Both products watch your internet-facing assets from the outside, and both will tell you about subdomains you forgot existed. From there they diverge substantially — in depth, in method, and in price. This comparison is written by the Bastion team, so read it knowing where we stand; we have tried to keep every factual claim about Detectify fair, and where capabilities change over time you should confirm details on their site.
What each product is
Detectify (founded 2013, Stockholm) combines two engines: surface monitoring across discovered assets, and a deep web-application scanner that actively tests running applications with payloads sourced from its crowdsourced ethical-hacker network. It is genuinely good at finding exploitable web vulnerabilities — the kind of active testing that goes well beyond configuration review.
Bastion is an external attack surface monitor. It runs passive checks — security headers, TLS and certificate health, DNS and email authentication, subdomain discovery from certificate transparency logs, lookalike-domain watching, and TCP connect checks of common ports — on a schedule, scores the results 0–100, and alerts you when something changes. It never sends attack payloads, and it only scans domains whose ownership you have proven via DNS.
Head to head
| Bastion | Detectify | |
|---|---|---|
| Core approach | Passive external monitoring + change detection | EASM + active web-app vulnerability scanning |
| Finds XSS/SQLi-class bugs | No — out of scope by design | Yes — its core strength |
| TLS, headers, DNS, email auth | Yes, with per-check evidence and fixes | Yes, within its surface monitoring |
| Subdomain discovery | Certificate transparency logs | Multiple discovery techniques |
| Safe-by-construction scanning | Passive only; DNS ownership proof required before any scan | Active scanning; vendor-managed safety controls |
| Typical buyer | Agencies, SaaS teams, MSPs without a security team | Security teams at product companies |
| Pricing (as of this writing) | From $25/month, 7-day trial, no card | Quote-based / from roughly hundreds of dollars per month depending on scope |
Pricing for platforms like Detectify varies with asset count and modules, so treat the last row as an order-of-magnitude guide and get a current quote from them directly.
Where Detectify is the better choice
- You ship a substantial web application and want continuous active testing for injectable, exploitable bugs — not just configuration posture.
- You have a security function that will triage scanner findings and can absorb a platform-sized price.
- You want crowdsourced payload research applied to your app soon after new techniques appear.
Where Bastion is the better choice
- Nobody at your company reads scanner dashboards for a living. Bastion's output is a scored report and a short digest of what changed — designed to be read in two minutes by a generalist engineer.
- Your risk lives in configuration drift — expiring certificates, weakening SPF, new subdomains, ports that opened — more than in application code.
- You watch client domains. Agencies and MSPs can hand a branded PDF report to each client; DNS ownership verification keeps the whole thing consentful.
- Budget is real. $25–79/month versus a platform contract is often the entire decision for a small team.
Can you use both?
Reasonably, yes. Some teams run a cheap continuous monitor for drift and point a heavier active scanner at their main application quarterly. If you can only afford one and you own significant custom application code, pick the active scanner; if your estate is mostly hosted services, DNS and standard web infrastructure, passive monitoring covers the risks you actually have.
Frequently asked questions
Is Bastion a replacement for Detectify?
Only for the surface-monitoring part. Bastion does not perform active web application vulnerability scanning (XSS, SQL injection and similar), which is Detectify's core strength. Bastion replaces Detectify only when passive external monitoring — TLS, headers, DNS, email authentication, exposed services and change detection — is what you actually need.
Why does Bastion only do passive checks?
Passive checks cannot disrupt production, cannot trip WAFs into blocking real users, and are safe to run continuously against domains verified by their owner. They also cover the failure modes small teams most often actually have: expired certificates, missing headers, weak email authentication and forgotten exposed services.
Which is cheaper, Bastion or Detectify?
Bastion starts at $25/month with a 7-day free trial and no card required. Detectify is priced for security teams and typically costs an order of magnitude more depending on asset count and modules; check their site for current pricing.