Coverage
Built to test every application. Every kind.
One platform, five surfaces. While other tools cover a single layer, RedPick tests the full application stack with the same depth as a specialist pentester, from classic web flaws to the new AI attack surface.
Web application testing
In-depth testing against modern frameworks (React, Angular, Vue, server-side rendered apps, SPAs) across 17 core vulnerability categories. Not surface-level scanning: real penetration testing powered by specialist AI agents.
RedPick covers the full OWASP Top 10, from injection and broken access control to insecure deserialization, plus the business-logic flaws no checklist will ever catch.
Mobile application testing
Android and iOS applications tested end-to-end, from the app itself to its API backend, with full coverage of the OWASP Mobile Top 10.
Static and dynamic analysis, from insecure storage and secrets in binaries to certificate-pinning bypass and data leakage. RedPick tests the app and its API as one system: a client-side bypass only counts if the server fails to re-validate.
API security testing
REST, GraphQL, and SOAP APIs tested with the same depth as a specialist API pentester, with complete coverage of the OWASP API Security Top 10.
RedPick imports OpenAPI, Swagger, GraphQL, or WSDL specs and maps every endpoint, or discovers them by crawling and traffic analysis when there is no spec. GraphQL and authentication get specialist depth, from introspection and query-complexity abuse to JWT and OAuth flaws.
Desktop application testing
Windows, macOS, Linux, and Electron applications. Thick clients tested with the same rigor as web apps.
Binary analysis (reverse engineering, memory corruption), local security (privilege escalation, insecure permissions, IPC), and secrets storage, with platform-specific depth: DLL hijacking on Windows, Gatekeeper and Keychain on macOS, context isolation on Electron, SUID/SGID on Linux.
LLM and AI security testing
Your AI features are an attack surface. Prompt injection, data extraction, jailbreaking, tested by AI that understands AI, with full OWASP LLM Top 10 coverage.
Prompt injection is the SQL injection of the AI era, and most teams are not equipped to test for it. RedPick tests direct and indirect injection, data extraction, tool abuse, and multi-step jailbreaking. Static scanners fire fixed payloads; LLM exploitation needs adaptive, multi-turn attacks from agents that understand language models because they are language models.
FAQ
Common questions.
What can RedPick test?
Web, mobile (iOS and Android), API (REST, GraphQL, SOAP), desktop (Windows, macOS, Linux, Electron), and LLM or AI features. Coverage is aligned to the OWASP Top 10, API Security Top 10, ASVS, MASVS, and LLM Top 10, with a testing methodology informed by the OWASP testing guides (WSTG for web, MASTG for mobile).
Does RedPick need source code?
No. RedPick is built for black-box testing and needs only a URL, plus credentials for authenticated testing. Every published benchmark result was achieved in black-box, no-hint mode. Grey-box and white-box modes are available when you want to share more.
Can RedPick test authenticated areas behind a login?
Yes. Give RedPick credentials or an authentication flow and it tests as a logged-in user. Multi-user, multi-role, and SSO / SAML / MFA setups are covered on the Professional tier, so access-control and privilege-escalation flaws between roles are in scope, not just the public surface.
Does RedPick also test the underlying system or infrastructure?
Where the target's deployment is in scope, yes. Beyond the application layer, RedPick also runs vulnerability scanning against the underlying system — exposed services, software with known CVEs, and host or network misconfigurations — so a flaw in the app and a weakness in the stack beneath it surface in the same report. It complements the application pentest; it is not a substitute for a dedicated infrastructure engagement.
