Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Application Security (ASPM)

Application Security (ASPM)

Build an evaluation questionnaire →

How vendors compareSource labelsThe chip next to each vendor shows where the assessment came from and how independently it's been verified. A higher label is a more independent source — not a better product. See the full trust model at How trust works.

balanced · vendor-sourced

Neutral strengths and gaps for each vendor in this category, from vendors' own public materials — so the questionnaire favors no single vendor. Gaps reflect capabilities not emphasized in public materials, not rankings.

VendorStrengthsGaps / watch-outs
Aikido Security AI baselineConsolidated, developer-friendly all-in-one (SAST/SCA/secrets/CSPM/DAST) for lean teams, with AI code coverage.Consolidation trades some depth versus specialist tools, and the enterprise track record is younger.
Apiiro AI baselineDeep code-to-runtime risk graph with design/architecture risk analysis and reachability-based prioritization.Emphasizes risk orchestration and graphing; native scanner depth can vary versus dedicated specialists.
Black Duck AI baselineComprehensive enterprise AppSec suite (SCA, Coverity SAST, DAST, IAST, fuzzing, ASPM) with deep compliance.Breadth and enterprise tooling can mean heavier deployment and higher cost.
Checkmarx AI baselineBroad AppSec coverage (SAST, SCA, API, IaC, container, ASPM) built for enterprise scale.Breadth can add configuration/tuning overhead, and result volume needs strong prioritization.
Cycode AI baselineASPM plus software supply chain security spanning SAST, SCA, secrets, and CI/CD pipeline protection.Newer ASPM entrant; individual native scanners may be lighter than specialist point tools.
Endor Labs AI baselineReachability-based SCA that cuts dependency noise, plus AI SAST and supply-chain malware prevention.Best known for SCA reachability; broader ASPM breadth is still expanding in public materials.
Legit Security AI baselineASPM and SDLC posture with software supply chain, secrets, and AI-SDLC coverage.Orchestration-focused; depth of some native scanning depends on integrated tools.
Mend AI baselineStrong SCA heritage plus SAST, container, and AI application security.SCA is the anchor; ASPM orchestration breadth is emphasized less than composition analysis.
Ox Security AI baselineASPM that prioritizes reachable risks and unifies code-to-cloud and supply chain with secrets and SBOM.Aggregation/prioritization focus; relies on integrated scanners for some analysis depth.
Semgrep AI baselineFast, customizable rule-based SAST/SCA/secrets with strong developer adoption and an open core.Rule-based approach can require tuning; DAST and runtime are not the focus.
Snyk AI baselineDeveloper-first SCA, SAST, container, and IaC scanning with strong IDE and pull-request workflow and broad ecosystem coverage.Public materials emphasize developer breadth; orchestration of third-party scanners into a unified ASPM view is less central.
Sonar AI baselineDeep code quality plus security (SAST/SCA) with a mature IDE, server, and cloud footprint.Heritage is code quality; supply-chain and runtime concerns are less central than code analysis.
Veracode AI baselineEstablished SAST/DAST/SCA with ASPM (Risk Manager) and strong policy, compliance, and remediation guidance.Historically scan-service oriented; developer-native speed is emphasized less than governance.

Analyst coverage

Public fact of coverage — not proprietary ratings
  • Forrester — (awaiting analyst)
    Unverifiedsource ↗
  • Gartner — (awaiting analyst)
    Unverifiedsource ↗
  • IT-Harvest — Richard Stiennon
    Unverifiedsource ↗
  • Latio Tech — James Berthoty
    Unverifiedsource ↗

Integration ecosystemUI-25 — integration network graphEvery Application Security (ASPM) vendor with a detected integration, plus the vendors they integrate with (any category) — integrations are mostly cross-category in practice, so this shows the real neighborhood, not just same-category edges. Application Security (ASPM) vendors are highlighted; connected vendors from other categories are dimmer. Circle size = how many integrations that vendor has. Sourced from each vendor's own published integration/partner pages (see UI-12).

624 edges

Status alerts in Application Security (ASPM)UI-182 — category status-page rollupVendors in this category whose own public status page most recently reported degraded performance or a major outage — sourced from each vendor's real status page, never inferred. Not a live feed: each row shows exactly when it was last checked (rechecked roughly every 30 days), so treat this as a recent signal to verify directly on the vendor's own status page, not a real-time monitor.

  • Tenablemajor outagestatus page ↗as of 8/14/2026

CVE exposure in Application Security (ASPM)UI-71 — vendor/CVE treemapEvery Application Security (ASPM) vendor with at least one tracked CVE, sized by count — same data and coloring as the full-catalog version on the Browse page, scoped to just this category.

RSS ⇢

41 vendors with at least one tracked CVE, sized by how many. Color = relative volume.About CVE trackingSourced from the public NVD database, matched by vendor name (same data as each vendor's own CVE list). Tracking is capped at 100 CVEs per vendor as a scan guard — 1 vendor shown here hit that cap, so their real count may be higher than what's plotted. Vendor-level only, not per-product/version — always check the linked NVD record before drawing conclusions about a specific product.

Ivanti100+ (tracking cap) CVEsRapid785 CVEsManifest71 CVEsTanium56 CVEsSonatype54 CVEsTenable49 CVEsJFrog43 CVEsDatadog28 CVEsFortra26 CVEsCobalt19 CVEsBearer19 CVEsRaven18 CVEsSnyk17 CVEsHackerOne16 CVEsEscape15 CVEsGuardRails13 CVEsIntruder9 CVEsSonar8 CVEsCoder7 CVEsNullify7 CVEsCheckmarx6 CVEsBlack Duck6 CVEsAnchore6 CVEsAcunetix6 CVEs

Security posture in Application Security (ASPM)UI-108 — category security rollupA category-level rollup of the same per-vendor signals shown on each vendor's own page (UI-90/99/102): security-header checks against each vendor's own homepage, and keyword-matched compliance certifications. Coverage is partial — only vendors checked so far are counted, not the whole category — so this describes what's known, not a claim about every vendor in Application Security (ASPM).

41/53
checked vendors have a strong security-header posture (3+/5)
2
vendors with a disclosed certification
53/158
vendors in this category checked so far

Vendors (158)

⚖ Compare vendors side-by-side

Pick 2–4 vendors, then compare their products and neutral strengths/gaps.

0/4 selected
  • Acunetix2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API vulnerability scanning and testing for REST, SOAP, and GraphQL APIs
    Acunetix Web Application & API Security
  • AdaCore1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Static analysis tool for C/C++ and enterprise languages, now part of AdaCore
    CodeSecure
  • aDolus Technology6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SaaS platform for software supply chain monitoring across IT, IoT, and OT.
    aDolus SBOM Creation / FACT Platform
  • Adronite1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered secure code platform for vulnerability detection & codebase analysis.
    Adronite
  • Aikido Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Developer-first application security platform.
  • Almanax1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered SAST tool for vulnerability detection, triaging, and patching
    Almanax
  • Amplify Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated vulnerability remediation tool that fixes code security issues
    Amplify Security Fix Your Code
  • Anchore3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SBOM-powered SCA platform for container & source code security scanning
    Anchore Anchore Enterprise
  • Apiiro15 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management.
    Apiiro ASPM PlatformApiiro AI SASTApiiro Deep Code AnalysisApiiro Dev-centric, enterprise-grade application risk managementApiiro IaC SecurityApiiro SCAApiiro XBOMApiiro DesignApiiro DevelopSecrets Detection & ValidationContextual SCA
  • AppCheck6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API vulnerability scanner with support for REST, SOAP, and GraphQL APIs
    AppCheck API ScannerAppCheck CMS Security ScanningAppCheck DAST ToolAppCheck SPA ScannerAppCheck Web App Scanner
  • Appknox3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Binary-based SBOM generation for mobile apps with vulnerability analysis
    Appknox SBOM
  • AppSecAI1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI platform that triages AppSec findings & generates validated fix PRs.
    AppSecAI
  • AquilaX1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    An application security platform that combines multiple security scanners including SAST, SCA, container security, and compliance reporting with CI/CD integration capabilities.
    AquilaX
  • Archipelo1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DevSPM platform attributing CVEs and security findings to developer actions.
    Archipelo DevSPM Platform
  • ArmorCode7 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    ASPM platform unifying findings from code, cloud, and infrastructure scanners
    ArmorCode Application Security Posture ManagementArmorCode ASPM PlatformArmorCode DevSecOps PlatformArmorCode Mergers and Acquisitions SecurityArmorCode Platform
  • ArmourZero1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered automated vuln scanning for apps, APIs, domains, and cloud
    ArmourZero Automated Vulnerability Management
  • Arnica6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Developer-native supply chain security.
    Arnica ASPMAI SASTArnica SCAHardcoded SecretsArnica Pipelineless AppSec
  • Astra Security4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Website security suite with DDoS, WAF, malware scanning & bot protection.
    Astra Security DAST ScannerAstra Website Scanner
  • Beagle Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered automated penetration testing platform for web apps, APIs & GraphQL
    Beagle Security AI Pentesting Platform
  • Bearer1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Developer-first SAST tool for finding security & privacy vulns in code.
    Bearer
  • Black Duck6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security and software composition analysis.
    Black Duck Black Duck SCABlack Duck Code Sight IDE Plug-inBlack Duck Coverity Static AnalysisBlack Duck Polaris PlatformBlack Duck Seeker IASTBlack Duck Signal™
  • Boman.ai2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    ASPM platform for monitoring, prioritizing, and remediating risks across SDLC
    Boman.ai AppSec ToolBoman.ai Boman
  • BoostSecurity4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    ASPM platform for monitoring and hardening app security across SDLC
    BoostSecurity ASPMBoostSecurity Continuous AppSec Testing
  • Bright Security3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered AppSec platform for DAST, IAST, and API security testing
    Bright Sec Bright STARBright Security Bright STARBright Security Dynamic Application Security Testing
  • Checkmarx17 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security testing platform.
    Checkmarx OneCheckmarx SASTCheckmarx ASPMCheckmarx NG SASTCheckmarx SCACheckmarx One Application Security PlatformCheckmarx One AssistCheckmarx One DASTCheckmarx One IaC SecurityCheckmarx One Malicious Package ProtectionCheckmarx One Software Composition Analysis (SCA)Checkmarx Tromzo AI Powered Application Security Posture Management
  • CloudDefense.AI2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered CNAPP combining SAST, DAST, API, SCA, CSPM, CWPP, and CIEM capabilities
    CloudDefense.AI QINA (App Security)
  • CloudMatos10 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime security gateway for multi-agent AI systems with policy enforcement
    CloudMatos Application Security Posture ManagementMatosSphere Software Composition Analysis
  • Clover Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI agent platform for product security across the software dev lifecycle.
    Clover Platform
  • COANA1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA tool using reachability analysis to eliminate 80%+ false positive vulnerabilities.
    Coana Remediate Vulnerabilities
  • Cobalt3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Continuous external asset discovery and monitoring with daily domain scans.
    Cobalt DAST
  • Codacy1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Code security and quality platform with SAST, SCA, DAST, and AI code protection
    Codacy Security and Code Quality
  • Code Intelligence1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-automated fuzz testing platform for detecting software vulnerabilities.
    Code Intelligence
  • Coder1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Self-hosted dev environment platform with AI agent governance via Terraform.
    Coder
  • CodeThreatAI1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-native AppSec platform for code security analysis and vulnerability detection
    CodeThreat AI-Native AppSec Platform
  • Complioty1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Integrated product security platform covering threat modeling, CVE monitoring, and CVD.
    Complioty
  • Contrast Security7 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime protection for apps and APIs detecting and blocking exploits and attacks
    Contrast Application Security Testing (AST)Contrast ContrastScan (SAST)Contrast OneContrast Runtime Security PlatformContrast Software Composition Analysis (SCA)
  • Conviso2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Orchestrates and centralizes app security testing results from multiple scanners
    Conviso AppScanConviso Vuln Intelligence
  • CredShields3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cloud security audit service for AWS, Azure, and GCP infrastructure
    CredShields SolidityScan
  • Cybeats2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automates SBOM ingestion, validation, and vulnerability monitoring for supply chain risk.
    Cybeats SBOM ConsumerCybeats SBOM Studio
  • Cycode12 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management and software supply chain security.
    Cycode SASTNext-Gen SCASecrets ScanningCycode ASPMCycode Enterprise Software Composition AnalysisCycode IaC SecurityCycode SAST - Static Application Security TestingCycode Source Code Leakage Detection
  • Dam Secure1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    IDE-native guardrails that enforce security rules on AI-generated code in real time.
    Dam Secure
  • Data Theorem6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security platform for discovery, testing, and runtime protection
    Data Theorem AppSecData Theorem Code SAST SecureData Theorem Web Secure
  • Datadog11 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime protection for web apps and APIs against attacks and threats
    Datadog Code SecurityDatadog Runtime Code Analysis (IAST)Datadog Software Composition AnalysisDatadog Static Code Analysis
  • Dedge Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Web3 security platform for smart contract analysis and blockchain development
    Dedge Security W3SPM
  • DeepSource3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered code cleanup tool that automatically fixes security and quality issues
    DeepSource Autofix™ AIDeepSource SASTDeepSource SCA
  • Delphos Labs1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered reverse engineering tool for analyzing compiled binaries
    Delphos Labs Analyze
  • DeployHub3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Continuous vulnerability detection platform for live production environments
    DeployHub Automated Vulnerability Detection PlatformDeployHub OrteliusDeployHub SBOM Vulnerability Management
  • depthfirst1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered AppSec platform for code, supply chain, secrets & DAST.
    depthfirst Platform
  • DerSecur5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DAST tool that scans live web apps to detect vulnerabilities in real-time
    DerScanner Dynamic Application Security Testing (DAST)DerScanner Full Cycle Application Security TestingDerSecur DerScannerDerSecur Software Composition Analysis (SCA)
  • DigitSec1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated app security testing platform for Salesforce and B2C Commerce
    DigitSec Automated Application Security Testing
  • DryRun Security6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-native application security with contextual code analysis: SAST, PR review, secrets, IaC, and natural-language code policies.
    DryRun AI-Native SASTDryRun PR Code ReviewDryRun DeepScan AgentDryRun Custom Code PoliciesDryRun Secrets DetectionDryRun Security AppSec Agents
  • Edgescan6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API discovery, vulnerability scanning, and penetration testing platform
    Edgescan Managed Application Security Testing
  • Endor Labs7 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain and ASPM.
    Endor LabsEndor AI SASTEndor SCA ReachabilityEndor Secrets DetectionEndor Labs Application Security
  • Entersoft Security6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cloud-based vulnerability assessment tool for web application security
    EnProbe CybersecurityEntersoft Application Security
  • Escape8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security from code to cloud: attack surface management, business-logic-aware DAST, AI pentesting, and AI-powered remediation.
    Escape API Security PlatformEscape DASTEscape GraphQL Security Testing
  • Exodos Labs1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Unified SBOM management platform for supply chain security, compliance, and license
    Exodos Labs Exodos Labs Platform
  • Feroot1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    GLBA compliance monitoring for financial institutions' websites and apps
    Feroot GLBA Compliance Monitoring
  • Fluid Attacks5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered AppSec platform combining automated testing with pentesting
    Fluid Attacks Continuous HackingFluid Attacks Dynamic Application Security Testing (DAST)Fluid Attacks SASTFluid Attacks SCA
  • Flyingduck1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA tool for identifying & resolving vulnerabilities in dependencies
    Flyingduck Software Composition Analysis
  • Fortra13 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Black box fuzzer and DAST tool for testing application security
    Fortra BeSTORM
  • FOSSA1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain security platform for managing open source dependencies
    FOSSA
  • FossID1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA tool for code scanning, license identification, and SBOM generation
    FossID Software Composition Analysis
  • FYEO5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Security audit service for agentic AI systems via threat modeling & red teaming.
    FYEO Third Party Library Scanner
  • Gomboc AI1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered IaC remediation tool that auto-generates merge-ready security fix PRs.
    Gomboc AI ACSA
  • GrammaTech6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    FPGA trust assessment tool for detecting hardware Trojans and counterfeits
    GrammaTech Bug-Injector
  • Greenbone AG6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI assistant that transforms OpenVAS scans into prioritized remediation plans
    Greenbone Web App Scanning
  • Guardian3604 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    24/7 network intrusion detection with immediate alert notifications.
    Guardian360 Lighthouse
  • GuardRails1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DevSecOps platform for vulnerability detection and developer security training
    GuardRails
  • HackerOne3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Human-led AI red teaming service for testing AI models, APIs, and integrations
    HackerOne Code
  • Haicker1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Continuous automated pentesting platform with GitHub integration and AI agents
    Haicker
  • Halo Security7 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DAST tool for detecting web app vulnerabilities like SQL injection and XSS
    Halo Security Application Scanning
  • Heeler1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
    Heeler Application Security Auto-Remediation
  • HeroDevs1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Platform to identify, remediate, and prevent EOL open source software risk.
    HeroDevs
  • Hopper Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven platform that patches OSS CVEs in-place without version upgrades.
    Hopper Security
  • Indusface6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Managed DDoS protection service for websites and APIs with 24x7 SOC monitoring
    Indusface WAS - Website Vulnerability Scanner
  • Insignary1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA tool for source code, binaries, and AI-generated code vulnerability detection
    Insignary Clarity
  • Intruder10 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Continuous attack surface and vulnerability management: ASM, external/internal scanning, AI pentesting, and cloud config checks in one platform.
    Intruder Web Application Scanning
  • Invicti4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security testing platform with discovery, scanning, and remediation
    Invicti Software Composition AnalysisInvicti ASPMInvicti DAST
  • Ivanti14 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Remote access VPN with zero trust security and unified client access
    Ivanti Neurons for ASPM
  • JFrog5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    App security testing platform with SAST, SCA, secrets detection, and IaC scanning
    JFrog Advanced Security
  • Jit6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management with AI agents that orchestrate code, cloud, and compliance workflows.
    Jit AI Agents for Product SecurityJit Vulnerability Detection AgentsJit Vulnerability Management AgentsJit Secure SDLC AgentsJit Governance AgentsJit Execute Your Product Security Workflows with AI Agents
  • Kodem2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Unified engine correlating static & runtime analysis for app security
    Kodem C.O.R.E.Kodem Zero-waste Application Security
  • Labrador Labs4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Integrated portal for open source vulnerability analysis and action plan mgmt.
    Labrador IVASLabrador SCA
  • Legit Security9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture and software supply chain.
    Legit ASPMLegit Code SecurityLegit Secrets DetectionLegit AI-Native ASPM PlatformLegit Security Vulnerability Management
  • Lineaje9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain management and SBOM.
    Lineaje Open Source ManagerLineaje SCA 360
  • Manifest5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Creates structured inventories of AI system components for transparency & risk mgmt
    Manifest Platform
  • Mayhem Security2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Dynamic SBOM tool that reduces noise by identifying reachable CVEs in runtime
    Dynamic SBOMMayhem Code Security
  • Mend6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security (SCA/SAST), formerly WhiteSource.
    Mend AI Native AppSec PlatformMend DASTMend Mend AI Native AppSec PlatformMend SCA
  • MergeBase1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA platform for managing open source vulnerabilities across SDLC
    MergeBase Software Composition Analysis
  • Meterian4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA tool for scanning container images for vulnerabilities and compliance.
    Meterian BOSSC (Container Scanner)Meterian ISAACMeterian Project ScannerMeterian Web Scanner
  • Miggo4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application monitoring and security platform that provides runtime visibility, threat detection, and automated response capabilities for application-layer security
    Miggo Predictive Vulnerability Database
  • MindFort1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered platform for continuous automated penetration testing of web apps
    MindFort
  • Mobb1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven automated vulnerability remediation for DevSecOps workflows
    Mobb For DevSecOps
  • Mycroft6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered platform automating security compliance for companies.
    Mycroft App Security
  • NightVision1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DAST platform for scanning web apps & APIs within CI/CD pipelines.
    NightVision Platform
  • Nokod Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Security platform for enterprise low-code, no-code, and AI agent environments.
    Nokod Security
  • Nullify1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI platform that finds, triages, and auto-remediates vulnerabilities end-to-end.
    Nullify
  • Offensive3601 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SAST tool using virtual compilers to analyze source code for vulnerabilities
    Offensive 360 O360
  • olympix2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Enterprise security tools for smart contract vulnerability detection in Web3/DeFi
    Olympix Enterprise-Grade Security ToolsOlympix Security Tools
  • Onward Security4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cloud-based DDoS attack simulation & monitoring platform for defense testing.
    HERCULES SecSAM
  • OpenRefactory1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated C code analysis and repair tool benchmarked against NIST SAMATE.
    OpenRefactory iCR for C
  • Opsera2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DevSecOps platform for unified tool integration, security, and governance
    Opsera DevSecOps Platform
  • Ox Security6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management and supply chain.
    OX Secrets/PII DetectionOX ASPMOX CodeOX Application Security
  • Pathlock9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Identifies and manages SoD and sensitive access risks across business apps
    Pathlock SAP Cybersecurity
  • Perforce Software1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Static code analyzer & SAST tool for C, C++, Java, JavaScript, Python, Kotlin
    Perforce Klocwork
  • Phoenix Security6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Risk-based vulnerability and application security: unified VM ingesting 30+ scanners, AI SAST/SCA, threat-centric scoring, a supply-chain firewall, and agentic remediation.
    Phoenix Security ASPM
  • Pi1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Agentic product security platform that prevents recurring vulns via institutional memory.
    Pi
  • Pixee1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered automated code security remediation bot for vulnerability fixes
    Pixee Pixeebot
  • PlaxidityX8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    IDPS for automotive CAN bus networks detecting threats and anomalies.
    PlaxidityX DevSecOps PlatformPlaxidityX SW Supply Chain Security
  • PortSwigger Ltd.2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    An enterprise-scale dynamic application security testing (DAST) platform that provides automated vulnerability scanning and security assessment for web applications.
    Burp Suite Enterprise Edition
  • Prancer Enterprise5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven autonomous pentesting platform for continuous vulnerability discovery
    Prancer Unified White-Box + Black-Box
  • Probely1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DAST scanner for discovering and testing APIs and web apps for vulns.
    Probely (Snyk API & Web)
  • ProjectDiscovery2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI agent for AppSec workflows that adapts to environments at dev speed
    ProjectDiscovery Neo
  • Qodo1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI platform for automated code review, security risk detection across the SDLC.
    Qodo AI Code Review Platform
  • Qwiet4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered SAST tool for scanning code vulnerabilities with low false positives
    Qwiet AI SASTQwiet SBOM
  • Rapid716 productsUnclaimed
    InsightAppSecRapid7 InsightAppSec
  • Raven5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime detection & response for cloud workloads and application libraries
    Raven Runtime SCA
  • Reflectiz4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Remote web scanning tool for DORA compliance in financial services.
    Reflectiz Platform
  • Rein Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Agentless appsec platform providing real-time visibility into app behavior
    Rein Security Rein Application Security Platform
  • Root.io3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated vulnerability patching for open-source libraries and containers
    Root
  • Safe Security6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cyber risk quantification platform using FAIR methodology for financial analysis
    Balbix Comprehensive SBOM
  • Saltworks1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AppSec posture mgmt platform for aggregating & reporting app security data
    SaltWorks SaltMiner
  • SaltyCloud3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated web vulnerability scanner for SQLi, XSS, and other web app flaws
    SaltyCloud Dorkbot
  • SCANOSS2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Identifies cryptographic algorithms and libraries in code for compliance
    SCANOSS Encryption DatasetSCANOSS Security Dataset
  • Scantist1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AppSec platform for supply chain security, SBOM analysis & vuln mgmt
    Scantist TrustX
  • Seal Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automates open source vulnerability remediation and patch management
    Seal Security
  • Sec110 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven CSPM for multi-cloud risk detection and compliance monitoring
    Sec1 KairoSec1 ProSASTSec1 Scopy
  • Secure Blink1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DAST platform for web app & API vulnerability scanning with AI-enabled features
    Secure Blink ThreatSpy
  • Secure Decisions2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    GIS-based visual analytics tool for wireless security risk assessment.
    Secure Decisions Code Dx
  • Semgrep6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Code and supply-chain security (SAST).
    Semgrep CodeSemgrep Supply ChainSemgrep SecretsSemgrep AppSec PlatformSemgrep GuardianSemgrep Assistant
  • Snyk11 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Developer-first application security (SCA/SAST).
    Snyk ContainerSnyk Open SourceSnyk CodeSnyk IaCSnyk AI Security Posture ManagementSnyk Continuous Offensive SecuritySnyk AI Security PlatformSnyk API & WebSnyk DeepCode AISnyk Open Source License Compliance
  • Software Improvement Group1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software portfolio governance platform for code quality and security analysis
    Software Improvement Group Sigrid®
  • Sonar3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Code quality and static analysis (SonarQube).
    SonarSource SonarQubeSonarSource SonarQube Cloud
  • Sonatype3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Container security platform for vulnerability scanning and policy enforcement
    Sonatype LifecycleSonatype SBOM Manager
  • SOOS4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Container vulnerability & license scanner with deep dependency tree analysis.
    SOOS DASTSOOS SASTSOOS SBOM Manager
  • Spectral3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA tool for detecting OSS vulnerabilities in code and dependencies
    Check Point CloudGuard Spectral
  • StackHawk4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API discovery tool that maps application attack surface from source code
    StackHawk AppSecStackHawk AppSec Intelligence PlatformStackHawk StackHawk
  • Staris1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven AppSec platform that validates exploitable vulns in ~4 hours.
    Staris
  • Start Left® Security8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Scans IaC templates for misconfigs and vulns before deployment.
    Start Left® IaC SecurityStart Left® Security DASTStart Left™ SaaS Security Mgmt Platform
  • Strobes Security4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven threat exposure mgmt platform for vuln discovery & prioritization
    Strobes Application Security Posture Management
  • Symbiotic Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Real-time AI-powered code security tool for IDE vulnerability detection & fix
    Symbiotic Security
  • Tanium11 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Digital certificate discovery, monitoring, and expiration management platform
    Tanium SBOM
  • Tenable8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Exposure and vulnerability management.
    Tenable Web App Scanning
  • The Code Registry3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered code analysis platform for security, quality, and developer insights
    The Code Registry AI-Powered Code IntelligenceThe Code Registry Technical Due DiligenceThe Code Registry Application & Supply Chain Security
  • Threatrix1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Autonomous open source supply chain security & license compliance platform.
    Threatrix Autonomous Platform
  • TrustInSoft1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Formal verification tools & services for C/Rust software security & safety.
    TrustInSoft
  • Trustlook2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-based Android malware scanning via SDK and REST API for mobile/IoT.
    Trustlook Smart Contract Audit
  • Upwind9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime-powered cloud security (CNAPP).
    Upwind Code Security
  • Veracode12 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security testing and management.
    Veracode Static AnalysisVeracode SCAVeracode Risk Manager (ASPM)Veracode SASTVeracode DASTVeracode Application Risk ManagementVeracode Application Risk Management PlatformVeracode Comprehensive Application Risk ManagementVeracode Risk ManagerVeracode Secure SDLC
  • VeriBee1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Source code verification tool that finds bugs and security vulnerabilities
    Veribee
  • VicOne5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    GenAI-powered automotive security platform for risk mgmt & threat detection
    VicOne xZETA
  • Vidoc Security Lab1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Real-time vulnerability detection and automated fixing for AI-generated code
    Vidoc SecureAI
  • VigilantOps1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SBOM lifecycle management platform for software supply chain security
    Vigilant Ops SBOM Lifecycle Management
  • VulnSign1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DAST tool for scanning web apps, microservices, and APIs for vulnerabilities
    VulnSign Dynamic Application Security Testing
  • Wabbi1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    DevSecOps platform embedding AppSec policies into the SDLC.
    Wabbi
  • Websecurify1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Suite of web security tools, platforms, and open-source frameworks.
    Websecurify
  • ZAST.AI1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI agent that finds, exploits & verifies zero-day vulns with zero false positives.
    ZAST.AI
  • ZeroPath8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered policy engine for defining and enforcing custom code security rules
    Policy EnginePR ReviewsZeroPath AI-Native SASTSAST Auto-FixZeroPath IaCZeroPath RiskZeroPath Software Composition Analysis