Enterprise security testing across a large, mixed estate
Unlimited targets and cloud accounts, SAML and SCIM, custom roles, and unlimited retention — with tenancy enforced in the database rather than in application code.
RedStrike is a continuous security testing and cloud posture platform for enterprise security teams. The Enterprise plan removes limits on targets, cloud accounts, cloud resources, seats, and retention, and adds SAML single sign-on with SCIM provisioning, custom roles, and audit logging. Multi-tenancy is enforced with PostgreSQL row-level security, so isolation between organisations and workspaces holds at the storage layer. Findings map to SOC 2, ISO/IEC 27001:2022, PCI DSS 4.0.1, NIST SP 800-53 Rev. 5, HIPAA, GDPR, NIS2, and the EU Cyber Resilience Act, with the framework edition pinnable to the one an assessment is against.
The problem
Why enterprise programmes fragment
Not for lack of tools. Because a dozen tools produce a dozen severity scales, a dozen consoles, and no single answer.
Findings arrive in incompatible formats
Each scanner has its own severity model and its own idea of what counts as one issue. Reconciling them into a ranked list is manual work that is redone every reporting cycle.
The estate spans everything at once
Legacy on-premises services, containers, multiple cloud providers, mobile apps, and third-party APIs. Coverage that understands one of those leaves the rest unmeasured.
Access to findings is itself sensitive
A consolidated vulnerability list is an attacker's roadmap. Who can read it must map onto your identity model and be recorded, which rules out tools with a flat user list.
Multiple frameworks, multiple editions, one estate
Different business units are assessed against different frameworks, and an assessment underway against a superseded edition does not want to be silently re-scored against a new one.
How RedStrike helps
Built to survive enterprise identity, scale, and procurement
Each item is an Enterprise-plan entitlement or an architectural property of the platform.
SAML SSO, SCIM, and custom roles
Single sign-on with SAML, SCIM provisioning for lifecycle management, and custom roles map platform access onto your existing identity model. Audit logging records who accessed what.
Isolation enforced in PostgreSQL
Row-level security policies scope every query by organisation, so tenancy does not depend on application code getting each query right. Cloud credentials are encrypted at rest with Fernet.
One engine, whole estate
Web, API, network, TLS, container, infrastructure-as-code, mobile, and multi-cloud posture testing run from one platform with one severity model and one de-duplicated queue.
Framework edition pinning
An engagement can be pinned to the framework edition its assessment is against, so a mid-cycle standard revision does not invalidate evidence already collected.
Attack surface and posture drift
Continuous discovery keeps the asset inventory current, and posture drift tracking surfaces configuration changes between scans rather than at the next audit.
Machine-readable evidence
Exports include PDF, HTML, Markdown, JSON, CSV, SARIF, OpenVEX, and OSCAL, with attestation documents and white-labelled branding available.
Compliance coverage
Which frameworks this maps to — and exactly how far the mapping goes
Every framework in the registry is available, and editions can be pinned per engagement. Framework-labelled cloud rulesets run on AWS; Azure and GCP accounts are graded against CIS Foundations benchmarks.
| Framework | Edition mapped | Cloud coverage |
|---|---|---|
| ISO/IEC 27001ISO/IEC | 2022 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| SOC 2AICPA | 2017 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| PCI DSSPCI Security Standards Council | 4.0.1 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| NIST SP 800-53NIST | r5 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| NIS2European Union | 2022/2555 | Mapped on findings from application, API, and network testing. No native cloud-resource checks — pair with CIS benchmark grading for cloud evidence. |
| HIPAA Security RuleUS HHS | security-rule | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
Every cloud account is graded against CIS Foundations benchmarks on AWS, Azure, GCP, and Kubernetes clusters against the CIS Kubernetes benchmark, regardless of which frameworks above apply to you. Evidence can be exported as a report or pushed into Vanta or Drata.
How it works
From connected to evidence in four steps
Define scope
Add the domains, APIs, and cloud accounts in scope, with rules of engagement recorded before any test runs.
Test continuously
Application, API, network, container, and cloud checks run on a schedule instead of once a year, so drift is caught within a scan cycle.
Verify & de-duplicate
Findings from multiple tools are correlated into one issue, evidence is collected, and severity is scored so the list you read is the list that matters.
Export evidence
Results are mapped to framework controls and exported as a report, or pushed into Vanta or Drata.
Outcomes
What changes once this is running
- Replace a dozen severity scales with one normalized, de-duplicated, exploitability-weighted queue.
- Map platform access onto your identity provider with SAML, SCIM, and custom roles.
- Cover legacy, container, cloud, and mobile estate from one programme rather than four.
- Pin framework editions so an in-flight assessment is not re-scored mid-cycle.
- Export evidence as OSCAL, SARIF, and OpenVEX instead of into a manual transcription step.
Related
Go deeper on the parts that matter to you
Continuous Pentesting
Always-on, verified offensive testing across apps, APIs, and network — not a once-a-year snapshot.
Learn more →Cloud Security (CSPM)
CIS-benchmarked posture across AWS, Azure, and GCP, with drift caught inside a scan cycle.
Learn more →Pricing
What each plan includes, which limits are metered, and where the feature lines are drawn.
Learn more →FAQ
Frequently asked questions
Common questions about RedStrike for Enterprise.
What are the Enterprise plan limits?
Targets, cloud accounts, cloud resources, scans per day, seats, and data retention are all unlimited on Enterprise. Pricing is custom rather than published, because the shape depends on estate size. The Compliance plan below it covers 50 targets, 15 cloud accounts, and 100,000 cloud resources with three years of retention at $2,499 per month.
How is multi-tenancy enforced?
With PostgreSQL row-level security policies scoping queries by organisation, so isolation holds at the database layer rather than depending on every application query being written correctly. Stored cloud credentials are encrypted at rest with Fernet, and all organisation-modifying actions are recorded in an audit log.
Does RedStrike support SAML and SCIM?
Yes, on the Enterprise plan, alongside custom roles. Single sign-on without SCIM provisioning is available from the Team plan upward, and audit logging is included from Team as well.
Can it be deployed inside our own infrastructure?
The platform is deployed with Docker Compose and is Kubernetes-ready, using PostgreSQL, MongoDB, and Redis, so it can run in infrastructure you control. Specific hosting, network isolation, and data-residency requirements are worth raising directly before an evaluation rather than after.
What does framework edition pinning actually do?
Frameworks change. An assessment underway against ISO/IEC 27001:2013 or PCI DSS 3.2.1 should keep being scored against that edition until it completes. Edition pinning fixes an engagement to a specific edition, and reports label superseded editions explicitly rather than printing a bare framework name.
How do findings reach our existing workflow?
Findings file into Jira and GitHub Issues with automatic filing rules, webhooks dispatch on scan and finding events, compliance evidence pushes into Vanta or Drata, and the platform API covers scan creation, finding retrieval, and report generation.
One programme across the whole estate
Unlimited scale, enterprise identity, and evidence in the formats your process expects.