Back to field notes

PRODUCT UPDATE · PAY AS YOU GO

Security scanning,priced by the work.

A clear platform fee. A flexible usage wallet. An estimated scan cost that reflects the depth of the security work—not a generic package.

01$100/mo

Platform fee

02$100

Welcome credit

03$17.39

Median completed scan

048,958

June scans sampled

Not every security job is the same size.

A small unauthenticated marketing site should not carry the same estimated cost as an authenticated application audit with custom directives, repository context, exploit validation, follow-up reasoning, and a compliance-ready report.

PAYG lets teams start smaller, scale when they have more to test, and pay for the depth they actually use. One platform fee keeps the account active; security work draws from the usage wallet as BugBunny completes it.

Three parts. No mystery package.

01

Platform

A $100 monthly platform fee keeps the BugBunny audit workflow available to your team.

02

Wallet

Usage draws from a wallet. New accounts receive $100 in welcome credit to begin scanning.

03

Work

Each scan draws what its agents, models, browsers, validation, and reporting actually require.

If the wallet gets too low during a scan, BugBunny can pause the work and resume after a top-up instead of making your team start again.

What the work looked like in June.

We examined completed June 2026 scans and excluded stopped, failed, and sub-$0.10 early-exit runs. The result is a planning view of substantive customer work.

JUNE 2026 · COMPLETED SCANSEstimated cost distribution
8,958 SCANS
BugBunny June 2026 scan cost distribution with markers for the 25th percentile, median, average, and 75th percentile.
Completed scans only. Stopped, failed, and sub-$0.10 early-exit runs are excluded. The right tail reflects a smaller number of substantially deeper audits.
01

25th percentile

$7.22
02

Median

$17.39
03

Average

$32.11
04

75th percentile

$45.80
THE PRACTICAL NUMBER

The median completed scan cost $17.39. The average was $32.11 because deeper audits pull the mean upward.

Similar URLs can require very different audits.

BugBunny measures the work needed to test the target—not a generic page view. Exploration, reasoning, validation, and reporting change with the environment.

  1. 01

    Target size, route count, and reachable functionality

  2. 02

    Authentication, account setup, and role coverage

  3. 03

    Repository or dependency context attached to the audit

  4. 04

    Custom directives, depth settings, and requested follow-up work

  5. 05

    Exploit validation, reproduction effort, and report generation

A planning signal, not a fixed quote.

Use the June distribution as a rough expectation. A typical completed scan landed near the median, while authenticated products, larger scopes, repository-backed audits, and deeper validation cost more. The estimate follows the depth of the work.

READY FOR REAL WORK

Put BugBunny on the next security job.

Start a security audit
Pay-As-You-Go Security Scanning at BugBunny | BugBunny.ai