Application Security
Securing web applications, mobile apps, and software throughout the development lifecycle.
17 companies ranked by Innovation Matrix score.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…
Contrast Security
Instruments applications from within using IAST and RASP to find and block vulnerabilities as code actually executes, rather…
Cycode
Unified ASPM platform with its own proprietary SAST, SCA, secrets, IaC, and container scanners covering the pipeline from…
Checkmarx
Unified 'Checkmarx One' application security platform spanning code, software supply chain, and cloud infrastructure scanning with SecOps integrations.
Mend.io
Software composition analysis platform, formerly WhiteSource, that uses reachability analysis to prioritize which open-source vulnerabilities are actually exploitable.
GitGuardian
Secrets detection and non-human identity security platform that scans code, CI/CD, and collaboration tools for exposed credentials in…
OX Security
'Active ASPM' platform combining native SDLC scanning with attack-path analysis and a software bill-of-materials lineage (PBOM) to prioritize…
Black Duck
Software composition analysis and static analysis platform (formerly Synopsys Software Integrity Group) focused on SBOM generation and open-source…
Veracode
SaaS-delivered application security platform offering static, dynamic, and software composition analysis with an annual industry benchmark report.
Legit Security
AI-native ASPM platform for discovering, prioritizing, and remediating risk across the software supply chain, with a separate module…
Invicti Security
A DAST-first web and API application security platform, formed from the 2018 merger of Netsparker and Acunetix, now…
OpenText Fortify
Long-established static, dynamic, and interactive application security testing suite, now an OpenText product line after passing through HP…