RedCapraRedCapra
Launch workbench →

Documentation

Everything you need to get started with RedCapra.

Getting Started

What is RedCapra?

RedCapra is a local-first security audit workbench for penetration testers. It runs 44 bounded checks against web targets you own or are authorized to test, then generates client-ready reports.

How do I run my first scan?

Go to the workbench, enter a target URL, confirm you're authorized to test it, choose a scan preset (Quick Surface is a good start), and click Run RedCapra Scan. Results appear in the right panel.

Is my data stored anywhere?

By default, RedCapra is local-first — scan results stay in your browser. With a paid plan, you can enable cloud sync via Vercel KV for multi-device access and durable storage.

Scan Presets

Quick Surface

A fast, non-intrusive scan covering TLS, DNS, security headers, and exposure checks. Safe to run against any target. Takes about 30 seconds.

Web App Standard

The most common preset for web app pentests. Adds CORS, XSS reflection, SQL signals, cookie analysis, CSP checks, and form auditing on top of Quick Surface.

Deep Authorized

Full-depth scan including injection checks (SSRF, path traversal, CRLF, SSTI, command injection), session analysis, and authenticated route discovery. Only use on targets where you have explicit written authorization.

DNS/TLS Only

Focused audit of DNS records (SPF, DMARC, DKIM, CAA, DNSSEC) and TLS configuration. No HTTP requests to the target.

Client-Safe Recon

Passive reconnaissance only — WAF detection, security.txt, CT logs, HTTP methods. Safe to show clients during initial scoping calls.

Pathfinder

Read-only access-depth mapping. Discovers routes from the homepage, robots.txt, and sitemap, then maps which are public vs authenticated.

Reports

What report formats are available?

Full technical Markdown, client-safe Markdown (redacted evidence), JSON export, and report packs (all formats + retest scripts + rules of engagement).

Can I share reports?

Yes. Generate a shared report link with a token. Links expire after 14 days by default. Recipients don't need a RedCapra account.

Portfolio & Workspace

What is a managed domain?

A target you track across multiple scans. Add domains to your portfolio to compare findings over time, track remediation, and batch-scan groups.

Can I export my workspace?

Yes. Export your entire workspace as JSON from the workbench settings. Import it on another machine or share it with a colleague.

Plans & Billing

What's included in the free Solo plan?

Unlimited local scans with all 44 checks. No cloud sync, no AI triage, no shared reports. Your data stays in your browser.

What does Analyst add?

Cloud sync and backup, multi-device access, PDF/JSON export, and shared report links.

What does Pro add?

AI-assisted triage (Claude-powered), team workspaces with 3 seats, custom report templates, and priority support.

What does Team add?

Unlimited seats, SSO/SAML authentication, audit log, and custom policy profiles for enterprise compliance.

How do I manage my subscription?

Go to the billing portal via the workbench settings or visit /api/stripe/portal directly.

RedCapra — Security Audit Workbench