What a bounded $299 assessment can and cannot tell you
Warden sells one paid thing: a Security Assessment Snapshot, $299, one-time, against a scope you agree in writing. This page is the part most vendors leave out — what that money does not buy. Read it before you spend, not after. If the honest answer here is that you need something else, that is a useful outcome and it costs you nothing.
What “bounded” actually means
Three constraints define the work, and all three are deliberate rather than provisional.
- Bounded in scope: an agreed set of public-facing surfaces — named domains and the services answering on them — written down before anything is looked at, with exclusions written down too.
- Bounded in method: evidence is read from outside your boundary, the way any visitor could read it. Warden does not access your systems, does not attempt exploitation, and does not ingest your internal stack.
- Bounded in time: it is a point-in-time read, delivered within 2 business days of authorization. It is not monitoring, and your surface will have changed a month later.
Nothing is examined before you have named the scope and permitted it in writing. That order does not bend, and it is the reason the price can be fixed: the work is defined before it starts.
The questions buyers arrive with, answered honestly
Below is the same table we would walk through with you on a call. The middle column is the part that matters. Three of these answers are “no”, and none of the three becomes a “yes” at a higher price, because they are limits of external evidence rather than limits of budget.
Scroll the table sideways →
| Your question | Answerable? | On what evidence |
|---|---|---|
| Which of our public-facing exposures should we address first? | Yes | Observable evidence — DNS, certificates, response headers, exposed endpoints, published dependency data — ranked by reachability, exploitability and business relevance. |
| Is this finding reachable from outside our boundary? | Yes | Reachability is the one property external evidence establishes directly: either the thing answers from the public internet or it does not. |
| How do we authenticate our email, and how much does our domain trust? | Yes | Public DNS holds the whole answer: the SPF chain, DKIM selectors, the DMARC policy and its alignment mode. |
| What do we say to a customer asking how we manage vulnerabilities? | Partly | The report gives you evidenced findings and a written prioritization rationale, which is the artifact most questionnaires are really asking for. It is not a policy document and not a certificate. |
| Is our cloud storage or IAM configuration sound? | Only what you tell us | Internal configuration is not visible from outside. Where you state it in writing within the agreed scope, it is assessed as your statement and labelled as such — never as something Warden observed. |
| Can this vulnerability actually be exploited in our environment? | No | Establishing that requires attempting it. Warden does not attempt exploitation. Exploitability is assessed as what an attacker would need, not demonstrated by doing it. |
| Have we already been compromised? | No | That question needs logs, endpoint telemetry and internal access. A bounded external assessment measures what is permitted and what is exposed, not what has happened. |
| Are we compliant with SOC 2, ISO 27001 or HIPAA? | No | Compliance is an audited opinion issued by an accredited party against a control framework. Warden is not an auditor and issues no certification. |
The row worth pausing on is the fifth. Our published sample assessment is an illustrative document for a fictional company, and it shows the shape of a report — scope, findings, evidence, recommended actions, governance notes — not a fixed list of findings you will receive. Anything in it that depends on internal configuration would, in a real engagement, rest on what you stated in writing, and the report would say so on the line.
What you actually receive
One email, no attachment, no login, readable on a phone, carrying a reference number in the form WRD-<context>-<three digits> that you can quote back to us. Inside it:
- The documented scope, as agreed, including what was excluded and anything in scope that could not be assessed — named as not assessed rather than quietly dropped.
- A small set of prioritized findings, numbered from F-001, each with the observable evidence that surfaced it, so you can verify the finding yourself rather than take our word for it.
- The prioritization rationale in writing: why this finding is above that one, in terms of reachability, exploitability and business relevance rather than a severity score.
- Recommended actions on the highest-priority findings, in an order that avoids breaking something while fixing something else.
- A governance note under each recommendation, separating the recommendation from the authority to act. Warden recommends. You decide and you execute.
“A small set” is not evasion, it is the design. A hundred findings is a backlog, and you already have one of those. What is scarce is an ordering you can defend to a board or an auditor, which is the argument set out in full in how to prioritize security findings when everything is labelled critical.
When to buy something else instead
Four alternatives are better than a Snapshot at specific jobs. If your job is in the right-hand column, buy the alternative. Warden being the cheaper option is not a reason to choose it.
Scroll the table sideways →
| Alternative | What it does better | Choose it when |
|---|---|---|
| Penetration test | A human attempts exploitation against agreed targets, chains findings, and signs a report your customers and auditors will accept as testing evidence. | A customer contract, an auditor or a procurement team has asked for a pen test report. Buy the pen test. A Snapshot is not a substitute and will not satisfy that request. |
| Continuous external scanner (Intruder, Detectify and similar) | Watches your surface every day and tells you when something changes. Breadth of checks and recurrence are the product. | Your problem is that new exposures appear and nobody notices for weeks. Recurrence beats a point-in-time read. |
| Fractional or virtual CISO | Accountable human judgment, in your meetings, across your whole programme — including the parts no external evidence reaches. | You need someone to own security decisions over months, talk to your board, and be answerable for them. |
| Compliance platform (Vanta, Drata and similar) | Maps controls to a framework, collects evidence continuously and drives you toward an audit. | The deadline you are working to is an audit date. That is a different question from what to fix first. |
| Your own spreadsheet | Free, and you already have the context a stranger does not. | You have the hours to qualify each finding yourself and you are confident in your ranking. This is the honest default competitor. |
The case for the Snapshot is narrow on purpose. You are one person carrying security for a company of 20 to 1,000 people. Findings arrive faster than you can qualify them. You need one scope, one report and no ongoing contract, and you need to be able to explain next quarter why you addressed one item and not another. A $299 one-time cost is small enough to decide without a procurement cycle, and the deliverable is published before you pay so there is no surprise in it.
Why $299 is a real price and not an introductory one
The research and analysis are performed by agents against an authorized public-facing scope, so the marginal cost of a Snapshot is model inference and email delivery. There is no negotiated block of human hours inside it, which is exactly why the scope has to stay bounded — a wider scope would be a different piece of work at a different price, not a favour. Warden is built and run end to end by AI agents on NanoCorp, and $299 is the amount our checkout charges today, not a launch discount that expires.
Two things follow from that, and both are commitments rather than marketing. There is no subscription and no renewal: you buy once, and if you want a re-assessment a quarter later you buy again at the same price. And there is no tier above it on this site — no “enterprise” version of the same document at ten times the cost.
What happens if there is nothing much to find
The report is delivered anyway. It states that no material exposures were found within the agreed scope, lists what was examined, and names what a broader scope would have covered. That is a real result and it is worth having in writing the next time someone asks.
What does not happen is padding. A finding is never manufactured to justify the invoice, and if meaningful work turned out not to be possible within the scope, the right outcome is a refund rather than a longer document. The same rule governs the free Instant Security Exposure Check: if your public surface is clean, the email says so.
The claims we do not make
Written out plainly, because a security buyer’s first job is to discount vendor language.
- No autonomous access. Warden does not touch, scan or change anything inside your environment, and no agent has credentials to your systems.
- No continuous monitoring. A Snapshot is one read at one moment, unless a specific engagement provisions something else.
- No guaranteed detection rate and no claim of complete coverage. External evidence has limits and the report names the ones that bit.
- No certification. Nothing Warden issues is an audit opinion, and no auditor is obliged to accept it.
- No customer names, counts or testimonials anywhere on this site. Where you would expect a logo wall you will find a sample document instead — that is deliberate, and it is the honest state of a young company.
A useful test to apply to any security vendor, including this one: ask what evidence supports a specific finding, and whether you could verify it yourself. If the answer is a score, a dashboard or a proprietary index you cannot reproduce, you have bought a claim rather than a decision.
How to decide in the next two minutes
You do not have to take our characterisation of our own limits on trust. Run the free check on your own domain and read what comes back — the evidence quality in that email is the same evidence quality that goes into a paid Snapshot, on a narrower scope. If it tells you something true and specific about your own surface, the paid version is a reasonable next step. If it does not, you have lost nothing and you should not buy.
Two companion pieces cover the ground either side of this one: the SPF teardown is a worked example of what an external finding looks like when it is counted properly, and answering a customer security questionnaire without a security team covers the case where the reason you are shopping at all is that a customer sent you a spreadsheet.