RedLens AI pricing
Five published plans, from free to enterprise. Every plan runs the full Master Attack Schema and maps every finding to all seven frameworks; plans differ only in how much you can run and how it is deployed.
Simple, transparent pricing
Every plan includes a free assessment so you see exactly what we find before you commit to anything.
Every plan includes the full Master Attack Schema, every finding mapped to all seven frameworks, the evidence package, PDF reports, email alerts, SIEM export and the CI/CD build gate. Plans differ only in the limits below, and each one is enforced in the platform, not just written here.
- ✓ 300 hosted scans a month
- ✓ Up to 25 scans a day
- ✓ No cap on AI assets under test
- ✓ Full-strength judge model on every scan
- ✓ Self-serve checkout
- ✓ 1 AI agent or model under test
- ✓ 1 monitored production workflow
- ✓ Monthly automated scans
- ✓ Single-methodology scheduled scans
- ✓ Self-serve checkout
- ✓ Up to 25 monitored production workflows
- ✓ 50,000 attack simulations/mo included
- ✓ Weekly automated scans
- ✓ Recurring full-coverage sweeps: every methodology on one schedule
- ✓ No cap on AI assets under test
- ✓ No platform cap on workflows, assets or simulations
- ✓ Daily automated scans
- ✓ Recurring full-coverage sweeps, weekly at most on every plan
- ✓ Self-hosted on-premise Docker deployment
- ✓ Custom SLA available
Every plan starts with a free AI security assessment. No credit card required to try it · Enterprise starting at $150k/yr, custom pricing for complex deployments
Three free options, and how they differ
An account that stays free
25 hosted scans a month, up to 5 a day, one AI asset under test, judged by Claude Haiku 4.5. No card. It is not a trial and it does not expire.
Create a free account →The full Team plan for two weeks
300 scans a month, 25 a day, the full-strength judge and no asset cap, with no card. On day 14 you keep Team by adding a payment method, or move to the free tier with everything kept.
Start the trial →One guided assessment, no account
RedLens writes adversarial prompts for the AI system you describe; you send each one to your AI and paste its reply back, and RedLens judges the replies and gives you a report mapped to HIPAA, the NIST AI RMF and the OWASP GenAI Top 10. To have RedLens send the attacks itself, use the free tier.
Run the free assessment →The terms on the plan cards, defined
- Hosted scan
- One red-team run of one methodology against one target, using RedLens's attacker and judge models. The count is of scans started, so a scan that errors still counts.
- Monthly and daily limits
- Monthly allowances count scans started in the calendar month and reset on the 1st (UTC). The daily limit is a fair-use throttle that resets at midnight UTC.
- Monitored production workflow
- A saved scan target with automatic scans switched on. Scans you start by hand do not use one.
- Attack simulations
- The individual attacks sent during scans. Professional includes 50,000 a month.
- Judge model
- The model that decides whether each attack succeeded. The free tier uses Claude Haiku 4.5; every paid plan uses the full-strength judge.
- Full-coverage sweep
- One schedule that runs every standard methodology against a target, so coverage does not depend on someone remembering to run each one. Professional and Enterprise, weekly at most.