Best API Security Tools - Page 2

How Many API Security Tools Products Does G2 Track?

Total Products under this Category: 72

Category Stats (Sep 2026)

  • Average Rating: 4.56/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: AppSentinels (+2.08%) - Among all products in this category, AppSentinels recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank API Security Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,200+ Authentic Reviews
  • 72+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for API Security Tools

G2 Grid® for API Security Tools plotting products by satisfaction and market presence

Highlighted products: Postman, Cloudflare Application Security and Performance, apisec.ai, Check Point WAF (formerly CloudGuard WAF), Fastly's Web Application and API Security, Astra Pentest, Rakuten SixthSense Observability, and Harness Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/api-security/grids.json?focus%5B%5D=postman&focus%5B%5D=cloudflare-application-security-and-performance&focus%5B%5D=apisec-ai&focus%5B%5D=check-point-waf-formerly-cloudguard-waf&focus%5B%5D=fastly-s-web-application-and-api-security&focus%5B%5D=astra-pentest&focus%5B%5D=rakuten-sixthsense-observability&focus%5B%5D=harness-platform)

Cequence Security

Cequence protects the applications and data that power enterprises in the agentic era. More than a decade of bot defense and API security experience has established Cequence as the leader of safe and secure agentic AI adoption. The Cequence platform delivers deep insight into user, entity, and agent behavior, enabling organizations to secure and control agentic AI workflows while protecting against bad actors and rogue agents. Cequence delivers value in minutes rather than days or weeks with a highly scalable, no-code approach. Trusted by the largest and most demanding private and public sector organizations, Cequence protects more than 10 billion daily API interactions and 4 billion user accounts. Agentic AI Governance – Every Agent, Under Control The Cequence AI Gateway provides security, governance, and control for agentic AI workflows, enabling organizations to unlock AI-driven productivity and growth. Built-in governance and guardrails constrain agent behavior using capabilities that include least privilege access, rate-limiting, and sensitive data protection. The AI Gateway’s agentic zero trust architecture enables enterprises to confidently deploy agentic workflows for internal productivity and customer-facing experiences. Bot Management – Bot Detection, Mitigation, and Fraud Prevention Cequence Bot Management protects organizations from the full range of automated attacks to prevent data loss, theft, and fraud. Bot Management is network based, requiring no agents, JavaScript, or SDKs. Behavioral fingerprints and multi-dimensional analytics provide a deep understanding of business context to identify and natively block attacks in real time. It mitigates a wide variety of cyberattacks including business logic attacks, exploits, automated bot activity, online fraud, and OWASP API Security Top 10 threats. API Security – API Security Posture Management, Testing, and Remediation Cequence API Security is an AI-first solution that discovers, monitors, and tests APIs, assessing a broad range of risks that often lead to compliance or governance issues, data loss, and business disruption. Providing complete visibility and monitoring of internal, external, and third-party APIs, Cequence helps organizations keep up with API changes, uncover sensitive data exposure, and identify vulnerabilities and security risks including those in the OWASP API Security Top 10. Built-in API security testing enables organizations to test their pre-production and runtime APIs against specifications – and automatically generate them if specs are not available. The AI Assistant guides practitioners of all skill levels from day one and the built-in MCP server enables teams to integrate API Security into their internal agentic workflows. API Security lays the groundwork to ensure that you are fully aware of the risks inherent in your API applications and enables you to remediate critical security issues before they are exploited by attackers.

Average Rating: 4.6/5.0

Total Reviews: 55

How Do G2 Users Rate Cequence Security?

  • API Testing: 8.4/10 (Category avg: 9.1/10)
  • API Monitoring: 9.2/10 (Category avg: 8.9/10)

Who Is the Company Behind Cequence Security?

  • Seller: Cequence Security
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Santa Clara, CA
  • Twitter: @cequenceai
    689 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Telecommunications, Information Technology and Services
  • Company Size: 40% Small, 35% Large

What Do G2 Reviewers Say About Cequence Security?

AI-generated summary from verified user reviews

Pros
  • Users value the robust protection against sophisticated bot attacks provided by Cequence Security, enhancing online security effectively.
  • Users value the powerful threat detection capabilities of Cequence Security, effectively mitigating sophisticated bot attacks and enhancing security.
  • Users value the time-saving automation of Cequence Security, allowing SOC teams to focus on critical tasks instead.
  • Users appreciate the effective vulnerability detection of Cequence Security, enhancing security while minimizing disruptions for legitimate users.
  • Users value the visibility and security Cequence Security provides for APIs, enhancing protection against advanced bot threats.
Cons
  • Users find the complex setup of Cequence Security challenging, requiring significant time for optimization and rule configuration.
  • Users find the difficult learning curve of Cequence Security requires significant technical expertise for effective setup and usage.
  • Users experience slow performance with Cequence Security, particularly during large data queries and incident responses.
  • Users experience lag and slow response times on the Cequence Security dashboard, hindering efficient data interpretation and decision-making.
  • Users report encountering false positives with Cequence Security, which complicates their traffic management and leads to frustration.

What Are Recent G2 Reviews of Cequence Security?

What Are G2 Users Discussing About Cequence Security?

Tenable Nessus

Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to help security professionals quickly and easily identify and fix vulnerabilities, including software flaws, missing patches, malware, and misconfigurations - across a variety of operating systems, devices, and applications. With features such as pre-built policies and templates, customizable reporting, group “snooze” functionality, and real-time updates, Nessus is designed to make vulnerability assessment simple, easy, and intuitive. The result: less time and effort to assess, prioritize, and remediate issues.

Average Rating: 4.5/5.0

Total Reviews: 292

Who Is the Company Behind Tenable Nessus?

  • Seller: Tenable
  • Company Website:
  • HQ Location: Columbia, MD
  • Twitter: @TenableSecurity
    87,752 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,350 employees on LinkedIn®
  • Ownership: NASDAQ: TENB

Who Uses This Product?

  • Who Uses This: Security Engineer, Network Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 40% Medium, 34% Large

What Do G2 Reviewers Say About Tenable Nessus?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the extensive vulnerability identification capabilities of Tenable Nessus, enhancing their security risk management efforts.
  • Users value the comprehensive vulnerability detection in Tenable Nessus, enhancing their ability to manage security risks effectively.
  • Users praise the automated scanning of Tenable Nessus for its thoroughness and comprehensive vulnerability reporting.
  • Users value the ease of use of Tenable Nessus, appreciating its simple setup and user-friendly interface.
  • Users value the extensive reporting and automation capabilities of Tenable Nessus for better asset scanning.
Cons
  • Users note that slow scanning can take 2-3 days and may disrupt production environments due to high resource usage.
  • Users highlight the high costs of maintaining Tenable Nessus, which can be a barrier for many organizations.
  • Users find the limited features of Tenable Nessus restrictive, especially regarding host capacity and mobile app testing.
  • Users find the complexity of licensing and features in Tenable Nessus challenging, impacting overall usability and resource management.
  • Users report that false positives from Nessus can create additional workload and complicate vulnerability management processes.

What Are Recent G2 Reviews of Tenable Nessus?

What Are G2 Users Discussing About Tenable Nessus?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • API Testing: 9.0/10 (Category avg: 9.1/10)
  • API Monitoring: 8.9/10 (Category avg: 8.9/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    91 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Edgescan, highlighting its intuitive interface and straightforward navigation.
  • Users value the automated vulnerability detection features of Edgescan for efficient risk assessment and remediation support.
  • Users value the excellent customer support from Edgescan, noting their responsiveness and proactivity in addressing queries.
  • Users value the detailed vulnerability identification from Edgescan, enabling effective risk management and threat mitigation strategies.
  • Users value Edgescan for its intuitive interface and comprehensive functionality that streamlines security assessments and support.
Cons
  • Users find the complex UI of Edgescan challenging, often requiring guidance to navigate key functions effectively.
  • Users find limited customization options frustrating, particularly with filtering systems and administrative functionalities.
  • Users find the poor interface design of Edgescan challenging, causing navigation and task completion difficulties.
  • Users experience slow performance with Edgescan as manual reviews lead to longer scan completion times.
  • Users find the user interface challenging and unintuitive, leading to difficulties in navigation and task completion.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Invicti

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti?

  • API Testing: 8.8/10 (Category avg: 9.1/10)

Who Is the Company Behind Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    335 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Invicti, facilitating quick setup and effective vulnerability scanning in their workflow.
  • Users value the quick and easy scanning technology of Invicti, enhancing workflow efficiency and accuracy in vulnerability detection.
  • Users value the simplicity and integration of Invicti, enhancing security measures through user-friendly report generation and detailed views.
  • Users value the easy-to-read and well-formatted reports from Invicti, enhancing efficiency and supporting ISO certification needs.
  • Users value the high accuracy and ease of use in Invicti's vulnerability detection, effectively identifying true issues.
Cons
  • Users find the customer support lacking, often experiencing slow responses and inadequate technical assistance.
  • Users experience slow performance during scans and setups, impacting overall efficiency and satisfaction.
  • Users experience slow scanning issues with Invicti, often leading to frustrating delays during the scanning process.
  • Users face API scanning issues with Invicti, limiting its effectiveness for their specific needs despite decent support.
  • Users find the complex setup of Invicti challenging initially, hindering their ability to quickly navigate configurations.

What Are Recent G2 Reviews of Invicti?

What Are G2 Users Discussing About Invicti?

Levo.ai

APIs are no longer technical plumbing. They are the foundation of modern business, powering customer experiences, partner ecosystems, and digital revenue streams. But with that centrality comes risk. Unsecured APIs are now the leading cause of breaches, compliance failures, and stalled innovation. Levo exists to change this. We are the first platform to deliver true end-to-end API Security. From continuous discovery and automated documentation to exploit aware testing, policy-driven monitoring, passive detection, and inline protection, Levo covers every phase of the API lifecycle. Our architecture was designed from first principles: 1. Privacy preserving architecture: no sensitive data leaves your environment. 2. Cost efficient: lightweight sensors that run on minimal compute, saving enterprises hundreds of thousands in inflated cloud costs. 3. Developer aligned: seamless workflows that integrate directly into CI/CD, removing friction instead of adding it. This foundation gives enterprises something legacy tools never could: clarity across every API, precision in detecting real risks, and the confidence to block attacks without breaking business. With Levo, security does not slow down APIs. It scales them, safely, compliantly, and at the speed of modern business. Our vision is simple: a world where security and growth are never tradeoffs.

Average Rating: 4.8/5.0

Total Reviews: 13

How Do G2 Users Rate Levo.ai?

  • API Testing: 9.8/10 (Category avg: 9.1/10)
  • API Monitoring: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Levo.ai?

  • Seller: Levo
  • Year Founded: 2021
  • HQ Location: San Francisco, US
  • Twitter: @levoinchq
    104 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 54% Medium, 46% Small

What Do G2 Reviewers Say About Levo.ai?

AI-generated summary from verified user reviews

Pros
  • Users highlight the advanced API management capabilities of Levo.ai, enabling robust security and seamless visibility for modern applications.
  • Users highlight Levo.ai's real-time security and unified visibility, enabling smooth integration and enhanced protection for APIs and AI agents.
  • Users appreciate the advanced security Levo.ai offers, ensuring continuous visibility and precise tracking of sensitive data.
  • Users highlight unified visibility provided by Levo.ai, dramatically enhancing security across APIs and AI agents in real-time.
  • Users appreciate the automation capabilities of Levo.ai, simplifying security processes and enhancing efficiency for modern applications.
Cons
  • Users find the difficult learning curve of Levo.ai challenging, especially for teams new to observability and security tools.
  • Users note the need for better integration with observability dashboards and existing SIEM and SOAR workflows.
  • Users find the complex setup of Levo.ai challenging, especially for teams new to observability and security tools.
  • Users note the need for improved integration issues with existing systems, wishing for smoother workflows and customizations.
  • Users find the steep learning curve of Levo.ai challenging, especially for teams new to observability and security tools.

What Are Recent G2 Reviews of Levo.ai?

Wallarm API Security Platform

Protect any API. In any environment. Against any threats. Wallarm is the platform security teams choose to protect cloud-native APIs. The Wallarm platform gives teams the ability to detect and block API attacks. Customers choose Wallarm because it delivers a complete inventory of their APIs, AI apps, and agentic AI, along with patented AI/ML API abuse detection, real-time blocking on day zero, and an API SOC-as-a-service. Whether you protect legacy or brand new cloud-native APIs, Wallarm’s multi-cloud platform delivers the capabilities to secure your business against emerging threats. -> Robust protection for the entire API and AI portfolio Mitigate the OWASP API Top 10 threats and more; business logic abuse, bad bots, account takeover (ATO), and more. Get the robust API protection that no other tool can provide. -> Native inline blocking Wallarm is built from the ground up for inline blocking. Why deploy API security that can’t actually defend against API attacks? -> Unparalleled visibility into malicious traffic Gain full insights about attacks and attackers in the responsive Wallarm Console. Enjoy the Dashboard, search, and reporting capabilities, including visibility into API sessions. -> Complete API inventory Wallarm API Discovery provides full visibility into all your APIs, AI apps, and AI agents, including sensitive data flows, risk posture, shadow APIs and change detection. -> Understand Your Attack Surface You can’t protect what you don’t know about. Wallarm provides a comprehensive view of your API attack surface, including assessment of security controls and leaked sensitive API data. -> Quick integrations Setup cross-team collaboration with seamless integrations to your SIEM/SOAR, messaging applications, and workflow management.

Average Rating: 4.7/5.0

Total Reviews: 93

How Do G2 Users Rate Wallarm API Security Platform?

  • API Testing: 9.2/10 (Category avg: 9.1/10)
  • API Monitoring: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind Wallarm API Security Platform?

  • Seller: Wallarm
  • Company Website:
  • Year Founded: 2016
  • HQ Location: San Francisco, California
  • Twitter: @wallarm
    3,197 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    159 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, CTO
  • Top Industries: Mechanical or Industrial Engineering, Information Technology and Services
  • Company Size: 43% Medium, 42% Small

What Do G2 Reviewers Say About Wallarm API Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the accurate real-time threat detection of Wallarm API Security Platform, ensuring robust API protection.
  • Users value the real-time API threat detection of Wallarm, effectively minimizing false positives and enhancing security.
  • Users value the accurate real-time threat detection of Wallarm API Security Platform, ensuring minimal false positives.
  • Users value the accurate real-time monitoring of Wallarm API Security Platform, ensuring robust protection against API threats.
  • Users value the real-time vulnerability detection of Wallarm, ensuring robust API protection with minimal false positives.
Cons
  • Users often face API issues with unclear pricing during the trial, impacting their decision-making process.
  • Users find the configuration process complex, making it a challenge for newcomers to effectively utilize the platform.
  • Users find the configuration and tuning process complex, which can be challenging and time-consuming, especially for newcomers.
  • Users find the complex setup of Wallarm API Security Platform to be time-consuming, particularly for newcomers.
  • Users find the configuration and tuning process difficult, particularly facing challenges as new users of the platform.

What Are Recent G2 Reviews of Wallarm API Security Platform?

What Are G2 Users Discussing About Wallarm API Security Platform?

AppTrana

AppTrana API is a fully managed API security platform that provides continuous API discovery, automated vulnerability detection, and real-time protection against API attacks. It combines 24/7 AI-driven intelligence with human-led operations to deliver runtime security with a Zero False Positive Guarantee. Trusted by over 6,500 customers across 95+ countries, it offers unmetered protection with 100% availability. AppTrana API includes SwyftComply, an industry-first autonomous remediation capability that virtually patches API vulnerabilities without code changes, enabling zero-vulnerability compliance reports.

Average Rating: 4.8/5.0

Total Reviews: 34

Who Is the Company Behind AppTrana?

  • Seller: Indusface
  • Year Founded: 2012
  • HQ Location: Vadodara
  • Twitter: @Indusface
    3,472 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    180 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 54% Medium, 23% Small

What Do G2 Reviewers Say About AppTrana?

AI-generated summary from verified user reviews

Pros
  • Users praise the comprehensive protection from AppTrana, ensuring safety against real-time attacks and vulnerabilities.
  • Users value the 24/7 cybersecurity support from AppTrana, ensuring peace of mind and robust protection against threats.
  • Users commend AppTrana's highly effective WAF that ensures complete protection with excellent support and low complexity.
  • Users value the exceptional bot detection capabilities of AppTrana, ensuring robust protection against threats 24/7.
  • Users commend the fantastic DDoS protection of AppTrana, offering peace of mind with comprehensive security measures.
Cons
  • Users find the difficult reporting of AppTrana limits their ability to analyze data effectively over time.
  • Users find the complex setup challenging due to poor documentation and difficulty in handling third-party certificates.
  • Users express concern over the high cost of AppTrana, especially when managing multiple application instances.
  • Users find the learning difficulty in installing and managing third-party certificates to be frustrating and not well supported.
  • Users find the poor documentation for installation and third-party certificate replacement frustrating and unhelpful.

What Are Recent G2 Reviews of AppTrana?

What Are G2 Users Discussing About AppTrana?

StackHawk

StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate StackHawk?

  • API Testing: 8.9/10 (Category avg: 9.1/10)
  • API Monitoring: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind StackHawk?

  • Seller: StackHawk
  • Year Founded: 2019
  • HQ Location: Denver, CO
  • Twitter: @StackHawk
    1,137 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Small, 35% Medium

What Do G2 Reviewers Say About StackHawk?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of StackHawk, facilitating seamless setups with major CI tools and configurations.
  • Users praise the excellent customer support from StackHawk, highlighting their responsiveness and helpfulness in addressing queries.
  • Users value the customizability of StackHawk, appreciating its flexibility and integration options for unique workflows.
  • Users find that StackHawk greatly enhances efficiency, enabling quicker identification and resolution of security vulnerabilities.
  • Users commend StackHawk for its scanning efficiency, enabling quick identification of vulnerabilities and seamless CI/CD integration.
Cons
  • Users find the complex setup challenging, particularly with the YAML configurations and onboarding processes for applications.
  • Users find the high learning curve of StackHawk challenging due to its complex scripting and setup process.
  • Users find StackHawk lacking features, specifically in API management and vulnerability reproducibility, hindering its usability.
  • Users find the limited scope of StackHawk restricts functionality and automation in vulnerability management.
  • Users find the setup complexity of StackHawk frustrating due to YAML configuration and onboarding challenges.

What Are Recent G2 Reviews of StackHawk?

What Are G2 Users Discussing About StackHawk?

AppSentinels

AppSentinels protects your APIs by securing the business logic that drives your operations. Continuous discovery, automated API pen testing, and real-time defense stop hidden threats before they disrupt your business, ensuring seamless, risk-free innovation without slowing development.

Average Rating: 4.9/5.0

Total Reviews: 10

How Do G2 Users Rate AppSentinels?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind AppSentinels?

  • Seller: AppSentinels
  • Year Founded: 2021
  • HQ Location: Boston , US
  • Twitter: @appsentinelsai
    122 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    39 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Medium, 20% Small

What Do G2 Reviewers Say About AppSentinels?

AI-generated summary from verified user reviews

Pros
  • Users value the automated discovery of shadow and undocumented APIs, enhancing their API testing efficiency.
  • Users commend the responsive and knowledgeable support team behind AppSentinels, enhancing their overall user experience.
  • Users value the automated vulnerability detection, enhancing security through smart API management and robust support.

What Are Recent G2 Reviews of AppSentinels?

Akto API Security Platform

Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — API discovery, API security posture management, sensitive data exposure, and API security testing solutions enables organizations to gain visibility in their API security posture. 1,000+ Application Security teams globally trust Akto for their API security needs. Akto use cases: 1. API Discovery 2. API Security Testing in CI/CD 3. API Security Posture Management 4. Authentication and Authorization Testing 5. Sensitive data Exposure 6. Shift left in DevSecOps

Average Rating: 4.5/5.0

Total Reviews: 54

How Do G2 Users Rate Akto API Security Platform?

  • API Testing: 8.8/10 (Category avg: 9.1/10)
  • API Monitoring: 9.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Akto API Security Platform?

  • Seller: Akto.io
  • Company Website:
  • Year Founded: 2022
  • HQ Location: San Francisco, California
  • Twitter: @Aktodotio
    1,357 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 44% Medium, 40% Small

What Do G2 Reviewers Say About Akto API Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the automated security testing capabilities of Akto API Security Platform, enhancing their API protection efforts.
  • Users value the autonomous AI agents in Akto, enhancing API security with efficient discovery and vulnerability testing.
  • Users appreciate the user-friendly interface of Akto, finding the platform easy to navigate and manage projects.
  • Users praise Akto for its seamless integration with CI/CD pipelines, enhancing API security testing with minimal manual effort.
  • Users value the effortless integration of automation testing in Akto, enhancing efficiency within their CI/CD workflow.
Cons
  • Users find the complex initial setup challenging due to poor documentation and a steep learning curve.
  • Users find the setup complexity of Akto API Security Platform challenging due to poor documentation and steep learning curve.
  • Users find the steep learning curve and integration complexities challenging when adopting Akto API Security Platform.
  • Users find the learning curve steep with Akto, especially for those unfamiliar with API security concepts and configurations.
  • Users find the difficult configuration of Akto API Security Platform challenging, impacting their initial setup experience.

What Are Recent G2 Reviews of Akto API Security Platform?

Beagle Security

Beagle Security helps you identify vulnerabilities in your web applications, APIs, GraphQL and remediate them with actionable insights before hackers harm you in any manner. With Beagle Security, you can integrate automated penetration testing into your CI/CD pipeline to identify security issues earlier in your development lifecycle and ship safer web applications. Major features: - Checks your web apps & APIs for 3000+ test cases to find security loopholes - OWASP & SANS standards - Recommendations to address security issues - Security test complex web apps with login - Compliance reports (GDPR, HIPAA & PCI DSS) - Test scheduling - DevSecOps integrations - API integration - Team access - Integrations with popular tools like Slack, Jira, Asana, Trello & 100+ other tools

Average Rating: 4.7/5.0

Total Reviews: 85

How Do G2 Users Rate Beagle Security?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 3.3/10 (Category avg: 8.9/10)

Who Is the Company Behind Beagle Security?

  • Seller: Beagle Security
  • Year Founded: 2020
  • HQ Location: San Francisco, US
  • Twitter: @beaglesecure
    206 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, Director
  • Top Industries: Marketing and Advertising, Information Technology and Services
  • Company Size: 91% Small, 7% Medium

What Do G2 Reviewers Say About Beagle Security?

AI-generated summary from verified user reviews

Pros
  • Users commend the attractive reporting of Beagle Security, finding it easy to configure and comprehensive.
  • Users appreciate the easy setup of Beagle Security, finding it efficient for quick and effective implementation.

What Are Recent G2 Reviews of Beagle Security?

What Are G2 Users Discussing About Beagle Security?

APPCHECK

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a hacker would, leveraging multiple proprietary crawling engines to analyse target behaviour across both modern and traditional technologies, including Single Page Applications (SPAs), APIs, and complex authentication flows such as SSO, 2FA, and TOTP. Organisations can conduct unlimited security assessments across Web Applications, SPAs, APIs, cloud services, networks, across internal or external assets. Supporting production and UAT testing, AppCheck also helps organisations ‘shift left’ by integrating with CI/CD pipelines and build servers, including ADO, GitHub, Jenkins, TeamCity, CircleCI, TravisCI, Bamboo, and GitLab CI/CD. Allowing automated security testing throughout development, identifying risks as soon as changes are introduced. AppCheck are proud to be part of the CVE Numbering Authority (CNA), contributing to global security research

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate APPCHECK?

  • API Testing: 9.4/10 (Category avg: 9.1/10)
  • API Monitoring: 9.2/10 (Category avg: 8.9/10)

Who Is the Company Behind APPCHECK?

  • Seller: APPCHECK
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Leeds, GB
  • Twitter: @AppcheckNG
    649 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    106 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 49% Medium, 30% Small

What Do G2 Reviewers Say About APPCHECK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of AppCheck, making complex processes straightforward and efficient.
  • Users commend AppCheck for its exceptional vulnerability detection, providing thorough coverage and easy integration into workflows.
  • Users value the excellent pricing and functionality of AppCheck, praising its usability and proactive support from the team.
  • Users commend AppCheck for its efficiency in pentesting, notably for thorough vulnerability coverage and seamless integration.
  • Users love the scanning efficiency of AppCheck, finding it reliable and easy to integrate within development workflows.
Cons
  • Users suggest that UX improvements in scoring, customization, and integrations could enhance the AppCheck experience.
  • Users find the API issues frustrating, as endpoint changes require a service request and delays functionality.
  • Users find difficult customization in AppCheck's reporting features, needing more flexibility for contextual adjustments.
  • Users experience a notable difficult learning curve with Appcheck, which may hinder initial ease of use.
  • Users find the false positives in scan results problematic, necessitating manual validation and complicating the reporting process.

What Are Recent G2 Reviews of APPCHECK?

Salt Security

Salt Security protects the APIs that form the core of every modern application. Its patented API Protection Platform is the only API security solution that combines the power of cloud-scale big data and time-tested ML/AI to detect and prevent API attacks. By correlating activities across millions of APIs and users over time, Salt delivers deep context with real-time analysis and continuous insights for API discovery, attack prevention, and shift-left practices. Deployed in minutes and seamlessly integrated within existing systems, the Salt Security platform gives customers immediate value and protection, so they can innovate with confidence and accelerate their digital transformation initiatives. Salt protects APIs across their full lifecycle – build, deploy and runtime phases, utilizing cloud-scale big data combined with AI and ML to baseline millions of users and APIs. By delivering context-based insights across the entire API lifecycle, Salt enables users to detect the reconnaissance activity of bad actors and block them before they can reach their objective. Through its unique API Context Engine (ACE) architecture, the Salt platform provides design analysis in pre-production, discovers all APIs, pinpoints and stops API attackers, and provides remediation insights. Salt Security holds the only granted patent for using AI to identify and prevent API attacks and is the only solution that automatically and continuously discovers all APIs. This approach enables a complete and up-to-date inventory of all APIs. The Salt API security platform leads the market with the simplest, most comprehensive, and most effective API security offering. In its Series D round, Salt raised $140M at a valuation of $1.4 billion. Led by CapitalG, Alphabet's independent growth fund, the round included participation from all existing investors, including Sequoia Capital, Y Combinator, Tenaya Capital, S Capital VC, Advent International, Alkeon Capital, and DFJ Growth.

Average Rating: 4.7/5.0

Total Reviews: 12

How Do G2 Users Rate Salt Security?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Salt Security?

  • Seller: Salt Security
  • Year Founded: 2018
  • HQ Location: Palo Alto, US
  • Twitter: @SaltSecurity
    4,958 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    208 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 83% Large, 8% Medium

What Are Recent G2 Reviews of Salt Security?

What Are G2 Users Discussing About Salt Security?

Chronoloq

Chronoloq is an AI and API security platform for small and mid-sized organizations. It scans a company's AI/LLM features and API endpoints to identify exposed attack surface, then delivers a prioritized risk score (the "Chronoloq Score") alongside a remediation plan and compliance-ready reports. The platform operates agentlessly and is designed to complete an initial assessment in under 30 minutes, without requiring a dedicated security team or a lengthy enterprise deployment. It also includes an active protection gateway layer (LLM Shield) that monitors and controls AI model behavior in real time. The end result is continuous visibility into AI and API risk, and audit documentation usable for SOC2, HIPAA, and FERPA reviews.

Average Rating: 4.5/5.0

Total Reviews: 13

How Do G2 Users Rate Chronoloq?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Chronoloq?

Who Uses This Product?

  • Company Size: 77% Medium, 15% Small

What Are Recent G2 Reviews of Chronoloq?

BugDazz API Scanner

BugDazz API Security Scanner by SecureLayer7 is a comprehensive tool designed to automatically detect vulnerabilities, misconfigurations, and security gaps in API endpoints, aiding security teams in protecting digital assets against increasing API-related threats and potential exploits. It offers real-time scanning capabilities, enabling the automatic detection of vulnerabilities as they arise. It supports authentication and access control management, allowing for the management of API controls within a single platform. BugDazz assists in achieving compliance by accelerating the generation of reports for standards such as PCI DSS and HIPAA. It integrates seamlessly with existing CI/CD pipelines, facilitating the acceleration of product rollouts. The scanner goes beyond standard OWASP Top 10 vulnerabilities, providing comprehensive protection against critical API security risks.

Average Rating: 4.9/5.0

Total Reviews: 11

How Do G2 Users Rate BugDazz API Scanner?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 9.3/10 (Category avg: 8.9/10)

Who Is the Company Behind BugDazz API Scanner?

  • Seller: SecureLayer7
  • Year Founded: 2012
  • HQ Location: Pune, Maharshtra
  • Twitter: @SecureLayer7
    2,522 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    127 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 91% Small, 9% Medium

What Do G2 Reviewers Say About BugDazz API Scanner?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of results from BugDazz API Scanner, enhancing collaboration and efficiency in workflow processes.
  • Users love the smooth integration with CI/CD pipelines, enabling efficient and timely security scans without delays.
  • Users value the seamless CI/CD integration of BugDazz API Scanner, enhancing efficiency without slowing down builds.
  • Users appreciate the ease of use of BugDazz API Scanner, facilitating quick integration and reliable results.
  • Users value the fast and accurate scans of BugDazz, seamlessly integrating into CI/CD workflows with minimal friction.
Cons
  • Users find documentation lacking, particularly in infrastructure guidance and clarity for Jerkins integration.
  • Users acknowledge a difficult learning curve with BugDazz API Scanner, requiring time to optimize scan configurations effectively.
  • Users suggest that the lack of guidance in documentation hinders effective usage of BugDazz API Scanner.
  • Users find the lack of detailed information in BugDazz API Scanner's documentation limiting for infrastructure-specific guidance.
  • Users note a learning curve in optimizing scans for various scenarios, but find it manageable overall.

What Are Recent G2 Reviews of BugDazz API Scanner?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024