The platform
Born from offense. Built for defense.
RedPick is the application security platform built by the team behind BeDefended, who achieved perfect scores on every major pentesting benchmark.
We got tired of tools that miss what matters.
BeDefended has been doing application security for years, manually. Hundreds of pentests, thousands of vulnerabilities found, across every type of application. We know exactly how human pentesters think, where they look, and what they find.
RedPick is that knowledge encoded into an autonomous agent. It reasons about your application and tests it the way our pentesters do, running many assessments in parallel, around the clock.
Proof, not promises.
RedPick was not just built and claimed to work. It was submitted to the hardest independent application security benchmarks in the world, and achieved perfect scores on all of them.
Among publicly reported results, no other tool has currently matched these scores on all of these benchmarks. See the full evidence, category by category.
See the benchmarksFounded by the BeDefended team
The domain expertise behind the autonomous execution.
RedPick Inc. was founded by the team at BeDefended, an application security consultancy active since 2018. RedPick’s vulnerability patterns and attack techniques are rooted in the real engagements carried out by that team.
Leadership
The management team.
RedPick Inc. is an independent company. The profiles below are the management team: the two founders who built the platform, alongside an experienced CEO and COO.
A serial cybersecurity entrepreneur and B2B SaaS investor. Aviram co-founded Beyond Security and led it as CEO until its acquisition by Fortra in 2021, has two further successful exits behind him, and holds an early-stage portfolio of 40+ B2B SaaS companies across the US, Israel, and Korea. At RedPick he drives company strategy, go-to-market, and US expansion.
Application security consultant with 14+ years of experience in pentesting and code review. Co-author of the OWASP Testing Guide v4, he holds 12 security certifications (including OSCP+, OSWE, CRTO, CSSLP), has spoken at Security Summit and HackInBo, and has been a trainer at OWASP AppSec Europe. Davide founded BeDefended in 2018 and today leads RedPick's product vision.
An application security consultant with 11+ years in pentesting and code review of web and mobile applications. He discovered a critical SSL vulnerability in a popular iOS library that gained worldwide attention and contributed to the Italian translation of the OWASP Testing Guide v4. A certified EC-Council instructor, he has delivered training at OWASP AppSec Europe. At RedPick, he leads technical development and the platform's agentic architecture.
An operations executive with a career spanning the US and APAC: CEO of Jiran Group USA since 2016, previously VP at Namo Interactive and, for over a decade, an executive at Microsoft in the APAC region across Windows, Office marketing, Xbox channel operations, and supply chain. At RedPick he oversees finance and day-to-day operations.
These four are the management team, not the whole company: behind them RedPick has a wider team of senior penetration testers, security engineers, and researchers, plus the partners and investors backing RedPick Inc.
What makes RedPick different
Application-first
Pure application security is where RedPick goes deep: web, mobile, API, desktop, and LLM. It now also scans the infrastructure the application runs on, the network surface an attacker reaches once through the app, so a test maps the full path rather than the application alone. That focus is why it stays the best at the application layer.
Agentic, not automated
There is a difference between automation (run the same checks every time) and agency (reason about what to do next). RedPick makes decisions, adapts strategies, and chains findings like a human would.
Built by real pentesters
RedPick was built by penetration testers who encoded years of hands-on offensive-security experience into the engine, not by a machine-learning team new to application security.
Let’s go
Ready to see what RedPick finds?
Start a pentest, or see how RedPick scores against the public benchmarks.
