Plans, credits and limits
Two separate things decide what Hunto will do for you, and mixing them up is the usual source of confusion:
- Your plan decides which checks are allowed to run.
- Your credits decide how much work you can run.
A check your plan does not include stays locked no matter how many credits you hold. A check your plan includes still needs credits to run.
What each plan includes
The catalogue is 45 checks. The plan decides how many of them run against you.
| Plan | Checks | What it adds |
|---|---|---|
| Free | 38 of 45 | Passive discovery: hosts, subdomains, DNS and mail posture, certificates, exposed code, leaked credentials, lookalike domains. A real score and a real finding list. |
| Basic | 42 of 45 | Active scanning — open ports, running services, insecure protocols, exposed credential services. The single largest jump in coverage. |
| Professional | 45 of 45 | The deep analysis passes, plus brand protection and dark-web monitoring. |
| Enterprise | 45 of 45 | The flow library — pick individual checks and build your own detectives — plus takedowns. |
Free is deliberately not a crippled product. It is the whole passive surface, and the checks it cannot run are shown to you as locked, not hidden. That is on purpose: a tenant with no ports scanned must never look like a tenant with no ports open.
Why a check says "needs a higher plan"
Active checks touch your hosts rather than reading public sources, and the deep passes cost materially more to run. They are grouped, not sold individually:
| Locked check | Needs |
|---|---|
| Port scanning, service detection, insecure protocols, credential services | Basic |
| Technology-to-CVE matching and the other deep analysis passes | Professional |
If ports have never been scanned, several other findings cannot exist either — vulnerability matching has nothing to match against. That is why Basic moves the number most.
Credits
Work that costs us money to run costs you credits.
| Work | Credits |
|---|---|
| Discovery run | 10 per run |
| Takedown request | 10 per takedown |
| Active scan target | 2 per target |
| AI generation | 1 per 1,000 tokens |
| Investigation query | 1 per query |
| Leak lookup | 1 per lookup |
| Report export | 1 per export |
| API calls | 1 per 1,000 requests |
Your balance and this month's consumption per meter are on Billing & Usage → Usage & credits.
When you run out
Your balance can go negative — work already started is not abandoned halfway. Once it does:
- New metered work pauses. Scans, takedowns, AI generation and investigation queries stop starting.
- Reading stays open. Every finding, report, score and piece of history you already have remains visible and exportable. You are never locked out of your own data because of a balance.
Top up and metered work resumes immediately — there is nothing to re-enable.
If your billing is managed by a partner, plan changes and top-ups go through them, and the plans tab will say so instead of offering checkout.