Faraday review: an open-source and commercial vulnerability management platform that unifies 80+ pentest tools. See features, Community vs paid pricing, and…
Faraday is a vulnerability management and penetration-test collaboration platform originally released as an open-source project by a team with roots in Argentina's offensive security research community, connected to the Ekoparty security conference. The platform ingests output from more than 80 security tools and normalizes it into unified, deduplicated workspaces, letting testers and security teams track findings from discovery through remediation in one place instead of stitching together spreadsheets from disparate scanner reports.
The company behind Faraday, doing business as Faradaysec, is headquartered in Miami, Florida, with a research and development office in Buenos Aires, Argentina. It offers a free, GPL-3.0 licensed Community Edition alongside commercial Professional and Corporate tiers, and has expanded into a broader offensive security suite that includes continuous automated testing, external attack surface mapping, and AI-assisted vulnerability triage.
At its core, Faraday uses a plugin architecture with two ingestion paths: console plugins that read a security tool's output live as it runs, and report plugins that import previously generated scan artifacts. This lets it absorb both real-time manual testing sessions and automated batch scans from tools such as Nmap, Nessus, OpenVAS, Burp Suite, ZAP, Metasploit, and AWS Inspector without requiring a shared protocol between tools.
The Agents Dispatcher component orchestrates scanners running on remote machines, enabling scheduled, continuous scanning rather than one-off manual imports. A REST API and the faraday-cli command-line tool allow the platform to be scripted into continuous integration and delivery pipelines, while additional modules, Faraday Enrichment for context-based prioritization, Faraday CART for automated attack simulation, Faraday OPS for external attack surface management, and FaradAI for AI-assisted triage, extend the core vulnerability management workspace into a fuller offensive security program.
Faraday's Community Edition is free and open source under the GPL-3.0 license, providing self-hosted vulnerability aggregation, workspaces, and API access at no cost. Above it, a Professional Edition adds extra API endpoints, custom vulnerability attributes, and LDAP or SAML single sign-on, and a Corporate Edition layers on executive reporting, analytics, advanced notifications, and ticketing integrations with tools like Jira, ServiceNow, GitLab, and SolarWinds. Neither commercial tier publishes list pricing; both require contacting sales for a custom quote.
Separately, Faraday markets managed offensive security engagements through its public pricing page as three service packages: a one-time Pentest on Demand engagement, an Always On tier bundling continuous testing across the Platform, OPS, CART, Enrichment, and Labs modules, and a custom Enterprise-plus tier for large organizations needing tailored scope. All of these service tiers are quote-based rather than self-serve.
Faraday is used to centralize and manage vulnerability data from penetration tests and automated scans. It aggregates output from more than 80 security tools into shared workspaces so teams can deduplicate, prioritize, and track findings from discovery through remediation.
Yes, Faraday offers a Community Edition that is free and open source under the GPL-3.0 license. Commercial Professional and Corporate editions add features like single sign-on, executive reporting, and ticketing integrations for a custom quoted price.
The Community Edition is the free, open-source core with basic vulnerability aggregation and workspaces. Professional adds extra API endpoints, custom vulnerability attributes, and LDAP or SAML single sign-on. Corporate adds executive reporting, analytics, advanced notifications, and ticketing tool integrations such as Jira and ServiceNow.
Faraday integrates with more than 80 security tools through its plugin system, including Nmap, Nessus, OpenVAS, Burp Suite, OWASP ZAP, Metasploit, and cloud security tools like AWS Inspector, importing both live tool output and pre-generated scan reports.
Faraday was founded by Federico Kirschbaum and Francisco Amato, with roots in Infobyte, a security research firm connected to Argentina's offensive security community and the Ekoparty security conference. The company is generally dated to 2014, with the open-source project's early public releases documented around 2015.
The closest open-source alternative is DefectDojo, which leans more toward DevSecOps and continuous integration pipeline scanning. Commercial alternatives include PlexTrac, a more expensive but polished pentest-collaboration platform, and Dradis, which is stronger on client-facing report templating.