Ethical Hackers. On Demand.

    RedSOC: On-Demand Pentesting by Ethical Hackers

    RedSOC is Sectricity's on-demand pentesting model (PTaaS): ethical hackers pentest, validate and investigate when you decide. After a release, when a scanner flags something, or when an auditor asks for evidence. 35 services, one engagement model.

    Human-validated and accelerated by our AI research framework, with an audit-ready report and retest. No blind spots, no noise.

    RedSOC request flow
    Your requestsON DEMAND
    1
    Request
    2
    Test by an ethical hacker
    3
    Report and retest
    Webapp Pentest: payments.example.comScheduled for next sprint
    Vulnerability Validation: scanner finding CVE-2026-XXXXIn progress
    External Attack Surface Test: customer.example.comCompleted, report ready

    What RedSOC does

    On-demand Pentesting

    Launch a human-led security test as soon as a new asset, feature or change goes live. No procurement cycle, no fixed yearly slot, just direct access to ethical hackers when it matters.

    Manual Validation of Tool Findings

    Already running a scanner, ASV platform or AI pentesting tool? Send us the findings. Our hackers verify what is truly exploitable in your environment, filter false positives and tell you what to fix first.

    Compliance-Grade Reporting

    Every engagement produces an audit-ready report with a named lead tester, scope, methodology, findings, and remediation guidance. Direct evidence for NIS2, ISO 27001, DORA, and customer security questionnaires.

    Webapp, API and Business Logic Testing

    Automated platforms find known patterns. Our hackers find broken authorisation, IDOR, race conditions, payment-flow manipulation, and chained-logic flaws that no tool surfaces. This is where most real breaches start.

    Social Engineering and Red Team

    The human attack surface is invisible to scanners. Phishing, vishing, physical intrusion, full red team scenarios with assumed breach. Available on-demand from the same platform.

    35 Services, One Engagement Model

    Pentesting, social engineering, red team, awareness, and more. 35 services through one engagement model. Request through RedSOC and a senior ethical hacker picks it up.

    Offensive Security Wallet: one annual budget in RedSOC credits

    01

    1. Choose your annual budget

    An amount in credits that fits your release and audit calendar.

    02

    2. Request a test

    Web, API, cloud, external, identity, social engineering or a retest.

    03

    3. Your credits are put to work

    You pay for what you use, within your budget.

    04

    4. Report and retest

    An audit-ready report with a named lead tester.

    When customers reach for RedSOC

    After a major change goes live

    New product release, infrastructure migration, vendor onboarding, M&A integration. The annual pentest cycle does not keep pace with the pace of change. RedSOC tests within days of the change, not months later.

    When automated tools flag findings

    Your scanner, ASV platform, or AI pentesting tool reports vulnerabilities. Are they real? Are they exploitable in your context? Which one matters first? Our hackers validate manually, so you do not chase scanner ghosts.

    To prove effectiveness for NIS2 and ISO 27001

    Regulators and auditors expect proportional, documented, repeatable testing of critical systems. RedSOC delivers signed, audit-grade reports per engagement, mapped directly to control requirements.

    When something does not feel right

    A suspicious login, an unexpected exposure, a third-party report, a customer questionnaire. Spin up a focused test instead of waiting for the next scheduled audit cycle.

    Why RedSOC raises the bar

    Human expertise on-demand, not once a year
    Manual validation by senior ethical hackers
    Accelerated by our AI research framework, validated by ethical hackers
    Complements your existing scanner and security tooling
    35-service catalog accessible through one engagement model
    Audit-grade reporting per test for NIS2, ISO 27001, DORA
    Fast turnaround when changes, findings, or audits demand proof
    100%
    Manual validation by ethical hackers
    98.2%
    Remediation success rate, our own client data
    1D
    Average time from request to start, our own figures

    Frequently asked questions

    RedSOC is on-demand pentesting: a team of ethical hackers you call in whenever you want to test. A SOC monitors and raises alerts, RedSOC tests and proves what can really be exploited in your environment. That is why it works well next to an existing SOC, MDR or scanner.

    Automated platforms and AI pentesting tools are strong at scale, repetition and re-testing. RedSOC adds ethical hackers who decide what can really be exploited in your context and how serious it is, and who deliver the signed report. It complements your tools, it does not replace them.

    Yes, this is one of the most common reasons customers engage with RedSOC. Many already use AI pentesting, DAST, or adversarial validation tooling. RedSOC adds manual validation, deeper web app and API testing, social engineering, and compliance-grade reporting that those tools do not provide.

    Both frameworks require proportional, documented testing of security measures' effectiveness. RedSOC delivers per-engagement, audit-grade reports with a named lead tester, scope, methodology, findings, and evidence of remediation. Tests can be triggered by change events, by audit cycles, or to validate findings from other tools, mapping directly to NIS2 article 21 and ISO 27001 controls A.8.8 and A.8.29.

    A traditional penetration test is a point-in-time assessment: one engagement, fixed scope, fixed schedule. RedSOC works on demand. You request a test when something changes, when a tool flags a finding, or when an audit requires proof. The execution is identical: manually performed and validated by senior ethical hackers, accelerated by our AI research framework. But the timing and accessibility are fundamentally different. No long procurement cycles, tests start within days.

    RedSOC uses a transparent credit model: you only pay for what you use, with no fixed annual contracts. After a short intake you know exactly how many credits a test requires for your environment.

    It can, depending on your compliance obligations. For many organisations RedSOC fully replaces the annual pentest; others combine both and use RedSOC for change-driven tests between annual cycles.

    Test what matters, when it matters

    Request a RedSOC walkthrough and see how ethical hackers, accelerated by AI and validated by people, fit next to your existing tools, audit cycles, and change calendar.