// Pricing
Priced like an audit.
Not a toy.
Every scan is a real probe in an isolated box — ownership-proven, read-only by default. No free tier, no noise: just the access-control issues that matter, with the exact fix.
Plans
Pro
$2,388/yr billed annually · or $299/mo month-to-month
- 3 apps
- Continuous scanning (fair-use rate limits apply)
- Full six-vector probe suite — broken reads, missing RLS & Firestore rules, exposed storage, leaked keys, auth misconfig
- Exact one-line fixes + reproduction
- Re-scan to verify the fix
- Email support
Agency
$5,988/yr billed annually · or $649/mo month-to-month
- 20 client apps
- Continuous scanning (fair-use rate limits apply)
- Everything in Pro
Enterprise
For platforms & portfolios
- Unlimited apps
- Everything in Agency
- SSO, audit logs, SLA
- CI/CD & API access
- Dedicated support
// annual billing is the best rate · month-to-month has no lock-in · cancel anytime
No leak, full refund on your first month. If your first scan of a backend you own turns up nothing serious, we refund it — in full.
// Compare
Every plan, side by side.
| Feature | Pro | Agency | Enterprise |
|---|---|---|---|
| Apps | 3 | 20 | Unlimited |
| Continuous scanning | Included | Included | Included |
| Probe vectors | All six | All six | All six |
| Exact fixes + reproduction | Included | Included | Included |
| Re-scan to verify | Included | Included | Included |
| SSO · audit logs · SLA | Not included | Not included | Included |
| CI/CD & API access | Not included | Not included | Included |
| Support | Priority | Dedicated |
// FAQ
Straight answers.
Do you need access to my backend?
You connect via OAuth so we can confirm you own the Firebase or Supabase project. Scans are read-only by default and only ever run against apps you own.
What counts as one app?
One backend project — one Firebase project or one Supabase project.
Is there a free trial?
No free tier — every scan runs a real probe in an isolated box, which isn't free to run. Annual billing gets the best rate; month-to-month is available if you'd rather not commit.
What if you don't find anything?
Then you shouldn't pay. If your first scan of a backend you've verified you own surfaces no high or critical issue, we refund your first month in full and close it out. A read that's public by design doesn't count as a finding — we only keep your money when there's something real to fix.
Can I cancel?
Yes. Month-to-month has no lock-in, so you can cancel anytime. Annual plans run for the year and renew yearly.
How is this different from a scanner?
Scanners guess from static rules and flood you with false positives. DenyFirst proves the issue by actually reaching the data as an anonymous or signed-in user, then hands you the exact rule to change.
Ship it locked.
Scan my app// read-only by default · proof before packets · your data never leaves the box