RedCapraRedCapra
Local-first security audit workbench

The workbench for
serious penetration testers

Replace your spreadsheet-and-Burp-notes workflow. Structure engagements, triage findings with AI, and generate client-ready reports — without your data leaving your machine.

No credit card required · Free forever on Solo

Launch free workbench →See how it works
RedCapra — Scan results for example.com
Summary
High1
Medium2
Low1
Info1
44 checks completed
0 errors · 2.4s
HIGHMissing Content-Security-Policy headerHeaders
MEDSPF record allows +allDNS / Email
MEDCORS allows wildcard originHeaders
LOWX-Powered-By header exposes frameworkHeaders
INFOHSTS max-age below 1 yearTLS
🛡️
Read-only scans
Non-destructive checks only — no changes to your targets
🔒
Local-first
Data stays on your machine unless you opt into cloud sync
📜
Full audit trail
Every scan action logged with rollback guidance
44 checks
OWASP baseline, DNS, TLS, headers, injection, and more

How it works

Three steps from target to deliverable.

01
Define scope

Set your target, choose a scan profile, and configure checks. RedCapra handles 44 security checks out of the box.

02
Scan & triage

Run bounded, non-destructive scans. AI triage classifies findings by severity and suggests remediation priorities.

03
Report & track

Generate a client-ready report with executive summary. Track remediation progress across engagements over time.

A full engagement workflow

From scope to report — every phase covered.

🔍
Guided recon

Structured recon phases — passive, active, asset discovery — with built-in checklists to ensure nothing is missed.

⚠️
Finding triage

Log vulnerabilities with CVSS scoring, evidence attachments, and dispositions. Track open, confirmed, and closed findings.

📋
Engagement tracking

Scope definition, rules of engagement, client contacts, and timelines — all attached to the engagement, not a spreadsheet.

🤖
AI analysis

Claude-powered analysis suggests triage classifications, attack chain context, and remediation guidance from your raw findings.

🌐
Domain intelligence

Group and track domains across engagements. Flag high-risk assets and watch attack surface changes over time.

📄
Report generation

Generate professional pentest reports from your findings in one click — executive summary included.

Pricing

Solo tool is always free. Cloud sync and AI triage for professionals.

Solo
€0 forever
  • 3 scans per month
  • All 44 security checks
  • Full finding tracker
  • Report generation
  • Local-only storage
Current plan
Analyst
€29/mo
  • Everything in Solo
  • Unlimited scans
  • Cloud sync & backup
  • Multi-device access
  • Export to PDF / JSON
Start Analyst
Most popular
Pro
€79/mo
  • Everything in Analyst
  • AI-assisted triage
  • Team workspaces (3 seats)
  • Custom report templates
  • Priority support
Start Pro
Team
€199/mo
  • Everything in Pro
  • Unlimited seats
  • SSO / SAML
  • Audit log
  • Custom policy profiles
Start Team

Frequently asked questions

Is my data stored on your servers?+

By default, no. RedCapra is local-first — all scan data stays on your machine. Cloud sync is opt-in on paid plans and uses end-to-end encryption.

What security checks are included?+

44 checks across TLS/SSL, DNS & email auth (SPF, DKIM, DMARC), HTTP headers, CSP, injection vectors, SSRF, subdomain enumeration, and more.

Can I scan any website?+

You can scan any target you own or have explicit written authorization to test. RedCapra enforces an authorization checkbox before every scan.

What are the limits on the free Solo plan?+

Solo gives you 3 scans per month with all 44 checks, full finding tracker, and report generation. Data is local-only — no cloud sync, no AI triage.

Can I cancel my subscription anytime?+

Yes. Cancel from Settings or the Stripe billing portal at any time — no lock-in, no cancellation fees. Your local data is always yours.

Do you offer team plans?+

Yes. The Pro plan includes 3 seats, and the Team plan offers unlimited seats with SSO/SAML, audit logging, and custom policy profiles.

How does AI triage work?+

Findings are analyzed by Claude to suggest severity classifications, attack chain context, and prioritized remediation steps. You review and approve — AI assists, you decide.

How is RedCapra different from Burp Suite or Nessus?+

RedCapra is a structured engagement workbench, not a proxy or vulnerability scanner. Think of it as the layer above your scanner — where you triage, track, and deliver.

Ready to run your first scan?

Free forever on the Solo plan. No credit card required.

Launch free workbench →
RedCapra — Security Audit Workbench