
RedRays provides an end-to-end SAP security platform and services covering vulnerability assessment, penetration testing, ABAP code scanning, threat modeling, and incident response. The platform continuously scans entire SAP landscapes—including S/4HANA, NetWeaver, AS Java, SAP BTP, and HANA—in under one hour per system, with over 150 zero-day vulnerabilities discovered by its research team. It serves enterprises, consultants, and penetration testers through a single SAP-certified console with audit-ready reporting.
Funding
Funding not disclosed
Founders
Product
Problem
SAP systems are mission-critical business infrastructure, yet they are frequently targeted by attackers exploiting missing security notes, misconfigurations, and vulnerable custom ABAP code. Many organizations lack specialized SAP security expertise, leaving their landscapes exposed to external threats and insider fraud, while compliance requirements demand continuous, audit-ready security monitoring.
Solution
RedRays delivers a comprehensive SAP security platform and services that cover the full security lifecycle—from continuous automated scanning to hands-on penetration testing, ABAP code analysis, threat modeling, and incident response. The platform provides a single SAP-certified console to scan, assess, and monitor every system in a landscape, including S/4HANA, NetWeaver, AS Java, SAP BTP, and HANA, across on-premise, cloud, and hybrid environments. RedRays' team of SAP security specialists, who have discovered over 150 zero-day vulnerabilities, performs black, grey, and white-box penetration testing to identify real attack paths and provide clear remediation plans. The platform also offers static ABAP code scanning for injections, missing authority checks, backdoors, and hardcoded credentials, with results prioritized by business risk and exportable for audits.
Target Audience
Primary customers are enterprise SAP and security teams, SAP consultancies, internal red teams, and managed service providers that need continuous SAP security coverage, compliance reporting, and specialized offensive testing expertise.
Features
- Continuous vulnerability scanning across the entire SAP landscape, detecting missing SAP Security Notes, insecure configurations, and exposed services in under one hour per system
- Offensive penetration testing services (black, grey, and white-box) delivered by researchers with 150+ discovered SAP zero-days, including proof of exploitability
- Static ABAP code analysis for injections, missing authority checks, backdoors, and hardcoded credentials, available as a platform module, SAP BTP app, and Eclipse plugin
- Cloud and BTP penetration testing covering S/4HANA Cloud, SAP BTP, IAS, Build Work Zone, and Cloud Connector, including lateral movement between cloud and on-premise zones
- Threat modeling to map connections, trust relationships, and data flows between SAP systems to identify attacker movement paths
- Audit-ready reporting with PDF/Excel export, role-based governance, workflow management, MTTR tracking, and Jira/ServiceNow integrations
- Hybrid pentest model for partners where the platform runs automated discovery and the partner team drives manual exploitation