Best Runtime Application Self-Protection (RASP) Tools

How Many Runtime Application Self-Protection (RASP) Tools Products Does G2 Track?

Total Products under this Category: 32

Category Stats (Sep 2026)

  • Average Rating: 4.57/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Zimperium Mobile Application Protection Suite (MAPS) (+0.46%) - Among all products in this category, Zimperium Mobile Application Protection Suite (MAPS) recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Runtime Application Self-Protection (RASP) Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,800+ Authentic Reviews
  • 32+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Runtime Application Self-Protection (RASP) Tools

G2 Grid® for Runtime Application Self-Protection (RASP) Tools  plotting products by satisfaction and market presence

Highlighted products: Appdome, Zimperium Mobile Application Protection Suite (MAPS), Dynatrace, APP SHIELDING, Contrast Security, Jscrambler, DexGuard, and PreEmptive.

Underlying data: [Grid® JSON](https://www.g2.com/categories/runtime-application-self-protection-rasp-tools/grids.json?focus%5B%5D=appdome&focus%5B%5D=zimperium-mobile-application-protection-suite-maps&focus%5B%5D=dynatrace&focus%5B%5D=app-shielding&focus%5B%5D=contrast-security-contrast-security&focus%5B%5D=jscrambler&focus%5B%5D=dexguard&focus%5B%5D=preemptive)

Appdome

Appdome is an agentic platform that protects mobile apps and the mobile business at scale. Trusted by enterprises worldwide, Appdome automates mobile app security, fraud prevention, bot defense, and threat detection and response across Android and iOS applications. Unlike legacy SDK-based approaches that require manual implementation and ongoing maintenance, Appdome uses AI agents to embed protections directly into mobile apps, analyze threats in real time, and continuously adapt defenses without code or complex integration. Organizations use Appdome to protect mobile apps, APIs, identities, accounts, transactions, and users from fraud, bots, malware, account takeover, deepfakes, and other cyber threats. Appdome’s agentic mobile defense platform includes: Identity and reputation protection Fraud and account takeover (ATO) prevention Bot and API defense Mobile app security (RASP and app shielding) DevSecOps and CI/CD integration Threat management and response (including ThreatScope™ Mobile XDR, ThreatEvents™, and Threat Resolution Center™)

Average Rating: 4.8/5.0

Total Reviews: 93

Who Is the Company Behind Appdome?

  • Seller: Appdome
  • Company Website:
  • Year Founded: 2012
  • HQ Location: Redwood City, California, United States
  • Twitter: @appdome
    2,107 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    184 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Banking
  • Company Size: 49% Large, 35% Medium

What Do G2 Reviewers Say About Appdome?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent customer support from Appdome, highlighting their responsiveness and helpfulness throughout the process.
  • Users value the extensive security features of Appdome, enhancing mobile app protection effectively and efficiently.
  • Users value the ease of use with Appdome, praising its intuitive GUI for securing mobile applications effortlessly.
  • Users value the runtime application protection of Appdome, appreciating its ease and comprehensive security without coding.
  • Users appreciate the ease of implementation with Appdome, enabling fast and efficient integration without coding.
Cons
  • Users note that the licensing costs can be prohibitive, making it challenging for smaller companies to afford Appdome.
  • Users find the complexity of features in Appdome overwhelming, requiring time to understand proper integration and configuration.
  • Users find the initial learning curve challenging due to the extensive features, requiring time to understand configurations.
  • Users face a challenging learning difficulty due to the complexity of configurations and initial integration guidance required.
  • Users often struggle with poor documentation, leading to confusion during integration and configuration of Appdome.

What Are Recent G2 Reviews of Appdome?

Zimperium Mobile Application Protection Suite (MAPS)

Zimperium Mobile Application Protection Suite (MAPS)📱-- is a unified mobile app security platform built to protect iOS and Android apps across the entire lifecycle—from build and testing to deployment, runtime, and response. Zimperium MAPS provides on-device mobile threat detection, runtime application self-protection (RASP), application hardening, and cryptographic key protection—all integrated into a lightweight SDK that easily fits into modern DevSecOps workflows. Unlike cloud-reliant or wrapper-based tools, Zimperium MAPS delivers real-time, zero-delay protection against mobile app threats such as reverse engineering, code tampering, emulators, jailbroken/rooted environments, and malicious runtime behaviors. Zimperium MAPS Includes Four Integrated Modules: 📲 zScan – Mobile Application Security Testing (MAST): Scan iOS or Android app binaries pre-release to identify compliance, privacy, and security risks that could be exploited in production. zScan enables secure release cycles for highly regulated industries. 📲 zShield – Application Shielding for iOS and Android Apps: Protect source code, app binaries and intellectual property with advanced obfuscation, anti-tampering, and encryption—blocking reverse engineering and code modification. 📲 zDefend – Advanced Runtime Protection (RASP): Detects and responds to mobile threats in real time, on-device. zDefend protects apps from device compromise, dynamic instrumentation, emulators, and 0-day attacks—even without internet connectivity. 📲 zKeyBox – Cryptographic Key Protection: Secure encryption keys and sensitive logic within the app using white-box cryptography. zKeyBox prevents attackers from extracting secrets—even on rooted or jailbroken devices. Why Choose Zimperium MAPS for Mobile App Protection? 📱 + Unified Mobile Application Security Platform - Protect iOS and Android apps across the full lifecycle on one AI-Empowered platform. Optimize protection, accelerate releases, and respond to mobile threats faster. + End-to-end Security Visibility - Find build-time vulnerabilities, compliance violations, and real-world runtime threats in one view. + On-device Runtime Protection (RASP). Detect and block zero-day mobile threats, jailbreak and root attempts, and repackaging attacks in real time on the device. Works offline with no backend connectivity required. + Over-The-Air Security Updates - Push new mobile app protections to production without an app store release. Respond to emerging mobile threats in hours, not sprints. + Low-code and No-code app Protection - Apply code obfuscation, anti-tampering, and key protection with minimal engineering lift. Keep release velocity intact while hardening iOS and Android apps. + Flexible Deployment - Run MAPS on-prem or as SaaS to meet data residency, privacy, and regulatory compliance requirements. + AI Mobile App Response Agent - Enables SOC and Fraud analysts to trigger on-demand investigations on any device, and within minutes the agent determines whether an incident or fraud has occurred.

Average Rating: 4.3/5.0

Total Reviews: 35

Who Is the Company Behind Zimperium Mobile Application Protection Suite (MAPS)?

  • Seller: Zimperium
  • Company Website:
  • Year Founded: 2010
  • HQ Location: Dallas, TX
  • Twitter: @ZIMPERIUM
    10,785 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    290 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 42% Medium, 28% Large

What Are Recent G2 Reviews of Zimperium Mobile Application Protection Suite (MAPS)?

What Are G2 Users Discussing About Zimperium Mobile Application Protection Suite (MAPS)?

Dynatrace

Dynatrace is advancing observability for today’s digital businesses, helping to transform the complexity of modern digital ecosystems into powerful business assets. By leveraging AI-powered insights, Dynatrace enables organizations to analyze, automate, and innovate faster to drive their business forward. Learn more at www.dynatrace.com.

Average Rating: 4.5/5.0

Total Reviews: 1,233

Who Is the Company Behind Dynatrace?

  • Seller: Dynatrace
  • Year Founded: 2005
  • HQ Location: Boston, MA
  • Twitter: @Dynatrace
    18,668 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,181 employees on LinkedIn®
  • Ownership: NYSE: DT

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 69% Large, 23% Medium

What Do G2 Reviewers Say About Dynatrace?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Dynatrace, enjoying seamless application instrumentation and comprehensive support.
  • Users value the insightful dashboarding of Dynatrace, enhancing executive views and simplifying monitoring processes.
  • Users value the comprehensive monitoring capabilities of Dynatrace, enhancing problem identification and prevention effectively.
  • Users value the effective debugging capabilities of Dynatrace, enhancing their ability to identify and resolve issues promptly.
  • Users value the robust analytics and integration features of Dynatrace, enhancing their monitoring and debugging capabilities.
Cons
  • Users find the steep learning curve of Dynatrace challenging, making it hard to fully utilize its features.
  • Users find that missing features in Dynatrace hinder detailed analysis and communication regarding updates and fixes.
  • Users find Dynatrace's complexity overwhelming, with a steep learning curve and costly pricing affecting usability.
  • Users find the learning difficulty challenging due to overwhelming information and inconsistencies in functionality.
  • Users find the costly nature of Dynatrace challenging, making it more suitable for large enterprises only.

What Are Recent G2 Reviews of Dynatrace?

What Are G2 Users Discussing About Dynatrace?

APP SHIELDING

Build trust and drive growth by strengthening your mobile appsÔøΩ resistance to intrusion, tampering and reverse-engineering

Average Rating: 4.3/5.0

Total Reviews: 14

Who Is the Company Behind APP SHIELDING?

  • Seller: OneSpan
  • Year Founded: 1991
  • HQ Location: Boston, MA
  • Twitter: @OneSpan
    3,374 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    669 employees on LinkedIn®
  • Ownership: OSPN

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 43% Small, 36% Medium

What Are Recent G2 Reviews of APP SHIELDING?

Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

Average Rating: 4.5/5.0

Total Reviews: 49

Who Is the Company Behind Contrast Security?

  • Seller: Contrast Security
  • Year Founded: 2014
  • HQ Location: Pleasanton, CA
  • Twitter: @contrastsec
    5,468 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Insurance, Information Technology and Services
  • Company Size: 67% Large, 20% Medium

What Do G2 Reviewers Say About Contrast Security?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Contrast Security, ensuring greater precision in identifying vulnerabilities.
  • Users value the accuracy of results from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
  • Users commend the real-time vulnerability detection of Contrast Security, appreciating its quick feedback and agile support.
Cons
  • Users experienced performance issues with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

What Are Recent G2 Reviews of Contrast Security?

What Are G2 Users Discussing About Contrast Security?

Jscrambler

Jscrambler is the leader in Client-Side Security for the modern, composable web. As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces. Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled according to enterprise policy at the point of creation — before they leave the client environment. Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.

Average Rating: 4.4/5.0

Total Reviews: 31

Who Is the Company Behind Jscrambler?

  • Seller: Jscrambler
  • Company Website:
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @Jscrambler
    1,161 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    88 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 35% Medium, 29% Small

What Do G2 Reviewers Say About Jscrambler?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Jscrambler, highlighting its intuitive navigation and user-friendly interface.
  • Users find Jscrambler's automation capabilities beneficial for seamless integration and enhanced security within development workflows.
  • Users commend the rapid and helpful customer support of Jscrambler, enhancing their overall experience significantly.
  • Users value the robust security features of Jscrambler, effectively safeguarding their intellectual property during deployment.
  • Users value the comprehensive overview of Jscrambler, enhancing security and performance while enabling features gradually.
Cons
  • Users experience slow performance with Jscrambler, requiring tuning and noting insufficient documentation for improvement.
  • Users suggest that the dashboard can be improved to display more detailed information from each installation.
  • Users experience a difficult initiation due to a complex setup process requiring substantial understanding of application deployment.
  • Users face challenges with obfuscated pages not working and project file limits in large applications.
  • Users struggle with limited guidance and often face issues when exporting reports, hindering their experience.

What Are Recent G2 Reviews of Jscrambler?

What Are G2 Users Discussing About Jscrambler?

PreEmptive

PreEmptive secures apps against IP theft, hacking, and tampering with multi-layered protection for .NET, Java, and JavaScript. PreEmptive expertly balances cost, convenience, & functionality to secure your applications, making them more resistant to data & IP theft, hacking, & tampering. Our quick-to-implement, premium solutions provide multilayered in-app protection: Dotfuscator for .NET & Xamarin DashO for Java & Android JSDefender for JavaScript Our multi-layered approach to binary code protection employs obfuscation, encryption, root detection, shielding, & tamper-proofing to defend against exploitation by both humans and machines. PreEmptive offers passive & active defense capabilities, safeguarding trade secrets & intellectual property (IP), reducing piracy & counterfeiting, & preventing tampering of code & sensitive data inspection. Easily integrating into .NET, MAUI, Java, & Android applications, PreEmptive helps you manage application risks and ensure regulatory compliance. PreEmptive delivers premium application shielding, seamlessly integrating into your development workflow to secure software, protect your organization, and safeguard your customers. Choose PreEmptive for comprehensive, intelligent app security

Average Rating: 4.6/5.0

Total Reviews: 49

Who Is the Company Behind PreEmptive?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 44% Small, 40% Medium

What Are Recent G2 Reviews of PreEmptive?

What Are G2 Users Discussing About PreEmptive?

DexGuard

Full spectrum protection for Android apps. With extensive Android app obfuscation & security protocols, DexGuard provides the most comprehensive mobile app protection available. Secure your Android apps & SDKs through multiple layers of code hardening & RASP. The DexGuard NDK add-on extends all the protection offered by DexGuard — including multi-layered Android app code obfuscation., data obfuscation and RASP integration — to included C/C++ native libraries. DexGuard generates a Protection Report for each mobile app build that incorporates its protections. This report validates and assesses the applied protections, grading your app’s security configuration against key risk categories, providing further recommendations to improve security efficacy and surfacing potentially beneficial features to activate. When upgrading from ProGuard (or R8) to DexGuard, you can re-use your existing ProGuard configuration file. All you need to do is account for DexGuard’s additional functionality, including its RASP and obfuscation capabilities.

Average Rating: 4.2/5.0

Total Reviews: 21

Who Is the Company Behind DexGuard?

  • Seller: GuardSquare NV
  • Year Founded: 2014
  • HQ Location: Leuven, Belgium
  • Twitter: @GuardSquare
    4,049 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    183 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Small, 33% Medium

What Are Recent G2 Reviews of DexGuard?

What Are G2 Users Discussing About DexGuard?

OpenText Core Application Security

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

Average Rating: 4.1/5.0

Total Reviews: 34

Who Is the Company Behind OpenText Core Application Security?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Large, 32% Small

What Are Recent G2 Reviews of OpenText Core Application Security?

What Are G2 Users Discussing About OpenText Core Application Security?

DoveRunner

DoveRunner, formerly known as AppSealing, is a comprehensive mobile app and content security platform designed to help businesses protect both their mobile applications and premium video content against evolving digital threats. The platform combines advanced mobile app shielding technologies with enterprise-grade video content protection solutions, enabling organizations to secure their digital ecosystem through a unified security approach. DoveRunner offers robust Runtime Application Self-Protection (RASP) capabilities for mobile apps helping businesses safeguard their intellectual property without requiring extensive coding or complex integrations. One of the standout strengths of DoveRunner is its ability to protect applications from tampering, reverse engineering, repackaging, and unauthorized modifications while simultaneously securing premium video content from piracy and illegal distribution. Through advanced security protocols, the platform actively detects and neutralizes threats targeting mobile applications and streaming environments, ensuring the integrity of both the app experience and the content delivery pipeline. DoveRunner’s user-friendly implementation process allows businesses to integrate powerful security capabilities into their existing applications and content workflows with minimal operational complexity. Its no-code and low-code deployment capabilities enable organizations to secure mobile apps and video services quickly, without lengthy development cycles or heavy infrastructure requirements. This combination of ease of use, scalability, and enterprise-grade protection makes DoveRunner an ideal choice for businesses seeking to strengthen both their mobile app security and premium content protection strategies. In summary, DoveRunner provides a unified security platform that addresses the critical challenges faced by modern app-driven and content-centric businesses. By delivering advanced mobile app shielding alongside robust video content protection and anti-piracy solutions, DoveRunner helps organizations defend their applications, protect premium content, preserve revenue streams, and create a safer digital experience for users worldwide.

Average Rating: 4.7/5.0

Total Reviews: 48

Who Is the Company Behind DoveRunner?

  • Seller: DoveRunner
  • Company Website:
  • Year Founded: 2000
  • HQ Location: San Jose, US
  • Twitter: @doverunner_inc
    12 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Small, 42% Medium

What Do G2 Reviewers Say About DoveRunner?

AI-generated summary from verified user reviews

Pros
  • Users value the intuitive interface and real-time performance tracking of DoveRunner for efficient data management.
  • Users appreciate the intuitive interface of DoveRunner, finding it efficient for analyzing and managing data seamlessly.
  • Users love the clean, intuitive interface of DoveRunner, enhancing their efficiency in data management and analysis.
Cons
  • Users find that some advanced features have a steep learning curve and lack clear in-app guidance for newbies.

What Are Recent G2 Reviews of DoveRunner?

What Are G2 Users Discussing About DoveRunner?

Waratek

Waratek is the only Security-as-Code automation platform, enabling control through policy to scale security with modern development. The world’s largest companies trust Waratek products to deliver application security at scale. Work with us to accelerate your transition from manual processes to self-service automation and DevSecOps excellence.

Average Rating: 4.7/5.0

Total Reviews: 11

Who Is the Company Behind Waratek?

  • Seller: Waratek
  • Year Founded: 2009
  • HQ Location: Dublin, County Dublin
  • Twitter: @waratek
    749 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 64% Large, 27% Medium

What Do G2 Reviewers Say About Waratek?

AI-generated summary from verified user reviews

Pros
  • Users find the configuration ease of Waratek ideal for quickly securing applications without disruptive changes.
  • Users appreciate the effective application security of Waratek, which seamlessly protects unsecure programs and supports compliance.
  • Users find Waratek exceptionally easy to use, appreciating its user-friendly design and efficient configuration options.
  • Users appreciate Waratek for its user-friendly application security, effectively protecting unsecure programs without extensive changes.
  • Users value the application security provided by Waratek, finding it user-friendly and effective for their needs.

What Are Recent G2 Reviews of Waratek?

LIAPP

LIAPP is a specialized mobile application shielding and runtime application self-protection (RASP) solution designed to secure Android and iOS environments from unauthorized access and cyber threats. This security tool allows developers and enterprises to protect their mobile applications by applying robust security layers to the final application binary, ensuring protection against tampering and reverse engineering without requiring changes to the existing source code. The primary function of LIAPP is to maintain the integrity of mobile applications in high-stakes industries, including mobile banking, fintech, and global gaming. By implementing LIAPP, organizations can defend against various attack vectors such as rooting, jailbreaking, debugging, and memory manipulation. This solution is particularly effective for businesses that need to align their mobile services with international security standards and regional financial regulations. In addition to its core shielding capabilities, LOCKIN Company offers supplementary security modules that can be implemented alongside or independently of LIAPP to address specific vulnerabilities: LISS (Screen Protection): A dedicated solution designed to block unauthorized screen captures, screen recording, and remote access attempts to protect visual data integrity. LIKEY (Security Keypad): A specialized virtual keypad that encrypts and secures sensitive user input to prevent data interception from keyloggers and other malicious methods. LIAPP’s deployment model is optimized for rapid integration into the development lifecycle, minimizing the technical burden on engineering teams. This allows organizations to maintain their scheduled release cycles while providing a secure environment for their end-users. The solution provides several key technical advantages: Comprehensive App Shielding: Prevents unauthorized modification and repackaging of the application to ensure the software functions as originally intended. Dynamic Runtime Protection: Actively detects and blocks security threats during the application's execution to prevent data breaches in real-time. Modular Security Expansion: Enables users to enhance their security posture by adding LISS for screen protection or LIKEY for secure data entry based on specific operational needs. Regulatory Compliance Support: Provides the necessary technical infrastructure to assist financial institutions in meeting stringent mobile transaction security and fraud prevention requirements. Through its specialized focus on application integrity, LIAPP assists users in managing the security lifecycle of their mobile products. It offers monitoring capabilities and threat intelligence, allowing stakeholders to identify emerging risks and maintain a resilient mobile presence.

Average Rating: 4.8/5.0

Total Reviews: 20

Who Is the Company Behind LIAPP?

Who Uses This Product?

  • Top Industries: Computer Games
  • Company Size: 60% Medium, 35% Small

What Are Recent G2 Reviews of LIAPP?

What Are G2 Users Discussing About LIAPP?

DexProtector

Mobile applications are increasingly targeted by attackers looking to reverse engineer code, bypass security controls, and manipulate app behavior at runtime. DexProtector is an EMVCo-evaluated and approved mobile application protection tool that helps organizations protect their mobile apps in the wild. It secures application logic, prevents tampering, and detects compromised environments without requiring code changes or complex integrations. Used by organizations in more than 75 countries and protecting applications on over 500 million devices, DexProtector is trusted by teams building secure mobile banking, payment, and other high-risk applications. Protect apps without changing your code: DexProtector integrates directly into your build process as a CLI, Gradle, or CI/CD task. Protections are automatically applied to Android and iOS apps and SDKs (APKs, AABs, AARs, IPAs, frameworks), with no SDKs, no refactoring, and no disruption to development workflows. Prevent reverse engineering, tampering, and runtime attacks: DexProtector combines multiple layers of protection to secure both application code and runtime behavior. • Protects code with advanced obfuscation and encryption • Detects compromised environments (rooted, jailbroken, and emulated devices) • Prevents debugging, dynamic instrumentation, and runtime manipulation • Enforces application integrity and anti-tampering controls Built for regulated and high-risk environments: DexProtector has been evaluated and approved under EMVCo SBMP (Software-Based Mobile Payments) as a Software Protection Tool (SPT), helping to streamline certification for applications and SDKs, and supporting compliance in highly-regulated industries. Extend protection with real-time threat intelligence: DexProtector can be integrated with Licel's Alice Threat and Device Intelligence solution to provide real-time insight into device risk, threat signals, and suspicious behavior. This enables teams to detect and respond to threats beyond the application layer. Key capabilities: • String, class, and native library encryption • Cross-platform code protection (React Native, Flutter, Xamarin, etc.) • Root, jailbreak, and emulator detection • Debugging and dynamic instrumentation detection • Public key certificate validation • White-box cryptography • Anti-malware mechanisms • Mobile API Protection • Anti-tampering and integrity enforcement

Average Rating: 4.9/5.0

Total Reviews: 10

Who Is the Company Behind DexProtector?

  • Seller: Licel
  • Year Founded: 2011
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Medium, 27% Small

What Are Recent G2 Reviews of DexProtector?

What Are G2 Users Discussing About DexProtector?

Approov

Approov provides a robust mobile app and API security solution designed to prevent unauthorized access, fraud, and API abuse. By ensuring that only genuine, untampered mobile applications can communicate with backend services, Approov protects businesses across industries such as finance, healthcare, eCommerce, and connected vehicles. The solution combines app attestation and runtime application self-protection (RASP) to detect and block threats from scripts, bots, and modified apps in real time. Approov also secures API keys, secrets, and certificates at runtime, preventing leakage and unauthorized use. Unlike traditional security measures that rely on static defenses, Approov dynamically adapts to evolving threats, providing scalable, developer-friendly protection without generating false positives.

Average Rating: 4.8/5.0

Total Reviews: 5

Who Is the Company Behind Approov?

  • Seller: Approov Limited
  • Year Founded: 2001
  • HQ Location: Edinburgh, GB
  • Twitter: @approov_io
    1,200 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Approov?

Imperva Runtime Application Self-Protection (RASP)

As cyber threats evolve, organizations need more than just perimeter defenses to protect their applications. Imperva Runtime Application Self-Protection (RASP) takes application security to the next level by embedding protection directly into the application itself. Unlike traditional security solutions, RASP continuously monitors and protects applications from within, identifying and blocking attacks in real time without affecting performance or requiring changes to application code. Imperva RASP provides comprehensive protection against a wide range of threats, including SQL injections, cross-site scripting, and other OWASP Top 10 vulnerabilities. By analyzing application behavior and understanding the context of each request, RASP can accurately differentiate between legitimate activity and attacks, reducing false positives and allowing legitimate traffic to flow uninterrupted. This capability ensures that applications remain secure without slowing down operations or impacting user experience. One of RASP's key benefits is its ability to protect new and legacy applications, as well as third-party components, without the need for expensive and time-consuming code modifications. This makes it an ideal solution for organizations looking to enhance their security posture without disrupting their development pipeline. Additionally, RASP seamlessly integrates into DevOps workflows, ensuring continuous protection even in fast-paced development environments. Imperva RASP is backed by continuously updated threat intelligence, allowing it to defend against zero-day attacks and emerging threats as they surface. With RASP, organizations can reduce their reliance on perimeter defenses, which may not be enough to protect against sophisticated, targeted attacks. Instead, RASP provides real-time, in-application security that stops attacks at the source, ensuring your applications remain safe and your business can continue to operate without disruption. By providing proactive, real-time defense with minimal operational impact, Imperva RASP offers a powerful solution to protect critical applications in today’s dynamic threat landscape.

Average Rating: 5.0/5.0

Total Reviews: 2

Who Is the Company Behind Imperva Runtime Application Self-Protection (RASP)?

  • Seller: Thales Group
  • HQ Location: Austin, Texas
  • Twitter: @ThalesCloudSec
    6,935 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    46 employees on LinkedIn®
  • Ownership: EPA:HO
  • Total Revenue (USD mm): $15,854

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Imperva Runtime Application Self-Protection (RASP)?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated January 8, 2025

Learn More About Runtime Application Self-Protection (RASP) Tools

Traditional security measures struggle to keep up with evolving threats in a fast-paced digital landscape. That's where Runtime Application Self-Protection (RASP) steps in. RASP empowers applications to defend themselves in real time. Explore how RASP software adapts to the ever-changing threat landscape, making it a crucial tool for safeguarding applications.

What are runtime application self-protection (RASP) tools?

Runtime application self-protection software is a security technology designed to protect applications from cyber threats in real time. It operates by integrating directly into the application’s runtime environment, allowing it to monitor and respond to potential threats based on the application's internal state and behavior.

By doing so, RASP tools safeguard against data breaches, malware, and other threats, offering a proactive approach that strengthens application security. 

RASP solutions analyze incoming requests and application usage to detect suspicious activity, like SQL injection attempts. When a potential threat is identified, RASP tools can take immediate action—like blocking malicious requests or restricting access—to prevent bot attacks and other vulnerabilities. 

Advanced RASP tools can even predict potential threats, providing early warnings that further enhance security.

How does RASP work?

RASP integrates into the application's runtime environment to monitor application behavior and fix issues when a security event occurs. 

Unlike traditional security measures that rely on external defenses (like firewalls), RASP utilizes the context of the application’s operations to make informed decisions about potential threats within the application environment. 

It continuously monitors data flow, execution pathways, and system calls and uses a combination of predefined security policies and dynamic analysis to establish a baseline of normal application behavior. This capability allows it to effectively differentiate between legitimate requests and malicious actions.

When deviations from this baseline occur, RASP triggers alerts or takes protective actions. These anomalies can be unauthorized access attempts or unusual system calls that might indicate cross-site scripting (XSS) attacks, SQL injection attacks, or other malicious activity. 

While stopping potential threats, RASP doesn't modify the application’s code but controls the app's behavior, allowing it to stop threats quickly before they cause significant damage. This real-time control makes RASP a proactive solution for safeguarding applications against evolving cyber threats.

In essence, RASP provides a comprehensive shield for applications, is constantly vigilant against evolving threats, and offers real-time protection without disrupting the development workflow. 

Features of RASP 

RASP software offers several key features to enhance application security and protect against various threats:

  • Control runtime execution: RASP enforces security policies within the application, analyzing requests, performing checks, and controlling access in real time to prevent breaches.
  • Monitor performance: RASP monitors application performance during runtime, tracking metrics to identify abnormal activities that might indicate security threats. 
  • Detect intrusions: RASP analyzes application behavior to detect intrusions and suspicious patterns, including common attacks like SQL injection and unauthorized access attempts. This real-time detection helps mitigate security risks.
  • Automated actions: Upon detecting suspicious activity, RASP automatically takes predefined actions, such as terminating user sessions, blocking malicious requests, or alerting security personnel. This automation helps in mitigating threats without requiring manual intervention.
  • Flexible deployment options: RASP can be deployed in different modes, such as monitor mode (where it reports on attacks without blocking them) and protection mode (where it actively blocks malicious activities). This flexibility allows organizations to tailor their security approach based on their needs.
  • API security: RASP software can secure communication between different parts of an application or between the application and external services through Application programming interfaces (APIs). It can detect unauthorized access attempts, data manipulation, and other API-specific threats.
  • Protect mobile applications: RASP technology can be implemented for mobile applications to safeguard against attacks that target mobile devices, such as jailbreaking, rooting, and reverse engineering. It can also protect against data breaches and unauthorized access on mobile platforms.
  • Integration with application code: RASP is designed to be embedded within the application’s runtime environment. This is achieved through agent-based or library integrations, allowing security features to be implemented without extensive code rewrites. With this integration, RASP provides tailored security measures specific to each application’s needs without significant changes to the application code. 

Benefits of RASP 

The benefits of RASP software are numerous and impactful:

  • Visibility into application-layer attacks: With deep insight into the application layer, RASP tools can uncover a wide range of potential attacks and vulnerabilities that traditional methods might miss.
  • Zero-day protection: RASP goes beyond signature-based detection. By analyzing anomalous behaviors, it can identify and block even zero-day attacks.
  • Lower false positives: By understanding an application's internals, RASP can accurately differentiate true threats from false alarms, freeing security teams to focus on genuine issues.
  • Enhanced user experience: By minimizing false positives and responding swiftly to threats, RASP ensures smooth application performance with minimal interruptions to end users.
  • Lower CapEx and OpEx: RASP's ease of deployment and effectiveness in protecting applications lead to lower upfront costs and ongoing maintenance compared to manual patching and traditional security measures like WAFs.
  • Easy maintenance: RASP operates based on application insight rather than traffic rules or blacklists, making it more reliable and resource-efficient for security teams.
  • Flexible deployment: RASP solutions can adapt to various application architectures and standards, making them suitable for protecting a wide range of applications beyond just web applications.
  • Cloud support: RASP software seamlessly integrates with cloud environments, allowing deployment wherever the protected on-premises or cloud-native applications run.
  • DevSecOps support: RASP integrates into DevOps CI/CD pipelines, facilitating easy deployment and supporting DevSecOps practices by incorporating security throughout the development lifecycle.

What is the difference between WAF and RASP? 

While both RASP and WAF are crucial for application security, they take distinct approaches.

  • A WAF sits at the perimeter of a network, acting as a gatekeeper to block or allow traffic based on predefined rules. In contrast, RASP is embedded within the application itself, providing internal protection by monitoring runtime behavior and taking immediate action on threats.
  • WAFs focus on detecting and filtering known attack patterns like SQL injection or cross-site scripting using static rules. RASP, however, uses dynamic analysis to understand the application’s behavior, making it more effective against zero-day attacks and insider threats.
  • While WAFs operate independently of the application’s code, RASP integrates with the application’s runtime environment, allowing it to control internal processes without extensive code changes. 
  • WAFs primarily block external threats, while RASP mitigates both internal and external threats in real time.

Choosing the right tool: The optimal choice hinges on specific needs. RASP excels for complex applications with unique security requirements or where protection against zero-day attacks is paramount. WAF is well-suited for broader web-facing applications with simpler architectures, offering a strong first line of defense.

For the most comprehensive application security, consider a layered approach that incorporates both RASP and WAF.

Who uses RASP solutions?

Organizations of all sizes across various industries can benefit from implementing RASP as an additional layer of defense for their applications. This includes:

  • Large enterprises: RASP strengthens security for complex applications, especially those handling sensitive data.
  • Small businesses: RASP offers easy-to-use protection against common threats for web and mobile apps, even without a big security team.
  • Software companies: Build-in security with RASP makes software more attractive to customers.
  • Financial institutions: RASP helps protect online banking, payments, and other financial apps from cyberattacks.
  • Healthcare organizations: Healthcare organizations benefit from RASP for safeguarding patient data in electronic health record (EHR) systems, telemedicine platforms, and other healthcare applications.
  • Government agencies: RASP helps secure web portals, citizen apps, and internal systems from cyber threats and breaches.
  • Tech companies: RASP is used as part of the cybersecurity to boost the cloud or SaaS platform's security.

RASP security solutions pricing

The cost of RASP solutions can vary depending on factors like the organization's size, deployment preferences, and required security features. Vendors often offer flexible pricing options, including annual subscriptions or multi-year contracts, to suit different needs.

Typically, RASP is available through perpetual licensing, allowing organizations to make a one-time purchase for full ownership. This enables easy on-site deployment and customization by in-house InfoSec teams. Additional charges may apply for ongoing maintenance and support services.

Challenges with RASP tools

RASP solutions, while effective in enhancing application security, face several challenges that organizations need to address:

  • False positives and negatives: RASP tools can struggle with false positives (flagging harmless actions as threats) and false negatives (missing real threats). Fine-tuning configurations and leveraging threat intelligence tools are crucial to achieving optimal accuracy.
  • Performance overhead: RASP monitoring adds processing overhead, potentially slowing down applications. Careful configuration and optimization are necessary to minimize performance degradation.
  • Limited support for legacy systems: RASP solutions might not fully support older systems due to compatibility or instrumentation limitations. Organizations with legacy applications may need alternative security solutions or consider modernization efforts.
  • Evolving threat landscape: The cyber threat landscape is ever-changing. RASP needs consistent updates with the latest threat intelligence to combat evolving attack methods effectively.
  • Compliance issues: Regulations in certain industries might impose specific security controls or reporting requirements. Organizations need to ensure their RASP system implementation aligns with relevant compliance standards.

Which companies should buy RASP tools?

Companies that should consider investing in Runtime Application Self-Protection (RASP) software typically fall into industries where application security is critical to operations, compliance, or customer trust. This includes organizations that: 

  • Face continuous threats: Organizations facing constant security threats like cyberattacks, data breaches, or vulnerability exploitation attempts benefit greatly from RASP's real-time protection within the application environment.
  • Store, handle, and/or process personally identifiable information (PII) or other sensitive data: Companies that store, handle, or process sensitive data like PII, financial information, healthcare records, or intellectual property require robust security. RASP helps safeguard this data by detecting and preventing unauthorized access, breaches, and other compromising incidents.
  • Develop and sell software-as-a-service (SaaS) and technology tools: Software providers, SaaS companies, and tech firms dealing with continuous application development benefit from RASP’s integration with DevSecOps pipelines. RASP supports security throughout the software development lifecycle, identifying and blocking vulnerabilities instantly.
  • Need an additional layer of security: Organizations prioritizing a layered security approach can leverage RASP alongside existing controls like firewalls, IDS, and antivirus software. RASP complements these by offering application-level protection, strengthening defense-in-depth strategies, and reducing attack success rates.

How to choose the best RASP security solution

Selecting the most suitable RASP tool requires carefully considering needs and environment. Here's a breakdown of critical factors to evaluate:

  • Identify vulnerabilities: Begin by pinpointing the specific vulnerabilities to which applications are susceptible. Seek a RASP tool that mitigates these threats.
  • Choose certified solutions: Prioritize RASP products endorsed by recognized security organizations like the Center for Internet Security (CIS) and Open Web Application Security Project (OWASP), ensuring their proven and reliable effectiveness.
  • Compare features and pricing: Evaluate various vendors' RASP offerings, considering features, pricing models, and scalability to find the best fit.
  • Compatibility: Opt for RASP solutions that are compatible with programming languages and existing hardware/software infrastructure to streamline integration and optimize performance.
  • Seamless integration: Ensure smooth integration with the current security systems, such as SIEM and WAF, for centralized management and cohesive incident response capabilities. Consider RASP solutions bundled with WAF for a holistic security strategy.
  • Ease of deployment: Look for RASP solutions that boast rapid deployment without requiring extensive rule creation or learning periods. This ensures swift implementation and minimal disruption to operations.

RASP implementation 

Here are some key steps for effectively implementing RASP software:

  • DevSecOps integration: Integrate RASP into the software development life cycle (SDLC) alongside security testing and secure coding practices. This ensures applications are built with security in mind from the beginning.
  • Deployment flexibility: RASP can be deployed through source code instrumentation, where libraries are added to the application code, or through agent-based deployment, where a lightweight agent is installed on the application server. Choose the method that best suits the development environment and expertise. Typically, agent-based deployment is often easier for legacy systems, while source code instrumentation is better suited for new or microservices-based applications.
  • Synergy with security systems: Ensure RASP integrates smoothly with the existing security ecosystem, including WAFs, intrusion detection and prevention systems (IDPS), and SIEM tools. Many RASP tools provide application programming interfaces (APIs) to enable better communication with other security systems, improving response coordination This fosters coordinated threat response and avoids conflicts between security controls.
  • Tune security policies: Most RASP solutions allow customization of security policies. This helps to balance comprehensive protection with minimizing false positives that can disrupt application functionality.
  • Continuous monitoring and updates: Keep the RASP solution updated with the latest security patches and signatures to ensure protection against evolving threats. Monitor RASP logs and security alerts to identify suspicious activity and potential attacks.