Support
Frequently asked
questions
Everything about deployment, data handling, licensing, and our services. Can't find your answer? Talk to us.
Product & Capabilities
What is RedStrike?
RedStrike is an autonomous DAST platform that combines AI agents with proven engines like ZAP / Burp Suite or any MCP-capable tooling. It crawls your application, tests it like a real attacker across 12 injection classes, and returns findings with complete evidence — screenshots, HTTP traces, HAR files, and reproduction steps. Explore the platform →
What makes it different from traditional DAST scanners?
Traditional scanners rely on hardcoded selectors and flood you with false positives. RedStrike's AI reads your application like an attacker — discovering login forms, business logic, and chained exploit paths — while cross-validation with any existing tools with MCP support confirms findings through AI-assisted pentesting. Every report is evidence-backed, so your team verifies instead of triaging.
What applications and protocols does it cover?
Web applications, REST and GraphQL APIs, and non-HTTP services including Redis, WebLogic T3/IIOP, SSH, and MySQL. Coverage maps to OWASP Top 10, OWASP API Security Top 10, SANS/CWE Top 25, and WSTG. See standards coverage →
Is CI/CD integration available?
CI/CD mode is currently in beta. It supports pipeline-driven authentication and can fail builds on Critical and High findings, with a GitHub Actions workflow included. Contact us for early access.
Deployment & Data
Where does RedStrike run?
Entirely on your infrastructure. The platform ships as a single executable — no server to provision, no agent to install on targets. Your scan results, evidence bundles, and configuration live on your machines, under your control.
How does the BYO LLM model work?
You configure RedStrike with your own LLM API key — OpenAI, Anthropic, or Azure. The tool calls the model directly from your machine. We never proxy, store, or see your key, and you keep full control over usage and cost — it simply depends on your application size.
Do you see our scan results?
No. For self-hosted deployments, scan data never leaves your network apart from the LLM API calls to your own provider. For the Starter service, we run the scan under agreed rules of engagement and deliver only the final report. Read our privacy policy →
What are the system prerequisites?
A dedicated on-prem or cloud Windows instance — preferably sandboxed — with 16 GB or more RAM and 500 GB of storage is sufficient. Our experts will guide the one-time setup and provide step-by-step documentation so you're ready to use right away.
Can RedStrike scan production systems?
RedStrike includes scope controls, path exclusions, and non-destructive testing defaults. For production targets, we recommend defining scope and exclusions carefully and starting against a staging environment first.
Pricing & Licensing
What is the difference between Starter and Self-Hosted?
Starter ($399 per application) is an AI pentest service: we run RedStrike against your application and deliver an evidence-based report by email, with one retest included. Self-Hosted ($1,499 per user/year) is the full platform: unlimited scans and applications on your own infrastructure with a BYO LLM key. Compare plans →
Is the 50% launch discount permanent?
No — it's a limited-time offer for early customers as we grow. Lock it in now and it applies to your license term.
How does per-user licensing work?
Each Self-Hosted license is assigned to a named user for 12 months. Multiple team members can benefit from the results (reports are shareable), but operating the scanner requires a licensed seat. Volume pricing is available — talk to us.
Services
What does the Starter AI pentest include?
A single-application AI pentest covering OWASP Top 10, CWE weaknesses, and custom test cases. You receive an evidence-based report by email with reproduction steps and remediation guidance, plus one retest.
What does the retest cover?
One retest of the same application and scope within 30 days of the original test, verifying that your fixes closed the reported findings. Additional retests or expanded scope can be quoted separately.
Does RedStrike replace pentesters?
No — and that's deliberate. RedStrike is human-in-the-loop by design: your testers prompt and steer the AI like they'd brief a colleague, review and validate findings mid-scan, and handle the business-logic reasoning machines can't. The platform removes the grunt work — crawling, payload iteration, evidence capture, report formatting — so testers cover more ground per engagement and every member of the team produces the same standardized, evidence-backed output.
Do you offer other security services?
Yes — web application security, API security testing, network security assessments, and STRIDE threat modelling, delivered by our expert team. View services →
Still have questions?
Our security experts are happy to walk you through deployment, licensing, and coverage.