ImmuniWeb
Swiss application security platform pairing proprietary AI with CREST-accredited human testers. It runs web, API and mobile penetration tests and scans, maps external attack surface, watches the dark web and flags compliance gaps across roughly thirty regulations.
What is ImmuniWeb?
ImmuniWeb is the application security platform of ImmuniWeb SA, a Swiss company headquartered on Quai de l'Ile in Geneva with further offices in London, Washington D.C. and Dubai. Its pitch is summed up on the homepage as human-expert application security at the speed of AI: proprietary models, more than fifty of them according to the vendor, handle the volume, while accredited testers are kept for the work that genuinely needs a person. That approach earned its first international recognition in 2018 at the SC Awards Europe, in the machine learning and AI category.
Six products sit on the platform. Discovery covers continuous threat exposure management, attack surface discovery, dark web monitoring, threat intelligence and third-party risk. Neuron and Neuron Mobile handle premium scanning of web, API and mobile targets. On-Demand and MobileSuite deliver full penetration tests, from a one-day Express Pro engagement up to ten days of manual testing at OWASP ASVS Level 3. Continuous merges scanning and pentesting into a round-the-clock service. Together they are marketed across twenty-four use cases, from API penetration testing to phishing website takedown.
What sets the commercial terms apart is the guarantee structure. Neuron and On-Demand carry a contractual zero false-positive SLA backed by a money-back guarantee for a single false positive, and On-Demand adds a delivery-speed guarantee. Reports arrive as HTML, PDF, JSON, XML or CSV, with CVSSv4, EPSSv4 and SSVCv2 scoring, MITRE ATT&CK mapping and step-by-step reproduction notes. Thirty-five named integrations connect the results to CI/CD, ticketing, WAF and SSO tooling, and an API key generated in the Portal exposes project data as JSON. Expert assistance runs 24/7, claimed in thirty languages.
A free Community Edition offers seven open tests covering SSL, email, website security and privacy, mobile apps, dark web exposure and an overall CyberScore rating, with a counter on the site past 485 million tests. ImmuniWeb SA is CREST accredited and ISO 9001 and ISO 27001 certified, reports more than a thousand enterprise customers across over fifty countries, and has contributed to the Verizon Data Breach Investigations Report since 2025.
What it does
- Run AI-assisted penetration tests on web applications, APIs and mobile apps, reviewed by human experts
- Scan web, API and mobile assets continuously against OWASP Top 10, API, LLM and Agentic lists plus MITRE CWE Top 25
- Discover and classify the external attack surface, including cloud, SaaS, shadow IT and abandoned assets
- Monitor the dark web for stolen credentials, leaked data, compromised machines and fake social accounts
- Detect phishing sites, typosquatted domains and trademark abuse, then have the fraudulent sites taken down
- Assess third-party and supplier exposure through the dedicated risk management package
- Measure technical compliance against roughly thirty regulations and surface the gaps
When to use ImmuniWeb / When not to
A quick filter to help you decide if ImmuniWeb is the right fit.
When to use ImmuniWeb
- CISOs and heads of security who need audit-ready penetration test reports without running an in-house red team
- Application security engineers and internal pentesters looking to industrialise recurring web, API and mobile testing
- DevSecOps and platform teams wiring security gates into CI/CD, ticketing, WAF and SIEM pipelines
- Compliance and GRC officers who must evidence technical controls under GDPR, DORA, NIS 2, PCI DSS, HIPAA or ISO 27001
- Vendor risk and procurement teams monitoring supplier exposure through the third-party risk module
When not to use ImmuniWeb
- Individuals with no digital estate to defend: the commercial catalogue is strictly business-to-business
- Anyone hoping to resell or white-label the free Community Edition, which the terms forbid outright with a stated penalty per breach
- Teams shopping for static source code analysis, since the offering is black-box and authenticated dynamic testing rather than code review
- Organisations that require a signed data processing agreement or EU-based hosting, neither of which the site offers
- Very small budgets on the paid tiers, where platform products start well above the twenty-five euro Community premium entry point
How to use ImmuniWeb
A typical end-to-end flow, from setup to results.
- Start with the free Community Edition: enter a domain, URL or mobile app on the SSL, website security, email, privacy, mobile, dark web or CyberScore test pages, no account required
- Create an account on the ImmuniWeb Portal, providing accurate business details, or sign in through Okta, Microsoft Entra ID, Google Sign-In or Amazon LWA
- Alternatively request a free demo, which comes with a free trial of the products, personalised pricing and a conversation with a technical expert
- Buy online from the Portal by card or bank wire, or take the expert-guided route for customised packages, volume discounts and flexible payment terms
- For Neuron, add your targets and pick a scan mode; for Neuron Mobile, upload the application instead
- For On-Demand or MobileSuite, define and schedule the penetration test, confirm the scope and your authorisation to test, then pay
- For Discovery, simply enter a company name and let discovered assets populate the dashboard within three business days
- Work the dashboard once results land: risk-based prioritisation, reproduction steps, exports in five formats and sharing via role-based access control
- Wire the findings into your pipeline through GitHub Actions, GitLab CI/CD, Jenkins or Azure Pipelines, into JIRA or ServiceNow, and into a WAF for one-click virtual patching
- Fix with help from the 24/7 expert team, rerun a patch verification scan, and collect the letter of compliance once the fixes are validated
Pros & Cons
Pros
- Prices are published product by product, which is unusual in enterprise application security: 595 EUR a year per Neuron target, 995 EUR for an Express Pro penetration test, 199 EUR a month per Continuous scanning target
- Purchase and start are immediate and online, with the vendor advertising zero paperwork and a dashboard ready the same day
- The zero false-positive SLA is contractual and refundable, and On-Demand adds a delivery-speed guarantee
- AI automation is paired with CREST-accredited human testers rather than sold as a scanner alone
- The free Community Edition is genuinely usable, with seven open tests and roughly 131,000 tests reported per day
- The vendor is an established Swiss company, ISO 9001 and ISO 27001 certified, self-funded and profitable rather than venture-backed
- The integration ecosystem is broad and documented, with thirty-five named tools, a public API and a Docker image for CI/CD
Cons
- There is no consolidated pricing page: figures are scattered across a table on each product page, and Discovery shows only three monthly tiers with no package detail
- Amounts were collected in euros from a European connection, so both currency and figures may differ by region
- No data processing agreement is published or offered, no Article 27 EU representative is named and no data protection officer is identified
- Data is hosted in Canada and Switzerland, with no EU hosting option on offer
- No subprocessor list is published; only Twilio is named, and solely for SMS alerts
- The site says nothing about whether customer data feeds model training, nor about any way to opt out
- Support has no email address at all: everything routes through Portal tickets, and urgent tickets are reserved for customers who have already paid for a project
Pricing & Plans
A permanent free plan is available in the form of the Community Edition, which provides seven open security tests with PDF reports and requires no subscription. The lowest paid entry point is the Community Edition Premium 50 subscription at 25.00 EUR per month for fifty tests. Platform products are priced separately and considerably higher, ranging from 199 EUR per month for a Continuous automated scanning target to 4,495 EUR per month for the top Discovery tier, with penetration tests sold per engagement from 995 EUR to 14,995 EUR. A free trial of the platform products is offered through the demo request form. Payment is accepted by bank wire or secure online purchase, and products can also be bought through the Microsoft Azure Marketplace.
- seven online tests with PDF reports
- non-commercial use only
- 50 tests per month
- full technical detail
- PDF export and an API key
- 100 tests per month
- 250 tests per month
- 500 tests per month
- 1
- 000 tests per month
- 2
- 500 tests per month
- 595 EUR annual or 395 EUR monthly subscription per target (FQDN)
- unlimited scans
- with a 15% or 5% discount on penetration testing
- 595 EUR annual or 395 EUR monthly subscription per target
- 199 EUR per month per automated scanning target
- 1
- 995 EUR per month per penetration testing target
- 1
- 495
- 2
- 495 or 4
- 495 EUR per month depending on tier
- Express Pro 995 EUR
- Corporate 2
- 995 EUR
- Corporate Pro 5
- 995 EUR
- Ultimate 14
- 995 EUR per penetration test
- with quarterly discounts from 5% to 20%
- Express Pro 2
- 995 EUR
- Corporate 5
- 995 EUR
- Corporate Pro 9
- 995 EUR
- Ultimate 14
- 995 EUR per penetration test
Data, GDPR & hosting
A consolidated view of how ImmuniWeb handles your data.
GDPR overview
ImmuniWeb never claims GDPR compliance for itself. Its privacy policy, version 2.2 dated 3 April 2024, is written under Swiss law, and the platform terms reference the revised Swiss Federal Act on Data Protection. The many GDPR, UK GDPR, DORA, NIS 2 and EU AI Act pages describe what the product helps customers monitor, not the vendor's own posture, and should not be read as such. Concrete measures do exist: deletion requests go to a dedicated address with a mandatory subject line, proxy requests need a signed power of attorney, accounts are removed within fifteen business days, and Canadian hosting is justified by the European Commission adequacy decision. No Article 27 EU representative, no named data protection officer and no data processing agreement appear anywhere on the site.
Who owns the data?
Under the platform terms, ImmuniWeb collects the personal details a customer volunteers on the Portal, such as name, business email and phone, plus the technical inputs and the usual ancillary telemetry like IP addresses. It uses them to run the service, honour the contract and pursue its own legitimate interests, including a weekly newsletter with one-click opt-out. Sharing is restricted to authorised technology or business partners bound by a non-disclosure agreement and by a privacy policy compliant with Swiss data protection law. Twilio is the one named recipient, for SMS alerts. Separately, the site terms state that all website content belongs exclusively to ImmuniWeb and may not be reused for AI training.
Reuse rights
Customers can view, download and keep their own assessment results, exported from the Portal as HTML, PDF, JSON, XML or CSV, and share them internally through role-based access control. Beyond that the reuse rights are deliberately narrow. The Security Seal and the Attestation Letter may only evidence that a test took place, never a level of security or compliance. Product documentation is treated as confidential and may not be passed to third parties without written consent. Community Edition certificates and badges come with no warranty and the user carries full liability for displaying them, while white-labelling or any commercial use of the Community Edition is prohibited. Website content itself is covered by a revocable browsing licence only, with reproduction, modification or redistribution requiring written permission.
Data retention & training
Hosting summary
Platform information is stored in a dedicated data centre located in Canada, with servers administered only by authorised ImmuniWeb personnel. The vendor justifies that location by pointing at the European Commission adequacy decision covering Canada, alongside Switzerland. The website privacy policy is slightly broader, stating that personal information collected through the site is stored and processed on ImmuniWeb systems in Canada and Switzerland. Governing law is Swiss and the exclusive venue is Geneva, and the revised Swiss Federal Act on Data Protection is the standard imposed on authorised partners. No European Union hosting option is mentioned anywhere. One transfer is named explicitly: if SMS notifications are switched on, phone numbers go to Twilio in California under a contractual commitment to use them only for that purpose. The Portal itself runs on Central European Time and is available around the clock apart from interruptions outside the vendor's control.
Things to keep in mind
Risks and trade-offs to weigh before adopting ImmuniWeb.
- Scans and penetration tests hit live systems, and the scope is defined by the customer alone, so a mistake in scoping can reach a third party
- You must be able to prove you are authorised to test the targets; testing without that right carries criminal exposure
- The Security Seal and Attestation Letter only prove that a test happened, and using them as a security label is explicitly forbidden
- Compliance findings are informational, the vendor is not a law firm and does not guarantee their accuracy, so a lawyer still has to review them
- Liability is capped very low on the website terms and users contractually waive the right to bring legal action, which is worth reading before relying on the service
- Reports vanish 100 days after the assessment, so an audit trail disappears unless someone remembers to archive it locally
- A clean scan describes one moment in time and can breed false confidence: no vendor guarantees exhaustive discovery of assets or leaks
Setup & Integrations
Technical difficulty
Very low to begin with: the Community Edition needs no installation and no account, just a URL, domain or app. Paid products are almost as quick, with online purchase, an instant start and a Neuron dashboard ready the same day; Discovery only asks for a company name and populates within three business days. Effort rises for authenticated scans behind SSO or multi-factor authentication, for API-key automation, for running the command-line tool in Docker inside a pipeline, and for deploying the AWS machine image needed to reach internally hosted applications.
Deployment
Integrations
Supported languages
Behind ImmuniWeb
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement ImmuniWeb.
Frequently asked questions
Can I use ImmuniWeb for free?
What do the platform products actually cost?
Is there a free trial?
Who is behind the tool?
Where is my data hosted?
How long do reports stay available?
Is there an API?
Is ImmuniWeb itself certified?
How do I get my data deleted?
Is a data processing agreement available?
Should you pick ImmuniWeb?
ImmuniWeb occupies an unusual position in enterprise application security: a Swiss vendor that publishes its prices, lets you buy online in minutes and backs its work with contractual money-back guarantees on false positives and delivery speed. The combination of proprietary AI with CREST-accredited human testers is more than a slogan here, since the deliverables list, the OWASP and MITRE coverage and the thirty-five named integrations all point at a mature product rather than a scanner with a marketing layer. A free Community Edition that has run hundreds of millions of tests gives anyone a way to judge the quality before committing, and ISO 9001, ISO 27001 and CREST credentials belong to the company itself rather than to a partner.
The reservations are mostly about paperwork and geography. There is no consolidated pricing page, so buyers must piece the figures together product by product, and Discovery in particular shows three monthly tiers without saying what separates them. Amounts appear in euros from a European connection and may vary elsewhere. More consequential for regulated buyers: no data processing agreement is published, no Article 27 representative is named, no subprocessor list exists beyond a single mention of Twilio, and hosting sits in Canada and Switzerland with no EU option. The site is also silent on whether customer data ever feeds model training.
For a security or compliance team that wants audit-ready testing without building a red team, the offering is credible and unusually legible on price. For a privacy team with strict EU requirements, several contractual questions will need answering before signature.
- Choosing a selection results in a full page refresh.
- Opens in a new window.