Best Interactive Application Security Testing (IAST) Software

How Many Interactive Application Security Testing (IAST) Software Products Does G2 Track?

Total Products under this Category: 19

Category Stats (Sep 2026)

  • Average Rating: 4.45/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Black Duck Polaris Platform (+2.92%) - Among all products in this category, Black Duck Polaris Platform recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Interactive Application Security Testing (IAST) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 800+ Authentic Reviews
  • 19+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Interactive Application Security Testing (IAST) Software

G2 Grid® for Interactive Application Security Testing (IAST) Software plotting products by satisfaction and market presence

Highlighted products: Aikido Security, Black Duck Polaris Platform, Checkmarx, HCL AppScan, OpenText Core Application Security, Invicti, Contrast Security, and Semgrep.

Underlying data: [Grid® JSON](https://www.g2.com/categories/interactive-application-security-testing-iast/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=black-duck-polaris-platform&focus%5B%5D=checkmarx&focus%5B%5D=hcl-appscan&focus%5B%5D=opentext-core-application-security&focus%5B%5D=invicti&focus%5B%5D=contrast-security-contrast-security&focus%5B%5D=semgrep)

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 263

How Do G2 Users Rate Aikido Security?

  • Ease of Use: 9.3/10 (Category avg: 8.3/10)
  • Quality of Support: 9.3/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Ease of Admin: 9.4/10 (Category avg: 8.6/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 79% Small, 14% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

How Do G2 Users Rate Black Duck Polaris Platform?

  • Ease of Use: 8.4/10 (Category avg: 8.3/10)
  • Quality of Support: 8.5/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.5/10 (Category avg: 8.6/10)

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate Checkmarx?

  • Ease of Use: 8.5/10 (Category avg: 8.3/10)
  • Quality of Support: 8.4/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.6/10)

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Medium

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

HCL AppScan

HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint application vulnerabilities, allowing for quick remediation in every phase of the software development lifecycle. Fast and Accurate Scanning for Secure DevOps Developers and DevOps teams can quickly and accurately scan code, applications, and APIs for security vulnerabilities while applications are being developed. This allows companies to fix issues at the earliest stages of the software development lifecycle, when it is least costly to the business. Focus on the Fix Continuous monitoring with IAST, along with auto issue correlation with DAST and SAST scan results allows DevOps teams to group and prioritize findings for faster, more streamlined remediation. Enterprise Management for Security Teams Centralized, easy-to-use dashboards provide visibility and oversight of all security scanning and remediation, and allow users to set scan parameters and compliance policies.

Average Rating: 4.1/5.0

Total Reviews: 86

How Do G2 Users Rate HCL AppScan?

  • Ease of Use: 8.4/10 (Category avg: 8.3/10)
  • Quality of Support: 8.5/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.2/10 (Category avg: 8.6/10)

Who Is the Company Behind HCL AppScan?

  • Seller: HCL Technologies
  • Company Website:
  • Year Founded: 1999
  • HQ Location: Noida, Uttar Pradesh
  • Twitter: @hcltech
    425,043 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    258,955 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 53% Large, 28% Small

What Are Recent G2 Reviews of HCL AppScan?

What Are G2 Users Discussing About HCL AppScan?

OpenText Core Application Security

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

Average Rating: 4.1/5.0

Total Reviews: 34

How Do G2 Users Rate OpenText Core Application Security?

  • Ease of Use: 8.2/10 (Category avg: 8.3/10)
  • Quality of Support: 7.9/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.6/10)

Who Is the Company Behind OpenText Core Application Security?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Large, 32% Small

What Are Recent G2 Reviews of OpenText Core Application Security?

What Are G2 Users Discussing About OpenText Core Application Security?

Invicti

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

Average Rating: 4.5/5.0

Total Reviews: 69

How Do G2 Users Rate Invicti?

  • Ease of Use: 9.1/10 (Category avg: 8.3/10)
  • Quality of Support: 8.9/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Ease of Admin: 9.2/10 (Category avg: 8.6/10)

Who Is the Company Behind Invicti?

  • Seller: Invicti Security
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Austin, Texas
  • Twitter: @InvictiSecurity
    2,557 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    326 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Large, 29% Medium

What Do G2 Reviewers Say About Invicti?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Invicti, facilitating quick setup and effective vulnerability scanning in their workflow.
  • Users value the quick and easy scanning technology of Invicti, enhancing workflow efficiency and accuracy in vulnerability detection.
  • Users value the simplicity and integration of Invicti, enhancing security measures through user-friendly report generation and detailed views.
  • Users value the easy-to-read and well-formatted reports from Invicti, enhancing efficiency and supporting ISO certification needs.
  • Users value the high accuracy and ease of use in Invicti's vulnerability detection, effectively identifying true issues.
Cons
  • Users find the customer support lacking, often experiencing slow responses and inadequate technical assistance.
  • Users experience slow performance during scans and setups, impacting overall efficiency and satisfaction.
  • Users experience slow scanning issues with Invicti, often leading to frustrating delays during the scanning process.
  • Users face API scanning issues with Invicti, limiting its effectiveness for their specific needs despite decent support.
  • Users find the complex setup of Invicti challenging initially, hindering their ability to quickly navigate configurations.

What Are Recent G2 Reviews of Invicti?

What Are G2 Users Discussing About Invicti?

Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

Average Rating: 4.5/5.0

Total Reviews: 49

How Do G2 Users Rate Contrast Security?

  • Ease of Use: 8.6/10 (Category avg: 8.3/10)
  • Quality of Support: 9.3/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.9/10 (Category avg: 8.6/10)

Who Is the Company Behind Contrast Security?

  • Seller: Contrast Security
  • Year Founded: 2014
  • HQ Location: Pleasanton, CA
  • Twitter: @contrastsec
    5,468 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Insurance, Information Technology and Services
  • Company Size: 67% Large, 20% Medium

What Do G2 Reviewers Say About Contrast Security?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Contrast Security, ensuring greater precision in identifying vulnerabilities.
  • Users value the accuracy of results from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
  • Users commend the real-time vulnerability detection of Contrast Security, appreciating its quick feedback and agile support.
Cons
  • Users experienced performance issues with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

What Are Recent G2 Reviews of Contrast Security?

What Are G2 Users Discussing About Contrast Security?

Semgrep

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

Average Rating: 4.6/5.0

Total Reviews: 56

How Do G2 Users Rate Semgrep?

  • Ease of Use: 9.1/10 (Category avg: 8.3/10)
  • Quality of Support: 8.8/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)
  • Ease of Admin: 9.1/10 (Category avg: 8.6/10)

Who Is the Company Behind Semgrep?

  • Seller: Semgrep
  • Year Founded: 2017
  • HQ Location: San Francisco, US
  • Twitter: @semgrep
    4,433 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    268 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 45% Large, 43% Medium

What Do G2 Reviewers Say About Semgrep?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD.
  • Users appreciate the flexibility and speed of Semgrep in enforcing coding standards and catching vulnerabilities effectively.
  • Users appreciate the effective vulnerability detection of Semgrep, facilitating quick identification and resolution of security issues.
  • Users appreciate the scanning efficiency of Semgrep, benefiting from rapid scans and streamlined CI/CD integration.
  • Users value Semgrep for its effective security vulnerability detection, enabling quick resolutions without hindering development speed.
Cons
  • Users find Semgrep not user-friendly due to a steep learning curve and complex initial setup requirements.
  • Users find the limited features of Semgrep restrict its usability and complicate effective vulnerability management.
  • Users find the difficult learning curve for Semgrep daunting, especially for creating advanced rules and setups.
  • Users express concerns about the lack of guidance in creating custom rules, complicating effective use of Semgrep.
  • Users note a steep learning curve for Semgrep's rule syntax, making it challenging for newcomers to master.

What Are Recent G2 Reviews of Semgrep?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Ease of Use: 7.3/10 (Category avg: 8.3/10)
  • Quality of Support: 8.0/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 9.2/10)
  • Ease of Admin: 7.4/10 (Category avg: 8.6/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?

Akto API Security Platform

Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — API discovery, API security posture management, sensitive data exposure, and API security testing solutions enables organizations to gain visibility in their API security posture. 1,000+ Application Security teams globally trust Akto for their API security needs. Akto use cases: 1. API Discovery 2. API Security Testing in CI/CD 3. API Security Posture Management 4. Authentication and Authorization Testing 5. Sensitive data Exposure 6. Shift left in DevSecOps

Average Rating: 4.5/5.0

Total Reviews: 54

How Do G2 Users Rate Akto API Security Platform?

  • Ease of Use: 8.6/10 (Category avg: 8.3/10)
  • Quality of Support: 9.0/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.1/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.4/10 (Category avg: 8.6/10)

Who Is the Company Behind Akto API Security Platform?

  • Seller: Akto.io
  • Company Website:
  • Year Founded: 2022
  • HQ Location: San Francisco, California
  • Twitter: @Aktodotio
    1,357 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 44% Medium, 40% Small

What Do G2 Reviewers Say About Akto API Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the user-friendly interface of Akto, finding the platform easy to navigate and manage projects.
  • Users praise Akto for its easy API security testing integration, seamlessly fitting into CI/CD pipelines and enhancing efficiency.
  • Users value the effortless integration of automation testing in Akto, enhancing efficiency within their CI/CD workflow.
  • Users praise Akto for its seamless integration with CI/CD pipelines, enhancing API security testing with minimal manual effort.
  • Users value the automated security testing capabilities of Akto API Security Platform, enhancing their API protection efforts.
Cons
  • Users find the complex initial setup challenging due to poor documentation and a steep learning curve.
  • Users find the documentation poor, making it challenging to configure advanced features effectively.
  • Users find that API issues hinder their experience, particularly due to a steep learning curve and complex configurations.
  • Users find the learning curve steep with Akto, especially for those unfamiliar with API security concepts and configurations.
  • Users find the setup complexity of Akto API Security Platform challenging due to poor documentation and steep learning curve.

What Are Recent G2 Reviews of Akto API Security Platform?

NowSecure

NowSecure Inc., based in Oak Park, Illinois, was formed in 2009 with a mission to advance mobile security worldwide. We help secure mobile devices, enterprises and mobile apps.

Average Rating: 4.6/5.0

Total Reviews: 27

How Do G2 Users Rate NowSecure?

  • Ease of Use: 8.2/10 (Category avg: 8.3/10)
  • Quality of Support: 9.7/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Ease of Admin: 9.0/10 (Category avg: 8.6/10)

Who Is the Company Behind NowSecure?

  • Seller: NowSecure
  • Year Founded: 2009
  • HQ Location: Chicago, Illinois
  • Twitter: @nowsecuremobile
    6,372 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    101 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 41% Medium, 37% Large

What Are Recent G2 Reviews of NowSecure?

What Are G2 Users Discussing About NowSecure?

GuardRails

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

Average Rating: 4.3/5.0

Total Reviews: 29

How Do G2 Users Rate GuardRails?

  • Ease of Use: 8.3/10 (Category avg: 8.3/10)
  • Quality of Support: 8.5/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.7/10 (Category avg: 8.6/10)

Who Is the Company Behind GuardRails?

  • Seller: GuardRails
  • Year Founded: 2017
  • HQ Location: Singapore, Singapore
  • Twitter: @guardrailsio
    1,553 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 52% Small, 48% Medium

What Do G2 Reviewers Say About GuardRails?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of GuardRails, ensuring efficient code scans and vulnerability management in DevSecOps.
  • Users value the vulnerability detection capabilities of GuardRails, enhancing security with automated, comprehensive code scans.
  • Users find GuardRails easy to use, offering integrated feedback on security issues directly within their development environment.
  • Users value the error reduction capabilities of GuardRails, enabling early detection and swift resolution of security issues.
  • Users value the effective threat detection of GuardRails, ensuring secure code and timely vulnerability alerts during development.
Cons
  • Users note missing features in GuardRails, such as limited developer support and lack of report generation capabilities.
  • Users find time management challenging with GuardRails due to insufficient resources and requirement for constant supervision.
  • Users face bug issues with GuardRails, resulting in frequent bottlenecks and complications during code pushing.
  • Users face challenges with dashboard issues, including insufficient report generation and syncing difficulties for new users.
  • Users report false positives in GuardRails, which can complicate the vulnerability management process despite a helpful dashboard.

What Are Recent G2 Reviews of GuardRails?

PT Application Inspector

PT Application Inspector™ (PT AI™) is a comprehensive source code analysis tool that offers protection for web applications of any scale. Its holistic approach combines the advantages of static, dynamic, and interactive analysis to maintain application security throughout every stage of development—from the very first line of code to the go-live.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate PT Application Inspector?

  • Ease of Use: 10.0/10 (Category avg: 8.3/10)
  • Quality of Support: 10.0/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Ease of Admin: 10.0/10 (Category avg: 8.6/10)

Who Is the Company Behind PT Application Inspector?

Who Uses This Product?

  • Company Size: 67% Large, 33% Small

What Are Recent G2 Reviews of PT Application Inspector?

What Are G2 Users Discussing About PT Application Inspector?

ZeroThreat

ZeroThreat is an AI-powered web application and API penetration testing platform designed to identify real, exploitable vulnerabilities, not just surface-level findings. Built for modern engineering teams, it combines Agentic AI pentesting with a high-performance scanning engine to deliver up to 10× faster, deeply validated security testing. Unlike traditional DAST tools that rely on static signatures and generate excessive noise, ZeroThreat executes adaptive, attacker-style workflows that evolve based on application behavior. Its interpreter-driven vulnerability intelligence continuously ingests emerging threats and newly disclosed CVEs, enabling near real-time detection updates and rapid CVE-to-exploit mapping. The platform supports over 100,000 vulnerability checks, including native Nuclei template execution, and extends beyond known issues with zero-day detection through behavioral pattern analysis. It validates every finding through live exploit execution, ensuring only real, impactful vulnerabilities are reported, with clear proof of risk and exposed data.

Average Rating: 4.8/5.0

Total Reviews: 10

How Do G2 Users Rate ZeroThreat?

  • Ease of Use: 8.7/10 (Category avg: 8.3/10)
  • Quality of Support: 9.4/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.8/10 (Category avg: 8.6/10)

Who Is the Company Behind ZeroThreat?

Who Uses This Product?

  • Company Size: 50% Large, 30% Medium

What Do G2 Reviewers Say About ZeroThreat?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of ZeroThreat, enjoying smooth integration and a user-friendly interface for security management.
  • Users value the real-time vulnerability detection of ZeroThreat, enhancing security without disrupting workflow and reducing false positives.
  • Users commend the accuracy of results from ZeroThreat, significantly reducing false positives and enhancing security efficiency.
  • Users appreciate the setup ease of ZeroThreat, enabling quick integration into existing workflows without complications.
  • Users appreciate the easy setup of ZeroThreat, allowing quick integration and immediate security scanning in their workflow.
Cons
  • Users find the inefficient filtering in ZeroThreat's reporting section makes locating specific results unnecessarily time-consuming.
  • Users experience integration issues with ZeroThreat, finding it challenging to connect with DevOps tools and proprietary software.
  • Users feel that the limited integrations with other tools hinder a more seamless experience with ZeroThreat.
  • Users report slow performance in ZeroThreat, with lagging features and longer loading times affecting productivity.
  • Users note that the UX improvement in ZeroThreat is needed for better navigation, filtering, and faster loading times.

What Are Recent G2 Reviews of ZeroThreat?

Staris

Staris is an AI-powered application security validation platform that continuously discovers, proves, and remediates exploitable vulnerabilities in running applications — in hours, not weeks. Traditional security scanners generate thousands of potential vulnerabilities, forcing teams to rely on expensive, slow manual pentesting to determine which ones are actually exploitable. Staris replaces that bottleneck by combining SAST, DAST, and context-rich whitebox testing to validate real attack paths in your running applications, delivering zero false positives with proof of exploitability for every finding. Staris is purpose-built for application security leaders, DevSecOps teams, and engineering organizations that need to move fast without compromising security. The platform ingests your documentation, policies, and source code to understand your unique application context, then continuously tests for vulnerabilities that matter — not hypothetical risks. Key capabilities: Proves exploitable vulnerabilities with evidence, not just flags them Delivers results in ~4 hours vs. the ~40 hours a typical expert requires (40:1 efficiency) Closed-loop AI-driven remediation that fixes issues and verifies the fix Integrates into CI/CD pipelines for continuous security validation Zero false positives — every finding is proven exploitable Staris is ideal for organizations that are tired of triaging thousands of scanner alerts, waiting weeks for pentest results, or shipping code without knowing whether their applications are actually secure.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Staris?

  • Ease of Use: 8.3/10 (Category avg: 8.3/10)
  • Quality of Support: 10.0/10 (Category avg: 8.9/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)
  • Ease of Admin: 8.3/10 (Category avg: 8.6/10)

Who Is the Company Behind Staris?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Staris?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024