eCommerceNews US - Technology news for digital commerce decision-makers
United States
ProjectDiscovery launches Neo v1 with pay-as-you-go pricing

ProjectDiscovery launches Neo v1 with pay-as-you-go pricing

Wed, 5th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

ProjectDiscovery has launched Neo v1 in general availability alongside a pay-as-you-go pricing model, following a six-month private beta with enterprise customers.

Neo is ProjectDiscovery's offensive security platform and is now available without a minimum commitment. The new pricing model is intended to open access to autonomous security testing for smaller teams as well as larger security organisations.

Testing model

The platform covers testing across code, web applications, APIs, networks, and cloud environments. It also includes exploitability validation, continuous testing across pull requests and releases, regression testing for previously fixed vulnerabilities, and integrations with existing security and engineering workflows.

ProjectDiscovery argues that security work is often driven by specific events rather than annual planning cycles. A product launch, incident, acquisition, vulnerability disclosure, or change to an external attack surface can all create a need for testing at short notice, while traditional penetration testing engagements are often booked months in advance.

That mismatch shaped the decision to introduce consumption-based pricing. Under the model, teams can run testing when needed rather than waiting for procurement approval or a scheduled annual engagement.

During the private beta, ProjectDiscovery identified three stages in how organisations adopt AI-based security testing. In the first, teams run tools and tests manually. In the second, testing becomes continuous across the full technology stack. In the third, testing is tied to every commit and deployment, and confirmed fixes are turned into regression tests.

The company said many organisations remain at the first stage while attackers move faster with increasing use of AI. Its argument is that more regular and automated testing can help defenders narrow that gap.

Platform updates

Neo v1 also adds integrations requested during the beta programme, including GitHub, Jira, Confluence, Slack, Linear, APIs, webhooks, and MCP.

The platform can run inside private environments and reach internal applications and networks over VPN or SSH. It also supports 1Password for credential handling.

Rishi Sharma, Chief Executive Officer, ProjectDiscovery, set out the company's position on access to security tools.

"ProjectDiscovery has believed since the beginning that the most advanced security capabilities should be available to everyone, not only the best-funded security teams," said Rishi Sharma, Chief Executive Officer, ProjectDiscovery.

He linked the new model to broader shifts in how cyber attacks are carried out.

"Attackers already operate with autonomous capabilities at machine speed, and defenders should not have to wait for a budget cycle to get access to the same class of technology. Outcome-based pricing is where this industry is going, and Pay-as-you-go is designed to balance outcome and cost efficiency for users," said Sharma.

Broader reach

ProjectDiscovery built its name through open source security tools used by practitioners to identify vulnerabilities and map attack surfaces. More than 100,000 practitioners use its toolchain, which includes Nuclei as well as tools such as Subfinder, httpx, and Naabu.

Neo represents a commercial layer on top of that base, combining static application security testing, dynamic application security testing, and automated penetration testing in a single platform. With the general release, ProjectDiscovery is trying to broaden its audience beyond enterprise buyers able to commit to negotiated contracts and annual testing budgets.

For smaller security teams and startups, that may be the more significant part of the announcement. Many need to investigate a newly disclosed vulnerability or test a changing attack surface quickly, but may lack the budget process or staffing to commission a traditional pentest each time.

Sharma said the goal is to remove manual effort from routine testing and triage work.

"Our goal is to move teams off manually driving tests and sorting findings, so their time goes to policy, priorities, and remediation," said Sharma. "That means testing at the speed your environment changes," added Sharma.