Compare
Enterprise DAST & application security platform
Invicti is an enterprise DAST and application security platform that now includes the Acunetix product (Acunetix is "now Invicti Web + API"). It is sold by quote, per target, with proof-based scanning, API security and CI/CD automation. Decloak is a self-serve alternative: a free single-page scan with no account, flat monthly plans from £29, and client-side supply chain and AI app-builder checks that Invicti does not advertise.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
Invicti (formerly Acunetix): Enterprise DAST & application security platform, United States
“Not advertised” means we could not confirm the capability from Invicti (formerly Acunetix)'s public website, not that it is absent.
| Capability | Decloak | Invicti (formerly Acunetix) |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Not advertised Proof-of-concept licenses are offered on request |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | No Web + API is sold by quote |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Quote only; Agentic Pentest listed at "$500 max per pentest" |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes DAST with proof-based scanning and runtime validation |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Not advertised |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes Multilayer API discovery and stateful API security |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Extra cost Agentic Pentest, priced per pentest |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Not advertised |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Partial CSPM integration in the AppSec Flex package |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Partial Compliance reporting in the AppSec Core and Flex packages |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Yes Audit-ready PDF reports with Agentic Pentest |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes CI/CD and issue-tracker integrations |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Partial API for custom integration; MCP not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Yes SSO included in Web + API |
Invicti does not publish Web + API pricing; it quotes per target, where one FQDN is one target and subdomains or extra ports count separately. The only listed figure is "$500 max per pentest" for Agentic Pentest. Decloak prices are flat monthly plans in GBP.
Decloak shows every price and lets anyone scan a page in about 15 seconds with no account. Invicti sells by quote and offers proof-of-concept licenses.
Decloak renders pages in a real browser and inspects third-party scripts, tag manager containers and vulnerable JavaScript libraries. Invicti does not advertise this layer.
Decloak checks Supabase, Lovable, Base44, Bubble and Next.js apps for readable databases, exposed service keys and known platform CVEs, on the free tier too.
Pro and above map each finding to ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA controls.
Invicti is built for large portfolios and confirms many vulnerabilities automatically to cut false positives. Decloak is built for a smaller number of sites.
AppSec Core and Flex add SAST, SCA, container, IaC and ASPM. Decloak is an external web security platform and does not scan source code.
Invicti lists cloud, on-premises, air-gapped and bring-your-own-cloud options. Decloak is cloud only.
For small and mid-sized teams that want self-serve pricing and web-layer coverage, yes. Decloak is free to try and costs £29 to £99 per month. For large portfolios needing proof-based scanning at scale or on-premises deployment, Invicti is the stronger fit.
Invicti's pricing page states "Acunetix is now Invicti Web + API". Searches for Acunetix pricing now lead to Invicti's quote-based packages.
Invicti Web + API is quote-only, priced per target. Decloak is free for single-page scans, then £29 (Starter), £79 (Pro) or £99 (Enterprise, with DAST and AI pentesting) per month.
Invicti (formerly Acunetix) details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with Invicti (formerly Acunetix). If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: