Application Security
Compare 154 application security tools to find the right one for your needs
π Subcategories
π§ Tools
Compare and find the best application security for your needs
Aikido Security
An all-in-one security platform that combines multiple scanners, including SAST, for SMBs.
Wib
A holistic API security platform covering the entire API lifecycle.
Prophaze WAF
A Kubernetes-native WAF that uses AI and behavioral analysis to protect web applications, APIs, and microservices.
Jit
A security orchestration platform that simplifies the implementation of DevSecOps.
PortSwigger Burp Suite
A set of tools for performing security testing of web applications.
Intruder
An online vulnerability scanner that finds cybersecurity weaknesses in digital infrastructure.
Astra Pentest
A penetration testing platform that combines automated and manual pentesting to secure web applications, APIs, and cloud infrastructure.
Semgrep
A fast, open-source static analysis tool for finding bugs and enforcing code standards.
Aikido Security
An all-in-one security platform that consolidates multiple open source tools.
42Crunch
An API security platform focused on a 'shift-left' approach.
Traceable AI
API security and observability for cloud-native applications.
Wallarm
A WAAP platform that protects websites, microservices, and APIs from threats.
ThreatX WAF
A managed WAF that blocks botnets and advanced attacks in real time, protecting both web applications and APIs.
Appdome
A no-code platform for adding security, anti-fraud, and other features to mobile apps.
Data Theorem
Automated security for mobile, API, cloud, and web applications.
Guardsquare (DexGuard and iXGuard)
Provides multi-layered security for mobile apps, including code hardening and RASP.
Approov
Provides mobile app and API shielding to ensure only genuine apps can access backend services.
Fastly Next-Gen WAF (formerly Signal Sciences)
A next-generation WAF and RASP solution that protects web applications, APIs, and microservices.
Appknox
A mobile application security platform combining automated and manual testing.
Pradeo
An AI-based security platform for mobile devices, applications, and data.
Appsealing
A cloud-based mobile app security solution with RASP capabilities.
Jamf
A comprehensive management and security platform for the Apple ecosystem.
Semgrep
A fast, open-source static analysis tool for finding bugs and enforcing code standards.
GitHub Advanced Security
A suite of security tools integrated into GitHub, featuring CodeQL-powered SAST.
CodeScene
A code analysis tool that prioritizes technical debt and security issues based on development activity.
Bright Security
A DAST solution that integrates into the SDLC to help developers find and fix vulnerabilities early.
Probely
A DAST tool that provides continuous and automated vulnerability scanning for web applications and APIs.
GitHub Advanced Security
A suite of security tools integrated into the GitHub platform.
Trivy
A popular open source scanner for vulnerabilities, misconfigurations, secrets, and SBOMs.
Cycode
A comprehensive platform for software supply chain and application security.
Noname Security
Discovers, analyzes, remediates, and tests all APIs in real-time.
Postman
A comprehensive platform for building, testing, and documenting APIs.
F5 BIG-IP Advanced WAF
A powerful WAF that provides comprehensive protection for web applications and APIs.
Tyk API Management
An open-source API gateway and management platform.
DataTheorem
An application security platform with a focus on API and mobile security.
Postman API Platform
A platform for building and using APIs, with integrated security features.
F5 Advanced WAF
Protects applications with behavioral analytics, proactive bot defense, and application-layer encryption of sensitive data.
Hdiv Security
Provides a unified platform for IAST, RASP, and SCA to protect applications throughout the SDLC.
DeepSource
An automated static analysis tool that helps developers write clean and secure code.
SpectralOps
A developer-focused security tool that combines SAST, SCA, and secrets scanning.
Detectify
A cloud-based DAST tool that helps organizations discover, classify, and scan all external assets.
StackHawk
A DAST and API security testing tool built for developers to find and fix security issues in CI/CD.
NowSecure
A mobile-first, mobile-only application security and privacy testing platform.
Snyk
Finds and fixes vulnerabilities in code, open source dependencies, containers, and IaC.
Sonatype Nexus Lifecycle
Automated open source governance and software supply chain management.
Salt Security
An API Protection Platform that discovers APIs, stops attacks, and eliminates vulnerabilities.
Cequence Security
A platform to discover, manage, and protect APIs from attacks.
Fortinet FortiWeb
A WAF that protects web applications and APIs from known and unknown threats.
Cloudflare WAF
A web application firewall that uses threat intelligence from millions of sites to identify and block emerging threats.
Sucuri WAF
A cloud-based WAF that protects websites from hacks, DDoS attacks, and zero-day exploits.
Check Point CloudGuard AppSec
An automated web application and API security solution that uses contextual AI to prevent attacks.
Contrast Protect (RASP)
Embeds security into applications to provide continuous protection from development to production.
Jscrambler
Provides JavaScript protection, including code obfuscation and runtime protection, to secure web and mobile applications.
Microsoft Defender for Endpoint
A comprehensive endpoint security platform for enterprises.
NowSecure
Automated mobile app security testing designed for developers.
Zimperium
Provides real-time, on-device threat defense for mobile devices against known and unknown threats.
Zimperium MAPS (Mobile Application Protection Suite)
A comprehensive mobile security platform that includes app shielding and RASP.
Lacework
A cloud security platform that provides runtime threat detection and response for cloud workloads.
ESET Endpoint Security
Endpoint protection platform that includes security for mobile devices.
Snyk
A developer-first security platform for code, dependencies, containers, and IaC.
Aqua Security Cloud Native Application Protection Platform (CNAPP)
A comprehensive security platform for cloud-native applications, including runtime protection.
Sysdig Secure
A cloud-native security platform with runtime threat detection and response.
Palo Alto Networks Prisma Cloud
A comprehensive CNAPP that includes runtime protection for cloud workloads.
Lookout
A security platform that protects data from endpoint to cloud.
Veracode
A cloud-native application security platform for the entire SDLC.
Guardsquare
Provides multi-layered mobile app protection and threat monitoring solutions.
F5 Distributed Cloud App Infrastructure Protection (AIP)
A cloud workload protection platform with RASP-like capabilities for modern applications.
Veracode Static Analysis
An enterprise-grade SAST solution that analyzes binaries for security vulnerabilities.
SonarQube
An open-core platform for continuous inspection of code quality and security.
Snyk Code
A developer-friendly SAST tool that scans code for vulnerabilities in real-time.
GitLab SAST
Integrated SAST capabilities within the GitLab DevOps platform.
Embold
A static analysis platform that helps developers find and fix issues in their code before deployment.
GuardRails
An AppSec platform that integrates with SCMs to scan for vulnerabilities on every pull request.
Invicti
Automated application and API security testing solution for enterprise organizations.
OWASP ZAP
An open-source web application security scanner.
Veracode
A comprehensive platform for managing application security risk across the entire software development lifecycle.
GitLab
A single application for the entire DevOps lifecycle, with built-in security scanning.
FOSSA
A platform for managing open source license compliance and security vulnerabilities.
Aqua Security
A comprehensive security platform for cloud-native applications.
Prisma Cloud
A comprehensive CNAPP from Palo Alto Networks for securing cloud environments.
SonarQube
An open-core platform for continuous inspection of code quality and security.
Cloudflare API Gateway
A comprehensive solution for API security and management built on Cloudflare's global network.
Imperva API Security
A solution that discovers APIs and protects them from vulnerabilities and attacks.
Palo Alto Networks Prisma Cloud
A comprehensive Cloud Native Application Protection Platform (CNAPP) with API security.
Google Apigee
A comprehensive API management platform with built-in security features.
MuleSoft Anypoint Platform
A unified platform for integration, API management, and automation.
Kong Konnect
A unified cloud-native API lifecycle platform.
SmartBear SwaggerHub
A platform for designing, documenting, and managing APIs with built-in governance.
Palo Alto Networks API Security
API security integrated into the Prisma Cloud platform.
F5 API Security
Comprehensive API security as part of F5's application security portfolio.
Google Cloud Apigee
A full lifecycle API management platform with advanced security features.
Amazon API Gateway
A fully managed service for creating, managing, and securing APIs.
Microsoft Azure API Management
A service to publish, secure, transform, maintain, and monitor APIs.
AWS WAF
A web application firewall that helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources.
Google Cloud Armor
Helps protect your applications and websites against denial of service and web attacks.
Barracuda WAF
Protects web applications from data breaches, defacement, and application-layer DDoS attacks.
Radware AppWall
A WAF that ensures fast, reliable, and secure delivery of mission-critical web applications and APIs.
Snyk
Developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure.
Datadog Application Security Management (formerly Sqreen)
Provides real-time threat detection and protection for applications, integrated into the Datadog platform.
Mend SAST
An AI-powered SAST solution focused on speed and accuracy, with automated remediation.
Veracode
A comprehensive software security platform that provides end-to-end security across the software development lifecycle.
Mend.io
An enterprise suite of application security tools designed to help organizations manage a proactive AppSec program.
Checkmarx
A unified application security platform offering SAST, SCA, IaC Security, and more.
Black Duck
Comprehensive SCA tool for managing security, license, and operational risks in open source.
JFrog Xray
SCA solution that integrates with JFrog Artifactory to secure the software supply chain.
Mend.io
A platform for automated application security, specializing in open source management.
Akamai API Security
Discovers and profiles API activity, detects threats, and provides data on API behavior.
Axway Amplify API Management
A platform for managing and securing APIs across multiple gateways and environments.
Azure Web Application Firewall
Provides centralized protection of your web applications from common exploits and vulnerabilities.
Checkmarx
An enterprise application security platform providing SAST, SCA, DAST, IaC, and API security.
Imperva RASP
Provides real-time protection for applications against known and zero-day vulnerabilities.
Checkmarx CxRASP
A RASP solution that provides real-time protection for applications, integrated with the Checkmarx One platform.
Veracode Runtime Protection
A RASP solution that provides real-time visibility and protection for applications in production.
Sophos Mobile
A Unified Endpoint Management (UEM) solution with integrated mobile threat defense.
Trend Micro Hybrid Cloud Security (incorporating IMMUNIO)
A comprehensive security solution for hybrid cloud environments, with RASP capabilities for application protection.
MobileIron (by Ivanti)
A leading Unified Endpoint Management (UEM) platform with integrated threat defense.
Checkmarx
A comprehensive AppSec platform offering SAST, DAST, IAST, SCA, and API security.
HCL AppScan
A suite of security testing tools for web, mobile, and APIs.
Arxan for Web
Provides comprehensive protection for web applications, including RASP and code obfuscation.
BlackBerry UEM
A unified endpoint management (UEM) solution with a strong security focus.
Checkmarx SAST
A powerful source code analysis tool for identifying security vulnerabilities in custom code.
Coverity
A SAST tool by Synopsys known for its accuracy, speed, and scalability in identifying critical defects.
Qualys SAST
A SAST solution integrated into the Qualys Cloud Platform for web application security.
HCL AppScan
A suite of application security testing tools, including a powerful SAST solution.
Acunetix
A DAST solution that helps small to mid-size organizations find, fix, and prevent vulnerabilities.
Checkmarx
A unified application security platform that helps organizations secure their applications from code to cloud.
Rapid7 InsightAppSec
A cloud-native DAST solution that automatically crawls and assesses web applications to identify vulnerabilities.
Anchore Enterprise
A platform for securing the software supply chain, with a focus on containers.
Red Hat 3scale API Management
An API management platform for controlling and securing API traffic.
Broadcom Layer7
An enterprise-grade platform for full lifecycle API management and security.
Fortify Static Code Analyzer
A comprehensive SAST tool from OpenText that supports a wide range of languages and provides detailed vulnerability analysis.
Qualys Web Application Scanning (WAS)
A cloud-based AppSec solution providing DAST, API security, and web malware detection.
Synopsys Seeker
An IAST solution that gives visibility into web app security posture and identifies vulnerability trends against compliance standards.
HCL AppScan
A suite of application security testing tools that helps organizations reduce the risk of web and mobile application attacks.
Fortify Application Defender
A RASP solution that provides real-time visibility and protection for applications in production.
Synopsys
A broad portfolio of application security testing tools and services.
Klocwork
A SAST tool by Perforce that provides real-time analysis for security, safety, and reliability.
Micro Focus Fortify WebInspect
An automated dynamic application security testing (DAST) tool that identifies and prioritizes security vulnerabilities in running applications.
IBM Security AppScan
A suite of application security testing tools to identify and remediate vulnerabilities in web, mobile, and API applications.
Waratek
Provides runtime protection for Java applications, specializing in virtual patching and vulnerability remediation.
K2 Cyber Security
Provides runtime protection for web applications and APIs, with a focus on zero-day attack prevention.
Talsec
A mobile RASP and app shielding solution for Android and iOS.
OpenRASP
An open-source RASP solution from Baidu that provides real-time protection for web applications.
Protectt.ai
A mobile security solution with RASP capabilities to protect against fraud and other threats.
TrueFort Fortress
A workload protection platform with RASP capabilities to secure applications from the inside.
Templarbit Shield
Information on this RASP solution is limited.
Promon SHIELDβ’
A mobile app shielding solution with RASP capabilities to protect against a wide range of threats.
Quokka (formerly Kryptowire)
An AI-powered platform for automated mobile app security and vulnerability analysis.
Codified Security
A self-service, automated platform for testing mobile app security.
App-Ray
An automated mobile security scanning solution that detects vulnerabilities and data leaks.
KyberSecurity Application Protection
Information on this RASP solution is limited.
InsiderSecurity SAST
A static analysis tool focused on simplicity and accuracy for modern web applications.
Grype
An open source vulnerability scanner from Anchore.
Dependabot
A GitHub-native tool that automatically creates pull requests to keep dependencies up-to-date.