RedRays
RedRays is a SAP-focused cybersecurity firm selling a SAP-certified vulnerability assessment platform, an ABAP code scanner, and professional penetration testing services to large enterprises, SAP consultants, and penetration testers globally.
- Company typePrivate
- Founded2010
- HeadquartersDover, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What RedRays does
RedRays is a private cybersecurity company that specializes exclusively in security for SAP enterprise software. The firm, founded in 2010 and operating from a Dover, Delaware headquarters with a research and development center in Yerevan, Armenia, sells a SAP-certified security platform that performs agentless, Docker-deployed vulnerability assessment, configuration checks, port and service scanning, and threat modeling across SAP Gateway, HANA, S/4HANA, ABAP, AS Java, Business Objects, and B1 environments. The product is delivered in three subscription editions targeted respectively at large enterprises, SAP consultants, and penetration testers, and is complemented by an add-on ABAP Code Scanner with 164 built-in security checks and an Eclipse IDE plugin for shift-left scanning.
Beyond the platform, RedRays monetizes a portfolio of professional services including black/gray/white-box SAP penetration testing, cloud and BTP-specific security audits, hybrid automated-plus-expert assessments, and a two-day hands-on SAP security training program. Open-source assets — the SAP Threat Modeling Tool and a Python 3 port of the pysap protocol library — anchor a community-led demand-generation motion alongside conference presence at Black Hat MEA, TROOPERS, Hack Paris, NULLCON, and NSEC. Customers are reported to include Fortune 500 companies and critical infrastructure organizations, alongside the SAP consultant and pentester personas reached through the platform's dedicated editions.
Revenue mechanics combine tiered monthly SaaS subscriptions (priced by SAP server count and feature set) with higher-margin professional services engagements. Distribution runs through direct sales, a global MSP/MSSP partner channel with local representatives in the US, Germany, Switzerland, France, Italy, Dubai, and Singapore, and—most recently—technology integrations with Checkmarx (October 2025) and a strategic alliance with Protiviti (January 2026) that embed RedRays' ABAP scanning capability inside a broader application security platform and global consulting practice.
RedRays firmographics
Firmographics- Name
- RedRays
- Legal name
- RedRays, Inc
- Website
- https://redrays.io
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- RedRays is a SAP-focused cybersecurity firm selling a SAP-certified vulnerability assessment platform, an ABAP code scanner, and professional penetration testing services to large enterprises, SAP consultants, and penetration testers globally.
- Ownership category
- akta.pro rank
RedRays industry classification
Industry- Product category
- SAP Application Security
- NAICS
- Computer Systems Design and Related Services (54151), Testing Laboratories and Services (541380)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Assessment & Scanning (HDADAHAA)
- akta.pro secondary industries
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC), Penetration Testing & Red Teaming (BPAKAHAF), Vulnerability Management & Penetration Testing Services (BPAEADAD), Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where RedRays is headquartered
LocationHeadquarters
- HQ city
- Dover
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
RedRays business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SAP Security Platform Subscription: Monthly subscription model providing access to RedRays Security Platform with tiered plans (Lite, Basic, Enterprise) for different SAP server counts and feature sets including vulnerability management, port scanning, threat modeling, and integrations
- Consultant Platform Subscription: SaaS platform subscription for SAP consultants with Standard, Ultimate, and Advanced tiers featuring vulnerability management, business object support, cloud connectors, and reporting integrations
- Pentester Platform Subscription: Virtual machine-based SaaS scanner for penetration testers with monthly pricing scaled to engagement scope, featuring vulnerability management, SAP NetWeaver/HANA support, and integration options
- SAP Penetration Testing Services: Professional penetration testing services including black-box/white-box/gray-box testing, SAP discovery, core services security, ABAP code assessment, and privilege escalation testing
- SAP Cloud Penetration Testing: Cloud-specific security assessment covering S/4HANA, BTP, SAP Build Work Zone, IAS/CIS, Cloud Connector, and CPI with structured 11-phase methodology and free retest
- SAP Security Training: Comprehensive two-day training program covering SAP security fundamentals, vulnerability assessment, penetration testing, threat modeling, and attack mitigation with hands-on labs and Q&A sessions
- ABAP Code Scanner Trial: Free 2-week full access trial with demo SAP system included, no credit card or auto-renewal, targeting SAP Basis admins, security consultants, and developers
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Basic SAP security for up to 3 SAP servers with vulnerability management, port scanning, and profile parameters checks |
| Subscription | Monthly | Comprehensive SAP security for up to 10 SAP servers with business object support and cloud connectors |
| Subscription | Monthly | Advanced security for 10+ SAP servers with full SAP HANA, NetWeaver, and business systems protection |
| Subscription | Monthly | Standard consultant plan with vulnerability management and port/service scanning for SAP HANA and S/4HANA |
| Subscription | Monthly | Enhanced consultant plan with password security, threat modeling, and cloud connectors for multiple SAP systems |
| Subscription | Monthly | Top-tier consultant protection with full business systems support, vulnerability assessment, and advanced cloud integration |
| Subscription | Monthly | Basic pentester plan with vulnerability management and SAP NetWeaver support |
| Subscription | Monthly | Comprehensive pentester plan with SAP Business Objects and cloud connectors |
| Subscription | Monthly | Advanced pentester plan with SAP HANA, NetWeaver, and business systems support |
| Freemium | Pay-as-you-go | Free 2-week full access trial for ABAP Code Scanner |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels6 records
RedRays product offering
Product offeringCore offering
RedRays sells a SAP-certified Security Platform available in Enterprise, Consultant, and Pentester editions under monthly subscription tiers, providing vulnerability assessment across 4,200+ known SAP issues, configuration checks, threat modeling, and integrations with Jira, ServiceNow, and Eclipse IDE. The company also offers the ABAP Code Scanner module for static code analysis with 164 built-in security checks, and a portfolio of professional services including on-premises, cloud, and hybrid SAP penetration testing, vulnerability assessment, SAP BTP custom application security audits, and instructor-led SAP security training.
Product overview
RedRays is a cybersecurity company specializing in SAP security with a platform-plus-services architecture. The core product is the SAP-certified RedRays Security Platform, available in three editions (for Enterprises, Consultants, and Penetration Testers) with subscription-based pricing. Key add-on modules include the ABAP Code Scanner for static code analysis and the open-source SAP Threat Modeling Tool. The portfolio is complemented by professional services including SAP Penetration Testing (on-premises, cloud, and hybrid), Vulnerability Assessment, BTP Security Audit, and Security Training. RedRays also maintains open-source tools including the Python 3 pysap library for protocol-level SAP testing. In October 2025, RedRays announced a partnership with Checkmarx to integrate its ABAP Code Scanner into the Checkmarx One platform.
Differentiator
Problem solved
Functional benefit
Products and services
- RedRays Security Platform SAP-certified security platform offering vulnerability assessment, configuration scanning, threat modeling, port/service scanning, ABAP code analysis, and integrations with Jira, ServiceNow, Slack, and Eclipse IDE for SAP landscapes (S/4HANA, HANA, ABAP, Gateway, AS Java, Business Objects, B1, Message Server). Sold as Enterprise, Consultant, and Pentester editions via monthly tiered subscriptions.
- RedRays ABAP Code Scanner Static code analysis product for detecting security vulnerabilities in custom ABAP code (Reports, Function Modules, Class Pools, Module Pools, BSP controllers, Web Dynpro components, OData services). Includes 164 security checks covering SQL injection, OS command injection, missing authorization, backdoors, secrets, and crypto weaknesses, with multi-threaded performance up to 30 concurrent threads. Includes an Eclipse IDE plugin and transport-request scanning for shift-left workflows.
- SAP Penetration Testing Professional security service delivering black-box, white-box, and gray-box penetration testing against SAP S/4HANA, SAP NetWeaver AS ABAP and Java, SAP HANA, and Business Suite. Covers SAP Discovery, Gateway/RFC/Message Server testing, ABAP code security assessment, privilege escalation, and cross-system attack path analysis.
- SAP Cloud Penetration Testing Cloud-specific security assessment service for SAP S/4HANA Cloud, SAP Business Technology Platform (BTP), SAP Build Work Zone, SAP Cloud Identity Services (IAS/CIS), SAP Cloud Connector, and SAP CPI integrations, executed as an 11-phase methodology covering all four attacker models and privilege levels with a free retest.
- Hybrid SAP Penetration Testing Hybrid assessment service combining automated scanning via the RedRays Security Platform with expert manual analysis, targeted at organizations without deep in-house SAP expertise and freelance pentesters expanding their service portfolio.
- SAP Vulnerability Assessment Vulnerability assessment service covering entry-point discovery, in-depth vulnerability analysis, business-critical prioritization, and strategic remediation planning with recommendations from RedRays' SAP security specialists with 15+ years of experience.
- SAP BTP Security Audit Security audit service for SAP Business Technology Platform (BTP) custom applications, identifying vulnerabilities, insecure configurations, and incorrect permissions in applications deployed on SAP BTP.
- SAP Security Training Two-day hands-on instructor-led training program covering SAP security fundamentals, threat analysis, vulnerability assessment, penetration testing, and threat modeling, including RFC vulnerabilities, SAP NW Java attacks, privilege escalation, SAP Cloud Connector security, and forensic techniques. Delivered by Vahagn Vardanian.
Quantifiable outcome
- Identifies vulnerabilities within 15 minutes for typical system with 100K lines of custom ABAP code
- +4 more outcomes
Companies that use RedRays
Customer profileNamed customers2 records
Segments4 records
Ideal customer profiles4 records
RedRays technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability3 records
Feature7 records
RedRays partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- ProtiviticoreStrategic partnership combining RedRays' technical SAP security expertise with Protiviti's global consulting experience. Joint offerings include deep technical audits using RedRays tools, strategic risk management methodology, and proactive defense strategies. Aims to set new standards for SAP system security.
- CheckmarxcoreRedRays ABAP Code Scanner is now integrated into Checkmarx One platform, bringing specialized SAP ABAP code security directly into the Checkmarx application security platform. This partnership enables customers to find and fix vulnerabilities in custom ABAP code alongside other applications in a unified security workflow. David Dewaele and Antero Silva from Checkmarx collaborated on this integration.
- SAPcoreOfficial SAP partnership with RedRays Security Platform receiving SAP certification. RedRays is the only cybersecurity company providing SAP BTP custom application security audit services. Partnership enables deep integration with SAP systems and access to SAP security ecosystem.
- Local Representatives NetworkminorRedRays has partnered with local representatives in various countries including United States, Germany, Switzerland, France, Italy, Dubai, and Singapore to provide localized service and support to clients in those regions.
Scale indicators10 records
Recent moves6 records
Expansion highlights5 records
RedRays competitors and assessment
Company assessmentBroad incumbents
- Checkmarx: Checkmarx is a broad application security platform that recently integrated RedRays ABAP Code Scanner into Checkmarx One. It is both a partner and a potential competitor, as Checkmarx could expand its own SAP/ABAP scanning capabilities over time.
- Veracode: Veracode is a major application security testing vendor covering SAST, DAST, and SCA across multiple languages. While not SAP-native, it competes for the broader application security budget that may be allocated to SAP code scanning.
- Synopsys (Black Duck / Coverity): Synopsys offers enterprise SAST and software composition analysis through Coverity and Black Duck. It competes for AppSec budgets in enterprises that include SAP custom code alongside other development stacks.
- SAP Enterprise Threat Detection: SAP's own security products (Enterprise Threat Detection, security features in BTP and S/4HANA Cloud) compete broadly with RedRays. As the platform owner, SAP represents both a partner and the most significant incumbent threat to RedRays' standalone tooling.
Emerging players
- Trustwave: Trustwave provides managed security services and penetration testing including SAP-specific practices. It is an emerging player in the SAP security services market that may compete with RedRays' pentesting and vulnerability assessment engagements.
Direct peers
- Pathlock: Pathlock provides application access governance and security for SAP and other ERP ecosystems, including vulnerability and risk analytics. It overlaps with RedRays in SAP-focused compliance and security posture management for large enterprises.
- Onapsis: Onapsis is the most established pure-play SAP cybersecurity platform, offering vulnerability management, threat detection, and compliance for SAP landscapes. It is the closest direct competitor to RedRays across both product and professional services.
- Protect4S: Protect4S delivers automated SAP vulnerability management and security monitoring for ABAP and HANA systems. It is a focused niche competitor with a similar SaaS-plus-services model targeting SAP Basis and security teams.
- SecurityBridge: SecurityBridge provides a SAP-native security platform covering code scanning, vulnerability management, and threat detection. It competes head-on with RedRays Security Platform for enterprise SAP accounts and MSSP channel partners.
- Bowbridge Software: Bowbridge offers SAP-native cybersecurity solutions including vulnerability assessment and anti-virus for SAP environments. It competes with RedRays in the SAP-specific vulnerability assessment niche, particularly for NetWeaver and HANA deployments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
RedRays social profiles
Digital presenceRedRays compliance and trust
Trust signalCompliance2 records
RedRays financial estimates
Financial estimateRevenue estimate
Valuation estimate
RedRays leadership team
Management profileNumber of profiles
Profiles1 record
RedRays funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
RedRays M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about RedRays
What does RedRays do?
RedRays sells a SAP-certified Security Platform available in Enterprise, Consultant, and Pentester editions under monthly subscription tiers, providing vulnerability assessment across 4,200+ known SAP issues, configuration checks, threat modeling, and integrations with Jira, ServiceNow, and Eclipse IDE. The company also offers the ABAP Code Scanner module for static code analysis with 164 built-in security checks, and a portfolio of professional services including on-premises, cloud, and hybrid SAP penetration testing, vulnerability assessment, SAP BTP custom application security audits, and instructor-led SAP security training.
Is RedRays a public or private company?
RedRays is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was RedRays founded?
RedRays was founded in 2010. It employs 1 to 10 people.
Where is RedRays based?
RedRays is headquartered in Dover, United States, in the North America region.
How does RedRays make money?
Seven revenue lines are on record. SAP Security Platform Subscription is the primary driver. The others are consultant Platform Subscription, pentester Platform Subscription, SAP Penetration Testing Services, SAP Cloud Penetration Testing, SAP Security Training and ABAP Code Scanner Trial.
Who are RedRays's main competitors?
Broad incumbents on record are Checkmarx, Veracode, Synopsys (Black Duck / Coverity) and SAP Enterprise Threat Detection. Trustwave is listed as an emerging player. Direct peers are Pathlock, Onapsis, Protect4S, SecurityBridge and Bowbridge Software.
Does RedRays have an API?
Yes. RedRays Security Platform offers API access for webhooks/integrations. The ABAP Code Scanner supports per-developer API key issuance, enabling developers to scan ABAP code from their IDE with scans automatically landing under a 'Developer Scans' project.
What industry is RedRays in?
RedRays's product category is SAP Application Security. Its primary akta.pro industry code is HDADAHAA, Vulnerability Assessment & Scanning, with a secondary code of HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 54151 and its SIC code is 8700.