Pricing
Go continuous, or pay per test.
Self-service AI pentesting you run on demand or wire into your CI/CD: subscribe for continuous coverage with unlimited retests, or run a one-off assessment when you need a point-in-time report. Every option covers all application types and every compliance framework — no per-vulnerability surcharges, no surprise invoices.
- 1 application
- 12 full AI pentests / year (monthly)
- Unlimited retests
- 17 vulnerability categories
- PDF technical report
- Email support
- Extra full scans at $990 each
- Everything in Starter, plus:
- Up to 5 applications
- 24 full pentests / year (pooled)
- CI/CD and API integration
- Branded reports and executive summary
- Signed attestation letter
- Priority support
- Everything in Growth, plus:
- Senior Penetration Tester review
- Application portfolio
- CI/CD-metered continuous scanning (volume rate)
- SLA guarantees
- Dedicated account manager
- On-premise deployment
All prices exclude VAT · billed annually · extra full scans $990 each · retests always unlimited.
Feature comparison
What each plan includes.
Testing capability is identical whether you subscribe or buy per-test — the same engine, categories, and compliance mapping across every plan. This table compares all five: the three subscriptions and the two per-test tiers.
| Feature | Starter | Growth | Scale | Professional | Enterprise |
|---|---|---|---|---|---|
| Applications covered | 1 | Up to 5 | Portfolio | Per test | Unlimited |
| CI/CD & API integration | - | Yes | Yes | - | Yes |
| Retests | Unlimited | Unlimited | Unlimited | 1 included | Unlimited |
| Branded report + exec summary | - | Yes | Yes | Yes | Yes |
| Signed attestation letter | - | Yes | Yes | Yes | Yes |
| Senior pentester review | - | - | Yes | - | Yes |
| SLA guarantees | - | - | Yes | - | Yes |
| Dedicated account manager | - | - | Yes | - | Yes |
| On-premise deployment | - | - | Yes | - | Yes |
| Support | Priority | Dedicated | Priority | Dedicated |
Need expert-led testing?
Beyond the software tiers, our founding partner BeDefended offers a fully managed pentest: senior pentesters running manual testing in parallel with RedPick’s AI engine. Compliance-mapped reports (PCI DSS, SOC 2, NIS2, DORA, ISO 27001, GDPR, OWASP ASVS), a free retest after remediation, and an executive debrief session. Custom-scoped and quoted.
FAQ
Common questions.
Per-test or subscription — which should I choose?
Per-test is a one-off, point-in-time assessment with a full report — ideal for a compliance deadline or a specific release. A subscription gives continuous coverage: recurring AI pentests on your registered applications plus unlimited retests, so you re-verify fixes and catch regressions between releases without re-scoping each time.
What counts as a scan versus a retest?
A full scan is a complete new assessment of an application. A retest re-verifies a specific finding we already reported, after you have fixed it — unlimited under fair use, and not an open re-scan of the app. Full scans are included up to each plan's monthly allowance, with extra scans at $990.
Is there human review, or is it fully automated?
Fully automated by default. The standard per-test and subscription tiers run autonomously — trigger them on demand or straight from your CI/CD and get results with no human in the loop. Senior penetration-tester review is reserved for Enterprise and custom plans, and the managed engagement adds manual testing in parallel with the AI engine.
How fast are results?
Automated tests return within one working day. Enterprise and managed engagements that add expert review take longer by design.
Does RedPick support compliance frameworks?
Yes. Findings are mapped to PCI DSS 4.0, SOC 2, ISO 27001, NIS2, DORA, GDPR, and OWASP ASVS, with audit-ready evidence and, on the higher tiers, a signed attestation letter.
