Compare
Passive security monitoring & AI pentesting
Barrion pairs passive monitoring with credit-based AI pentests, with human review available at higher credit levels. Decloak takes a different pricing shape: a flat £99/month Enterprise plan that includes DAST and one sandboxed AI pentest run per domain per day, alongside client-side supply chain analysis and compliance mapping on every finding.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Barrion: Passive security monitoring & AI pentesting, Sweden (data hosted in Sweden)
“Not advertised” means we could not confirm the capability from Barrion's public website, not that it is absent.
| Capability | Decloak | Barrion |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial Free plan with an account: 18 checks, 3 pages per scan |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Yes Free and Essential plans are self-serve |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Free; Essential €199/mo (€159/mo billed yearly), 410 pentest credits; Business custom |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Partial Passive scans (35+ checks) plus agent-based pentests |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Test accounts can be added for authenticated pentests |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes Tests web apps and APIs |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Yes DNS records and email authentication checks |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Extra cost Credit-based: Light 400, Standard 1,000, Deep 4,000 credits and up; 1-8 hour engineer review at higher levels |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Not advertised |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Not advertised |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Yes All 97 OWASP WSTG cases; supports SOC 2, ISO 27001, PCI DSS and NIS2 work |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes PDF, XLSX and JSON reports |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Partial Slack and Teams alerts; API to start pentests from a pipeline |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Partial API access (Business plan) |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Not advertised |
Barrion figures come from its public pricing page. Business pricing is custom, and credit costs per pentest level are listed in credits, not currency. Decloak prices are flat monthly plans with no credits.
Decloak Enterprise (£99/month) includes sandboxed sqlmap, dalfox, commix, nuclei, ffuf and jwt_tool runs, one per domain per day, with no credit balance to manage.
Decloak renders pages in a real browser and inspects third-party scripts, tag manager containers and vulnerable JavaScript libraries. Barrion does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases, exposed service keys and known platform CVEs, on the free tier too.
Pro and above map each finding to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls, with remediation tracking and evidence packages.
Barrion offers engineer review and sign-off at higher credit levels, which some auditors and procurement teams specifically ask for. Decloak reports are generated automatically with no human sign-off.
Barrion publishes that its reports map to all 97 OWASP WSTG test cases. Decloak publishes an OWASP Top 10 coverage checklist on every report, not a full WSTG mapping.
Credits let you buy a one-off deep test of a large application without committing to a monthly plan. Decloak AI pentesting is bundled in Enterprise and limited to one run per domain per day.
If you want continuous scanning plus AI pentesting on a flat monthly price, yes. Decloak Enterprise is £99/month and adds client-side supply chain checks and six-framework compliance mapping. If you need an engineer-reviewed pentest report, Barrion offers that at higher credit levels and Decloak does not.
Barrion has a free plan, Essential at €199 per month (about €159 billed yearly) with 410 pentest credits, and custom Business pricing. Pentests cost credits: Light is 400, Standard 1,000, Deep 4,000. Decloak is free for single-page scans, then £29, £79 or £99 per month, with AI pentesting included on Enterprise.
No. Decloak AI pentests run automatically in a sandbox and attach proof-of-exploit evidence, but reports are not reviewed or signed off by a human engineer.
Barrion details are taken from the sources above and were last checked on 6 October 2026. Product names belong to their owners and Decloak is not affiliated with Barrion. If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: