Last Updated: March 31, 2025
Synack Platform: Product Offering Comparison Guide
SYNACKLT
Penetration Test
SYNACK14
Penetration Test
SYNACK90
Continuous Penetration Testing
SYNACK365
Continuous Penetration Testing
API
Time of Engagement
5 days
14 days
90 days
365 days
Testing and proof of coverage reports on headless API endpoints
Synack Red Team Vulnerability Discovery
Guided
Open
Open
Open
API endpoint testing and reporting
Smartscan
N/A
Tester Rotation
N/A
Compliance and Industry Standards Testing
Optional – premium checklists (OWASP & NIST 800-53)
Optional – premium checklists (OWASP & NIST 800-53)
Optional – premium checklists (OWASP & NIST 800-53)
Includes 2 premium checklists (OWASP & NIST 800-53)
Proof of coverage report included
Synack Platform Tiers
STANDARD
PREMIUM
DISCLOSURE
PREMIUM
DISCOVERY
ELITE
Tracking for Researcher Testing Hours
Real-Time Reporting on Exploitable and Suspected Vulnerabilities
Attacker Resistance Score

Coverage Analytics

Testing Data History & Retention
Asset List That Catalogs All Tested Assets
Fingerprinting of External Assets to Inform Further Testing
Asset Details Highlighting Previous Testing Results
Synack API
Synack Basic Integrations (Jira, ServiceNow, Microsoft, Splunk, etc.)
Researcher Vetting
Proactive Researcher Rotation
Access to Researchers and Vulnerabilities
Fully Managed Researcher Payouts

Single Sign-On (SSO)
Role Based Access Control (RBAC)
Self-Service Pentest Creation

Pause Testing at the Click of a Button

Synack-Owned Virtual Security Researcher Workspaces

Enhanced Security with Testing Data Stored in Synack-Owned Endpoints

Data Cleansing Available on Customer’s Request

Synack Command and Control Infrastructure to Contain Traffic Stemming from Exploits Requiring Callbacks
Active Communication with Researchers

Patch Verification
3 per a vuln (5 credits for a PV for additional re-testing)
Included
Included
Included
Synack On-Demand Security Testing Catalog Access

Internal and External Testing
External testing only
External & internal
External & internal
External & internal
Number of VPN Connections

3
3
5
Vulnerability Disclosure Program Webform
Triage for Vulnerability Disclosure Program

200 submissions per a year (each additional submission is 1 credit)
Included
External Researcher Management

Real-Time Reporting

Self-Service Discovery of New Assets
Seed Groups to Help Organize Assets and Control Access
Continual Discovery of Assets to Surface Testing Candidates
Discovered Asset Reporting Dashboard
Proactive Identification of Test Issues
Customer Success Personnel
Pooled CSS
Named CSS
Named CSS
Named CSS & TAM