Loading...

Application Security

Industry-leading SAST, DAST, SCA, API security, and DevSecOps platform providers

Try:

Capability Legend

SAST SAST
DAST DAST
SCA SCA
IAST IAST
API API Security
Container Container Scanning
IaC IaC Security
Secrets Secret Detection
SBOM SBOM
Review Code Review
CI/CD CI/CD Integration
RASP Runtime App Protection
Showing 68 of 68 vendors

SAST & Code Analysis (11)

Checkmarx
Checkmarx is an information security company specializing in software application security testing and risk management for software supply chains. It
SAST DAST SCA
Veracode
Veracode helps organizations manage application security risks effectively with its Application Risk Management platform, built for today's AI-driven
SAST DAST SCA
Semgrep
Semgrep App Security Platform provides an extensible developer-friendly application security platform that scans source code to surface true and actio
SAST SCA IaC
Backslash Security
Backslash provides an application security solution that merges code and cloud security findings for comprehensive protection. The platform offers vis
RASP
Bearer
Bearer provides developer-first software composition analysis and security testing tools to identify and remediate code security risks in DevSecOps wo
SAST SCA CI/CD
Dam Secure
Dam Secure provides AI-powered application security solutions that help development teams identify and remediate vulnerabilities in their software. Th
SAST
DeepSource
DeepSource automates code reviews to help teams ship faster with confidence, catching security issues and improving code quality across the developmen
SAST Review
Fluid Attacks
Fluid Attacks integrates AI, automated tools, and pentesters to continuously help development teams build secure software without delays. The company
SAST DAST SCA
Qwiet AI
Qwiet AI secures applications with AI-powered code analysis, natural language insights, and context-aware findings - built to empower developers and p
SAST Review CI/CD
SecureFlag
SecureFlag provides hands-on secure coding training for Developers, DevOps, Cloud and QA Engineers to write secure software from the first keystroke.
SAST
Security Journey
Security Journey trains developers to write secure code by having them exploit and fix vulnerabilities in a web-based sandbox, focusing on AI-assisted
SAST

DAST & Application Testing (10)

Invicti
Invicti is a web application and API security platform that provides accurate and automated application security testing for enterprise organizations.
DAST IAST API
PortSwigger
PortSwigger offers tools for web application security testing and scanning. The company provides software solutions for identifying vulnerabilities in
DAST API CI/CD
Bright Security
Bright Security helps teams to find and fix security issues fast with automated DAST, API, and cloud testing built for modern DevSecOps. The company's
DAST API CI/CD
CMD+CTRL Security
CMD+CTRL Security provides industry-leading application security training to help organizations create secure software through role-based learning and
DAST
DefendLab
DefendLab offers application security testing and vulnerability management services for enterprises. The company provides comprehensive security asses
CI/CD RASP
Detectify
Detectify is a cybersecurity company that provides web application security testing and vulnerability detection services to businesses. The company's
DAST
ImmuniWeb
ImmuniWeb develops machine learning and AI technologies for SaaS-based application security solutions provided via its proprietary ImmuniWeb AI Platfo
DAST API
Indusface
Indusface provides AI-powered application security solutions, including Web Application and API Protection, Web Application Firewall, DAST, and Malwar
DAST API
NightVision
NightVision is a web and API security testing platform that simplifies application security by providing fast, accurate, and comprehensive scans to id
SAST DAST API
StackHawk
StackHawk enables AppSec teams to prioritize testing and fixing what matters with its shift-left runtime testing (DAST) and attack surface discovery f
DAST API CI/CD

SCA & Supply Chain Security (11)

Sonatype
Sonatype provides intelligence & automated governance to help you build faster & safer with open source and AI. From the creators of Nexus Repository,
SCA Container SBOM
Mend.io
Mend.io offers the first AI native application security platform, purpose-built to secure AI-generated code and embedded AI components. It provides a
SCA Container SBOM
Anchore
Anchore provides software supply chain security solutions that automate vulnerability scanning, SBOM management, and compliance enforcement for contai
SCA Container SBOM
Endor Labs
Endor Labs provides an application security posture management platform that unifies SCA, SAST, secrets detection, and CI/CD security into a single de
SCA SBOM CI/CD
HeroDevs
HeroDevs provides secure drop-in replacements for end-of-life open source software, helping engineering teams eliminate risk from unsupported dependen
SCA CI/CD
Manifest
Manifest provides software supply chain security and SBOM generation solutions for highly regulated organizations. It automates SBOM creation, manages
SBOM
Phylum
Phylum is a software supply chain security company that defends applications against malicious open-source packages. The platform analyzes open-source
SCA SBOM CI/CD
SOOS
SOOS AppSec - Find & fix vulnerabilities with SCA, DAST, SAST, and Container scans. Manage SBOMs across your SDLC. The company provides enterprise-gra
SAST DAST SCA
Scantist
Scantist is a Singapore-based cybersecurity company that helps organisations secure modern software, digital products, and AI-driven systems by combin
SCA
Seal Security
Seal Security's AppSec Remediation Agent delivers real, human-vetted, production-ready fixes for open source vulnerabilities - resolving risk directly
SCA
Xygeni
Xygeni is an AI-powered application security platform that detects, prioritizes, and remediates vulnerabilities and malware end-to-end, without tradit
SAST SCA IaC

API Security (5)

42Crunch
The company provides an API Security platform that proactively tests, fixes, and protects APIs from security vulnerabilities throughout the developmen
API CI/CD RASP
AppSentinels
AppSentinels provides unified agentic AI and API security solutions to protect business logic across the entire application lifecycle. The company sec
API RASP
Escape
Escape is an AI-powered offensive security platform that helps teams replace legacy scanners with continuous discovery, pentesting, and remediation. T
API CI/CD
Nokod Security
Nokod Security provides enterprise low-code, no-code, and AI agent security solutions to detect and remediate hidden risks in citizen development. The
API RASP
Traceable AI
Traceable AI provides comprehensive security for applications and APIs by discovering, protecting, and testing all apps and APIs. The company's platfo
API RASP

DevSecOps & ASPM Platform (11)

GitLab
GitLab provides an intelligent orchestration platform for DevSecOps, offering a single platform for teams to plan, code, test, and deploy software fas
SAST DAST SCA
Apiiro
Apiiro is an application security posture management (ASPM) platform that helps enterprises prevent risks before code exists. It provides AI-powered t
SAST SCA API
ArmorCode
ArmorCode's Unified Exposure Management Platform helps security teams unify, prioritize, and remediate vulnerabilities 10x faster by leveraging AI-pow
SAST DAST SCA
Arnica
Arnica enhances application security through automated tools, providing secure code, streamlined development processes, and compliance ease. It offers
SAST SCA Secrets
Cycode
Cycode's Agentic Development Security Platform unites security and development teams with actionable, code-to-runtime context to identify, prioritize,
SAST SCA Container
DefectDojo
DefectDojo is a security tool that automates application security vulnerability management, providing a platform for smarter and scalable security. It
CI/CD
Digital.ai
Digital.ai is an AI-powered software delivery platform that unifies, secures, and generates predictive insights across the software lifecycle to enhan
SAST CI/CD RASP
Heeler
Heeler is a remediation platform that helps modern software teams mitigate open source risk through deterministic analysis and preventative guardrails
SCA
Legit Security
Legit Security is the AI-native ASPM platform to detect, fix and prevent AppSec risk from AI-generated code, secrets, and critical vulnerabilities. It
SAST SCA IaC
Palosade
Palosade: AI-Powered Cybersecurity Automation - Automate your security program and unleash your business potential with Palosade's AI agents that stre
CI/CD
Tromzo
Tromzo builds actionable context from code-to-cloud graph to accelerate remediation of critical risks across the software supply chain through AI-powe
SBOM CI/CD

Mobile Application Security (5)

Appknox
Appknox provides AI-powered enterprise-grade mobile application security solutions for enterprises. The company offers vulnerability assessment, penet
SAST DAST CI/CD
Corellium
Corellium provides virtual iOS and Android devices for security testing, research, and DevSecOps. The company offers solutions for mobile app pentesti
SAST DAST
DoveRunner
DoveRunner provides complete mobile app and content security solutions for top media, entertainment, financial, and OTT leaders. Its robust end-to-end
SAST
Guardsquare
Guardsquare is the leader in mobile application security, providing multi-layered protection for Android and iOS apps through its products such as Dex
SAST DAST CI/CD
Zimperium Mobile Security Solutions
Zimperium is the only mobile security platform purpose-built for enterprise, securing both mobile devices and applications so they can securely access
SAST DAST RASP

Specialized Application Security (14)

Contrast Security
Contrast Security delivers real-time and always-on application security INSIDE your apps and APIs. The company provides a runtime security platform th
SAST SCA IAST
AppOmni
AppOmni provides enterprise-level SaaS application security solutions, offering deep posture inspection, advanced detection, elastic scale, and leadin
CI/CD
AxisNow
AxisNow is a cloud-agnostic edge platform that provides multi-CDN and private CDN services, application security, and delivery solutions. It enables u
CI/CD
CalypsoAI
CalypsoAI provides an AI security and governance platform that enables enterprises to safely adopt and scale generative AI by monitoring, controlling,
CI/CD
Dynatrace
Dynatrace provides an AI-powered observability platform for monitoring, analyzing, and optimizing application performance, software development, cyber
CI/CD RASP
F5
F5, Inc. is an American technology company specializing in application security, multi-cloud management, online fraud prevention, and network security
API RASP
GuidePoint Security
GuidePoint Security provides trusted cybersecurity consulting expertise, solutions, and services that help organizations make better decisions and min
API
Imperva
Imperva provides complete cyber security by protecting what really matters most-your data and applications-whether on-premises or in the cloud. The co
API RASP
InstaSecure
InstaSecure delivers preventive cloud guardrails and virtual patching to remediate CNAPP/IAM risks in minutes-no code changes. Works with AWS, IdPs, a
IaC
ONEKEY
ONEKEY provides an all-in-one platform for product cybersecurity and compliance, offering automated SBOM management, vulnerability analysis, and compl
SAST SCA SBOM
OWASP Foundation
OWASP Foundation is a non-profit organization that works to improve the security of software through open-source information and resources on IoT, sys
CI/CD
Oligo Security
Oligo Security provides an application and AI runtime security platform that detects and prevents threats in real-time across cloud, code, and AI work
RASP
Thales
Thales Group is a global technology leader providing solutions in aerospace, space, defense, security, and transportation. The company offers a range
ThreatModeler
ThreatModeler provides an intelligent threat modeling solution that unifies applications, cloud, and infrastructure to give enterprises continuous vis
CI/CD
Vendor Directory
Lookup Tools
Analysis
Bulk & Enterprise
Resources
Close