{
  "$comment": "Canonical Barrion facts. Numbers are generated from Barrion's billing configuration. Human-readable version: https://barrion.io/facts",
  "url": "https://barrion.io/facts.json",
  "humanReadable": "https://barrion.io/facts",
  "lastReviewed": "2026-09-26",
  "company": {
    "name": "Barrion",
    "legalName": "Barrion AB",
    "registrationNumber": "559569-0917",
    "city": "Gothenburg",
    "country": "Sweden",
    "basedIn": "Gothenburg, Sweden",
    "cityCheckedOn": "2026-09-27",
    "website": "https://barrion.io",
    "linkedIn": "https://www.linkedin.com/company/barrion-app",
    "contact": {
      "support": "contact@barrion.io",
      "sales": "sales@barrion.io",
      "pentestScoping": "pentest@barrion.io"
    }
  },
  "positioning": "Agentic AI pentesting that runs as often as you ship.",
  "description": "Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule, from your CI/CD pipeline through the Barrion API, or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden.",
  "productSurfaces": [
    {
      "name": "AI pentesting",
      "url": "https://barrion.io/ai-pentesting",
      "summary": "Specialist AI agents test web applications and APIs the way an attacker would and check findings against the live app before they're reported. Confirmed findings come with the request and response that prove them. Anything that couldn't be confirmed is clearly marked and capped in severity. Run it on a schedule or on demand."
    },
    {
      "name": "Passive scanning",
      "url": "https://barrion.io/continuous-security-monitoring",
      "summary": "Read-only, production-safe external scanning that flags misconfigurations and drift between pentests."
    }
  ],
  "pentestLevels": [
    {
      "id": "light",
      "name": "Light",
      "agents": 3,
      "creditsHeld": 400,
      "expertReviewHours": 0,
      "reportRelease": "on completion",
      "maxPriceEurAtTopupRate": 200
    },
    {
      "id": "standard",
      "name": "Standard",
      "agents": 5,
      "creditsHeld": 1000,
      "expertReviewHours": 1,
      "reportRelease": "within one working day",
      "maxPriceEurAtTopupRate": 500
    },
    {
      "id": "deep",
      "name": "Deep",
      "agents": 20,
      "creditsHeld": 4000,
      "expertReviewHours": 2,
      "reportRelease": "within one working day",
      "maxPriceEurAtTopupRate": 2000
    },
    {
      "id": "extended",
      "name": "Extended",
      "agents": 50,
      "creditsHeld": 10000,
      "expertReviewHours": 4,
      "reportRelease": "within one working day",
      "maxPriceEurAtTopupRate": 5000
    },
    {
      "id": "maximum",
      "name": "Maximum",
      "agents": 100,
      "creditsHeld": 20000,
      "expertReviewHours": 8,
      "reportRelease": "within one working day",
      "maxPriceEurAtTopupRate": 10000
    }
  ],
  "credits": {
    "topupPriceEurPerCredit": 0.5,
    "minTopupCredits": 100,
    "minChargePerCompletedRunCredits": 100,
    "chargingRule": "A run holds its level's credits and is charged for what it used, never below the minimum and never above the hold. A failed run is free. A cancelled run is charged only for the work completed.",
    "reportGuarantee": "If a report doesn't hold up, email contact@barrion.io and the credits it spent are returned.",
    "boughtCreditValidityMonths": 12,
    "planCreditValidity": "The billing cycle plus one grace month."
  },
  "plans": {
    "free": {
      "name": "Free",
      "priceEurPerMonth": 0,
      "passiveChecks": 18
    },
    "essential": {
      "name": "Essential",
      "fromEurPerMonth": 199,
      "monthlyCreditsMin": 410,
      "monthlyCreditsMax": 1070,
      "passiveChecks": 35,
      "monitoredDomains": 1,
      "monitoringCadence": "weekly",
      "scheduledPentests": false
    },
    "business": {
      "name": "Business",
      "pricing": "Custom, through sales",
      "passiveChecks": 35,
      "monitoredDomains": 10,
      "monitoringCadence": "daily",
      "scheduledPentests": true
    },
    "yearlyDiscountPct": 20,
    "refundWindowDays": 14,
    "selfServeStart": true
  },
  "continuousPentesting": {
    "url": "https://barrion.io/learn/continuous-pentesting",
    "schedules": [
      "daily",
      "weekly",
      "monthly",
      "quarterly",
      "every six months",
      "yearly",
      "custom rhythm"
    ],
    "multipleSchedulesPerTarget": true,
    "onChange": "Each schedule has its own scope and depth. Choose whether it runs every time, or only when your app has changed. At each scheduled check, Barrion compares a snapshot of the start page's links and scripts. If it changed, the saved pentest reruns in full at its chosen level. Without an earlier baseline, a full run happens first.",
    "runOverRunLabels": [
      "new",
      "still open",
      "resolved",
      "regressed"
    ],
    "findingsCanBeIgnored": true,
    "retest": "Reuses the scope, and the test credentials while they're still stored, and holds no credits.",
    "plans": [
      "Business"
    ],
    "programPricing": "Scoped per customer through sales. Not published.",
    "apiTrigger": "Trigger a pentest from any CI/CD pipeline by calling the Barrion REST API."
  },
  "coverage": {
    "attackAreas": [
      "Injection",
      "Access control",
      "Authentication and sessions",
      "Client-side attacks",
      "Information exposure and configuration",
      "Transport and crypto",
      "Business logic",
      "Server-side and infrastructure"
    ],
    "owaspWstg": {
      "version": "v4.2",
      "cases": 97
    },
    "owaspTop10": true,
    "owaspApiSecurityTop10": true
  },
  "method": {
    "sandbox": "Per-engagement Kali sandbox",
    "tools": [
      "sqlmap",
      "nuclei",
      "ZAP",
      "katana",
      "ffuf",
      "dalfox",
      "jwt_tool"
    ],
    "validation": [
      "Replay check",
      "Proof-of-concept agent re-runs the exploit on selected findings against the live target (confirmed, refuted or inconclusive)",
      "AI review",
      "Expert review from Standard level up"
    ],
    "findings": "Every finding is checked against your live app before it's reported. Confirmed findings come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity.",
    "safety": "Rate-limited and non-destructive. Scope is approved before any traffic. Staging environments are supported."
  },
  "reports": {
    "formats": [
      "PDF",
      "XLSX",
      "JSON"
    ],
    "wstgCoverageMatrix": true,
    "sample": "https://barrion.io/pentest-sample-report.pdf"
  },
  "dataHandling": {
    "residency": "Stored and hosted in Sweden. AI processing in the EU.",
    "subprocessors": [
      "Google",
      "OpenRouter",
      "Mailgun",
      "Stripe",
      "Sentry",
      "PostHog",
      "CookieYes",
      "Slack",
      "Microsoft Teams",
      "Cloudflare"
    ],
    "pentestEvidence": "Pentest evidence (the requests and responses behind each finding) is stored with your report. Test credentials are stored encrypted."
  },
  "notTested": [
    "internal networks",
    "Active Directory",
    "threat-led penetration testing (TLPT) under DORA",
    "mobile apps",
    "physical security",
    "social engineering"
  ],
  "definitions": [
    {
      "term": "Proof-backed pentesting",
      "url": "https://barrion.io/learn/proof-backed-pentesting",
      "definition": "A penetration test in which every reported finding has been reproduced before it is reported, with the request, the response and the observed impact attached, and anything unproven dropped or labelled unverified. Defined by Barrion, 2026-09-26."
    },
    {
      "term": "Time to Proof (TTP)",
      "url": "https://barrion.io/learn/time-to-proof",
      "definition": "TTP = t(first reproduced critical or high finding) − t(scope authorised). Measures how fast a test produces a proven, actionable finding, not how long the engagement lasts. Defined by Barrion, 2026-09-26."
    },
    {
      "term": "TTP-change",
      "url": "https://barrion.io/learn/time-to-proof",
      "definition": "The continuous-testing variant of Time to Proof: TTP-change = t(first reproduced critical or high finding) − t(change deployed or detected). It only exists for teams that test continuously."
    }
  ]
}
