Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started

Simple pricing for serious bug bounty

Start free - every client-side tool stays free forever. Pay only when you need server-side recon, unmetered scans, and the API. Cancel anytime. 7-day full refund if it's not for you.

Live billing - payments via Razorpay (India) or Stripe (global).
Have a promo code?

Codes preview the discount here. If you're not logged in yet, your code stays applied through sign-up to checkout.

Free

Free

Free forever
  • All 19 client-side tools (forever free)
  • 8 free-tier server tools (WHOIS, DNS, CVE lookup and more)
  • 30 tokens / 6 hours (~120/day)
  • 7-day scan history
  • 1 project with scope
Get started free
Max

Max

2,999 / month
$36 USD / month
  • Everything in Pro
  • Unmetered scans (no token budget)
  • Unlimited projects with scope
  • Unlimited API calls
  • Highest rate limits
  • Priority support
Talk to sales
🔒
Cancel anytimeStops at end of current period. No retention games.
7-day refundFull refund within the first week. No questions.
🔐
Secure paymentsRazorpay or Stripe handle every cent. We never see card data.
💬
Real humansReply to any email - answered within one working day.

Compare every plan

Every feature, side-by-side. No surprises.

Feature Free₹0 Pro₹799 / mo Max₹2,999 / mo
Tools
Client-side tools (encoder, JSON, hash, CIDR…)All 19All 19All 19
Free-tier server tools (WHOIS, DNS, CVE…)8AllAll
Pro server tools (Subdomain Discovery, Footprint, Takeover, Vuln Scan…)-
Scans & limits
Token allowance per 6 hours30150Unmetered
Daily allowance equivalent~120 / day~600 / dayUnlimited
Per-tool rate limit (e.g. WHOIS / hour)30500Unlimited
Organisation
Projects with scope enforcement13Unlimited
Scan history retention7 days90 daysUnlimited
Data export (JSON, CSV, Markdown)
Automation
API access-
Programmatic key management-
Support
Community / docs
Email support-StandardPriority
Response time-Best-effortPriority

Pricing FAQ

What are tokens, and what happens when I run out?

Server-side scans cost 2-6 tokens depending on the tool. Free accounts get 30 tokens every 6 hours (about 120 per day), enough for a full target recon per window. Pro gets 150 per window, Max is unmetered. When you hit 0 you wait for the next refill or upgrade. Client-side tools never cost tokens.

Can I switch plans mid-cycle?

Yes. Upgrading takes effect immediately and we pro-rate the unused time. Downgrading takes effect at the next renewal so you keep what you've already paid for. No charge for switching.

What payment methods do you accept?

Razorpay for India (UPI, cards, net banking, wallets), Stripe for everyone else (Visa, MasterCard, Amex, Discover). The right gateway is selected at checkout based on your currency.

Is there a refund if I change my mind?

Yes - full refund within the first 7 days of any subscription. After that, you can cancel and your access continues until the end of the period; we don't refund unused time on monthly plans, but yearly plans get a pro-rated refund on request.

Do you store payment details?

No. Card information is tokenised by Razorpay or Stripe and never touches our servers. We only store the subscription reference and transaction status for accounting.

I'm a freelance bug bounty hunter - which plan?

Pro is what's built for you. ₹799/month gets you the full recon suite (Subdomain Discovery, Owner Footprint, DNS Recon Pro, Takeover Scanner, Vulnerability Scanner), 90 days of scan history, 3 projects, and full REST API access. Most solo hunters never come close to the limits.

I run a security agency / SOC - which plan?

Max. Unmetered scans, highest rate limits, unlimited projects and full API access - built for a heavy solo operator or consultant. Need multiple seats, SSO, audit-log export, dedicated infrastructure or a custom SLA? Those come as a custom Enterprise agreement - talk to us.

Is there a free trial of Pro?

Not as a separate trial - but the 7-day refund window effectively gives you the same thing. Subscribe, use it for a week, ask for a refund if it's not for you. We've never refused.

What's not included in any plan?

We don't run port scans or other actively-connecting scans from our servers (shared-host AUP rules forbid it). Tools that need active probing generate CLI commands you run from your own machine. We also don't do attack-tool-style features like reverse shell generators for non-authenticated users, since that affects how Google indexes the rest of the site.

Ready when you are

40+ tools, six-hour token windows, projects with scope, full API. Free forever for client-side work; pay only when you need the heavy stuff.