ImmuniWeb logo
Privacy Security · Security Code Scanning

ImmuniWeb

Swiss application security platform pairing proprietary AI with CREST-accredited human testers. It runs web, API and mobile penetration tests and scans, maps external attack surface, watches the dark web and flags compliance gaps across roughly thirty regulations.

Active Free plan · Free trial Freemium API available Verified by Guidaio
Overview

What is ImmuniWeb?

ImmuniWeb is the application security platform of ImmuniWeb SA, a Swiss company headquartered on Quai de l'Ile in Geneva with further offices in London, Washington D.C. and Dubai. Its pitch is summed up on the homepage as human-expert application security at the speed of AI: proprietary models, more than fifty of them according to the vendor, handle the volume, while accredited testers are kept for the work that genuinely needs a person. That approach earned its first international recognition in 2018 at the SC Awards Europe, in the machine learning and AI category.

Six products sit on the platform. Discovery covers continuous threat exposure management, attack surface discovery, dark web monitoring, threat intelligence and third-party risk. Neuron and Neuron Mobile handle premium scanning of web, API and mobile targets. On-Demand and MobileSuite deliver full penetration tests, from a one-day Express Pro engagement up to ten days of manual testing at OWASP ASVS Level 3. Continuous merges scanning and pentesting into a round-the-clock service. Together they are marketed across twenty-four use cases, from API penetration testing to phishing website takedown.

What sets the commercial terms apart is the guarantee structure. Neuron and On-Demand carry a contractual zero false-positive SLA backed by a money-back guarantee for a single false positive, and On-Demand adds a delivery-speed guarantee. Reports arrive as HTML, PDF, JSON, XML or CSV, with CVSSv4, EPSSv4 and SSVCv2 scoring, MITRE ATT&CK mapping and step-by-step reproduction notes. Thirty-five named integrations connect the results to CI/CD, ticketing, WAF and SSO tooling, and an API key generated in the Portal exposes project data as JSON. Expert assistance runs 24/7, claimed in thirty languages.

A free Community Edition offers seven open tests covering SSL, email, website security and privacy, mobile apps, dark web exposure and an overall CyberScore rating, with a counter on the site past 485 million tests. ImmuniWeb SA is CREST accredited and ISO 9001 and ISO 27001 certified, reports more than a thousand enterprise customers across over fifty countries, and has contributed to the Verizon Data Breach Investigations Report since 2025.

What it does

  • Run AI-assisted penetration tests on web applications, APIs and mobile apps, reviewed by human experts
  • Scan web, API and mobile assets continuously against OWASP Top 10, API, LLM and Agentic lists plus MITRE CWE Top 25
  • Discover and classify the external attack surface, including cloud, SaaS, shadow IT and abandoned assets
  • Monitor the dark web for stolen credentials, leaked data, compromised machines and fake social accounts
  • Detect phishing sites, typosquatted domains and trademark abuse, then have the fraudulent sites taken down
  • Assess third-party and supplier exposure through the dedicated risk management package
  • Measure technical compliance against roughly thirty regulations and surface the gaps
Audience

When to use ImmuniWeb / When not to

A quick filter to help you decide if ImmuniWeb is the right fit.

When to use ImmuniWeb

  • CISOs and heads of security who need audit-ready penetration test reports without running an in-house red team
  • Application security engineers and internal pentesters looking to industrialise recurring web, API and mobile testing
  • DevSecOps and platform teams wiring security gates into CI/CD, ticketing, WAF and SIEM pipelines
  • Compliance and GRC officers who must evidence technical controls under GDPR, DORA, NIS 2, PCI DSS, HIPAA or ISO 27001
  • Vendor risk and procurement teams monitoring supplier exposure through the third-party risk module

When not to use ImmuniWeb

  • Individuals with no digital estate to defend: the commercial catalogue is strictly business-to-business
  • Anyone hoping to resell or white-label the free Community Edition, which the terms forbid outright with a stated penalty per breach
  • Teams shopping for static source code analysis, since the offering is black-box and authenticated dynamic testing rather than code review
  • Organisations that require a signed data processing agreement or EU-based hosting, neither of which the site offers
  • Very small budgets on the paid tiers, where platform products start well above the twenty-five euro Community premium entry point
Get started

How to use ImmuniWeb

A typical end-to-end flow, from setup to results.

  1. Start with the free Community Edition: enter a domain, URL or mobile app on the SSL, website security, email, privacy, mobile, dark web or CyberScore test pages, no account required
  2. Create an account on the ImmuniWeb Portal, providing accurate business details, or sign in through Okta, Microsoft Entra ID, Google Sign-In or Amazon LWA
  3. Alternatively request a free demo, which comes with a free trial of the products, personalised pricing and a conversation with a technical expert
  4. Buy online from the Portal by card or bank wire, or take the expert-guided route for customised packages, volume discounts and flexible payment terms
  5. For Neuron, add your targets and pick a scan mode; for Neuron Mobile, upload the application instead
  6. For On-Demand or MobileSuite, define and schedule the penetration test, confirm the scope and your authorisation to test, then pay
  7. For Discovery, simply enter a company name and let discovered assets populate the dashboard within three business days
  8. Work the dashboard once results land: risk-based prioritisation, reproduction steps, exports in five formats and sharing via role-based access control
  9. Wire the findings into your pipeline through GitHub Actions, GitLab CI/CD, Jenkins or Azure Pipelines, into JIRA or ServiceNow, and into a WAF for one-click virtual patching
  10. Fix with help from the 24/7 expert team, rerun a patch verification scan, and collect the letter of compliance once the fixes are validated
Quick read

Pros & Cons

Pros

  • Prices are published product by product, which is unusual in enterprise application security: 595 EUR a year per Neuron target, 995 EUR for an Express Pro penetration test, 199 EUR a month per Continuous scanning target
  • Purchase and start are immediate and online, with the vendor advertising zero paperwork and a dashboard ready the same day
  • The zero false-positive SLA is contractual and refundable, and On-Demand adds a delivery-speed guarantee
  • AI automation is paired with CREST-accredited human testers rather than sold as a scanner alone
  • The free Community Edition is genuinely usable, with seven open tests and roughly 131,000 tests reported per day
  • The vendor is an established Swiss company, ISO 9001 and ISO 27001 certified, self-funded and profitable rather than venture-backed
  • The integration ecosystem is broad and documented, with thirty-five named tools, a public API and a Docker image for CI/CD

Cons

  • There is no consolidated pricing page: figures are scattered across a table on each product page, and Discovery shows only three monthly tiers with no package detail
  • Amounts were collected in euros from a European connection, so both currency and figures may differ by region
  • No data processing agreement is published or offered, no Article 27 EU representative is named and no data protection officer is identified
  • Data is hosted in Canada and Switzerland, with no EU hosting option on offer
  • No subprocessor list is published; only Twilio is named, and solely for SMS alerts
  • The site says nothing about whether customer data feeds model training, nor about any way to opt out
  • Support has no email address at all: everything routes through Portal tickets, and urgent tickets are reserved for customers who have already paid for a project
Pricing

Pricing & Plans

A permanent free plan is available in the form of the Community Edition, which provides seven open security tests with PDF reports and requires no subscription. The lowest paid entry point is the Community Edition Premium 50 subscription at 25.00 EUR per month for fifty tests. Platform products are priced separately and considerably higher, ranging from 199 EUR per month for a Continuous automated scanning target to 4,495 EUR per month for the top Discovery tier, with penetration tests sold per engagement from 995 EUR to 14,995 EUR. A free trial of the platform products is offered through the demo request form. Payment is accepted by bank wire or secure online purchase, and products can also be bought through the Microsoft Azure Marketplace.

Community Edition - free
  • seven online tests with PDF reports
  • non-commercial use only
Community Edition Premium 100 - 49 EUR per month
  • 100 tests per month
Community Edition Premium 250 - 149 EUR per month
  • 250 tests per month
Community Edition Premium 500 - 249 EUR per month
  • 500 tests per month
Community Edition Premium 1000 - 399 EUR per month
  • 1
  • 000 tests per month
Community Edition Premium 2500 - 499 EUR per month
  • 2
  • 500 tests per month
Plan 8
ImmuniWeb Neuron
  • 595 EUR annual or 395 EUR monthly subscription per target (FQDN)
  • unlimited scans
  • with a 15% or 5% discount on penetration testing
Plan 9
ImmuniWeb Neuron Mobile
  • 595 EUR annual or 395 EUR monthly subscription per target
Plan 10
ImmuniWeb Continuous
  • 199 EUR per month per automated scanning target
  • 1
  • 995 EUR per month per penetration testing target
Plan 11
ImmuniWeb Discovery
  • 1
  • 495
  • 2
  • 495 or 4
  • 495 EUR per month depending on tier
Plan 12
ImmuniWeb On-Demand
  • Express Pro 995 EUR
  • Corporate 2
  • 995 EUR
  • Corporate Pro 5
  • 995 EUR
  • Ultimate 14
  • 995 EUR per penetration test
  • with quarterly discounts from 5% to 20%
Plan 13
ImmuniWeb MobileSuite
  • Express Pro 2
  • 995 EUR
  • Corporate 5
  • 995 EUR
  • Corporate Pro 9
  • 995 EUR
  • Ultimate 14
  • 995 EUR per penetration test
Special offers — Educational institutions, governments and non-profit organisations may apply for a free Community Edition premium account · The Community Edition is presented as a way for SMEs, colleges, universities and small local governments to test their security at no cost · Neuron subscribers receive a discount on penetration testing products: 15% on an annual subscription, 5% on a monthly one · Quarterly penetration test discounts on On-Demand and MobileSuite range from 5% on Express Pro to 20% on Ultimate · Expert-guided purchasing offers customisable packages, volume and industry discounts and flexible payment terms · Contractual money-back guarantees apply to a single false positive and, on On-Demand, to a missed delivery date
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ImmuniWeb handles your data.

GDPR overview

ImmuniWeb never claims GDPR compliance for itself. Its privacy policy, version 2.2 dated 3 April 2024, is written under Swiss law, and the platform terms reference the revised Swiss Federal Act on Data Protection. The many GDPR, UK GDPR, DORA, NIS 2 and EU AI Act pages describe what the product helps customers monitor, not the vendor's own posture, and should not be read as such. Concrete measures do exist: deletion requests go to a dedicated address with a mandatory subject line, proxy requests need a signed power of attorney, accounts are removed within fifteen business days, and Canadian hosting is justified by the European Commission adequacy decision. No Article 27 EU representative, no named data protection officer and no data processing agreement appear anywhere on the site.

Who owns the data?

Under the platform terms, ImmuniWeb collects the personal details a customer volunteers on the Portal, such as name, business email and phone, plus the technical inputs and the usual ancillary telemetry like IP addresses. It uses them to run the service, honour the contract and pursue its own legitimate interests, including a weekly newsletter with one-click opt-out. Sharing is restricted to authorised technology or business partners bound by a non-disclosure agreement and by a privacy policy compliant with Swiss data protection law. Twilio is the one named recipient, for SMS alerts. Separately, the site terms state that all website content belongs exclusively to ImmuniWeb and may not be reused for AI training.

Reuse rights

Customers can view, download and keep their own assessment results, exported from the Portal as HTML, PDF, JSON, XML or CSV, and share them internally through role-based access control. Beyond that the reuse rights are deliberately narrow. The Security Seal and the Attestation Letter may only evidence that a test took place, never a level of security or compliance. Product documentation is treated as confidential and may not be passed to third parties without written consent. Community Edition certificates and badges come with no warranty and the user carries full liability for displaying them, while white-labelling or any commercial use of the Community Edition is prohibited. Website content itself is covered by a revocable browsing licence only, with reproduction, modification or redistribution requiring written permission.

Data retention & training

Retention summary
Assessment reports from On-Demand and MobileSuite stay on the Portal for 100 days after the assessment ends, then are securely deleted; customers can delete them sooner and are responsible for downloading and storing their own copies. Continuous, Neuron, Neuron Mobile and Discovery dashboards stay live while the subscription is paid, and their data is deleted 100 days after expiry or earlier on written request. Account deletion is requested through support and completed within fifteen business days, though ImmuniWeb may keep whatever the law requires or its legitimate interests justify under Swiss rules. Deleted information is not recoverable. Website personal data is kept only as long as needed to handle the request, and removal can be requested by email. Unpaid invoices allow the vendor to retain customer data as a lien.
GDPR contact

Hosting summary

Platform information is stored in a dedicated data centre located in Canada, with servers administered only by authorised ImmuniWeb personnel. The vendor justifies that location by pointing at the European Commission adequacy decision covering Canada, alongside Switzerland. The website privacy policy is slightly broader, stating that personal information collected through the site is stored and processed on ImmuniWeb systems in Canada and Switzerland. Governing law is Swiss and the exclusive venue is Geneva, and the revised Swiss Federal Act on Data Protection is the standard imposed on authorised partners. No European Union hosting option is mentioned anywhere. One transfer is named explicitly: if SMS notifications are switched on, phone numbers go to Twilio in California under a contractual commitment to use them only for that purpose. The Portal itself runs on Central European Time and is available around the clock apart from interruptions outside the vendor's control.

Hosting countries
🇨🇦 Canada🇨🇭 Switzerland
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ImmuniWeb.

  • Scans and penetration tests hit live systems, and the scope is defined by the customer alone, so a mistake in scoping can reach a third party
  • You must be able to prove you are authorised to test the targets; testing without that right carries criminal exposure
  • The Security Seal and Attestation Letter only prove that a test happened, and using them as a security label is explicitly forbidden
  • Compliance findings are informational, the vendor is not a law firm and does not guarantee their accuracy, so a lawyer still has to review them
  • Liability is capped very low on the website terms and users contractually waive the right to bring legal action, which is worth reading before relying on the service
  • Reports vanish 100 days after the assessment, so an audit trail disappears unless someone remembers to archive it locally
  • A clean scan describes one moment in time and can breed false confidence: no vendor guarantees exhaustive discovery of assets or leaks
Setup

Setup & Integrations

Technical difficulty

Very low to begin with: the Community Edition needs no installation and no account, just a URL, domain or app. Paid products are almost as quick, with online purchase, an instant start and a Neuron dashboard ready the same day; Discovery only asks for a company name and populates within three business days. Effort rises for authenticated scans behind SSO or multi-factor authentication, for API-key automation, for running the command-line tool in Docker inside a pipeline, and for deploying the AWS machine image needed to reach internally hosted applications.

Deployment

Web appAPIPlugin

Integrations

Amazon LWA Asana AWS Amazon Machine Image Azure Pipelines Azure Virtual Machine Barracuda WAF Bugzilla DefectDojo F5 BIG IP Advanced WAF FogBugz Fortinet FortiWeb WAF GitHub Actions GitLab CI/CD Google Sign In SSO Imperva WAF Jenkins JIRA Mantis MatterMost Micro Focus ALM/Quality Center Micro Focus ArcSight Logger Microsoft Entra ID Microsoft Teams Okta Single Sign On Pivotal Tracker Qualys WAF Rally Redmine Rocket.Chat ServiceNow Slack Splunk YouTrack Zapier Zoho BugTracker

Supported languages

EnglishFrenchGermanSpanish
Company

Behind ImmuniWeb

Company name
ImmuniWeb SA
Founded
16/10/2019
Country of origin
🇨🇭 Switzerland
Headquarters
Quai de l’Ile 13, Geneva, CH-1204, Switzerland
US office
1250 Connecticut Avenue Northwest, Suite 700, PMB 5329, Washington, District of Columbia 20036, United States
UBO
Ilia Kolochenko
UBO country
🇨🇭 Switzerland
Domain registrar country
🇺🇸 United States

Fundraising

No fundraising rounds are reported: the investors page states the company has no external debt and no third-party financing
ImmuniWeb SA describes itself as a private Swiss company owned and controlled by its founders, who come from Switzerland and the EU
The company reports being profitable and cash-positive since its first year of existence, funding growth organically
The history page describes the firm as self-funded and bootstrapped through the pandemic period
As of this review the company states it is not actively looking for external investors

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement ImmuniWeb.

I IBM Watson for Cybersecurity
FAQ

Frequently asked questions

Can I use ImmuniWeb for free?
Yes. The Community Edition gives open access to seven security tests for non-commercial use, with no account needed for the basic checks. A premium tier starts at 25 EUR per month if you need higher monthly volumes and an API key.
What do the platform products actually cost?
Entry points are 199 EUR per month per automated scanning target on Continuous, 595 EUR per year per target on Neuron, and 995 EUR for an Express Pro penetration test on On-Demand. Discovery runs from 1,495 to 4,495 EUR per month.
Is there a free trial?
Yes. The demo request form promises a free trial of the products alongside personalised pricing and a conversation with a technical expert.
Who is behind the tool?
ImmuniWeb SA, a Swiss corporation entered in the Geneva commercial register on 16 October 2019, headquartered on Quai de l'Ile in Geneva, with offices in London, Washington D.C. and Dubai.
Where is my data hosted?
Platform data sits in a dedicated data centre in Canada, and the website privacy policy adds that personal information is stored on ImmuniWeb systems in Canada and Switzerland. No EU hosting option is mentioned.
How long do reports stay available?
Assessment reports remain on the Portal for 100 days after the assessment completes, then are securely deleted and cannot be recovered. Downloading and storing them in time is the customer's responsibility.
Is there an API?
Yes, on two levels. Paying customers generate an API key in the Portal to pull project data as JSON, and each Community Edition test has its own documented public API with a command-line tool and a Docker image.
Is ImmuniWeb itself certified?
ImmuniWeb SA is CREST accredited and ISO 9001 and ISO 27001 certified, with the certificates published as PDFs on its own site. These belong to the vendor, unlike the SOC 2 or PCI DSS references found on the compliance pages, which describe what the product helps customers cover.
How do I get my data deleted?
Send a request to the dedicated removals address with the exact subject line "My PII Data Removal", as emails with a different subject are not delivered. Portal account deletion is requested through support and completed within fifteen business days.
Is a data processing agreement available?
None is published or presented as available on request, and no Article 27 EU representative is named anywhere on the site. Both points are worth raising directly with the vendor if you operate under EU rules.
Conclusion

Should you pick ImmuniWeb?

ImmuniWeb occupies an unusual position in enterprise application security: a Swiss vendor that publishes its prices, lets you buy online in minutes and backs its work with contractual money-back guarantees on false positives and delivery speed. The combination of proprietary AI with CREST-accredited human testers is more than a slogan here, since the deliverables list, the OWASP and MITRE coverage and the thirty-five named integrations all point at a mature product rather than a scanner with a marketing layer. A free Community Edition that has run hundreds of millions of tests gives anyone a way to judge the quality before committing, and ISO 9001, ISO 27001 and CREST credentials belong to the company itself rather than to a partner.

The reservations are mostly about paperwork and geography. There is no consolidated pricing page, so buyers must piece the figures together product by product, and Discovery in particular shows three monthly tiers without saying what separates them. Amounts appear in euros from a European connection and may vary elsewhere. More consequential for regulated buyers: no data processing agreement is published, no Article 27 representative is named, no subprocessor list exists beyond a single mention of Twilio, and hosting sits in Canada and Switzerland with no EU option. The site is also silent on whether customer data ever feeds model training.

For a security or compliance team that wants audit-ready testing without building a red team, the offering is credible and unusually legible on price. For a privacy team with strict EU requirements, several contractual questions will need answering before signature.