01 · WHY PAYG
Not every security job is the same size.
A small unauthenticated marketing site should not carry the same estimated cost as an authenticated application audit with custom directives, repository context, exploit validation, follow-up reasoning, and a compliance-ready report.
PAYG lets teams start smaller, scale when they have more to test, and pay for the depth they actually use. One platform fee keeps the account active; security work draws from the usage wallet as BugBunny completes it.
02 · HOW BILLING WORKS
Three parts. No mystery package.
Platform
A $100 monthly platform fee keeps the BugBunny audit workflow available to your team.
Wallet
Usage draws from a wallet. New accounts receive $100 in welcome credit to begin scanning.
Work
Each scan draws what its agents, models, browsers, validation, and reporting actually require.
If the wallet gets too low during a scan, BugBunny can pause the work and resume after a top-up instead of making your team start again.
03 · COMPLETED SCAN COSTS
What the work looked like in June.
We examined completed June 2026 scans and excluded stopped, failed, and sub-$0.10 early-exit runs. The result is a planning view of substantive customer work.

25th percentile
$7.22Median
$17.39Average
$32.1175th percentile
$45.80THE PRACTICAL NUMBERThe median completed scan cost $17.39. The average was $32.11 because deeper audits pull the mean upward.
04 · WHAT CHANGES THE WORK
Similar URLs can require very different audits.
BugBunny measures the work needed to test the target—not a generic page view. Exploration, reasoning, validation, and reporting change with the environment.
- 01
Target size, route count, and reachable functionality
- 02
Authentication, account setup, and role coverage
- 03
Repository or dependency context attached to the audit
- 04
Custom directives, depth settings, and requested follow-up work
- 05
Exploit validation, reproduction effort, and report generation
05 · WHAT TO EXPECT
A planning signal, not a fixed quote.
Use the June distribution as a rough expectation. A typical completed scan landed near the median, while authenticated products, larger scopes, repository-backed audits, and deeper validation cost more. The estimate follows the depth of the work.
READY FOR REAL WORK