with the hours in the table above.

See one first: sample pentest report (PDF).

Coverage

What does Barrion test?

Eight areas, mapped to all 97 OWASP WSTG v4.2 cases. Together they cover the OWASP Top 10 and the OWASP API Security Top 10.

AreaExamples
InjectionSQL and NoSQL injection, command injection, SSTI, XXE
Access controlBroken access control, IDOR, BOLA, BFLA, privilege escalation, multi-tenant isolation
Authentication and sessionsSession flaws, JWT and token abuse, brute force and rate limiting
Client-side attacksXSS, CSRF, open redirects
Information exposure and configurationExcessive data exposure, mass assignment
Transport and cryptoTLS and certificate weaknesses
Business logicWorkflow abuse, chained exploit paths
Server-side and infrastructureSSRF, file upload, path traversal
Scope

What doesn't Barrion test?

We test web applications and APIs. We don't test internal networks, Active Directory, threat-led penetration testing (TLPT) under DORA, mobile apps, physical security or social engineering.

Method

How does a run work?

  1. You approve targets, credentials, surfaces and off-limits paths. Nothing is sent before that.
  2. A root agent maps hosts, endpoints, parameters and auth flows.
  3. It hands each attack area to a specialist agent. They work in parallel with real tools (sqlmap, nuclei, ZAP, katana, ffuf, dalfox, jwt_tool and others) inside a Kali sandbox built for your engagement alone.
  4. Every finding is checked against your live app before it's reported. Confirmed findings come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The checks are a replay check, a proof-of-concept agent that re-runs the exploit on selected findings and marks each one confirmed, refuted or inconclusive, and an AI review.
  5. From Standard level up, a security engineer reviews the report and it's released within one working day.
  6. You fix, then run the retest.

The run itself finishes within hours.

Safety

Is it safe to run against production?

Probes are rate-limited and non-destructive. Scope is approved before any traffic goes out, and you can point a test at staging, a preview or a pre-launch environment instead.

Passive scanning

What does a passive scan cover?

Passive scans look at what your live app already exposes: TLS, HTTP security headers, cookie attributes, CORS, DNS, email authentication, exposed services and known CVEs in shipped JavaScript libraries. They're read-only.

Free runs 18 checks. Paid plans run 35+. Essential scans 1 domain and its subdomains weekly, and Business scans 10 domains daily.

Definitions

Terms we use

Proof-backed pentesting
A penetration test in which every reported finding has been reproduced before it is reported, with the request, the response and the observed impact attached, and anything unproven dropped or labelled unverified. Defined by Barrion, 2026-09-26.
Time to Proof (TTP)
TTP = t(first reproduced critical or high finding) − t(scope authorised). Measures how fast a test produces a proven, actionable finding, not how long the engagement lasts. Defined by Barrion, 2026-09-26.
TTP-change
The continuous-testing variant of Time to Proof: TTP-change = t(first reproduced critical or high finding) − t(change deployed or detected). It only exists for teams that test continuously.
Company

Company facts

FactValue
Legal nameBarrion AB
Registration number559569-0917 (Sweden)
Based inGothenburg, Sweden
Supportcontact@barrion.io
Sales and plan helpsales@barrion.io
Pentest scopingpentest@barrion.io
LinkedInlinkedin.com/company/barrion-app
Data residencyStored and hosted in Sweden. AI processing in the EU.
SubprocessorsGoogle, OpenRouter, Mailgun, Stripe, Sentry, PostHog, CookieYes, Slack, Microsoft Teams and Cloudflare
Pentest evidenceThe requests and responses behind each finding are stored with your report. Test credentials are stored encrypted.
FAQ

Questions people ask

Is a human involved in a Barrion pentest?
Yes, from Standard level up. The agents do the testing. At Standard, Deep, Extended and Maximum, a security engineer reviews the report before it's released, with 1, 2, 4 or 8 hours of review. A Light report is released as soon as the run finishes, without review.
Can Barrion pentest continuously?
Yes. Save a pentest and put it on a schedule, from daily to yearly or a custom rhythm, and choose whether each scheduled run goes ahead every time or only when your app has changed. Each run labels its findings new, still open, resolved or regressed against the run before. Scheduled pentests are part of the Business plan.
Is the retest free?
Yes. After you ship fixes, you rerun the same pentest as a retest. It reuses the original scope, and the test credentials while they're still stored, checks each finding again and marks it fixed, not fixed or inconclusive. A retest holds no credits and there's no separate charge.
What happens if a pentest fails or I cancel it?
A failed run isn't charged, and its whole hold goes back to your balance. A cancelled run is charged only for the work it got through, with no minimum. A finished run is charged for what it used, with a 100 credit minimum.
Will a Barrion report satisfy a SOC 2 or ISO 27001 auditor?
The report produces evidence that supports an audit: scope, a method mapped to OWASP WSTG, findings with proof and remediation, and retest status. A security engineer reviews the report from Standard up and signs it off from Deep up. Whether it's accepted is the auditor's call and depends on your scope. Barrion doesn't guarantee compliance with any framework.
Can Barrion replace a manual penetration test?
It covers the OWASP Top 10, the OWASP API Security Top 10 and all 97 WSTG cases with proof attached to confirmed findings, and a security engineer reviews the report from Standard up. Deep business-logic judgement and bespoke manual work still belong to people. A sensible setup is continuous AI pentesting as the ongoing layer, plus a periodic manual engagement for the paths that need a human.
How long does a Barrion pentest take?
The run itself finishes within hours. From Standard level up, a security engineer reviews the report and it's released within one working day. A Light report is released on completion.
Where can I see a real report?
There's a sample at barrion.io/pentest-sample-report.pdf. It shows ranked findings, the request and response behind each confirmed one, the affected surface, WSTG and CWE references, remediation steps and the full 97-case coverage matrix, in the same PDF format every customer gets.

Found something out of date? Tell us.

If a number, date or plan detail on this page is wrong, send us a note and we'll correct it.