Compare
Manual web testing toolkit & enterprise DAST
PortSwigger makes Burp Suite, the standard toolkit for manual web penetration testing, plus Burp Suite DAST for scanning large portfolios. Burp Professional is a tool a skilled tester drives; Decloak is a hosted scanner that runs on its own, explains findings in plain English and maps them to compliance controls. They suit different people, and many teams use both.
Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, third-party scripts and exposed backends to produce a scored report anyone can read, with optional DAST and sandboxed AI pentesting on Enterprise.
By Stephen Gray, CEO & Co-founder · Published · Last verified
PortSwigger (Burp Suite): Manual web testing toolkit & enterprise DAST, United Kingdom
“Not advertised” means we could not confirm the capability from PortSwigger (Burp Suite)'s public website, not that it is absent.
| Capability | Decloak | PortSwigger (Burp Suite) |
|---|---|---|
| Getting started & pricing | ||
| Free scan with no account | Yes Single-page scan in about 15 seconds, no login, shareable report | Partial Community Edition is free but, by PortSwigger's description, covers manual tools |
| Published, self-serve pricing | Yes Monthly plans, cancel any time | Partial Professional is self-serve; Burp Suite DAST is quote only |
| What it costs | Free; Starter £29/mo; Pro £79/mo; Enterprise (DAST + AI pentesting) £99/mo | Community free; Professional listed at $499; DAST quote only |
| Web application & external surface | ||
| Web application DAST | YesEnterprise+ Forced browsing, CORS, reflected-input, HTTP-method and postMessage probes | Yes Burp Scanner in Professional; Burp Suite DAST for portfolios |
| Authenticated (logged-in) scanning | PartialEnterprise+ Logged-in session capture via browser extension (works with passkeys); no scripted login replay | Yes Session-aware scanning with OAuth 2.0, bearer token, API key and basic auth |
| API discovery & testing | YesEnterprise+ REST, GraphQL and SOAP via OpenAPI, introspection, WSDL and page-JavaScript discovery | Yes Postman, OpenAPI, SOAP, WSDL and GraphQL schemas |
| Subdomain discovery & takeover detection | YesStarter+ Wordlist and certificate transparency discovery, dangling-CNAME takeover checks | Not advertised |
| DNS, email-auth & TLS checks | YesStarter+ SPF, DMARC, DNSSEC, CAA, certificate expiry, protocol and cipher strength | Not advertised |
| Client-side & supply chain | ||
| Vulnerable JavaScript library detection | Yes Retire.js database, exact file and version, CVE linked | Not advertised |
| Third-party script & domain mapping | Yes Every external domain a real browser contacts, with registration age and threat intel | Not advertised |
| Tag manager (GTM) inspection | Yes GTM containers, tags, triggers and where they send data | Not advertised |
| AI app-builder checks (Supabase, Lovable, Base44, Bubble) | Yes Readable Supabase tables, exposed service_role keys, Bubble Data API, platform CVEs | Not advertised |
| Pentesting | ||
| Exploitation-confirmation (AI pentesting) | YesEnterprise+ Sandboxed sqlmap, dalfox, commix, nuclei (including out-of-band SSRF/XXE), ffuf and jwt_tool with proof-of-exploit evidence; one run per domain per day | Partial Toolkit for human pentesters; not an autonomous pentest |
| Infrastructure & cloud | ||
| Network / infrastructure vulnerability scanning | Partial For IP targets, a passive probe of about 18 common service ports; not a full infrastructure scanner | Not advertised |
| Internal network scanning | No External scanning only | Not advertised |
| Cloud account connectors (AWS / Azure / GCP) | Planned Decloak Cloud Connect is scoped on our roadmap | Not advertised |
| Compliance & reporting | ||
| Per-finding compliance control mapping | YesPro+ ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF and EU CRA | Not advertised |
| Plain-English AI executive summary | Yes On every scan, plus a ranked Priority Remediation Plan on Starter and up | Not advertised |
| Audit evidence export | YesStarter+ PDF reports on Starter and up, date-range evidence ZIP packages on Pro and up | Partial Automated reporting and audit trails in Burp Suite DAST |
| White-label reports | YesPro+ Your logo, colours and fonts on every PDF | Not advertised |
| Workflow & integrations | ||
| Ticketing & chat integrations | PartialPro+ Slack, signed webhooks and email alerts today; native Jira and Microsoft Teams are planned | Yes Jira, ServiceNow, Azure Boards, GitHub Issues and CI/CD pipelines in Burp Suite DAST |
| API & MCP server for AI agents | YesPro+ REST API with OpenAPI docs plus an MCP server | Partial GraphQL API in Burp Suite DAST; MCP not advertised |
| SSO (SAML / OIDC) | Planned SAML / OIDC for Enterprise teams is proposed on our roadmap | Yes SAML SSO, Okta and Microsoft Entra ID in Burp Suite DAST |
PortSwigger lists Burp Suite Professional at $499 on its product page; third-party reviews describe it as an annual per-user licence, so confirm the term at purchase. Burp Suite DAST is quote only. Decloak prices are flat monthly plans in GBP.
Decloak scans on demand or on a schedule and writes a plain-English report. Burp Professional is operated by a person who interprets what it finds.
Decloak publishes £29, £79 and £99 monthly plans. Burp Suite DAST is quote only.
Decloak maps findings to eight frameworks (ISO 27001, SOC 2, NIS2, DORA, LGPD, PCI DSS, NIST CSF, EU CRA) and adds an AI summary on every scan.
Decloak inspects third-party scripts, tag managers, external domains and platform misconfigurations for Supabase, Lovable, Base44 and Bubble apps.
Burp is the reference toolkit for hands-on web pentesting, with Intruder, BChecks and 300+ extensions. Decloak automates; it does not give a tester an interactive proxy.
Burp Suite DAST lists CI/CD triggers for Jenkins, GitHub Actions, GitLab CI and more, SAML SSO, and Jira and ServiceNow connectors. Decloak has Slack, webhooks, an API and an MCP server; SSO is proposed on its roadmap.
Burp Suite DAST offers managed cloud, self-hosted installers and Kubernetes. Decloak is cloud only.
For automated, continuous website scanning with plain-English results, yes. For hands-on manual penetration testing with an interactive proxy and extensions, no: Burp is the better tool, and Decloak does not replace it.
Yes. Decloak monitors continuously and flags what changed; a tester can then use Burp to go deeper on a specific finding.
Burp Community is free, Professional is listed at $499, and Burp Suite DAST is quote only. Decloak is free for single-page scans, then £29, £79 or £99 per month.
PortSwigger (Burp Suite) details are taken from the sources above and were last checked on 7 October 2026. Product names belong to their owners and Decloak is not affiliated with PortSwigger (Burp Suite). If anything here is out of date, email support@decloak.dev and we will correct it.
Free security scan
Decloak's free scan runs in about 15 seconds, no account required, and covers: