Transparent pricing

Pricing that scales with your attack surface

Start with continuous testing on a few targets and grow into full multi-cloud coverage, integrations, and compliance evidence — without renegotiating a pentest every quarter.

Starter

$199/month

For a single team securing a handful of web apps and APIs.

Start free trial
  • Up to 3 targets
  • Weekly continuous scans
  • Verified findings
  • Slack + email alerts
Most popular

Team

$799/month

For growing security teams that need daily coverage and integrations.

Request a demo
  • Up to 15 targets
  • Daily scans + on-change triggers
  • Jira, GitHub, PagerDuty integrations
  • Multi-cloud CSPM (AWS/Azure/GCP)
  • SSO + RBAC

Enterprise

Custom

For organizations with compliance, scale, and procurement requirements.

Contact sales
  • Unlimited targets
  • Continuous engagements
  • SAML SSO, SCIM, audit logs
  • Compliance evidence & SLAs
  • Dedicated support + TAM

Prices in USD. Annual billing available at a discount. Need something specific? Talk to our team.

Compare plans

What's included in each plan?

A full breakdown of scanning coverage, workflow, and administration across Starter, Team, and Enterprise.

FeatureStarterTeamEnterprise
Scanning & coverage
Targets315Unlimited
Scan cadenceWeeklyDaily + on-changeContinuous
Recon & attack surface mapping
Web app testing (DAST)
CVE & misconfiguration matching
Cloud posture (AWS/Azure/GCP)
Exploit verification
Attack surface change monitoring
Concurrent scan capacitySharedPriorityDedicated
Workflow & reporting
Verified, prioritized findings
HTML & PDF reports
Slack & email alerts
Jira, GitHub, PagerDuty, Teams
Webhooks & API access
Branded / white-label reports
Compliance evidence (SOC 2 / ISO 27001 / PCI)Add-on
Data retention90 days1 yearCustom
Security & administration
Tenant isolation & encryption
SSO & RBAC
SAML, SCIM provisioning
Audit logs
Custom roles & approval workflows
SupportEmailPriorityDedicated + SLA
OnboardingSelf-serveGuidedWhite-glove + TAM

Add-ons

What can you bolt on as you grow?

Extend any plan with the capabilities that matter to your program — without over-buying a tier you don't need yet.

Compliance evidence pack

Auto-map verified findings and cloud posture to SOC 2, ISO 27001, and PCI DSS controls, with exportable auditor-ready reports. Included on Enterprise; available as an add-on on Team.

Additional targets

Need more than your plan's included targets? Add capacity in blocks as your attack surface grows — no need to jump a full tier before you're ready.

White-label reporting

Brand exported reports with your own logo and colors — ideal for MSSPs and consultancies delivering findings to their own clients.

Dedicated success & TAM

A named technical account manager, priority engineering escalation, and quarterly program reviews for teams that run RedStrike as a core control.

Choosing a plan

Which plan is right for you?

Most teams pick based on coverage cadence, integration needs, and compliance requirements. Here's the quick way to decide.

Choose Starter if

You're a single team getting started

You have a handful of apps and one cloud account, want to see verified findings quickly, and need Slack and email alerts without heavier integrations or SSO yet.

Choose Team if

You're a growing security function

You need daily and on-change coverage across more targets, multi-cloud CSPM, and findings routed into Jira, GitHub, and PagerDuty — plus SSO and RBAC for a real team.

Choose Enterprise if

You have scale and compliance needs

You need unlimited targets, continuous engagements, SAML/SCIM, audit logs, built-in compliance evidence, SLAs, and a dedicated TAM — with procurement and security review support.

Return on investment

Why is continuous cheaper than one big pentest?

A single annual engagement costs tens of thousands and covers one day of your posture. Continuous testing spreads that spend across the whole year — and catches the issues a point-in-time test structurally can't.

  • Fewer breaches to clean up. Catching a public bucket or a fresh CVE within hours is far cheaper than incident response after exposure.
  • Less engineer time wasted. Verified findings mean no more days lost triaging false positives — engineers fix real issues instead.
  • Audit prep becomes a byproduct. Continuous, framework-mapped evidence replaces the annual scramble and the consultant hours that come with it.
  • Coverage scales flat. Add targets, not pentester days — the marginal cost of testing one more app stays low.
24/7
Coverage vs. one day a year
~0
False-positive triage cost
Flat
Cost to add a target
3
Frameworks, evidence included

FAQ

Frequently asked questions

Common questions about plans, billing, add-ons, and getting started.

How does RedStrike pricing work?

Plans are billed monthly or annually and scale by the number of targets and the depth of coverage you need. Starter and Team have published prices; Enterprise is quoted to your scope, compliance, and support requirements. Annual billing includes a discount over monthly.

What counts as a target?

A target is an asset you authorize RedStrike to test — typically a web application, an API, a network range, or a cloud account. You can add, remove, and re-scope targets at any time as your environment changes, and add capacity in blocks without jumping a full tier.

Is there a free trial?

Yes. You can start a trial from the demo request flow to run RedStrike against assets you own or are authorized to test, and see verified findings before you commit to a plan. No agents to install and no long procurement to get started.

Can I change plans later?

Absolutely. You can upgrade or downgrade at any time. Upgrades take effect immediately and are prorated; downgrades apply at the start of your next billing cycle. Your targets, findings, and history carry over across plan changes.

How is annual billing discounted?

Annual plans are billed once for the year at a discount compared to twelve monthly payments. If you're weighing budget against coverage, annual is the most cost-effective way to run continuous testing — talk to sales for the current annual rate.

What add-ons are available?

Common add-ons include the compliance evidence pack (SOC 2 / ISO 27001 / PCI DSS mapping and reports), additional target capacity, white-label reporting for MSSPs, and a dedicated technical account manager. Add-ons attach to Team and Enterprise plans.

Do you offer compliance-ready reporting?

Yes. Team includes compliance evidence as an add-on and Enterprise includes it by default, mapping verified findings to SOC 2, ISO 27001, and PCI DSS controls. See the compliance solution page for how the mapping works.

How do you handle authorization and safe testing?

Every engagement requires you to confirm you own or are permitted to test the target. RedStrike uses non-destructive verification and honors your rules of engagement. Read the security and responsible-disclosure pages for specifics on how testing runs safely.

Is there a discount for MSSPs or multiple tenants?

Yes. MSSPs and consultancies running RedStrike across many client tenants get multi-tenant management, white-label reporting, and volume pricing. Contact sales to scope a partner arrangement.

Not sure which plan fits?

Tell us about your attack surface and compliance goals — we'll recommend the right coverage.