Overview
Dashboard: findings, methodologies and assets
Each Dradis project combines manual findings, with those identified from security scanners, screenshots, evidence and notes.
Dashboard: findings, methodologies and assets
Rich text format for Issues and Evidence
Built-in testing methodology support
Free, self-hosted pentest reporting. For teams where confidentiality isn't negotiable. Dradis Community Edition is an extensible, cross-platform, open-source security framework designed to streamline collaboration, deliver consistent and accurate results, and automate pentest reporting, saving you hours on every project. Built by leading security experts, generate professional reports - without vendor lock-in or licensing costs. 47+ Integrations. Import findings from Burp, Nessus, Nmap, Qualys, and more. And if we don't have an integration for your favorite tool, it's easy to create one!
Highlights
- Create Reports with One Click. Combine the output of your favourite security scanning tools, manual findings, and notes to generate consistent reports in a fraction of the time of writing them manually
- Collaborate with your Team. Track the progress of your project, split tasks, and comment on findings with other team members. Centralized project details keeps everyone on the same page.
- Trusted by over 1,171 InfoSec teams in 75 countries.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Unconditional 100% refund guarantee.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Default delivery option
- Amazon ECS
- Amazon EKS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
v5.0.0 (March 2026)
- Activities: Remove ActivityTracking for Issues and use EventPublisher
- Docker:
- Update default attachments & templates locations to storage/
- Include assets for all integrations regardless of enabled/disabled status
- Echo: Add configurable, reusable prompts for Issues
- Forms: Improve visibility of form actions
- Layout: Add light/dark/auto theme toggle to support dark mode
- Nodes:
- Add more types and icons
- Rename upload and parent node types and add distinguishing icons
- Update associated evidence, notes and child nodes' updated_at columns on node merge
- Warn on node merge that methodology will not be copied
- Profile: Update default user avatar
- QA: Add in-line comment threads
- Show don't gate:
- Issue Library
- Remediation Tracker
- Ticketing integrations
- Word/Excel templates
- Sidebar:
- Add resize functionality
- Textile:
- Add support for paragraph alignment
- Add support for image resizing, alignment, and borders
- Keep sidebar open when editing issues in large viewports
- Wizard:
- Add analytics sharing step
- Mark as done after Kit step, without waiting for the background job
- OWASP kit: Add with 3 report template variations
- Red Team kit: Add with MITRE ATT&CK methodology and kill chain report
- Welcome kit: Update with OWASP Top 10:2025 methodology
- Upgraded gems:
- bcrypt, nokogiri, rack, rails, tilt
- Bugs fixes:
- Nodes: Display error message and preserve input on properties update
- Notifications: Ensure correct link for note and issue comments
- REST/JSON API enhancements:
- Issues: Add support for search
- Security Fixes:
- Medium: Authenticated (author) horizontal privilege escalation allowing cross-project subscription and subscriber enumeration
Additional details
Usage instructions
After launch, point your browser to https://<use.your.ip>/ it supports SSL auto-provisioning via Let's Encrypt and Thruster.
Resources
Support
Vendor support
Community Edition Forum:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.