Pricing that scales with your attack surface
Start with continuous testing on a few targets and grow into full multi-cloud coverage, integrations, and compliance evidence — without renegotiating a pentest every quarter.
Starter
For a single team securing a handful of web apps and APIs.
Start free trial- Up to 3 targets
- Weekly continuous scans
- Verified findings
- Slack + email alerts
Team
For growing security teams that need daily coverage and integrations.
Request a demo- Up to 15 targets
- Daily scans + on-change triggers
- Jira, GitHub, PagerDuty integrations
- Multi-cloud CSPM (AWS/Azure/GCP)
- SSO + RBAC
Enterprise
For organizations with compliance, scale, and procurement requirements.
Contact sales- Unlimited targets
- Continuous engagements
- SAML SSO, SCIM, audit logs
- Compliance evidence & SLAs
- Dedicated support + TAM
Prices in USD. Annual billing available at a discount. Need something specific? Talk to our team.
Compare plans
What's included in each plan?
A full breakdown of scanning coverage, workflow, and administration across Starter, Team, and Enterprise.
| Feature | Starter | Team | Enterprise |
|---|---|---|---|
| Scanning & coverage | |||
| Targets | 3 | 15 | Unlimited |
| Scan cadence | Weekly | Daily + on-change | Continuous |
| Recon & attack surface mapping | |||
| Web app testing (DAST) | |||
| CVE & misconfiguration matching | |||
| Cloud posture (AWS/Azure/GCP) | |||
| Exploit verification | |||
| Attack surface change monitoring | |||
| Concurrent scan capacity | Shared | Priority | Dedicated |
| Workflow & reporting | |||
| Verified, prioritized findings | |||
| HTML & PDF reports | |||
| Slack & email alerts | |||
| Jira, GitHub, PagerDuty, Teams | |||
| Webhooks & API access | |||
| Branded / white-label reports | |||
| Compliance evidence (SOC 2 / ISO 27001 / PCI) | Add-on | ||
| Data retention | 90 days | 1 year | Custom |
| Security & administration | |||
| Tenant isolation & encryption | |||
| SSO & RBAC | |||
| SAML, SCIM provisioning | |||
| Audit logs | |||
| Custom roles & approval workflows | |||
| Support | Priority | Dedicated + SLA | |
| Onboarding | Self-serve | Guided | White-glove + TAM |
Add-ons
What can you bolt on as you grow?
Extend any plan with the capabilities that matter to your program — without over-buying a tier you don't need yet.
Compliance evidence pack
Auto-map verified findings and cloud posture to SOC 2, ISO 27001, and PCI DSS controls, with exportable auditor-ready reports. Included on Enterprise; available as an add-on on Team.
Additional targets
Need more than your plan's included targets? Add capacity in blocks as your attack surface grows — no need to jump a full tier before you're ready.
White-label reporting
Brand exported reports with your own logo and colors — ideal for MSSPs and consultancies delivering findings to their own clients.
Dedicated success & TAM
A named technical account manager, priority engineering escalation, and quarterly program reviews for teams that run RedStrike as a core control.
Choosing a plan
Which plan is right for you?
Most teams pick based on coverage cadence, integration needs, and compliance requirements. Here's the quick way to decide.
Choose Starter if
You're a single team getting started
You have a handful of apps and one cloud account, want to see verified findings quickly, and need Slack and email alerts without heavier integrations or SSO yet.
Choose Team if
You're a growing security function
You need daily and on-change coverage across more targets, multi-cloud CSPM, and findings routed into Jira, GitHub, and PagerDuty — plus SSO and RBAC for a real team.
Choose Enterprise if
You have scale and compliance needs
You need unlimited targets, continuous engagements, SAML/SCIM, audit logs, built-in compliance evidence, SLAs, and a dedicated TAM — with procurement and security review support.
Return on investment
Why is continuous cheaper than one big pentest?
A single annual engagement costs tens of thousands and covers one day of your posture. Continuous testing spreads that spend across the whole year — and catches the issues a point-in-time test structurally can't.
- Fewer breaches to clean up. Catching a public bucket or a fresh CVE within hours is far cheaper than incident response after exposure.
- Less engineer time wasted. Verified findings mean no more days lost triaging false positives — engineers fix real issues instead.
- Audit prep becomes a byproduct. Continuous, framework-mapped evidence replaces the annual scramble and the consultant hours that come with it.
- Coverage scales flat. Add targets, not pentester days — the marginal cost of testing one more app stays low.
FAQ
Frequently asked questions
Common questions about plans, billing, add-ons, and getting started.
How does RedStrike pricing work?
Plans are billed monthly or annually and scale by the number of targets and the depth of coverage you need. Starter and Team have published prices; Enterprise is quoted to your scope, compliance, and support requirements. Annual billing includes a discount over monthly.
What counts as a target?
A target is an asset you authorize RedStrike to test — typically a web application, an API, a network range, or a cloud account. You can add, remove, and re-scope targets at any time as your environment changes, and add capacity in blocks without jumping a full tier.
Is there a free trial?
Yes. You can start a trial from the demo request flow to run RedStrike against assets you own or are authorized to test, and see verified findings before you commit to a plan. No agents to install and no long procurement to get started.
Can I change plans later?
Absolutely. You can upgrade or downgrade at any time. Upgrades take effect immediately and are prorated; downgrades apply at the start of your next billing cycle. Your targets, findings, and history carry over across plan changes.
How is annual billing discounted?
Annual plans are billed once for the year at a discount compared to twelve monthly payments. If you're weighing budget against coverage, annual is the most cost-effective way to run continuous testing — talk to sales for the current annual rate.
What add-ons are available?
Common add-ons include the compliance evidence pack (SOC 2 / ISO 27001 / PCI DSS mapping and reports), additional target capacity, white-label reporting for MSSPs, and a dedicated technical account manager. Add-ons attach to Team and Enterprise plans.
Do you offer compliance-ready reporting?
Yes. Team includes compliance evidence as an add-on and Enterprise includes it by default, mapping verified findings to SOC 2, ISO 27001, and PCI DSS controls. See the compliance solution page for how the mapping works.
How do you handle authorization and safe testing?
Every engagement requires you to confirm you own or are permitted to test the target. RedStrike uses non-destructive verification and honors your rules of engagement. Read the security and responsible-disclosure pages for specifics on how testing runs safely.
Is there a discount for MSSPs or multiple tenants?
Yes. MSSPs and consultancies running RedStrike across many client tenants get multi-tenant management, white-label reporting, and volume pricing. Contact sales to scope a partner arrangement.
Not sure which plan fits?
Tell us about your attack surface and compliance goals — we'll recommend the right coverage.