Coverage

Built to test every application. Every kind.

One platform, five surfaces. While other tools cover a single layer, RedPick tests the full application stack with the same depth as a specialist pentester, from classic web flaws to the new AI attack surface.

5 surfaces·17 core vulnerability categories·aligned to OWASP Top 10 · API · ASVS · MASVS · LLM

FAQ

Common questions.

What can RedPick test?

Web, mobile (iOS and Android), API (REST, GraphQL, SOAP), desktop (Windows, macOS, Linux, Electron), and LLM or AI features. Coverage is aligned to the OWASP Top 10, API Security Top 10, ASVS, MASVS, and LLM Top 10, with a testing methodology informed by the OWASP testing guides (WSTG for web, MASTG for mobile).

Does RedPick need source code?

No. RedPick is built for black-box testing and needs only a URL, plus credentials for authenticated testing. Every published benchmark result was achieved in black-box, no-hint mode. Grey-box and white-box modes are available when you want to share more.

Can RedPick test authenticated areas behind a login?

Yes. Give RedPick credentials or an authentication flow and it tests as a logged-in user. Multi-user, multi-role, and SSO / SAML / MFA setups are covered on the Professional tier, so access-control and privilege-escalation flaws between roles are in scope, not just the public surface.

Does RedPick also test the underlying system or infrastructure?

Where the target's deployment is in scope, yes. Beyond the application layer, RedPick also runs vulnerability scanning against the underlying system — exposed services, software with known CVEs, and host or network misconfigurations — so a flaw in the app and a weakness in the stack beneath it surface in the same report. It complements the application pentest; it is not a substitute for a dedicated infrastructure engagement.

Point RedPick at any surface. It tests from the outside.

Coverage — Web, Mobile, API, Desktop and LLM Testing | RedPick