2026 Best Software Awards are here!See the list

Top Free Application Security Posture Management (ASPM) Software

Check out our list of free Application Security Posture Management (ASPM) Software. Products featured on this list are the ones that offer a free trial version. As with most free versions, there are limitations, typically time or features.

If you'd like to see more products and to evaluate additional feature options, compare all Application Security Posture Management (ASPM) Software to ensure you get the right product.

View Free Application Security Posture Management (ASPM) Software

G2 takes pride in showing unbiased reviews on user satisfaction in our ratings and reports. We do not allow paid placements in any of our ratings, rankings, or reports. Learn about our scoring methodologies.
13 Application Security Posture Management (ASPM) Products Available
(138)4.6 out of 5
Optimized for quick response
1st Easiest To Use in Application Security Posture Management (ASPM) software
Entry Level Price:Free
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido hel

    Users
    • CTO
    • Founder
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 71% Small-Business
    • 17% Mid-Market
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Angel I.
    AI
    I appreciate that Aikido Security offers a single plane of glass with everything in one queue, which is very important to me. It's simple to use... Read review
    Sibil M.
    SM
    I find Aikido Security to have a very intuitive UI with good context around the issues, making navigation and prioritization easy. The generous... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2022
    HQ Location
    Ghent, Belgium
    Twitter
    @AikidoSecurity
    4,696 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    175 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido hel

Users
  • CTO
  • Founder
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 71% Small-Business
  • 17% Mid-Market
Angel I.
AI
I appreciate that Aikido Security offers a single plane of glass with everything in one queue, which is very important to me. It's simple to use... Read review
Sibil M.
SM
I find Aikido Security to have a very intuitive UI with good context around the issues, making navigation and prioritization easy. The generous... Read review
Seller Details
Company Website
Year Founded
2022
HQ Location
Ghent, Belgium
Twitter
@AikidoSecurity
4,696 Twitter followers
LinkedIn® Page
www.linkedin.com
175 employees on LinkedIn®
(51)4.8 out of 5
4th Easiest To Use in Application Security Posture Management (ASPM) software
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    OX is redefining product security for the AI era. Founded by Neatsun Ziv and Lion Arzi, former Check Point executives, OX is the company behind VibeSec — the first AI-native vibe security platform.

    Users
    • Security Engineer
    Industries
    • Financial Services
    • Information Technology and Services
    Market Segment
    • 63% Mid-Market
    • 25% Enterprise
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Verified User in Automotive
    EA
    As one of OX Security's first customers, I was searching for an effective solution to upscale Upstream Security's application security stack. I... Read review
    Verified User in Information Technology and Services
    UI
    Best Free Solution for private users who want to check their repos. Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2021
    HQ Location
    New York, USA
    LinkedIn® Page
    www.linkedin.com
    184 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

OX is redefining product security for the AI era. Founded by Neatsun Ziv and Lion Arzi, former Check Point executives, OX is the company behind VibeSec — the first AI-native vibe security platform.

Users
  • Security Engineer
Industries
  • Financial Services
  • Information Technology and Services
Market Segment
  • 63% Mid-Market
  • 25% Enterprise
Verified User in Automotive
EA
As one of OX Security's first customers, I was searching for an effective solution to upscale Upstream Security's application security stack. I... Read review
Verified User in Information Technology and Services
UI
Best Free Solution for private users who want to check their repos. Read review
Seller Details
Year Founded
2021
HQ Location
New York, USA
LinkedIn® Page
www.linkedin.com
184 employees on LinkedIn®
G2 Advertising
Sponsored
G2 Advertising
Get 2x conversion than Google Ads with G2 Advertising!
G2 Advertising places your product in premium positions on high-traffic pages and on targeted competitor pages to reach buyers at key comparison moments.
(66)4.6 out of 5
6th Easiest To Use in Application Security Posture Management (ASPM) software
Entry Level Price:Starting at £167.00
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a

    Users
    No information available
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 50% Mid-Market
    • 30% Small-Business
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Verified User in Medical Devices
    AM
    Value for money is the main key for me personally, we were spending more money on external companies doing scans once or twice a year. We now do... Read review
    Mark W.
    MW
    AppCheck is an excellent tool to provide full visibility into our estate and embed security into the CI/CD pipeline. Traditional pen testing... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    APPCHECK
    Company Website
    Year Founded
    2014
    HQ Location
    Leeds, GB
    Twitter
    @AppcheckNG
    653 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    99 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a

Users
No information available
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 50% Mid-Market
  • 30% Small-Business
Verified User in Medical Devices
AM
Value for money is the main key for me personally, we were spending more money on external companies doing scans once or twice a year. We now do... Read review
Mark W.
MW
AppCheck is an excellent tool to provide full visibility into our estate and embed security into the CI/CD pipeline. Traditional pen testing... Read review
Seller Details
Seller
APPCHECK
Company Website
Year Founded
2014
HQ Location
Leeds, GB
Twitter
@AppcheckNG
653 Twitter followers
LinkedIn® Page
www.linkedin.com
99 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Strobes is an AI-driven exposure management platform that unifies ASM, ASPM, RBVM, and PTaaS in one streamlined workflow. With 120+ integrations, it pulls findings into a single view, enriches them wi

    Users
    No information available
    Industries
    • Computer Software
    Market Segment
    • 39% Mid-Market
    • 29% Enterprise
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Atul S.
    AS
    I have been using Strobes Security for the past three years and have found it to be an all-in-one solution. All reports, their statuses, and... Read review
    Dhruv P.
    DP
    It doesn’t just dump vulnerability data-it prioritizes what actually matters based on risk and exploitability. The correlation between SAST, DAST.... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2019
    HQ Location
    Plano, US
    Twitter
    @StrobesHQ
    215 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    90 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Strobes is an AI-driven exposure management platform that unifies ASM, ASPM, RBVM, and PTaaS in one streamlined workflow. With 120+ integrations, it pulls findings into a single view, enriches them wi

Users
No information available
Industries
  • Computer Software
Market Segment
  • 39% Mid-Market
  • 29% Enterprise
Atul S.
AS
I have been using Strobes Security for the past three years and have found it to be an all-in-one solution. All reports, their statuses, and... Read review
Dhruv P.
DP
It doesn’t just dump vulnerability data-it prioritizes what actually matters based on risk and exploitability. The correlation between SAST, DAST.... Read review
Seller Details
Company Website
Year Founded
2019
HQ Location
Plano, US
Twitter
@StrobesHQ
215 Twitter followers
LinkedIn® Page
www.linkedin.com
90 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    SonarQube is the industry leader in automated code review, serving as the verification layer for code quality and security in the AI-powered SDLC. SonarQube ensures all code—whether written by develop

    Users
    • DevOps Engineer
    • Software Engineer
    Industries
    • Information Technology and Services
    • Computer Software
    Market Segment
    • 42% Enterprise
    • 38% Mid-Market
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • TG
    they sell that is good , i don't have a change to fully test Read review
    Mukesh K. R.
    MR
    Simple deployment. Very easy installing is practiced particularly on Kubernetes using YAML formats. Moreover, integration with GitHub by means of... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Company Website
    Year Founded
    2008
    HQ Location
    Geneva, Switzerland
    Twitter
    @SonarSource
    10,908 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    871 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

SonarQube is the industry leader in automated code review, serving as the verification layer for code quality and security in the AI-powered SDLC. SonarQube ensures all code—whether written by develop

Users
  • DevOps Engineer
  • Software Engineer
Industries
  • Information Technology and Services
  • Computer Software
Market Segment
  • 42% Enterprise
  • 38% Mid-Market
TG
they sell that is good , i don't have a change to fully test Read review
Mukesh K. R.
MR
Simple deployment. Very easy installing is practiced particularly on Kubernetes using YAML formats. Moreover, integration with GitHub by means of... Read review
Seller Details
Company Website
Year Founded
2008
HQ Location
Geneva, Switzerland
Twitter
@SonarSource
10,908 Twitter followers
LinkedIn® Page
www.linkedin.com
871 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Edgescan is a comprehensive platform for continuous proactive security, exposure management, and Penetration Testing as a Service (PTaaS). It is designed to assist organizations in gaining a thorough

    Users
    No information available
    Industries
    • Information Technology and Services
    • Computer Software
    Market Segment
    • 33% Enterprise
    • 31% Mid-Market
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Evan B.
    EB
    The services that they offer are easy to integrate and simple to monitor. The people behind the product are some of the best in the industry and... Read review
    Mark H.
    MH
    Edgescan allows us to execute penetration tests and security scans monthly at a great price point. Uncovered vulnerabilities can be addressed more... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Edgescan
    Company Website
    Year Founded
    2017
    HQ Location
    Dublin, Dublin
    Twitter
    @edgescan
    2,274 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    89 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Edgescan is a comprehensive platform for continuous proactive security, exposure management, and Penetration Testing as a Service (PTaaS). It is designed to assist organizations in gaining a thorough

Users
No information available
Industries
  • Information Technology and Services
  • Computer Software
Market Segment
  • 33% Enterprise
  • 31% Mid-Market
Evan B.
EB
The services that they offer are easy to integrate and simple to monitor. The people behind the product are some of the best in the industry and... Read review
Mark H.
MH
Edgescan allows us to execute penetration tests and security scans monthly at a great price point. Uncovered vulnerabilities can be addressed more... Read review
Seller Details
Seller
Edgescan
Company Website
Year Founded
2017
HQ Location
Dublin, Dublin
Twitter
@edgescan
2,274 Twitter followers
LinkedIn® Page
www.linkedin.com
89 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Mend.io is the leading application security solution, helping organizations reduce application risk efficiently. Built for modern, AI-driven, and traditional development environments alike, Mend.io pr

    Users
    • Software Engineer
    Industries
    • Computer Software
    • Information Technology and Services
    Market Segment
    • 38% Small-Business
    • 34% Mid-Market
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Vivek Kumar S.
    VS
    Interface and flow of the application.Also the simplicity Read review
    Meer T.
    MT
    The best thing is the security and easy to use. The mend bot offers couple of qualities to protect your projects against several security protocols... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Mend
    Company Website
    Year Founded
    2011
    HQ Location
    Boston, Massachusetts
    Twitter
    @Mend_io
    11,331 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    267 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Mend.io is the leading application security solution, helping organizations reduce application risk efficiently. Built for modern, AI-driven, and traditional development environments alike, Mend.io pr

Users
  • Software Engineer
Industries
  • Computer Software
  • Information Technology and Services
Market Segment
  • 38% Small-Business
  • 34% Mid-Market
Vivek Kumar S.
VS
Interface and flow of the application.Also the simplicity Read review
Meer T.
MT
The best thing is the security and easy to use. The mend bot offers couple of qualities to protect your projects against several security protocols... Read review
Seller Details
Seller
Mend
Company Website
Year Founded
2011
HQ Location
Boston, Massachusetts
Twitter
@Mend_io
11,331 Twitter followers
LinkedIn® Page
www.linkedin.com
267 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Vulnerability management tool on steroids 📈 Measure and control your application security state; 🔎 Scan your code, containers, web and mobile applications using ANY tool; 🔥 Remove duplicates, v

    Users
    No information available
    Industries
    No information available
    Market Segment
    • 60% Mid-Market
    • 20% Small-Business
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Konstantin S.
    KS
    It’s the first platform I’ve encountered that combines professional-level functionality with an accessible price, making it a good option for... Read review
    Denis R.
    DR
    A very cost-effective solution for companies looking for an alternative to DefectDojo, but unwilling to spend big money on unproven solutions from... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2020
    HQ Location
    Tallinn, EE
    LinkedIn® Page
    www.linkedin.com
    16 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Vulnerability management tool on steroids 📈 Measure and control your application security state; 🔎 Scan your code, containers, web and mobile applications using ANY tool; 🔥 Remove duplicates, v

Users
No information available
Industries
No information available
Market Segment
  • 60% Mid-Market
  • 20% Small-Business
Konstantin S.
KS
It’s the first platform I’ve encountered that combines professional-level functionality with an accessible price, making it a good option for... Read review
Denis R.
DR
A very cost-effective solution for companies looking for an alternative to DefectDojo, but unwilling to spend big money on unproven solutions from... Read review
Seller Details
Year Founded
2020
HQ Location
Tallinn, EE
LinkedIn® Page
www.linkedin.com
16 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Flyingduck is a Comprehensive Code security Intelligence platform that identifies and remediates security vulnerabilities in the code base. Key modules are SBOM Compliance, SCA, SAST, Secrets Analysis

    Users
    No information available
    Industries
    No information available
    Market Segment
    • 75% Mid-Market
    • 25% Small-Business
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • SR
    The dashboard layout, along with the segmentation and navigation of SAST, SCA, and Secret findings within the console, are notable aspects. Read review
    Venkata R.
    VR
    Flyingduck provides a comprehensive 360° view of SBOM (Software Bill of Materials), security vulnerabilities, and guardrails, including insights at... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2024
    HQ Location
    Hyderabad, IN
    LinkedIn® Page
    www.linkedin.com
    11 employees on LinkedIn®
    Ownership
    Sarat Lingamallu
    Phone
    +919550681242
Product Description
How are these determined?Information
This description is provided by the seller.

Flyingduck is a Comprehensive Code security Intelligence platform that identifies and remediates security vulnerabilities in the code base. Key modules are SBOM Compliance, SCA, SAST, Secrets Analysis

Users
No information available
Industries
No information available
Market Segment
  • 75% Mid-Market
  • 25% Small-Business
SR
The dashboard layout, along with the segmentation and navigation of SAST, SCA, and Secret findings within the console, are notable aspects. Read review
Venkata R.
VR
Flyingduck provides a comprehensive 360° view of SBOM (Software Bill of Materials), security vulnerabilities, and guardrails, including insights at... Read review
Seller Details
Year Founded
2024
HQ Location
Hyderabad, IN
LinkedIn® Page
www.linkedin.com
11 employees on LinkedIn®
Ownership
Sarat Lingamallu
Phone
+919550681242
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    AccuKnox Zero Trust CNAPP cloud security protects public and private clouds, Kubernetes and VMs. AccuKnox is a AI-powered Zero Trust Cloud Native Security Platform that helps organizations comply with

    Users
    No information available
    Industries
    No information available
    Market Segment
    • 46% Enterprise
    • 31% Mid-Market
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Verified User in Hospital & Health Care
    AH
    I had a very good initial conversation with the sales team and had a successful demo. The solution is very capable. The solutions offered are... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Seller
    Accuknox
    Year Founded
    2020
    HQ Location
    California, USA
    Twitter
    @AccuKnox
    344 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    171 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

AccuKnox Zero Trust CNAPP cloud security protects public and private clouds, Kubernetes and VMs. AccuKnox is a AI-powered Zero Trust Cloud Native Security Platform that helps organizations comply with

Users
No information available
Industries
No information available
Market Segment
  • 46% Enterprise
  • 31% Mid-Market
Verified User in Hospital & Health Care
AH
I had a very good initial conversation with the sales team and had a successful demo. The solution is very capable. The solutions offered are... Read review
Seller Details
Seller
Accuknox
Year Founded
2020
HQ Location
California, USA
Twitter
@AccuKnox
344 Twitter followers
LinkedIn® Page
www.linkedin.com
171 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Phoenix Security is a Contextual ASPM focused on product security. It combines risk-based Vulnerability Management, Application Security Posture Management, and Cloud into a risk and remediation-first

    Users
    No information available
    Industries
    No information available
    Market Segment
    • 100% Small-Business
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Verified User in Information Technology and Services
    UI
    Simple UI level of customization Effortless User Experience with Simple UI Phoenix Security's platform offers a straightforward, intuitive user... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2021
    HQ Location
    London, GB
    Twitter
    @sec_phoenix
    270 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    19 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Phoenix Security is a Contextual ASPM focused on product security. It combines risk-based Vulnerability Management, Application Security Posture Management, and Cloud into a risk and remediation-first

Users
No information available
Industries
No information available
Market Segment
  • 100% Small-Business
Verified User in Information Technology and Services
UI
Simple UI level of customization Effortless User Experience with Simple UI Phoenix Security's platform offers a straightforward, intuitive user... Read review
Seller Details
Year Founded
2021
HQ Location
London, GB
Twitter
@sec_phoenix
270 Twitter followers
LinkedIn® Page
www.linkedin.com
19 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage secur

    Users
    No information available
    Industries
    No information available
    Market Segment
    • 60% Small-Business
    • 40% Mid-Market
  • What G2 Users Think
    Expand/Collapse What G2 Users Think
  • Óscar G.
    ÓG
    - Real-time malware detection: Xygeni’s early warning system has been a game-changer, identifying malicious open source components before they can... Read review
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2021
    HQ Location
    Madrid, ES
    Twitter
    @xygeni
    196 Twitter followers
    LinkedIn® Page
    www.linkedin.com
    30 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage secur

Users
No information available
Industries
No information available
Market Segment
  • 60% Small-Business
  • 40% Mid-Market
Óscar G.
ÓG
- Real-time malware detection: Xygeni’s early warning system has been a game-changer, identifying malicious open source components before they can... Read review
Seller Details
Year Founded
2021
HQ Location
Madrid, ES
Twitter
@xygeni
196 Twitter followers
LinkedIn® Page
www.linkedin.com
30 employees on LinkedIn®
  • Overview
    Expand/Collapse Overview
  • Product Description
    How are these determined?Information
    This description is provided by the seller.

    Heeler empowers application security teams to shift left with the context they need to reduce noise, accelerate remediation, and move beyond traditional vulnerability management. By combining ASPM, SC

    We don't have enough data from reviews to share who uses this product. Leave a review to contribute, or learn more about review generation.
    Industries
    No information available
    Market Segment
    No information available
  • Seller Details
    Expand/Collapse Seller Details
  • Seller Details
    Year Founded
    2023
    HQ Location
    N/A
    LinkedIn® Page
    www.linkedin.com
    20 employees on LinkedIn®
Product Description
How are these determined?Information
This description is provided by the seller.

Heeler empowers application security teams to shift left with the context they need to reduce noise, accelerate remediation, and move beyond traditional vulnerability management. By combining ASPM, SC

We don't have enough data from reviews to share who uses this product. Leave a review to contribute, or learn more about review generation.
Industries
No information available
Market Segment
No information available
Seller Details
Year Founded
2023
HQ Location
N/A
LinkedIn® Page
www.linkedin.com
20 employees on LinkedIn®