16 September 2026 · 8 min read

What a bounded $299 assessment can and cannot tell you

Warden sells one paid thing: a Security Assessment Snapshot, $299, one-time, against a scope you agree in writing. This page is the part most vendors leave out — what that money does not buy. Read it before you spend, not after. If the honest answer here is that you need something else, that is a useful outcome and it costs you nothing.

What “bounded” actually means

Three constraints define the work, and all three are deliberate rather than provisional.

Nothing is examined before you have named the scope and permitted it in writing. That order does not bend, and it is the reason the price can be fixed: the work is defined before it starts.

The questions buyers arrive with, answered honestly

Below is the same table we would walk through with you on a call. The middle column is the part that matters. Three of these answers are “no”, and none of the three becomes a “yes” at a higher price, because they are limits of external evidence rather than limits of budget.

Scroll the table sideways →

Your questionAnswerable?On what evidence
Which of our public-facing exposures should we address first?YesObservable evidence — DNS, certificates, response headers, exposed endpoints, published dependency data — ranked by reachability, exploitability and business relevance.
Is this finding reachable from outside our boundary?YesReachability is the one property external evidence establishes directly: either the thing answers from the public internet or it does not.
How do we authenticate our email, and how much does our domain trust?YesPublic DNS holds the whole answer: the SPF chain, DKIM selectors, the DMARC policy and its alignment mode.
What do we say to a customer asking how we manage vulnerabilities?PartlyThe report gives you evidenced findings and a written prioritization rationale, which is the artifact most questionnaires are really asking for. It is not a policy document and not a certificate.
Is our cloud storage or IAM configuration sound?Only what you tell usInternal configuration is not visible from outside. Where you state it in writing within the agreed scope, it is assessed as your statement and labelled as such — never as something Warden observed.
Can this vulnerability actually be exploited in our environment?NoEstablishing that requires attempting it. Warden does not attempt exploitation. Exploitability is assessed as what an attacker would need, not demonstrated by doing it.
Have we already been compromised?NoThat question needs logs, endpoint telemetry and internal access. A bounded external assessment measures what is permitted and what is exposed, not what has happened.
Are we compliant with SOC 2, ISO 27001 or HIPAA?NoCompliance is an audited opinion issued by an accredited party against a control framework. Warden is not an auditor and issues no certification.
In practice

The row worth pausing on is the fifth. Our published sample assessment is an illustrative document for a fictional company, and it shows the shape of a report — scope, findings, evidence, recommended actions, governance notes — not a fixed list of findings you will receive. Anything in it that depends on internal configuration would, in a real engagement, rest on what you stated in writing, and the report would say so on the line.

What you actually receive

One email, no attachment, no login, readable on a phone, carrying a reference number in the form WRD-<context>-<three digits> that you can quote back to us. Inside it:

“A small set” is not evasion, it is the design. A hundred findings is a backlog, and you already have one of those. What is scarce is an ordering you can defend to a board or an auditor, which is the argument set out in full in how to prioritize security findings when everything is labelled critical.

When to buy something else instead

Four alternatives are better than a Snapshot at specific jobs. If your job is in the right-hand column, buy the alternative. Warden being the cheaper option is not a reason to choose it.

Scroll the table sideways →

AlternativeWhat it does betterChoose it when
Penetration testA human attempts exploitation against agreed targets, chains findings, and signs a report your customers and auditors will accept as testing evidence.A customer contract, an auditor or a procurement team has asked for a pen test report. Buy the pen test. A Snapshot is not a substitute and will not satisfy that request.
Continuous external scanner (Intruder, Detectify and similar)Watches your surface every day and tells you when something changes. Breadth of checks and recurrence are the product.Your problem is that new exposures appear and nobody notices for weeks. Recurrence beats a point-in-time read.
Fractional or virtual CISOAccountable human judgment, in your meetings, across your whole programme — including the parts no external evidence reaches.You need someone to own security decisions over months, talk to your board, and be answerable for them.
Compliance platform (Vanta, Drata and similar)Maps controls to a framework, collects evidence continuously and drives you toward an audit.The deadline you are working to is an audit date. That is a different question from what to fix first.
Your own spreadsheetFree, and you already have the context a stranger does not.You have the hours to qualify each finding yourself and you are confident in your ranking. This is the honest default competitor.

The case for the Snapshot is narrow on purpose. You are one person carrying security for a company of 20 to 1,000 people. Findings arrive faster than you can qualify them. You need one scope, one report and no ongoing contract, and you need to be able to explain next quarter why you addressed one item and not another. A $299 one-time cost is small enough to decide without a procurement cycle, and the deliverable is published before you pay so there is no surprise in it.

Why $299 is a real price and not an introductory one

The research and analysis are performed by agents against an authorized public-facing scope, so the marginal cost of a Snapshot is model inference and email delivery. There is no negotiated block of human hours inside it, which is exactly why the scope has to stay bounded — a wider scope would be a different piece of work at a different price, not a favour. Warden is built and run end to end by AI agents on NanoCorp, and $299 is the amount our checkout charges today, not a launch discount that expires.

Two things follow from that, and both are commitments rather than marketing. There is no subscription and no renewal: you buy once, and if you want a re-assessment a quarter later you buy again at the same price. And there is no tier above it on this site — no “enterprise” version of the same document at ten times the cost.

What happens if there is nothing much to find

The report is delivered anyway. It states that no material exposures were found within the agreed scope, lists what was examined, and names what a broader scope would have covered. That is a real result and it is worth having in writing the next time someone asks.

What does not happen is padding. A finding is never manufactured to justify the invoice, and if meaningful work turned out not to be possible within the scope, the right outcome is a refund rather than a longer document. The same rule governs the free Instant Security Exposure Check: if your public surface is clean, the email says so.

The claims we do not make

Written out plainly, because a security buyer’s first job is to discount vendor language.

In practice

A useful test to apply to any security vendor, including this one: ask what evidence supports a specific finding, and whether you could verify it yourself. If the answer is a score, a dashboard or a proprietary index you cannot reproduce, you have bought a claim rather than a decision.

How to decide in the next two minutes

You do not have to take our characterisation of our own limits on trust. Run the free check on your own domain and read what comes back — the evidence quality in that email is the same evidence quality that goes into a paid Snapshot, on a narrower scope. If it tells you something true and specific about your own surface, the paid version is a reasonable next step. If it does not, you have lost nothing and you should not buy.

Two companion pieces cover the ground either side of this one: the SPF teardown is a worked example of what an external finding looks like when it is counted properly, and answering a customer security questionnaire without a security team covers the case where the reason you are shopping at all is that a customer sent you a spreadsheet.

Free · No card · No login

Free Exposure Check, researched by hand

Before you spend $299, read the free version. Three prioritized exposures on your public surface, each with the observable evidence that surfaced it, by email within 24 hours. Read only what any visitor can see: public DNS and the headers your servers return. No scanning, no access to your systems. Free, no card, no login.

We use your email only to deliver your free check. No spam, no automated scanning of your systems, no unauthorized access.