Documentation
Everything you need to get started with RedCapra.
Getting Started
What is RedCapra?
RedCapra is a local-first security audit workbench for penetration testers. It runs 50 bounded checks against web targets you own or are authorized to test, then generates client-ready reports.
How do I run my first scan?
Go to the workbench, enter a target URL, confirm you're authorized to test it, choose a scan preset (Quick Surface is a good start), and click Run RedCapra Scan. Results appear in the right panel.
Is my data stored anywhere?
Scans run on RedCapra's servers, but by default the results stay in your browser — we keep only a short operational record of each scan (time, target, and counts) to enforce plan limits and investigate abuse. With a paid plan you can enable cloud sync for multi-device access and durable storage.
Scan Presets
Quick Surface
A fast, non-intrusive scan covering TLS, DNS, security headers, and exposure checks. Safe to run against any target. Takes about 30 seconds.
Web App Standard
The most common preset for web app pentests. Adds CORS, XSS reflection, SQL signals, cookie analysis, CSP checks, and form auditing on top of Quick Surface.
Deep Authorized
Full-depth scan including injection checks (SSRF, path traversal, CRLF, SSTI, command injection), session analysis, and authenticated route discovery. Only use on targets where you have explicit written authorization.
DNS/TLS Only
Focused audit of DNS records (SPF, DMARC, DKIM, CAA, DNSSEC) and TLS configuration. No HTTP requests to the target.
Client-Safe Recon
Passive reconnaissance only — WAF detection, security.txt, CT logs, HTTP methods. Safe to show clients during initial scoping calls.
Pathfinder
Read-only access-depth mapping. Discovers routes from the homepage, robots.txt, and sitemap, then maps which are public vs authenticated.
Reports
What report formats are available?
Full technical Markdown, client-safe Markdown (redacted evidence), JSON export, and report packs (all formats + retest scripts + rules of engagement).
Can I share reports?
Yes. Generate a shared report link with a token. Links expire after 14 days by default. Recipients don't need a RedCapra account.
Portfolio & Workspace
What is a managed domain?
A target you track across multiple scans. Add domains to your portfolio to compare findings over time, track remediation, and batch-scan groups.
Can I export my workspace?
Yes. Export your entire workspace as JSON from the workbench settings. Import it on another machine or share it with a colleague.
Plans & Billing
What's included in the free Solo plan?
3 scans per month with 47 of the 50 checks. No cloud sync, no AI triage, no shared reports. Your results stay in your browser.
What does Analyst add?
The 3 remaining advanced checks (Pathfinder, Blind SSRF, Gentle bump) for all 50, cloud sync and backup, multi-device access, PDF/JSON export, and shared report links.
What does Pro add?
AI-assisted triage (Claude-powered), team workspaces with 3 seats, full report pack export, and the audit log.
What does Team add?
Unlimited seats, SSO (OIDC) authentication, custom policy profiles, and priority onboarding for enterprise compliance.
How do I manage my subscription?
Open Settings in the workbench and use Manage billing — that opens the Stripe billing portal.
RedCapra