Dradis Framework
Dradis Framework, built by Security Roots Ltd since 2007, is a self-hosted, open-source penetration testing management platform that automates reporting, deduplicates findings from 47+ scanners, and tracks remediation for security consultancies and enterprise security teams.
- Company typePrivate
- Founded2007
- HeadquartersBoston, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Dradis Framework does
Dradis Framework, operated by Security Roots Ltd and founded in 2007, is a self-hosted, open-source (GPLv2) penetration testing management platform that automates the reporting, deduplication, and remediation-tracking workflows of security engagements. The product aggregates findings from 47+ security scanners (Nessus, Burp Suite, Qualys, Nmap, Metasploit, OpenVAS, OWASP ZAP, and others) via a Rules Engine and Mappings Manager, normalizes them into an Issue Library of vetted vulnerability descriptions, and generates pixel-perfect branded Word/Excel reports via a concierge template conversion service. Modules include Gateway (interactive client portal), Remediation Tracker with bidirectional Jira/Azure DevOps/ServiceNow sync, Business Intelligence dashboards, Risk Calculators (CVSSv4, DREAD, MITRE ATT&CK), Quality Assurance workflows, Audit Logging, and an Echo local AI writing assistant built on Ollama. Deployment options span on-premises, Docker, AWS, Azure, GCP, and fully air-gapped networks.
Dradis Framework firmographics
Firmographics- Name
- Dradis Framework
- Legal name
- Security Roots Ltd
- Website
- https://dradis.com
- Company type
- Private
- Founded year
- 2007
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Dradis Framework, built by Security Roots Ltd since 2007, is a self-hosted, open-source penetration testing management platform that automates reporting, deduplicates findings from 47+ scanners, and tracks remediation for security consultancies and enterprise security teams.
- Ownership category
- akta.pro rank
Dradis Framework industry classification
Industry- Product category
- Penetration Testing Management Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where Dradis Framework is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Dradis Framework business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Subscriptions (Dradis Pro): Tiered subscription plans (Assess, Remediate, Enterprise) with per-seat pricing and annual or monthly billing. Revenue is primarily recurring; additional seats are billed at fixed per-user monthly rates. The Community Edition is free, providing a free-tier acquisition funnel into paid plans.
- Professional Services — Template Conversion & Onboarding: Concierge report template conversion service (included with Pro subscriptions) recreates customer Word/Excel templates into Dradis templates. Personalized onboarding and training sessions are bundled with Pro plans.
- Enterprise Procurement Extensions: Enterprise tier adds done-for-you upgrades, priority SLA support, dedicated success managers, and flexible contract terms (NET30, multi-year), representing upsell/expansion revenue from Assess/Remediate customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Community Edition — free forever |
| Subscription | Annual | Assess — for testing and delivering findings |
| Subscription | Annual | Remediate — Assess + remediation tracking and ticketing |
| Subscription | Multi-year contract | Enterprise — for regulated industries with advanced compliance needs |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Dradis Framework product offering
Product offeringCore offering
Dradis Framework is a self-hosted, open-source penetration testing management platform that consolidates security assessment workflows. It imports findings from 47+ security scanners, deduplicates vulnerabilities, manages an Issue Library of vetted findings, and generates branded pentest reports. The product is sold as a commercial subscription (Dradis Pro) with optional add-on concierge template conversion services.
Product overview
Dradis Framework is a self-hosted, penetration testing management platform built on an open-source (GPLv2) foundation. The product portfolio consists of three commercial tiers (Assess, Remediate, Enterprise) alongside a free Community Edition, plus a concierge reporting service. The platform integrates a core set of modules including Gateway (client portal), Contributor Questionnaires, Remediation Tracker, Project Scheduler, Business Intelligence, Mappings Manager, Risk Calculators (CVSSv4, DREAD, MITRE ATT&CK), Methodologies, Issue Library, Quality Assurance, Audit Log, One Time Password MFA, Echo AI assistant, Rules Engine, Webhooks, and REST API. Dradis supports 47+ security scanner integrations for automated vulnerability aggregation and deduplication, with ticketing integrations (Jira, Azure DevOps, ServiceNow) and identity/SSO integrations (LDAP, Okta, SAML, Azure AD, DUO). Deployment options include on-premises, private cloud (AWS, Azure, GCP), Docker, and air-gapped environments.
Differentiator
Problem solved
Functional benefit
Brands
- Dradis Pro: Commercial version with advanced features including custom reporting, team collaboration, API access, webhooks, and professional support.
- Dradis Community Edition
Products and services
- Dradis Community Edition Free, self-hosted, open-source (GPLv2) pentest reporting and collaboration platform for security teams. Includes 47+ scanner integrations, one-click reporting, team collaboration, testing methodologies, QA flow, risk calculators, and community support. Distributed via direct download, GitHub, and bundled in Kali Linux, BlackArch Linux, and ArchStrike Linux.
- Dradis Pro Commercial, self-hosted penetration testing management subscription available in three tiers: Assess ($249/mo, 3 seats) for testing and findings delivery; Remediate ($499/mo) adding remediation tracking and ticketing integrations (Jira, Azure DevOps, ServiceNow); and Enterprise (quote-based) for regulated industries with SSO/SAML/LDAP, MFA enforcement, granular RBAC, full audit logging, dedicated success manager, priority SLA support, and compliance with FISMA, HIPAA, NIS2, SOC 2, PCI-DSS, SOX, and NIST 800-53. Available in USD, GBP, and EUR with annual billing discount and 30-day money-back guarantee.
- Concierge Reporting Service Template conversion service included with Dradis Pro subscriptions that recreates a customer's existing report layouts, sections, table structures, and visual styles from Word/Excel as Dradis templates. Over 1,179+ pixel-perfect templates have been converted since 2010. Personalized onboarding and training sessions are bundled with Pro plans.
Quantifiable outcome
- Saves 4 hours per project (per Erik Cabetas, Include Security)
- +6 more outcomes
Companies that use Dradis Framework
Customer profileNamed customers15 records
Segments3 records
Ideal customer profiles3 records
Dradis Framework technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration35 records
AI capability4 records
Feature7 records
Dradis Framework partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered core and major.
- Nessus (Tenable)coreNative integration for importing vulnerability assessment results. Nessus output is automatically parsed, normalized, and deduplicated via the Rules Engine and Mappings Manager into Dradis project data.
- Burp Suite (PortSwigger)coreNative connector for importing web application security scan results into Dradis. Findings are normalized and deduplicated alongside other tool outputs.
- NmapcoreNative integration for network discovery and port scanning results. Imported findings are combined with manual notes and other scanner output for consolidated reporting.
- QualyscoreNative integration for cloud-based vulnerability scanning and compliance assessment data, imported and processed through the Rules Engine.
- Metasploit (Rapid7)coreNative integration for importing Metasploit framework findings and exploit verification data into Dradis projects.
- Jira (Atlassian)coreBidirectional ticketing integration: Dradis can create Jira tickets from findings with full context (description, evidence, affected hosts, remediation guidance), and ticket status changes sync back to Dradis. Mappings Manager customizes field mapping.
- ServiceNowcoreCreates ServiceNow Vulnerability Items directly from Dradis findings. Bidirectional sync maintains link between finding and external ticket for real-time remediation visibility.
- Azure DevOps (Microsoft)coreSecure integration via Microsoft Entra ID app registrations to sync work items from Dradis findings to Azure DevOps. Includes customizable field mapping via Mappings Manager and bidirectional status sync.
- OktamajorEnterprise SSO integration via Okta for seamless and secure single sign-on authentication into Dradis Pro, satisfying NIST IA-2 and PCI-DSS 8.3 requirements.
- LDAP / Active DirectorymajorNative integration with Active Directory and LDAP directory services for enterprise user management and authentication, enabling centralized identity management.
- SAMLmajorBuilt-in SAML authentication support enabling integration with enterprise identity providers beyond LDAP/AD, with no workarounds required.
- Azure Authentication / Microsoft Entra IDmajorAzure Identity Platform and Authentication integration for MFA enforcement via Azure MFA and secure authentication through Microsoft Entra ID.
- OllamacoreLocal LLM runtime powering Dradis Echo AI assistant. BYOLLM approach allows customers to run any Ollama-compatible model locally — findings never leave the network. Anthropic, OpenAI, and Gemini are also supported as frontier providers.
- Nexpose (Rapid7)coreNative integration for importing Nexpose vulnerability management scan results into Dradis projects for consolidated reporting.
- OpenVAScoreNative integration for importing OpenVAS (Greenbone) vulnerability scanning results into Dradis.
- ZAP (OWASP Zed Attack Proxy)coreNative integration for importing OWASP ZAP web application scanner output into Dradis for consolidated reporting alongside other tool findings.
- Kali Linux / BlackArch Linux / ArchStrike LinuxmajorDradis Community Edition is included in Kali Linux, BlackArch Linux, and ArchStrike Linux penetration testing distributions, providing a distribution-level endorsement and frictionless access for the core security testing audience.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Dradis Framework competitors and assessment
Company assessmentEmerging players
- Cobalt.io: Pentest-as-a-Service platform combining a global researcher network with a SaaS platform for managing engagements. Adjacent to Dradis — both serve pentest program management, but Cobalt owns the testing supply side and is cloud-native.
- Pentera: Automated Security Validation vendor running continuous breach-and-attack simulations. Adjacent to Dradis — Pentera replaces some manual pentest work and competes for the same security testing budget; Dradis has a native Pentera integration.
Direct peers
- Faraday: Open-source collaborative penetration test and vulnerability management platform (originally by Infobyte). Comparable to Dradis's Community Edition positioning as an open-source pentest management tool with multi-tool data ingestion and reporting.
- Plextrac: Cloud-based pentest reporting and management platform used by consulting firms and internal security teams. Directly comparable to Dradis in target buyer and core workflow (finding aggregation, deduplication, report generation, remediation tracking), but delivers as SaaS rather than self-hosted.
- Resolver (PentestPad): Pentest management platform (formerly PentestPad) targeting consulting firms and corporate security teams. Overlaps with Dradis on reporting automation, finding consolidation, and workflow standardization for security testing engagements.
- Serpico: Open-source pentest reporting and collaboration tool. Comparable to Dradis's Community Edition as an OSS alternative focused on report template management, finding consolidation, and team collaboration.
- AttackForge: Pentest management and collaboration platform with project tracking, finding imports, and reporting workflows. Closely aligned with Dradis's consulting-team use case, with overlapping feature sets in vulnerability aggregation, project management, and client portals.
Broad incumbents
- ServiceNow (Vulnerability Response): Enterprise workflow platform with Vulnerability Response and Security Operations modules. Dradis integrates with ServiceNow, but ServiceNow's remediation-tracking capabilities represent a broader alternative for enterprise security program management.
- Tenable (Nessus / Tenable.sc): Vulnerability management incumbent behind Nessus and Tenable.sc. Competes for vulnerability lifecycle workflow budget, though Dradis complements Nessus today via integration; Tenable's broader reporting and prioritization capabilities are an adjacent alternative.
- Rapid7 (Metasploit / InsightConnect): Security analytics and operations platform owning Metasploit and InsightConnect. Overlaps with Dradis in pentest tooling and vulnerability prioritization workflows; broader portfolio could subsume parts of the pentest management use case over time.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Dradis Framework social profiles
Digital presenceDradis Framework compliance and trust
Trust signalCompliance8 records
Dradis Framework financial estimates
Financial estimateRevenue estimate
Valuation estimate
Dradis Framework leadership team
Management profileNumber of profiles
Dradis Framework funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Dradis Framework M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Dradis Framework
What does Dradis Framework do?
Dradis Framework is a self-hosted, open-source penetration testing management platform that consolidates security assessment workflows. It imports findings from 47+ security scanners, deduplicates vulnerabilities, manages an Issue Library of vetted findings, and generates branded pentest reports. The product is sold as a commercial subscription (Dradis Pro) with optional add-on concierge template conversion services.
Is Dradis Framework a public or private company?
Dradis Framework is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Dradis Framework founded?
Dradis Framework was founded in 2007. It employs 11 to 50 people.
Where is Dradis Framework based?
Dradis Framework is headquartered in Boston, United States, in the North America region.
How does Dradis Framework make money?
Three revenue lines are on record. Software Subscriptions (Dradis Pro) is the primary driver. The others are professional Services — Template Conversion & Onboarding and enterprise Procurement Extensions.
Who are Dradis Framework's main competitors?
Emerging players on record are Cobalt.io and Pentera. Direct peers are Faraday, Plextrac, Resolver (PentestPad), Serpico and AttackForge. Broad incumbents are ServiceNow (Vulnerability Response), Tenable (Nessus / Tenable.sc) and Rapid7 (Metasploit / InsightConnect).
Does Dradis Framework have an API?
Yes. Comprehensive REST API enabling manipulation and interaction with Dradis instance from any tool in any language. Supports import of Team, User, IssueLibrary, and Project data from external tools; retrieval of findings for publishing to internal systems; connection with existing Business Intelligence tools. Features scoped Personal Access Tokens for agentic workflows - each token can be limited to minimum required access for specific tools or workflows. Supports Bash scripting interface with direct access to tool connectors and export operations, including scheduling tasks like project creation or report generation, parsing security scanner output, and automatic backup and archive operations. Advanced Ruby scripting available for querying the internal database and accessing all functionality. Developer documentation is at dradis.com/support/guides/rest_api.
What industry is Dradis Framework in?
Dradis Framework's product category is Penetration Testing Management Software. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 54151 and its SIC code is 7372.