All comparisons

Compare

Decloak vs Intruder

decloak.dev
Pricing
Free; £29, £79 or £99 per month, flat
Free scan
Yes - 15 seconds, no account
Pentesting
Included in Enterprise (£99/mo)
Best for
Websites, web apps and compliance evidence
Intruder logo

Vulnerability management & attack surface monitoring

Pricing
Cloud from £227/mo, plus about £56/mo per web app
Free scan
14-day free trial
Pentesting
AI pentests from $3,500 per test
Best for
Infrastructure, cloud and internal vulnerability management

Intruder is a strong choice if you need infrastructure, cloud-account and internal network vulnerability scanning in one place. Decloak is the better fit if your risk lives in your website and web app: it covers the client-side supply chain (JavaScript libraries, tag managers, third-party scripts), maps every finding to eight compliance frameworks, and includes DAST and sandboxed AI pentesting on a £99/month self-serve plan.

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.

By Stephen Gray, CEO & Co-founder · Published · Last verified

Intruder: Vulnerability management & attack surface monitoring, London, UK

Key takeaways

  • Intruder is broader on infrastructure: Tenable Nessus, OpenVAS, Nuclei and Nmap engines, internal agents, cloud-account scanning and container images. Decloak is external and web-focused.
  • Decloak goes deeper on the website itself: what a real browser loads, which third parties it talks to, vulnerable JavaScript, and AI app-builder misconfigurations.
  • Intruder Cloud starts at £227/month on monthly billing (5 infrastructure targets) before web app licences. Decloak Enterprise, with DAST and AI pentesting, is £99/month.
  • Intruder sells AI pentests per engagement from $3,500 per test. Decloak Enterprise includes one sandboxed AI pentest run per domain per day.

Decloak vs Intruder feature comparison

“Not advertised” means we could not confirm the capability from Intruder's public website, not that it is absent.

Feature-by-feature comparison of Decloak and Intruder, last verified 2 October 2026
CapabilityDecloakIntruder
Intruder logo
Getting started & pricing
Free scan with no account
Yes

Single-page scan in about 15 seconds, no login, shareable report

No

14-day free trial with an account

Published, self-serve pricing
Yes

Monthly plans, cancel any time

Yes

Online price calculator, priced per target

What it costs

Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo

Cloud from £227/mo (5 infrastructure targets); about £56/mo per authenticated web app; Pro from £379/mo; Enterprise custom

Web application & external surface
Web application DAST
YesEnterprise+

Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes

Yes

ZAP-powered, 75+ application checks, single-page apps supported

Authenticated (logged-in) scanning
PartialEnterprise+

Logged-in session capture via browser extension (works with passkeys); no scripted login replay

Yes

Scans behind login pages

API discovery & testing
YesEnterprise+

REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery

Yes

API security testing

Subdomain discovery & takeover detection
YesStarter+

Wordlist and certificate transparency discovery, dangling-CNAME takeover checks

Yes

Attack surface monitoring with subdomain and shadow IT discovery

DNS, email-auth & TLS checks
YesStarter+

SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength

Partial

Covered through its infrastructure scanning engines

Client-side & supply chain
Vulnerable JavaScript library detection
Yes

Retire.js database, exact file and version, CVE linked

Yes

"Vulnerable components" in web app scans

Third-party script & domain mapping
Yes

Every external domain a real browser contacts, with registration age and threat intel

Not advertised
Tag manager (GTM) inspection
Yes

GTM containers, tags, triggers and where they send data

Not advertised
AI app-builder checks (Supabase, Lovable, Base44, Bubble)
Yes

Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs

Not advertised
Pentesting
Exploitation-confirmation (AI pentesting)
YesEnterprise+

Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day

Extra cost

AI web app pentests from $3,500 per test

Infrastructure & cloud
Network / infrastructure vulnerability scanning
Partial

For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner

Yes

Tenable Nessus, OpenVAS, Nuclei and Nmap; port monitoring scales by plan

Internal network scanning
No

External scanning only

Yes

Agent-based internal scanning (Pro and up)

Cloud account connectors (AWS / Azure / GCP)
Planned

Decloak Cloud Connect is scoped on our roadmap

Yes

Agentless AWS, Azure and Google Cloud checks

Compliance & reporting
Per-finding compliance control mapping
YesPro+

ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA

Partial

Reports used for SOC 2, ISO 27001 and Cyber Essentials; per-control mapping not advertised

Plain-English AI executive summary
Yes

On every scan, plus a ranked Priority Remediation Plan on Starter and up

Partial

GregAI analyst for triage and prioritisation

Audit evidence export
YesStarter+

PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up

Partial

Compliance-ready reports

White-label reports
YesPro+

Your logo, colours and fonts on every PDF

Not advertised
Workflow & integrations
Ticketing & chat integrations
PartialPro+

Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned

Yes

15+ including Jira, Slack, Teams, GitHub, GitLab and ServiceNow

API & MCP server for AI agents
YesPro+

REST API with OpenAPI docs plus an MCP server

Partial

API access

SSO (SAML / OIDC)
Planned

SAML / OIDC for Enterprise teams is proposed on our roadmap

Partial

Okta listed as an integration

Intruder figures come from its public pricing calculator at monthly billing in GBP; annual billing saves 20%. Web app licences are added on top of the infrastructure plan. Decloak prices are flat monthly plans with no per-target add-ons.

Where Decloak is stronger

The website your customers actually load

Decloak renders every page in a real browser and records every request, so it sees third-party scripts, tag manager containers and data flows that an infrastructure-focused scanner is not built to inspect. That is where Magecart-style skimming and leaky analytics live.

Compliance mapping on every finding

On Pro and above, each finding is tagged to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls, with remediation tracking and date-range evidence packages for auditors.

Pentesting without a per-test invoice

Intruder prices AI pentests per engagement from $3,500. Decloak Enterprise (£99/month) includes sandboxed exploitation-confirmation runs with sqlmap, dalfox, commix, nuclei, ffuf and jwt_tool, one run per domain per day.

Try it without signing up

Paste a URL and get a full scored report in about 15 seconds, with no account and no trial clock. Intruder starts with a 14-day trial.

Where Intruder is stronger

Infrastructure and internal networks

Intruder runs commercial and open-source engines across every exposed port, plus agents for internal devices. Decloak only probes about 18 common service ports on IP targets and does not scan internal networks.

Cloud and container coverage

Intruder connects to AWS, Azure and Google Cloud accounts and scans container images. Decloak Cloud Connect is scoped on our roadmap but not built, and we do not scan container images.

Integrations

Intruder lists 15+ integrations including native Jira, Microsoft Teams and ServiceNow. Decloak has Slack, signed webhooks, a REST API and an MCP server today; native Jira and Teams integrations are planned.

Which should you choose?

Intruder logo

Choose Intruder if…

  • Your main exposure is servers, IP ranges, cloud accounts or internal devices rather than web applications.
  • You need native Jira, ServiceNow or Microsoft Teams workflows out of the box.
  • You want one vendor for infrastructure and web app vulnerability management.
The right fit
decloak.dev

Choose Decloak if…

  • Your risk is concentrated in websites and web apps, including what third-party scripts and tag managers do in the browser.
  • You need per-finding mapping to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF or EU CRA for audit evidence.
  • You want DAST and AI pentesting on a predictable monthly plan instead of per-test pricing.
  • Your app is built on Supabase, Lovable, Base44, Bubble or Next.js and you want those platform-specific checks.

Decloak vs Intruder: frequently asked questions

Is Decloak a good Intruder alternative?

For web application and website security, yes. Decloak covers DAST, API testing, authenticated scans, AI pentesting and compliance mapping on a £99/month Enterprise plan. If you mainly need infrastructure, internal-network or cloud-account scanning, Intruder covers that and Decloak does not.

How much does Intruder cost compared with Decloak?

Intruder Cloud starts at £227 per month on monthly billing for five infrastructure targets, with authenticated web app scanning at about £56 per app per month on top, and AI pentests from $3,500 per test. Decloak is free for single-page scans, £29/month for Starter, £79/month for Pro and £99/month for Enterprise with DAST and AI pentesting included.

Does Decloak scan internal networks or cloud accounts like Intruder?

No. Decloak is an external scanner focused on websites, web apps, APIs, DNS/TLS and subdomains. It has no internal agents. Cloud account connectors for AWS, Azure and Google Cloud are scoped on our roadmap but not available yet.

Can I use Decloak and Intruder together?

Yes. A common split is Intruder for infrastructure and cloud, and Decloak for the website layer: client-side supply chain, tag managers, JavaScript CVEs, compliance-mapped evidence and AI pentesting of web apps.

Sources

Intruder details are taken from the sources above and were last checked on 2 October 2026. Product names belong to their owners and Decloak is not affiliated with Intruder. If anything here is out of date, email support@decloak.dev and we will correct it.

More comparisons

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary