> For the complete documentation index, see [llms.txt](https://bugrecon.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugrecon.gitbook.io/docs/subscription-plans.md).

# Subscription plans

Your capabilities in the application depend on your **subscription plan**: **Free**, **Basic**, **Premium**, or **Enterprise**. The application enforces quotas and permissions per plan

***

## Plan names and pricing

| Plan       | Price      | Description                                                                                              |
| ---------- | ---------- | -------------------------------------------------------------------------------------------------------- |
| Free       | $0         | Basic scanning capabilities to get started.                                                              |
| Basic      | $19/mo     | More scanning power and quotas.                                                                          |
| Premium    | $29/mo     | Unlimited scans, CertStream, and advanced features.                                                      |
| Enterprise | On request | All Premium features plus custom subdomain, dedicated VPS, adapted reporting, multi-users, admin access. |

* **Free**\
  Perfect for getting started with basic scanning capabilities (port, HTTP, basic auth, takeover, screenshot). Scan quota: 15 completed scans per billing period. **Subdomain enumeration is not available** (0 subdomain targets). **Vulnerability scanning is not available.** No CertStream, no Queue, no URL/leaks/JavaScript scans. **Public API access is not available.**
* **Basic**\
  Ideal for professionals: URL, vulnerability, leaks, and JavaScript scans; 300 completed scans per period overall; CertStream (15 domains) and Queue; **Public API access** with personal API tokens. **Subdomain enumeration is not available** on Basic - upgrade to Premium for subdomain scans (30 targets/period). No scan logs, no BugBounty platform integration, no automation functionality.
* **Premium**\
  For power users: unlimited general scans and CertStream; **30 subdomain targets per billing period** (same counting rules as Basic); access to scan logs; Bug Bounty integration; automation functionality; **scan collaboration** (share scans with other users by email, read-only or writer); **Public API access** with personal API tokens.
* **Enterprise**\
  Same subdomain **target** allowance as Premium (**30** per billing period) unless otherwise agreed in your contract. All Premium features, plus: custom subdomain, dedicated VPS (with provider choice), adapted reporting with executive summary, multi-users, and admin access.

  All plans get a 24/7 support on Discord.

***

## Plan comparison table

| Feature                                                                          | Free              | Basic             | Premium   | Enterprise |
| -------------------------------------------------------------------------------- | ----------------- | ----------------- | --------- | ---------- |
| **Subdomains scanning**                                                          | ❌                 | ❌                 | ✅         | ✅          |
| **Subdomain targets quota (per billing period)**                                 | 0 (not available) | 0 (not available) | 30        | 30         |
| **Port scanning**                                                                | ✅                 | ✅                 | ✅         | ✅          |
| **HTTP scanning**                                                                | ✅                 | ✅                 | ✅         | ✅          |
| **URL scanning**                                                                 | ❌                 | ✅                 | ✅         | ✅          |
| **Vulnerability scanning**                                                       | ❌                 | ✅                 | ✅         | ✅          |
| **Leaks scanning**                                                               | ❌                 | ✅                 | ✅         | ✅          |
| **Basic auth scanning**                                                          | ✅                 | ✅                 | ✅         | ✅          |
| **Domain takeover scanning**                                                     | ✅                 | ✅                 | ✅         | ✅          |
| **Screenshot scanning**                                                          | ✅                 | ✅                 | ✅         | ✅          |
| **JavaScript files scanning (hidden secrets + api endpoints)**                   | ❌                 | ✅                 | ✅         | ✅          |
| **AI scan (LLM triage of subdomains/HTTP results)**                              | ❌                 | ✅                 | ✅         | ✅          |
| **Scan collaboration (share scan, invite by email, read-only/writer)**           | ❌                 | ❌                 | ✅         | ✅          |
| **Scan quota (per month)**                                                       | 15                | 300               | Unlimited | Unlimited  |
| **CertStream quota**                                                             | ❌                 | 15                | Unlimited | Unlimited  |
| **Access to scan logs**                                                          | ❌                 | ❌                 | ✅         | ✅          |
| **Search functionality**                                                         | ✅                 | ✅                 | ✅         | ✅          |
| **Spraying functionality**                                                       | ✅                 | ✅                 | ✅         | ✅          |
| **Bug Bounty platforms integration (YesWeHack, HackerOne, Bugcrowd, Intigriti)** | ❌                 | ❌                 | ✅         | ✅          |
| **Automated tasks functionality**                                                | ✅                 | ✅                 | ✅         | ✅          |
| **Queue functionality**                                                          | ❌                 | ✅                 | ✅         | ✅          |
| **CertStream monitoring**                                                        | ❌                 | ✅                 | ✅         | ✅          |
| **Automation functionality**                                                     | ❌                 | ❌                 | ✅         | ✅          |
| **API access**                                                                   | ❌                 | ✅                 | ✅         | ✅          |
| **Support 24/7**                                                                 | ✅                 | ✅                 | ✅         | ✅          |
| **Custom subdomain**                                                             | ❌                 | ❌                 | ❌         | ✅          |
| **Dedicated VPS (with provider choice)**                                         | ❌                 | ❌                 | ❌         | ✅          |
| **Adapted reporting with executive summary**                                     | ❌                 | ❌                 | ❌         | ✅          |
| **Multi-users**                                                                  | ❌                 | ❌                 | ❌         | ✅          |
| **Admin access**                                                                 | ❌                 | ❌                 | ❌         | ✅          |

***

## Quotas by plan

### Scan quota (per month)

* **Free:** 15 scans per period.
* **Basic:** 300 scans per period.
* **Premium:** Unlimited.
* **Enterprise:** Unlimited.

When you hit your scan quota, you cannot start new scans until the next period (or until you upgrade).

### Subdomain target quota (per billing period)

Subdomain **enumeration** is limited separately from the general scan quota. The limit applies to **how many subdomain targets** you process in the period, **not** how many scan jobs you launch: one scan job can include several domains, and **each domain in the batch counts**.

* **What counts as “used”:** only targets that belong to **completed** (`completed` status) subdomain scans. Failed or canceled runs do not add to this total.
* **Enforcement:** **Running** subdomain scans **reserve** the same number of targets (sum of domains in the batch) so overlapping jobs cannot exceed the cap before previous runs finish.
* **Period:** same as your subscription billing window (or calendar month if you have no entitled subscription).

Plan caps:

* **Free:** 0 - subdomain scanning is disabled.
* **Basic:** 0 - subdomain scanning is disabled. Upgrade to Premium to access subdomain enumeration.
* **Premium:** 30 targets per period from valid completed work (+ running reservations).
* **Enterprise:** 30 per period by default (contract may differ).
* **Users with the Admin role:** unlimited (not tied to subscription plan).

When no subdomain slots are left, you can still run other scan types if your general scan quota allows.

### CertStream quota (monitored domains)

* **Free:** 0 (CertStream feature not available).
* **Basic:** 15 domains.
* **Premium:** Unlimited.
* **Enterprise:** Unlimited.

Only Basic, Premium and Enterprise users can add domains to CertStream monitoring.

***

## Downgrades

The application does not support self-service downgrades (e.g. from Premium to Basic or Free). If you need to downgrade, you must contact support.

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://bugrecon.gitbook.io/docs/subscription-plans.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
