Skip to content
Category

Application Security

Securing web applications, mobile apps, and software throughout the development lifecycle.

17 companies ranked by Innovation Matrix score.

83 /100

Endor Labs

Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.

Meaningful Innovator Application Security
78 /100

JFrog

Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…

Meaningful Innovator Application Security
78 /100

Snyk

Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.

Meaningful Innovator Application Security
73 /100

Apiiro

Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…

Meaningful Innovator Application Security
72 /100

Sonar

Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…

Meaningful Innovator Application Security
72 /100

ArmorCode

Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…

Meaningful Innovator Application Security
72 /100

Contrast Security

Instruments applications from within using IAST and RASP to find and block vulnerabilities as code actually executes, rather…

Meaningful Innovator Application Security
67 /100

Cycode

Unified ASPM platform with its own proprietary SAST, SCA, secrets, IaC, and container scanners covering the pipeline from…

Incremental Innovator Application Security
67 /100

Checkmarx

Unified 'Checkmarx One' application security platform spanning code, software supply chain, and cloud infrastructure scanning with SecOps integrations.

Incremental Innovator Application Security
67 /100

Mend.io

Software composition analysis platform, formerly WhiteSource, that uses reachability analysis to prioritize which open-source vulnerabilities are actually exploitable.

Incremental Innovator Application Security
65 /100

GitGuardian

Secrets detection and non-human identity security platform that scans code, CI/CD, and collaboration tools for exposed credentials in…

Incremental Innovator Application Security
65 /100

OX Security

'Active ASPM' platform combining native SDLC scanning with attack-path analysis and a software bill-of-materials lineage (PBOM) to prioritize…

Incremental Innovator Application Security
65 /100

Black Duck

Software composition analysis and static analysis platform (formerly Synopsys Software Integrity Group) focused on SBOM generation and open-source…

Incremental Innovator Application Security
63 /100

Veracode

SaaS-delivered application security platform offering static, dynamic, and software composition analysis with an annual industry benchmark report.

Incremental Innovator Application Security
62 /100

Legit Security

AI-native ASPM platform for discovering, prioritizing, and remediating risk across the software supply chain, with a separate module…

Incremental Innovator Application Security
55 /100

Invicti Security

A DAST-first web and API application security platform, formed from the 2018 merger of Netsparker and Acunetix, now…

Incremental Innovator Application Security
52 /100

OpenText Fortify

Long-established static, dynamic, and interactive application security testing suite, now an OpenText product line after passing through HP…

Incremental Innovator Application Security