RED CRICKET CLOUD

From fragmentation to a single security platform.

Eight tools you buy separately today, each with its own console and its own invoice, living here under one contract.

Start trial

THE REAL PROBLEM

Your risk surface grew faster than your way of managing it

Third-party vendors, business email, regulatory compliance, alerts from your own tools, exposed infrastructure — each one lives on a different platform today, with its own login and its own learning curve.

Dozens

of active vendors in a typical operation — how many are formally assessed?

THE REAL COST

Bought separately vs. bundled

Standalone tools, equivalent tier

$590 – $1,210/mo

Red Cricket Cloud, Growth tier

$349/mo

One contract, one dashboard, one provider accountable for everything working together.

THE MODULES

Each one solves a distinct, verifiable risk

AI in production, not on a roadmap: three modules already use it to classify alerts, summarize vendor questionnaires, and translate financial risk into a narrative a board can read.

TPRM
AI-assistedStarter

Vendor Risk

ISO 27001, SOC 2 and GDPR ask for documented due diligence on vendors. Sustaining it by hand means a spreadsheet someone has to keep current — and a spreadsheet isn't evidence: it's a good-faith reminder.

View module →
SPF · DKIM · DMARC
Starter

Email Authentication

Anyone can send email with your domain in the From line if SPF, DKIM and DMARC aren't configured and aligned. It takes no access to any system: it's enough that your DNS doesn't stop it.

View module →
ISO 27001 · SOC 2 · GDPR
Starter

Compliance Posture

Compliance evidence is almost never ready when a large customer demands it as a condition of the deal — and by then there's no time left to improvise.

View module →
CENTRALIZED ALERTS
AI-assistedGrowth

Alert Center

The alerts your tools already generate stay scattered across separate consoles. Reviewing them together means opening all of them, every day, and that tends not to be anyone's job in particular.

View module →
EXTERNAL RECON
Growth

Attack Surface

Subdomains from projects nobody remembers, expired certificates, ports left open from a test. It takes no sophisticated attack: it's enough that nobody is looking at what's already exposed.

View module →
CRQ
AI-assistedEnterprise

Financial Risk

A board doesn't react to 'critical vulnerability' — it reacts to a dollar figure. Without that, the risk conversation stays in language nobody in the room can act on.

View module →
BREACH MONITORING
Growth

Breach Exposure

Your team's credentials may already be circulating in a breach that wasn't even yours. Without monitoring that looks for them, that match doesn't surface on its own.

View module →
OPERATIONAL HYGIENE
Growth · add-on

Passwords & Backups

A reused password turns someone else's breach into yours, and a backup nobody has ever restored isn't a backup: it's an assumption. Neither one tells you on its own.

View module →

ANCHOR MODULE

Vendor Risk

Why it's strategic, not just useful

It's the most direct sales argument in front of an enterprise customer: audit-ready evidence, low implementation friction, with vendor limits that grow alongside your operation.

What it solves

Automatic per-vendor inventory and risk scoring, a standardized questionnaire sent by link with no account needed, exportable evidence, and renewal reminders.

The SaaS doesn't compete with consulting — it feeds it.

PRICING

Three tiers, no fine print

Prices in USD.

Starter

$149/mo

Vendor risk, compliance, and email authentication — three modules solved from month one.

  • ✓Vendor Risk (15 vendors)
  • ✓Compliance Posture (1 framework)
  • ✓Email Authentication (1 domain)
Start with Starter
Most popular

Growth

$349/mo

Active visibility into what's already happening across your tools — three more modules included on top of Starter, plus Passwords & Backups as a paid add-on.

  • ✓Everything in Starter, higher limits
  • ✓Vendor Risk (60 vendors)
  • ✓Email Authentication (3 domains)
  • ✓Unlimited compliance frameworks
  • ✓Alert Center (centralized alerts)
  • ✓Attack Surface (15 assets, 4 manual scans/mo)
  • ✓Breach Exposure
  • ✓Passwords & Backups (paid add-on)
  • ✓Advisor: 1 hour a month with a CTO/CISO (doesn't roll over)
Start with Growth

Enterprise

$799/mo

Adds Financial Risk to speak the board's language, and Passwords & Backups stops being an add-on.

  • ✓Everything in Growth: unlimited vendors, domains, and frameworks
  • ✓Financial Risk (CRQ)
  • ✓Passwords & Backups included
  • ✓Attack Surface (unlimited assets, 20 manual scans/mo)
  • ✓Advisor: 2 hours a month with a CTO/CISO (don't roll over)
Talk to sales

Advisor is time with a Red Cricket CTO/CISO included in your subscription, from Growth up: judgment and priorities on what the platform surfaces — advisory, not execution inside your systems. Unused hours don't roll over to the next month. See the fractional service →

HOW WE COMPARE

Against what's out there today

UpGuard · Panorays · Bitsight · PrevalentEnterprise GRCRobust, but built and priced for operations much larger than yours.
Vanta · SecureframeCompliance SuitesStrong on compliance, but don't cover vendor risk or live attack signal in the same place.
Risk 365Budget nicheAccessible price, limited coverage — a single module, not a full posture.
Red Cricket Cloud8-in-oneVendor risk, compliance posture, email authentication, alert center, attack surface, breach exposure, passwords and backups, and financial risk — one dashboard, priced like a single tool.

WHERE YOUR DATA COMES FROM

See your risk on day one, with nothing to install.

Most of what Red Cricket Cloud shows you needs no setup at all: it comes from public records anyone can look up — it's just that nobody reviews them systematically. What you do connect, you connect yourself, read-only.

01

Nothing to connect

The moment you type your domain, these three are already working.

  • Public DNS records

    We read your SPF, DKIM and DMARC the same way anyone on the internet reads them — including whoever wants to impersonate you. If your email can be spoofed, you find out before they do.

  • Certificate transparency

    Every certificate issued for your domain lands in a public log. That is where the forgotten subdomains come from — the ones nobody on your team remembered.

  • Known breach databases

    We match your organization's emails against already-published leaks. Your team's credentials may be circulating today in a breach that was not even yours.

02

What you connect

Three ways to bring the alerts your tools already generate into one place.

  • Cloudflare

    A read-only token you generate yourself and revoke whenever you want. Its security events land in your Alert Center alongside everything else.

  • WordPress

    Through the security plugin you already run. Events arrive by webhook, without giving us access to your site.

  • Any tool with a webhook

    If it can send a POST, it can come in. We give you a URL with its own token and you decide what you push.

No agents on your servers. No ports to open. No admin credentials. Everything you connect is read-only, and you revoke it from your side, not ours.

Start with Red Cricket Cloud

Choose the tier that matches your operation today — move up whenever you need to, without migrating platforms.

Start trial