Best Penetration Testing Tools for Medium-Sized Businesses

How Many Penetration Testing Tools Products Does G2 Track?

Total Products under this Category: 136

Category Stats (Aug 2026)

  • Average Rating: 4.64/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Cyver Core (+1.26%) - Among all products in this category, Cyver Core recorded the largest rating increase compared to last month

Last updated: August 05, 2026

How Does G2 Rank Penetration Testing Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,600+ Authentic Reviews
  • 136+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Penetration Testing Tools

G2 Grid® for Penetration Testing Tools plotting products by satisfaction and market presence

Highlighted products: Cobalt, vPenTest, Astra Pentest, NodeZero from Horizon3.ai, Burp Suite, H1 Platform, Bugcrowd, and Oneleet.

Underlying data: [Grid® JSON](https://www.g2.com/categories/penetration-testing-tools/grids.json?focus%5B%5D=cobalt-io-cobalt&focus%5B%5D=vpentest&focus%5B%5D=astra-pentest&focus%5B%5D=nodezero-from-horizon3-ai&focus%5B%5D=burp-suite&focus%5B%5D=h1-platform&focus%5B%5D=bugcrowd&focus%5B%5D=oneleet&segment=mid-market)

Sponsored

800.com

Smarter call tracking, now with AI Agents that answer when you can't. Never miss a call again. 800.com helps small businesses and agencies grow smarter with 800 AI Agents: intelligent agents that answer, handle, and qualify every inbound call, 24/7. No missed calls, no lost leads, no after-hours voicemail black hole. 800 AI Agents work hand-in-hand with 800 Intelligence and Enhanced Caller ID to unlock even more the moment a call comes in — call summaries, call scoring, recommended next steps, and data enrichment that gives you the caller's name, email, and address instantly. Combined with a professional phone number, intuitive call routing, and built-in call tracking, you can stop guessing where your leads are coming from and start focusing on what works. Even if you're new to call tracking, 800.com makes it easy to assign unique phone numbers to your campaigns (website, ads, social, print), track results in real time, and route calls to the right person or team — all from one simple dashboard. AI features include: – 800 AI Agents that answer, handle, and qualify calls 24/7 – Call summaries, call scoring, and recommended next steps via 800 Intelligence – Data enrichment through Enhanced Caller ID — name, email, and address the moment the phone rings – Call transcription and sentiment analysis for deeper insight into customer interactions For agencies and advanced users, 800.com supports powerful tools like: – Dynamic Number Insertion (DNI) to track exact sources of inbound calls – Integrations with GA4, Google Ads, Meta, and Microsoft Ads – Client-level account management with white-labeled dashboards for a consistent brand experience across every account Built for SMBs but scalable for agencies, 800.com also includes: – Call forwarding, voicemail, and customizable IVR – Call recording and transcription with playback for training or QA – In-depth call analytics and reporting – SMS campaigns for direct customer engagement – Mobile app so your business line goes everywhere you go Looking for advanced call forwarding and routing with custom greetings and an auto-attendant? We have that too. Whether you're just starting out or scaling fast, 800.com helps you look more professional, stay responsive, and make better marketing decisions — with AI agents doing the heavy lifting, without the complexity of traditional phone systems.

Visit website

Cobalt

Cobalt is the pioneer in pentesting as a service (PTaaS) and a leader in continuous offensive security testing grounded in human expertise. The Cobalt Offensive Security Platform spans the full spectrum of offensive security, from targeted, human-led pentesting to high-frequency, AI-driven autonomous security testing. Only Cobalt brings together the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry's largest dataset of real-world pentest results. Thousands of customers and hundreds of partners rely on Cobalt and its global network of 500+ vetted security experts to continuously identify, prioritize, and remediate exploitable risk with the speed, flexibility, and precision today's organizations require.

Average Rating: 4.5/5.0

Total Reviews: 179

How Do G2 Users Rate Cobalt?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.1/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.7/10 (Category avg: 9.1/10)
  • Extensibility: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Cobalt?

  • Seller: Cobalt
  • Company Website:
  • Year Founded: 2013
  • HQ Location: San Francisco, California
  • Twitter: @cobalt_io
    8,462 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    557 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 52% Medium, 23% Small

What Do G2 Reviewers Say About Cobalt?

AI-generated summary from verified user reviews

Pros
  • Users value the pentesting efficiency of Cobalt due to its seamless process and prompt report generation.
  • Users commend Cobalt for its exceptional customer support, providing expertise and assistance throughout the pentesting process.
  • Users value the ease of use of Cobalt, praising its seamless setup and quick reporting for pentests.
  • Users value the constant communication during the process, enhancing collaboration and transparency throughout their experience with Cobalt.
  • Users value the immediate and comprehensive reports from Cobalt, simplifying pentesting and ensuring compliance.
Cons
  • Users find Cobalt to be expensive, particularly for small organizations and due to costly credit requirements.
  • Users find the limited scope of Cobalt's functionality inadequate, lacking depth in testing and real-world application coverage.
  • Users find the lack of detail in instructions frustrating, as it complicates the setup process for tests.
  • Users find Cobalt's pricing model confusing, suggesting revisions for clarity and integration costs.
  • Users experience inaccuracy in audits with Cobalt, leading to confusion and inefficient resource allocation in security assessments.

What Are Recent G2 Reviews of Cobalt?

What Are G2 Users Discussing About Cobalt?

vPenTest

A Vonahi Security está construindo o futuro da cibersegurança ofensiva ao oferecer testes de penetração automatizados e de alta qualidade através de sua plataforma SaaS, vPenTest. Projetado para replicar as ferramentas, técnicas e metodologias de consultores experientes, o vPenTest traz os benefícios dos testes de penetração de rede manuais para uma solução automatizada e fácil de usar. Tradicionalmente, os testes de penetração têm sido um processo manual, demorado e caro que muitas organizações realizam apenas uma ou duas vezes por ano. Isso frequentemente deixa as empresas expostas a ameaças emergentes entre as avaliações. O vPenTest aborda essa lacuna ao oferecer testes rápidos, consistentes e sob demanda que ajudam as organizações a avaliar seu risco de cibersegurança em tempo real de forma mais eficaz. Impulsionado por uma estrutura proprietária que evolui através de pesquisa contínua e insights do mundo real, o vPenTest permanece alinhado com as últimas técnicas de ataque e melhores práticas da indústria. A plataforma é apoiada por mais de 13 anos de experiência em segurança ofensiva, com a equipe possuindo certificações como CISSP, OSCP, OSCE, CEH, entre outras. Seu conhecimento está incorporado diretamente na plataforma, garantindo que cada teste seja conduzido com profundidade, consistência e precisão—sem os atrasos ou variabilidade dos testes manuais. O vPenTest permite que as organizações realizem testes de penetração de rede internos e externos com a frequência necessária, seja mensalmente, trimestralmente ou antes de auditorias ou revisões de seguros. Os relatórios automatizados fornecem insights acionáveis que facilitam a priorização da remediação e demonstram progresso em direção à conformidade. Hoje, mais de 22.000 organizações confiam no vPenTest para fortalecer sua postura de segurança e reduzir riscos. Isso inclui provedores de serviços gerenciados, provedores de serviços de segurança gerenciados, instituições financeiras, organizações orientadas por conformidade e equipes internas de TI. Quer você esteja trabalhando para atender a requisitos regulatórios, garantir cobertura de seguro cibernético ou defender-se proativamente contra ameaças em evolução, o vPenTest torna os testes de penetração de rede fáceis, acessíveis e escaláveis.

Average Rating: 4.6/5.0

Total Reviews: 243

How Do G2 Users Rate vPenTest?

  • the product tem sido um bom parceiro comercial?: 9.4/10 (Category avg: 9.4/10)
  • Desempenho e Confiabilidade: 9.1/10 (Category avg: 9.2/10)
  • Varredura de vulnerabilidade: 9.0/10 (Category avg: 9.1/10)
  • Extensibilidade: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind vPenTest?

  • Vendedor: Kaseya
  • Website da Empresa:
  • Ano de Fundação: 2000
  • Localização da Sede: Miami, FL
  • Twitter: @KaseyaCorp
    17,411 seguidores no Twitter
  • Página do LinkedIn®: www.linkedin.com
    5,471 funcionários no LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Tecnologia da Informação e Serviços, Segurança de Redes e Computadores
  • Company Size: 69% Small, 24% Medium

What Do G2 Reviewers Say About vPenTest?

AI-generated summary from verified user reviews

Pros
  • Os usuários acham o vPenTest excepcionalmente fácil de usar, aumentando a eficiência e tornando os testes de penetração acessíveis para iniciantes.
  • Os usuários apreciam os relatórios técnicos incríveis da vPenTest, que fornecem etapas detalhadas de remediação e são revisados pela CREST.
  • Os usuários valorizam a interface amigável do vPenTest, melhorando a navegação e aumentando significativamente a eficiência dos testes de penetração.
  • Os usuários destacam a facilidade de configuração do vPenTest, apreciando sua implementação direta e interface amigável.
  • Os usuários valorizam a facilidade de implementação do vPenTest, desfrutando de uma configuração sem complicações e integração sem esforço no fluxo de trabalho.
Cons
  • Os usuários acham o processo de configuração complexo, exigindo várias tentativas e sem integração com os sistemas existentes.
  • Os usuários estão frustrados com o escopo limitado do vPenTest, pois ele não consegue atender a todas as necessidades de pentesting de forma eficaz.
  • Os usuários acham o vPenTest caro, especialmente devido aos modelos de preços que sobrecarregam organizações menores e contratos com clientes maiores.
  • Os usuários observam a relato inadequado no vPenTest, destacando problemas com a padronização e disponibilidade limitada de relatórios.
  • Os usuários observam a falta de detalhes no vPenTest, o que pode levar a confusão e exigir explicações adicionais.

What Are Recent G2 Reviews of vPenTest?

Astra Pentest

Astra Security is a leading continuous penetration testing platform that combines AI-powered autonomous pentesting with certified expert-led assessments. Powered by Attack AI, trained on 6.8M+ security findings and insights from 5,000+ real-world pentests. Astra deploys intelligent agents that continuously discover, validate, prioritize, and help remediate vulnerabilities at scale. While AI handles speed and scale, Astra’s certified security experts focus on what automation alone cannot: complex business logic flaws, multi-step attack chains, advanced exploit paths, and emerging AI/LLM-specific threats. Built for modern engineering teams, Astra integrates directly into CI/CD workflows, enabling continuous security validation between releases instead of relying on outdated annual pentests. The platform delivers comprehensive Autonomous Pentest powered by AI agents, DAST vulnerability scanner and human-driven pentests across web apps, AI/LLMs, mobile apps, APIs, cloud infrastructure. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV-certified vendor. Our team also led the development of the OWASP APTS framework, helping shape the industry standard for continuous security testing. Today, 1,500+ organizations across 70+ countries trust Astra Security, including Ford, Loom, CompTIA, Hitachi, HackerRank, and OLX.

Average Rating: 4.6/5.0

Total Reviews: 224

How Do G2 Users Rate Astra Pentest?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.0/10 (Category avg: 9.1/10)
  • Extensibility: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind Astra Pentest?

  • Seller: ASTRA IT, Inc.
  • Company Website:
  • Year Founded: 2018
  • HQ Location: New Delhi, IN
  • Twitter: @getastra
    694 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    130 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, CEO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 67% Small, 28% Medium

What Do G2 Reviewers Say About Astra Pentest?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the responsive customer support of Astra Pentest, enhancing their experience and ensuring smooth collaboration.
  • Users value the comprehensive vulnerability management features of Astra Pentest, enhancing their ability to address security issues effectively.
  • Users love the ease of use of Astra Pentest, appreciating its intuitive design and accessible features.
  • Users commend Astra Pentest for its efficient penetration testing, enabling swift execution and effective communication throughout the process.
  • Users value the thorough vulnerability identification of Astra Pentest, enhancing confidence and security in their development processes.
Cons
  • Users experience poor customer support, citing slow responses and difficulties with account setup and vulnerability inquiries.
  • Users find the poor interface design of Astra Pentest to be clunky and not user-friendly, affecting usability.
  • Users experience slow performance with Astra Pentest, affecting testing speed and response times for results.
  • Users feel that the UX could be improved for a smoother experience, as navigation can sometimes be confusing.
  • Users face a lack of information with Astra Pentest, as documentation and updates are often insufficient or slow to arrive.

What Are Recent G2 Reviews of Astra Pentest?

What Are G2 Users Discussing About Astra Pentest?

NodeZero from Horizon3.ai

Horizon3's NodeZero® platform empowers your organization to continuously find, fix, and verify your exploitable attack surface. Reduce your security risk by autonomously finding weaknesses in your network, knowing how to prioritize and fix them, and immediately verifying that your fixes work. NodeZero delivers production-safe autonomous pentests and other key assessment operations that scale across your largest internal, external, cloud, and hybrid cloud environments. No required agents, no code to write, and no consultants to hire.

Average Rating: 4.7/5.0

Total Reviews: 35

How Do G2 Users Rate NodeZero from Horizon3.ai?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.6/10 (Category avg: 9.1/10)
  • Extensibility: 9.8/10 (Category avg: 8.7/10)

Who Is the Company Behind NodeZero from Horizon3.ai?

  • Seller: Horizon3.ai
  • Company Website:
  • Year Founded: 2019
  • HQ Location: San Francisco, US
  • Twitter: @Horizon3ai
    2,802 Twitter followers
  • LinkedIn® Page: linkedin.com
    444 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 54% Medium, 20% Large

What Do G2 Reviewers Say About NodeZero from Horizon3.ai?

AI-generated summary from verified user reviews

Pros
  • Users value the intuitive communication of NodeZero, making it accessible for both technical and non-technical staff.
  • Users rave about the intuitive and thorough integration of NodeZero, making it essential for cybersecurity needs.
  • Users value the ease of implementation of NodeZero, finding it intuitive and accessible for all team members.
  • Users value the easy integrations of NodeZero, making it accessible for both technical and non-technical staff.
  • Users value the efficiency of NodeZero in quickly identifying longstanding misconfigurations and vulnerabilities in their environments.
Cons
  • Users find the inadequate reporting of Tripwires' machine success and failure states frustrating and unclear.
  • Users note a lack of detail in Tripwires reporting, making it hard to identify specific machine outcomes.

What Are Recent G2 Reviews of NodeZero from Horizon3.ai?

Burp Suite

Burp Suite is a complete ecosystem for web application and API security testing, combining two products: Burp Suite DAST - a best-of-breed, precision DAST solution that automates runtime testing, and Burp Suite Professional - the industry-standard toolkit for manual penetration testing. Developed by PortSwigger, more than 85,000 security professionals rely on Burp Suite to find, verify, and understand vulnerabilities across complex modern web applications. Burp Suite DAST is PortSwigger’s enterprise dynamic application security testing (DAST) solution, purpose-built for continuous, automated scanning of web applications and APIs. Unlike many DAST solutions, which are part of a wider AST offering, Burp Suite DAST is not a bolt-on tool - instead it’s precision-built from over 20 years of dynamic testing experience. Burp Suite DAST reveals the runtime issues that static analysis tools miss, such as authentication flaws, configuration drift, and chained vulnerabilities. Built on the same proprietary scanning engine that powers Burp Suite Professional, it delivers precise, low-noise results that security teams trust. Key capabilities of Burp Suite DAST include: Continuous, automated scanning of web applications and APIs, integration with CI/CD pipelines and vulnerability management tools, flexible deployment across cloud, and on-premise environments, shared scanning logic and configurations between automated and manual testing, accurate, low-noise detection informed by PortSwigger Research. Burp Suite Professional complements DAST with deep manual testing capability. It’s the industry-standard toolkit for penetration testers, consultants, and AppSec engineers who need complete insight and flexibility when validating or exploring vulnerabilities. Findings discovered by DAST can be investigated and verified in Burp Suite Professional, ensuring every result is accurate, contextual, and actionable. Together, Burp Suite DAST and Burp Suite Professional create a unified ecosystem that delivers automation at breadth and manual depth where it counts. Burp Suite is built for AppSec teams who need scalable, trustworthy coverage across web and API environments, enabling a seamless handoff between automated and manual testing.

Average Rating: 4.8/5.0

Total Reviews: 126

How Do G2 Users Rate Burp Suite?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.8/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.9/10 (Category avg: 9.1/10)
  • Extensibility: 8.9/10 (Category avg: 8.7/10)

Who Is the Company Behind Burp Suite?

  • Seller: PortSwigger
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Knutsford, GB
  • Twitter: @Burp_Suite
    138,186 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    345 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Cyber Security Analyst
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 41% Medium, 31% Small

What Do G2 Reviewers Say About Burp Suite?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Burp Suite, enabling quick setup for both beginners and advanced professionals.
  • Users appreciate the user-friendly interface of Burp Suite, making penetration testing straightforward and accessible for all levels.
  • Users value the deep automation and manual testing capabilities of Burp Suite for effective web and Android security testing.
  • Users admire the user-friendly interface and seamless integration of Burp Suite, enhancing both navigation and testing efficiency.
  • Users love the clear interface of Burp Suite, enabling effortless traffic interception and easy navigation.
Cons
  • Users find Burp Suite expensive, especially students, limiting accessibility to its powerful features and community support.
  • Users report slow performance with Burp Suite, particularly on low-spec systems and during resource-intensive scans.
  • Users find the steep learning curve of Burp Suite challenging, especially for beginners navigating its complex features.
  • Users struggle with the steep learning curve of Burp Suite, finding it challenging, especially for beginners.
  • Users find the limited customization options in Burp Suite restrict their ability to tailor the tool to their needs.

What Are Recent G2 Reviews of Burp Suite?

What Are G2 Users Discussing About Burp Suite?

H1 Platform

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's largest community of security researchers to secure the AI-native enterprise. The H1 Platform unites agentic AI solutions with security researchers ingenuity to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing.

Average Rating: 4.5/5.0

Total Reviews: 79

How Do G2 Users Rate H1 Platform?

  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.1/10)
  • Extensibility: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind H1 Platform?

  • Seller: HackerOne
  • Company Website:
  • Year Founded: 2012
  • HQ Location: San Francisco, California
  • Twitter: @Hacker0x01
    337,493 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    7,090 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 44% Large, 40% Medium

What Do G2 Reviewers Say About H1 Platform?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of HackerOne, enabling quick onboarding and seamless program management.
  • Users value the streamlined interface of H1 Platform, facilitating efficient bug management and collaboration with ethical hackers.
  • Users value the collaboration with skilled ethical hackers, enhancing security and improving vulnerability management effectively.
  • Users value the strong security protection offered by HackerOne, enhancing overall safety through expert vulnerability management.
  • Users value the responsive customer support of H1 Platform, consistently providing guidance and assistance when needed.
Cons
  • Users experience complexity issues with triage workflows and credentials management, affecting overall efficiency and satisfaction.
  • Users note the expensive pricing of the H1 Platform, which can strain budgets despite its valuable features.
  • Users find time management challenging on H1 Platform due to inconsistent triage speeds and complexities in report handling.
  • Users report poor customer support with slow response times and unresolved tickets affecting their overall experience.
  • Users find the poor interface design confusing and difficult to navigate, impacting their overall experience.

What Are Recent G2 Reviews of H1 Platform?

What Are G2 Users Discussing About H1 Platform?

Bugcrowd

Bugcrowd frees organizations with a low tolerance for risk from chronic talent shortages, noisy tools that breed false positives, and the fear of critical hidden or emerging vulnerabilities. Our SaaS platform provides access to the unlimited capacity and skills of the global ethical hacker/pentester community for deeper, proactive risk reduction and faster regulatory compliance. With 12+ years of experience and 1200+ customers in every industry (including OpenAI, National Australia Bank, Indeed, USAA, Twilio, and CISA), we know what long-term with crowdsourced security looks like.

Average Rating: 4.3/5.0

Total Reviews: 60

How Do G2 Users Rate Bugcrowd?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.5/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.3/10 (Category avg: 9.1/10)
  • Extensibility: 8.2/10 (Category avg: 8.7/10)

Who Is the Company Behind Bugcrowd?

  • Seller: Bugcrowd
  • Year Founded: 2012
  • HQ Location: San Francisco, CA
  • Twitter: @Bugcrowd
    199,211 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,701 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 34% Large, 33% Small

What Do G2 Reviewers Say About Bugcrowd?

AI-generated summary from verified user reviews

Pros
  • Users value the high reporting quality on Bugcrowd, appreciating detailed reports and organized submission processes for effective vulnerability discovery.
  • Users find Bugcrowd to be easy to use, with a seamless setup and an intuitive interface enhancing their experience.
  • Users praise Bugcrowd's excellent customer support, noting their responsiveness and genuine helpfulness throughout their experience.
  • Users value the consistent and transparent communication from Bugcrowd, enhancing the overall research experience.
  • Users value Bugcrowd for its efficient vulnerability detection through a skilled community, enhancing security and saving time.
Cons
  • Users express frustration with poor customer support, highlighting issues with triaging delays and unresponsive reporting processes.
  • Users often experience slow performance in triaging and report validation, affecting their engagement and satisfaction with Bugcrowd.
  • Users face slow response times and inconsistent triaging from companies, impacting their overall experience with Bugcrowd.
  • Users experience inadequate reporting, facing delays and slow validation that can hinder timely resolutions and frustrate researchers.
  • Users find the learning curve steep on Bugcrowd, making it challenging for beginners to navigate the platform.

What Are Recent G2 Reviews of Bugcrowd?

Oneleet

Oneleet is the all-in-one security and compliance platform that gets companies genuinely secure while achieving SOC 2, ISO 27001, HIPAA and other compliance certifications faster than traditional approaches. Unlike compliance platforms that focus on checkbox evidence collection, Oneleet implements real security first. Compliance follows automatically as a natural outcome of effective cybersecurity, not as a separate goal. Most companies face a false choice: painful but effective security, or painless but ineffective compliance theater. Traditional compliance platforms require juggling multiple vendors, managing fragmented tools, spending months with consultants, and doing manual evidence collection to achieve a certificate that doesn't actually make you secure. Oneleet consolidates what previously required half a dozen vendors into one integrated platform: penetration testing by real security experts (not just vulnerability scans), code scanning with SAST and DAST, cloud security posture management, attack surface monitoring, mobile device management, security training and awareness, policy generation and management, and continuous compliance monitoring. Because we build everything ourselves and control the entire stack, we deploy comprehensive security with a click. No blind spots. No integration gaps. No vendor sprawl. We guarantee audit outcomes because our standards are higher than auditors' standards. We use AI extensively but responsibly, automating threat modeling and risk assessments while keeping humans in the loop to ensure quality. Clients never see AI hallucinations. We take full responsibility for the entire security journey, from initial setup through audit completion and continuous monitoring. Companies achieve compliance readiness faster with Oneleet, not by doing less, but by making real security easier. We ship all the tools you would normally spend weeks or months setting up and adopting. Our customers regularly win deals they previously lost due to inadequate security postures. Oneleet is the fastest growing compliance company in the sector. A large number of Oneleet's newer clients come from platforms like Vanta and Drata. With Oneleet's all-in-one bundle pricing its ROI is significantly higher than that of Vanta, Drata and Delve. Companies that switch from Vanta, Drata, or Delve to Oneleet report faster audits, higher approval rates, and less manual effort. Vanta and Drata rely heavily on manual evidence collection and vendor integrations, creating delays and gaps. Delve emphasizes AI automation but often sacrifices accuracy—its generated outputs are frequently rejected or require manual fixes. Oneleet achieves both precision and speed by combining full-stack automation with expert oversight, producing the industry’s lowest audit-rejection rate and the fastest path to verified security. Oneleet serves SMBs and growth-stage companies that need compliance certifications to close enterprise deals, but want to be genuinely secure, not just certified on paper. Founded by professional penetration testers who spent over a decade breaching Fortune 500s and startups, we built Oneleet to end the disconnect between compliance and security.

Average Rating: 4.9/5.0

Total Reviews: 139

How Do G2 Users Rate Oneleet?

  • Performance and Reliability: 10.0/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 10.0/10 (Category avg: 9.1/10)
  • Extensibility: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Oneleet?

  • Seller: Oneleet
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Atlanta, US
  • LinkedIn® Page: www.linkedin.com
    40 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Engineer
  • Top Industries: Computer Software, Medical Devices
  • Company Size: 15% Small, 11% Medium

What Do G2 Reviewers Say About Oneleet?

AI-generated summary from verified user reviews

Pros
  • Users value the continuous security monitoring of Oneleet, transforming compliance into a seamless and efficient process.
  • Users value the automated compliance monitoring of Oneleet, making ISO 27001 and SOC2 documentation management seamless.
  • Users find Oneleet's platform to have exceptional ease of use, simplifying compliance and providing clear support throughout.
  • Users value the quick and expert responses from Oneleet, feeling supported like having a senior colleague available.
  • Users value the facilitated compliance management of Oneleet, which streamlines document handling and automates evidence collection.
Cons
  • Users face integration issues with Oneleet, limiting connections and requiring support from engineers for resolution.
  • Users are disappointed by the limited customization, as policies are restricted to only English with no multilingual support.
  • Users express frustration over limited integrations that hinder the platform's compatibility with preferred connections.
  • Users note a lack of integration with smaller platforms, limiting overall functionality and usability of Oneleet.
  • Users are disappointed by the lack of language customization, limiting accessibility and usability for non-English speakers.

What Are Recent G2 Reviews of Oneleet?

Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

Average Rating: 4.8/5.0

Total Reviews: 209

How Do G2 Users Rate Intruder?

  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 9.4/10)
  • Performance and Reliability: 9.4/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 9.6/10 (Category avg: 9.1/10)
  • Extensibility: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Intruder?

  • Seller: Intruder
  • Company Website:
  • Year Founded: 2015
  • HQ Location: London
  • Twitter: @intruder_io
    979 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    84 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, Director
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 57% Small, 36% Medium

What Do G2 Reviewers Say About Intruder?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Intruder perfect for configuring and scanning cloud resources efficiently.
  • Users appreciate the easy configuration of vulnerability detection, making it simple to secure cloud resources efficiently.
  • Users value the exceptional customer support from Intruder, highlighting quick responses and friendliness during their experience.
  • Users value Intruder's easy-to-use interface and seamless integration, enhancing their cybersecurity management experience significantly.
  • Users value the easy configuration of Intruder, allowing timely identification of vulnerabilities across cloud resources.
Cons
  • Users find the service to be expensive, suggesting improvements in pricing models for better value.
  • Users report slow scanning as Intruder misses some vulnerabilities and lacks integration with comprehensive testing tools.
  • Users struggle with the licensing model of Intruder, finding it complex and not immediately intuitive.
  • Users experience false positives from Intruder, leading to confusion between critical and lower-risk vulnerabilities.
  • Users find the limited features of Intruder frustrating, especially regarding reporting flexibility and license understanding.

What Are Recent G2 Reviews of Intruder?

What Are G2 Users Discussing About Intruder?

Pentera

Pentera is the category leader for Automated Security Validation, allowing every organization to test with ease the integrity of all cybersecurity layers, unfolding true, current security exposures at any moment, at any scale. Thousands of security professionals and service providers around the world use Pentera to guide remediation and close security gaps before they are exploited. Its customers include Casey's General Stores, Emeria, LuLu International Exchange, IP Telecom PT, BrewDog, City National Bank, Schmitz Cargobull, and MBC Group. Pentera is backed by leading investors such as K1 Investment Management, Insight Partners, Blackstone, Evolution Equity Partners, and AWZ. Visit https://pentera.io for more information.

Average Rating: 4.5/5.0

Total Reviews: 171

How Do G2 Users Rate Pentera?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.4/10)
  • Performance and Reliability: 8.6/10 (Category avg: 9.2/10)
  • Vulnerability Scan: 8.6/10 (Category avg: 9.1/10)
  • Extensibility: 7.4/10 (Category avg: 8.7/10)

Who Is the Company Behind Pentera?

  • Seller: Pentera
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Boston, MA
  • Twitter: @penterasec
    3,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    483 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Government Administration, Banking
  • Company Size: 52% Large, 36% Medium

What Do G2 Reviewers Say About Pentera?

AI-generated summary from verified user reviews

Pros
  • Users value the automation features of Pentera, enhancing ease of use and enabling efficient continuous operation.
  • Users recognize the powerful automation and detailed remediation suggestions of Pentera for effective vulnerability detection.
  • Users value Pentera's effective vulnerability scanning and remediation suggestions, enhancing their overall security posture and testing efficacy.
  • Users value the responsive customer support of Pentera, enhancing their overall vulnerability scanning experience.
  • Users appreciate the efficiency of Pentera, notably for its quick implementation and time-saving automation.
Cons
  • Users find the reporting inadequate, particularly for enterprise-level assessments, necessitating significant improvements.
  • Users experience a lack of essential features, including limited TTP updates and inadequate user permissions management.
  • Users find the reporting in Pentera lacking, especially for enterprise-level needs and multilingual support.
  • Users find Pentera demands a high amount of system resources, which can hinder overall performance and efficiency.
  • Users report technical issues, particularly with module compatibility and unexpected upgrade failures, though support is responsive.

What Are Recent G2 Reviews of Pentera?

Evolve Security

A plataforma Darwin Attack® da Evolve Security, com patente pendente, é uma ferramenta abrangente de colaboração e gestão projetada para ajudar as organizações a gerenciar seus serviços de cibersegurança e reduzir os riscos de ataques cibernéticos bem-sucedidos. A plataforma serve como um repositório para pesquisa, detalhes de vulnerabilidades e ataques, requisitos de conformidade, recomendações de remediação e controles de mitigação. Ela também funciona como um feed de segurança, ferramenta de colaboração, ferramenta de rastreamento, plataforma de gestão e plataforma de relatórios. A plataforma permite que as organizações gerenciem ativamente seu programa de segurança, fornecendo atualizações em tempo real sobre o progresso dos testes e descobertas, o que possibilita uma remediação oportuna. O Darwin Attack® é constantemente atualizado com novas informações e funcionalidades para garantir que continue eficaz e eficiente em atender às necessidades dos clientes da Evolve Security.

Average Rating: 4.8/5.0

Total Reviews: 53

How Do G2 Users Rate Evolve Security?

  • the product tem sido um bom parceiro comercial?: 9.8/10 (Category avg: 9.4/10)
  • Desempenho e Confiabilidade: 9.1/10 (Category avg: 9.2/10)
  • Varredura de vulnerabilidade: 9.4/10 (Category avg: 9.1/10)
  • Extensibilidade: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Evolve Security?

  • Vendedor: Evolve Security
  • Ano de Fundação: 2016
  • Localização da Sede: Chicago, Illinois
  • Twitter: @theevolvesec
    788 seguidores no Twitter
  • Página do LinkedIn®: www.linkedin.com
    65 funcionários no LinkedIn®

Who Uses This Product?

  • Top Industries: Serviços Financeiros
  • Company Size: 70% Medium, 21% Small

What Do G2 Reviewers Say About Evolve Security?

AI-generated summary from verified user reviews

Pros
  • Os usuários apreciam a inteligência acionável fornecida pela Evolve Security, aprimorando sua capacidade de lidar com vulnerabilidades de forma eficaz.
  • Os usuários valorizam a detecção eficaz de vulnerabilidades e a orientação fornecida pela equipe de especialistas da Evolve Security.
  • Os usuários elogiam a identificação eficaz de vulnerabilidades da Evolve Security, fornecendo instruções claras e comunicação durante todo o processo.
  • Os usuários valorizam o suporte completo de auditoria fornecido, garantindo comunicação clara e remediação eficaz das vulnerabilidades.
  • Os usuários elogiam a excelente comunicação da Evolve Security, facilitando o entendimento claro e a colaboração durante os testes de penetração.

What Are Recent G2 Reviews of Evolve Security?

Intigriti

A Intigriti é a líder confiável em segurança colaborativa, capacitando as maiores organizações do mundo a encontrar e corrigir vulnerabilidades antes que os cibercriminosos possam explorá-las. Desde 2016, a empresa tem ajudado seus clientes a reduzir riscos com a expertise de mais de 125.000 pesquisadores de segurança globais, permitindo a detecção de vulnerabilidades em tempo real e prevenindo violações custosas. A plataforma flexível da Intigriti oferece um conjunto completo de soluções, incluindo Bug Bounty, PTaaS, Sprints Focados e Eventos de Hacking ao Vivo, adaptados às suas necessidades digitais em evolução e entregues através de um modelo de pagamento por impacto, o que significa que você só paga por vulnerabilidades válidas submetidas. Nossas soluções abrangem: - Bug Bounty - Programas de Divulgação de Vulnerabilidades (VDP) - Sprints Focados - PTaaS - Eventos de Hacking ao Vivo - Serviços de Recompensa Com triagem líder na indústria, compromisso com a conformidade legal e um serviço ao cliente excepcional, a Intigriti é a escolha ideal para organizações como Coca-Cola, Microsoft e Intel para proteger seus ativos digitais e se manter à frente em um mundo em constante mudança.

Average Rating: 4.7/5.0

Total Reviews: 32

How Do G2 Users Rate Intigriti?

  • the product tem sido um bom parceiro comercial?: 9.5/10 (Category avg: 9.4/10)
  • Desempenho e Confiabilidade: 9.0/10 (Category avg: 9.2/10)
  • Varredura de vulnerabilidade: 6.7/10 (Category avg: 9.1/10)
  • Extensibilidade: 8.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Intigriti?

  • Vendedor: Intigriti
  • Ano de Fundação: 2016
  • Localização da Sede: Antwerpen, BE
  • Twitter: @intigriti
    209,768 seguidores no Twitter
  • Página do LinkedIn®: www.linkedin.com
    762 funcionários no LinkedIn®

Who Uses This Product?

  • Top Industries: Tecnologia da Informação e Serviços, Recursos Humanos
  • Company Size: 59% Medium, 34% Large

What Are Recent G2 Reviews of Intigriti?

Sprocket Security

Ao combinar automação com testes humanos conduzidos por especialistas, a Sprocket Security oferece Testes de Penetração Contínuos para ajudar as empresas a validar continuamente sua postura de segurança e resiliência. Esta solução inovadora é adaptada para organizações que buscam aprimorar suas medidas de cibersegurança, identificando proativamente vulnerabilidades e avaliando suas defesas contra ameaças potenciais. Ao empregar uma metodologia de teste durante todo o ano, a Sprocket Security garante que as empresas permaneçam vigilantes e preparadas no cenário em constante evolução das ameaças cibernéticas. A plataforma tem como alvo principal organizações de todos os tamanhos que estão comprometidas em melhorar suas estruturas de segurança. A Sprocket Security é particularmente benéfica para equipes de TI e segurança que precisam se antecipar a técnicas de ataque emergentes e se adaptar a mudanças em suas estruturas de TI. Com recursos como Gerenciamento de Superfície de Ataque, Testes de Penetração Contínuos e Simulação de Adversários, a Sprocket Security fornece um conjunto abrangente de ferramentas que capacitam as empresas a priorizar medidas de segurança ofensivas de forma eficaz. Um dos principais recursos da Sprocket Security é seu Gerenciamento de Superfície de Ataque, que permite que as organizações obtenham visibilidade sobre seus ativos digitais e vulnerabilidades potenciais. Ao monitorar e analisar continuamente a superfície de ataque, as empresas podem identificar pontos fracos antes que sejam explorados por atores mal-intencionados. Além disso, a plataforma oferece Testes de Penetração Contínuos, que simulam cenários de ataque do mundo real para avaliar a eficácia dos controles de segurança existentes. Esta abordagem de teste contínuo garante que as organizações possam adaptar suas defesas em resposta a novas ameaças e vulnerabilidades. Outro aspecto significativo da Sprocket Security é seu compromisso com a retestagem. Sempre que uma nova técnica de ataque surge, ocorre uma mudança na infraestrutura de TI ou uma descoberta é corrigida, a Sprocket Security oferece retestes ilimitados sem custo adicional. Este recurso não só melhora a postura geral de segurança de uma organização, mas também promove uma cultura de melhoria contínua e vigilância. Ao priorizar a segurança ofensiva, as empresas podem reduzir seu risco de TI e aumentar sua resiliência contra ameaças cibernéticas. No geral, a Sprocket Security se destaca no cenário de cibersegurança ao oferecer uma solução robusta e flexível que integra metodologias de teste automatizadas e conduzidas por humanos. Esta combinação única permite que as organizações mantenham uma postura proativa contra ameaças cibernéticas, garantindo que suas medidas de segurança evoluam em conjunto com a natureza dinâmica do cenário digital.

Average Rating: 4.8/5.0

Total Reviews: 15

How Do G2 Users Rate Sprocket Security?

  • the product tem sido um bom parceiro comercial?: 10.0/10 (Category avg: 9.4/10)
  • Desempenho e Confiabilidade: 9.3/10 (Category avg: 9.2/10)
  • Varredura de vulnerabilidade: 10.0/10 (Category avg: 9.1/10)
  • Extensibilidade: 8.6/10 (Category avg: 8.7/10)

Who Is the Company Behind Sprocket Security?

Who Uses This Product?

  • Company Size: 67% Medium, 13% Large

What Do G2 Reviewers Say About Sprocket Security?

AI-generated summary from verified user reviews

Pros
  • Os usuários valorizam o teste de penetração completo e do mundo real da Sprocket Security, melhorando sua postura geral de segurança.
  • Os usuários elogiam o atendimento ao cliente prestativo da Sprocket Security, tornando a resolução de problemas rápida e eficiente.
  • Os usuários acham a facilidade de uso da Sprocket Security benéfica, com uma interface limpa e suporte responsivo que melhoram a experiência.
  • Os usuários elogiam a Sprocket Security por sua expertise de primeira linha em cibersegurança, melhorando a eficácia geral da segurança e o suporte.
  • Os usuários destacam a eficiência de remediação da Sprocket Security, beneficiando-se de orientações claras e acionáveis para abordar rapidamente as vulnerabilidades.
Cons
  • Os usuários experimentam falsos positivos com a Sprocket Security, levando à fadiga de alarmes devido a alertas sobre atividades não maliciosas.
  • Os usuários acham a Sprocket Security cara, experimentando altas taxas de renovação e tempos de resposta lentos do suporte, causando frustração.
  • Os usuários destacam o escopo limitado de suporte da Sprocket Security, causando atrasos e problemas não resolvidos após o pentest.
  • Os usuários experimentam suporte ao cliente ruim, sofrendo com tempos de resposta lentos e comunicação ineficaz durante processos críticos de remediação.
  • Os usuários acham a integração deficiente do Sprocket Security problemática, levando a problemas como falsos positivos em ferramentas de alerta.

What Are Recent G2 Reviews of Sprocket Security?

SQLmap

Injeção SQL automática e ferramenta de tomada de controle de banco de dados

Average Rating: 4.3/5.0

Total Reviews: 37

How Do G2 Users Rate SQLmap?

  • the product tem sido um bom parceiro comercial?: 9.2/10 (Category avg: 9.4/10)
  • Desempenho e Confiabilidade: 8.0/10 (Category avg: 9.2/10)
  • Varredura de vulnerabilidade: 8.4/10 (Category avg: 9.1/10)
  • Extensibilidade: 7.8/10 (Category avg: 8.7/10)

Who Is the Company Behind SQLmap?

  • Vendedor: SQLmap
  • Ano de Fundação: 2008
  • Localização da Sede: San Francisco, CA
  • Twitter: @github
    2,673,925 seguidores no Twitter
  • Página do LinkedIn®: www.linkedin.com
    1 funcionários no LinkedIn®

Who Uses This Product?

  • Top Industries: Software de Computador, Segurança de Redes e Computadores
  • Company Size: 53% Small, 42% Medium

What Are Recent G2 Reviews of SQLmap?

What Are G2 Users Discussing About SQLmap?

Indusface WAS

Indusface WAS (Web Application Scanner) fornece uma solução abrangente de teste de segurança de aplicações dinâmicas gerenciada (DAST). É uma solução baseada em nuvem, sem toque e não intrusiva, que oferece monitoramento diário para aplicações web, verificando vulnerabilidades de sistemas e aplicações, e malware. Indusface WAS, com suas varreduras automatizadas e testes manuais realizados por especialistas em segurança certificados, garante que nenhuma das vulnerabilidades do OWASP Top10, lógica de negócios e malware passe despercebida. Com garantia de zero falso-positivo e relatórios abrangentes com orientação para remediação, a varredura de aplicativos web da Indusface garante que os desenvolvedores corrijam rapidamente as vulnerabilidades de forma contínua.

Average Rating: 4.6/5.0

Total Reviews: 64

How Do G2 Users Rate Indusface WAS?

  • the product tem sido um bom parceiro comercial?: 9.4/10 (Category avg: 9.4/10)
  • Desempenho e Confiabilidade: 9.2/10 (Category avg: 9.2/10)
  • Varredura de vulnerabilidade: 9.3/10 (Category avg: 9.1/10)
  • Extensibilidade: 8.7/10 (Category avg: 8.7/10)

Who Is the Company Behind Indusface WAS?

  • Vendedor: Indusface
  • Ano de Fundação: 2012
  • Localização da Sede: Vadodara
  • Twitter: @Indusface
    3,472 seguidores no Twitter
  • Página do LinkedIn®: www.linkedin.com
    180 funcionários no LinkedIn®

Who Uses This Product?

  • Top Industries: Software de Computador, Tecnologia da Informação e Serviços
  • Company Size: 53% Small, 37% Medium

What Do G2 Reviewers Say About Indusface WAS?

AI-generated summary from verified user reviews

Pros
  • Os usuários valorizam a detecção eficaz de vulnerabilidades do Indusface WAS, garantindo rápida priorização e suporte confiável de remediação.
  • Os usuários valorizam a detecção de vulnerabilidades consistente e confiável do Indusface WAS, garantindo implantações seguras com facilidade.
  • Os usuários elogiam o excelente suporte ao cliente do Indusface WAS, garantindo respostas rápidas e resolução eficaz de problemas.
  • Os usuários valorizam a eficiência de varredura do Indusface WAS para relatórios detalhados de vulnerabilidades e atualizações oportunas após implantações.
  • Os usuários valorizam as varreduras de segurança minuciosas do Indusface WAS, aprimorando seus processos de identificação de vulnerabilidades e acreditação.
Cons
  • Os usuários sentem que o preço do Indusface WAS é caro, especialmente em relação às verificações de ambiente de teste e desenvolvimento.
  • Os usuários acham a interface confusa do Indusface WAS um tanto desatualizada e precisando de melhorias para melhor usabilidade.
  • Os usuários acham que a falta de recursos para ambientes de teste e desenvolvimento limita seus testes no Indusface WAS.
  • Os usuários acham que o escopo limitado de preços para ambientes de teste restringe a funcionalidade e aumenta os desafios de teste.
  • Os usuários acham o design da interface desatualizado e não intuitivo, frequentemente desejando uma experiência mais amigável.

What Are Recent G2 Reviews of Indusface WAS?

What Are G2 Users Discussing About Indusface WAS?