Pricing that scales with your attack surface
Start with continuous testing on a few targets and grow into full multi-cloud coverage, integrations, and compliance evidence — without renegotiating a pentest every quarter.
Starter
For a single team securing a handful of web apps, APIs, and one cloud account.
Request a trial- 3 targets + 1 cloud account
- Up to 2,500 cloud resources
- Weekly continuous scans
- Verified findings
- Current-edition framework mapping
- Slack + email alerts
Team
For growing security teams that need daily coverage, integrations, and audit-ready evidence.
Request a demo- 15 targets + 5 cloud accounts
- Up to 25,000 cloud resources
- Daily scans + on-change triggers
- Compliance evidence included
- Multi-cloud CSPM (AWS/Azure/GCP)
- Jira, GitHub, PagerDuty integrations
- SSO + RBAC
Compliance
For teams inside an audit cycle who need the test evidence behind every control.
Talk to sales- 50 targets + 15 cloud accounts
- Up to 100,000 cloud resources
- Every framework edition, pinnable
- Retest-to-closure evidence
- Push to Vanta, Drata & Jira
- Signed assessment attestations
Enterprise
For organizations with scale, data-residency, and procurement requirements.
Contact sales- Unlimited targets & cloud accounts
- Dedicated scan capacity
- SAML SSO, SCIM, audit logs
- Data residency or private deployment
- Dedicated support + TAM
Prices in USD. Annual billing available at a discount. Need something specific? Talk to our team.
Compare plans
What's included in each plan?
A full breakdown of scanning coverage, workflow, and administration across Starter, Team, Compliance, and Enterprise.
| Feature | Starter | Team | Compliance | Enterprise |
|---|---|---|---|---|
| Scanning & coverage | ||||
| Application targets | 3 | 15 | 50 | Unlimited |
| Cloud accounts | 1 | 5 | 15 | Unlimited |
| Cloud resources included | 2,500 | 25,000 | 100,000 | Custom |
| Scan cadence | Weekly | Daily + on-change | Daily + on-change | Continuous |
| Recon & attack surface mapping | ||||
| Web app testing (DAST) | ||||
| CVE & misconfiguration matching | ||||
| Cloud posture (AWS/Azure/GCP) | ||||
| Container & IaC scanning | ||||
| Exploit verification | ||||
| Posture drift (new / fixed / still-failing) | ||||
| Attack surface change monitoring | ||||
| Concurrent scan capacity | Shared | Priority | Priority | Dedicated |
| Workflow & reporting | ||||
| Verified, prioritized findings | ||||
| HTML & PDF reports | ||||
| Slack & email alerts | ||||
| Jira, GitHub, PagerDuty, Teams | ||||
| Webhooks & API access | ||||
| Branded / white-label reports | ||||
| Compliance evidence (SOC 2 / ISO 27001 / PCI DSS) | ||||
| NIS2 & CRA mapping | ||||
| Framework edition pinning (superseded editions) | ||||
| OSCAL, VEX & SARIF exports | ||||
| Retest-to-closure evidence | ||||
| Push to Vanta & Drata | ||||
| Signed assessment attestations | ||||
| Data retention | 90 days | 1 year | 3 years | Custom |
| Security & administration | ||||
| Tenant isolation & encryption | ||||
| SSO & RBAC | ||||
| SAML, SCIM provisioning | ||||
| Audit logs | ||||
| Custom roles & approval workflows | ||||
| Support | Priority | Priority | Dedicated + SLA | |
| Onboarding | Self-serve | Guided | Guided | White-glove + TAM |
Add-ons
What can you bolt on as you grow?
Extend any plan with the capabilities that matter to your program — without over-buying a tier you don't need yet.
Additional targets — $29/month each
Need more than your plan's included application targets? Add them one at a time as your attack surface grows, at about a tenth of a Starter plan — no need to jump a full tier before you're ready.
Additional cloud accounts — $79/month each
Add AWS, Azure, or GCP accounts individually, at deliberate parity with what a standalone posture scanner charges for the same account. Resource capacity is pooled across your accounts.
White-label reporting
Brand exported reports with your own logo and colors — ideal for MSSPs and consultancies delivering findings to their own clients.
Dedicated success & TAM
A named technical account manager, priority engineering escalation, and quarterly program reviews for teams that run RedStrike as a core control.
Startup discount — 30% off
Under $1.5M raised and fewer than 10 people? Take 30% off Starter or Team for your first year. Tell us about your company when you get in touch and we'll apply it.
Choosing a plan
Which plan is right for you?
Most teams pick based on coverage cadence, integration needs, and compliance requirements. Here's the quick way to decide.
Choose Starter if
You're a single team getting started
You have a handful of apps and one cloud account, want to see verified findings quickly, and need Slack and email alerts without heavier integrations or SSO yet.
Choose Team if
You're a growing security function
You need daily and on-change coverage across more targets and several cloud accounts, findings routed into Jira and GitHub, framework-mapped evidence included, and SSO plus RBAC for a real team.
Choose Compliance if
You're in an audit cycle right now
You already run a compliance platform and need what it cannot produce: the test that proves each control. Every framework edition, retest-to-closure evidence, signed attestations, and push straight into Vanta, Drata, or Jira.
Choose Enterprise if
You have scale and procurement needs
You need unlimited targets and accounts, dedicated scan capacity, SAML/SCIM, data residency or private deployment, SLAs, and a dedicated TAM — with procurement and security review support.
Return on investment
Why is continuous cheaper than one big pentest?
A manual engagement typically runs $15,000–$50,000 and takes weeks to schedule and deliver — and it covers your posture on the days it ran. Continuous testing spreads that spend across the year and catches what a point-in-time test structurally cannot. It sits alongside your annual or required pentest, not in place of it.
- Fewer breaches to clean up. Catching a public bucket or a fresh CVE within hours is far cheaper than incident response after exposure.
- Less engineer time wasted. Verified findings mean no more days lost triaging false positives — engineers fix real issues instead.
- Audit prep becomes a byproduct. Continuous, framework-mapped evidence replaces the annual scramble and the consultant hours that come with it.
- Coverage scales flat. Add targets, not pentester days — the marginal cost of testing one more app stays low.
Weighing this against something else?
We publish honest comparisons against human-led PTaaS, continuous scanners, a pentest bundled with your compliance platform, and running the open-source tools yourself — each with a real section on when the alternative is the better buy.
FAQ
Frequently asked questions
Common questions about plans, billing, add-ons, and getting started.
How does RedStrike pricing work?
Plans are billed monthly or annually and scale on two meters: application targets for the testing side, and cloud accounts with a resource ceiling for the posture side. Starter, Team, and Compliance have published prices; Enterprise is quoted to your scope, residency, and support requirements. Annual billing includes a discount over monthly.
What counts as a target, and how are cloud accounts different?
A target is a single application asset you authorize us to test — a web app, an API, or a network range. Cloud accounts are metered separately, because the work of auditing an AWS account tracks the number of resources in it, not the fact that it exists. Each plan therefore includes a number of targets, a number of cloud accounts, and a pooled cloud-resource ceiling across those accounts. You can add either individually as an add-on without jumping a full tier.
What happens if I exceed my plan's resource ceiling?
Nothing breaks and no scan is cut off. We'll get in touch to move you to the next tier or add cloud-account capacity, and we'll show you the resource count behind the number so the conversation starts from data rather than a surprise invoice.
What's the difference between Team and Compliance?
Team includes framework-mapped evidence for current framework editions, which is what most teams need. Compliance is for a live audit: every framework edition including superseded ones you may still be certified against, retest-to-closure evidence proving a finding was fixed rather than just filed, signed assessment attestations, and direct push into Vanta, Drata, and Jira.
Is there a free trial?
Yes. You can start a trial from the demo request flow to run RedStrike against assets you own or are authorized to test, and see verified findings before you commit to a plan. No agents to install and no long procurement to get started.
Can I change plans later?
Absolutely. You can upgrade or downgrade at any time. Upgrades take effect immediately and are prorated; downgrades apply at the start of your next billing cycle. Your targets, findings, and history carry over across plan changes.
How is annual billing discounted?
Annual plans are billed once for the year at a discount compared to twelve monthly payments. If you're weighing budget against coverage, annual is the most cost-effective way to run continuous testing — talk to sales for the current annual rate.
What add-ons are available?
Additional application targets at $29/month each, additional cloud accounts at $79/month each, white-label reporting for MSSPs and consultancies, and a dedicated technical account manager. Early-stage companies under $1.5M raised with fewer than 10 people can take 30% off Starter or Team for the first year.
Do you offer compliance-ready reporting?
Yes, and it is included from Team upward rather than sold as an add-on. Verified findings and cloud posture map to versioned framework editions — OWASP Top 10, OWASP API Top 10, PCI DSS, ISO/IEC 27001, SOC 2, NIS2, the Cyber Resilience Act, NIST SP 800-53, HIPAA, and GDPR — with the specific edition labelled on every control, because auditors read version numbers. See the compliance solution page for how the mapping works.
I'm on the old $799 Team plan — what changes?
Nothing during your current term. Compliance evidence used to be a paid add-on on Team and is now included; existing Team customers get it at their current price for the rest of the term, and the new rate applies at renewal. Starter customers on the previous $199 price keep it through their term as well.
How do you handle authorization and safe testing?
Every engagement requires you to confirm you own or are permitted to test the target. RedStrike uses non-destructive verification and honors your rules of engagement. Read the security and responsible-disclosure pages for specifics on how testing runs safely.
Is there a discount for MSSPs or multiple tenants?
Yes. MSSPs and consultancies running RedStrike across many client tenants get multi-tenant management, white-label reporting, and volume pricing. Contact sales to scope a partner arrangement.
Not sure which plan fits?
Tell us about your attack surface and compliance goals — we'll recommend the right coverage.