Best Secure Code Review Software - Page 2

How Many Secure Code Review Software Products Does G2 Track?

Total Products under this Category: 70

Category Stats (Sep 2026)

  • Average Rating: 4.52/5 (↑0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Greptile (+9.71%) - Among all products in this category, Greptile recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Secure Code Review Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 70+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Secure Code Review Software

G2 Grid® for Secure Code Review Software plotting products by satisfaction and market presence

Highlighted products: GitHub, Aikido Security, GitGuardian, GitLab, Microsoft Defender for Cloud, SonarQube, Qodo, and Checkmarx.

Underlying data: [Grid® JSON](https://www.g2.com/categories/secure-code-review/grids.json?focus%5B%5D=github&focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=microsoft-defender-for-cloud&focus%5B%5D=sonarqube&focus%5B%5D=qodo&focus%5B%5D=checkmarx)

Kiuwan Code Security & Insights

Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner

Average Rating: 4.5/5.0

Total Reviews: 29

How Do G2 Users Rate Kiuwan Code Security & Insights?

  • Quality of Support: 8.9/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Kiuwan Code Security & Insights?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Banking
  • Company Size: 41% Large, 35% Medium

What Do G2 Reviewers Say About Kiuwan Code Security & Insights?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the accuracy of the results from Kiuwan Code Security & Insights, enhancing their overall experience.
  • Users value the accuracy of findings from Kiuwan, enhancing their satisfaction with code security and reporting.
  • Users commend the efficient customer support of Kiuwan, ensuring timely assistance and strong satisfaction overall.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, making it very easy to navigate.
  • Users appreciate the user-friendly interface of Kiuwan Code Security & Insights, enhancing ease of use for dashboards.

What Are Recent G2 Reviews of Kiuwan Code Security & Insights?

CodeScene

CodeScene is a code analysis, visualization, and reporting tool. Cross reference contextual factors such as code quality, team dynamics, and delivery output to get actionable insights to effectively reduce technical debt and deliver better code quality. We enable software development teams to make confident, data-driven decisions that fuel performance and developer productivity. CodeScene guides developers and technical leaders to: - Get a holistic overview and evolution of your software system in one single dashboard. - Identify, prioritize, and tackle technical debt based on return on investment. - Maintain a healthy codebase with powerful CodeHealth™ Metrics, spend less time on rework and more time on innovation. - Seamlessly integrate with Pull Requests and editors, get actionable code reviews and refactoring recommendations. - Set Improvement goals and quality gates for teams to work towards while monitoring the progress. - Support retrospectives by identifying areas for improvement. - Benchmark performance against personalized trends. - Understand the social side of the code, measure socio-technical factors like key personnel dependencies, knowledge sharing and inter-team coordination. - Put findings into context based on how your organization and your code evolves. Supporting 28+ programming languages, CodeScene offers an automated integration with GitHub, BitBucket, Azure DevOps or GitLab pull requests to incorporate the analysis results into existing delivery workflows. Get early warnings and recommendations about complex code before merging it to the main branch, set quality gates to trigger in case your code health declines.

Average Rating: 4.6/5.0

Total Reviews: 39

How Do G2 Users Rate CodeScene?

  • Quality of Support: 9.1/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.2/10 (Category avg: 8.7/10)

Who Is the Company Behind CodeScene?

  • Seller: CodeScene AB
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Malmö, SE
  • Twitter: @codescene
    1,239 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    29 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 41% Medium, 36% Small

What Do G2 Reviewers Say About CodeScene?

AI-generated summary from verified user reviews

Pros
  • Users value the knowledge base and code health features of CodeScene for improving team efficiency and code quality.
  • Users find issue identification with CodeScene invaluable for enhancing team knowledge and improving code quality.
  • Users value the actionable insights CodeScene provides, enhancing code quality and supporting informed decision-making in teams.
  • Users commend the fast and helpful customer support of CodeScene, enhancing their overall experience and satisfaction.
  • Users praise CodeScene for its actionable insights, improving code health and aiding informed decisions for development teams.
Cons
  • Users struggle with integration issues, particularly with proxies and firewall configurations, complicating workflow adoption.
  • Users find the difficult learning curve of CodeScene challenging due to advanced features and overwhelming terminology.
  • Users find the onboarding process challenging, making it difficult for beginners to effectively utilize CodeScene's features.
  • Users find the learning difficulty with CodeScene's advanced features and terminology challenging for newcomers.
  • Users struggle with difficult configuration and lack of seamless integration, impacting adoption and daily workflow usage.

What Are Recent G2 Reviews of CodeScene?

Klocwork

Perforce Klocwork is an enterprise grade SAST solution for C, C++, C#, Rust, Java, JavaScript, Python, and Kotlin. It helps development teams detect security vulnerabilities, quality issues, and reliability defects early, while supporting compliance with industry and regulatory standards. Klocwork is purpose built to analyze very large, complex codebases and scales to hundreds of millions of lines of code, well beyond the practical limits of many traditional SAST tools. This makes it especially suited for organizations developing long lived, safety critical, or security critical systems. Designed for DevOps and DevSecOps, Klocwork integrates with complex build systems, CI/CD pipelines, cloud and containerized environments, and common developer tools—enabling consistent security and quality enforcement without slowing development. Static Application Security Testing (SAST) Klocwork identifies a wide range of security vulnerabilities, including SQL injection, tainted data flows, buffer overflows, and other insecure coding practices. It also detects bugs and quality issues such as null pointer dereferences, memory and resource leaks, uncaught exceptions, and code smells. The solution supports compliance with internationally recognized standards including CWE, OWASP, CERT, PCI DSS, DISA STIG, and ISO/IEC TS 17961. Automated CI/CD integrations make continuous security testing practical even for very large systems. AI Assisted Code Remediation with MCP Klocwork extends static analysis with AI assisted code remediation, designed to help developers resolve findings faster and with greater confidence. Using MCP based capabilities, Klocwork securely exposes rich static analysis context—defect data, rule knowledge, and precise fix guidance—to supported AI code assist tools directly within the IDE. Rather than relying on generic AI suggestions, Klocwork’s remediation feature combines deep static analysis insights with comprehensive documentation and exact fix instructions, enabling AI assistants to propose accurate, context aware corrections for security vulnerabilities, quality defects, and coding standard violations. Fixes are presented as clear diffs and require developer review and approval, making the approach suitable for safety and security critical environments. By integrating remediation into the developer workflow, Klocwork reduces time spent interpreting analysis results, researching fixes, and switching between tools. Developers stay in their IDE, receive guided remediation aligned with secure coding standards and project specific rules, and can immediately re analyze code to validate fixes. This completes the optimal shift left approach—helping teams not only find issues early, but fix them efficiently and consistently. Project Streams and Enterprise Scalability Klocwork’s Project Streams feature simplifies managing shared codebases with multiple variants or branches. A single rule configuration can be applied across streams, issues common to multiple variants stay synchronized, and stream specific findings are clearly identified for reporting and compliance. Developer Focused and Centralized Klocwork integrates directly into popular IDEs to deliver fast, contextual feedback as developers write code. Out of the box compiler support eliminates manual setup, while centralized dashboards provide visibility into trends, risk, and compliance across projects of any size.

Average Rating: 4.4/5.0

Total Reviews: 22

How Do G2 Users Rate Klocwork?

  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.1/10 (Category avg: 8.9/10)
  • Ease of Setup: 7.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Klocwork?

  • Seller: Perforce
  • Year Founded: 1995
  • HQ Location: Minneapolis, MN
  • Twitter: @perforce
    5,090 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,009 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Medium, 35% Small

What Are Recent G2 Reviews of Klocwork?

Bito

Bito's AI Architect is the context layer that powers your entire engineering workflow so every agent reasons like your best architect. Engineering teams run on context that sits across codebases, Jira tickets, Confluence docs, Slack threads, and a handful of senior engineers. Fragmented, inaccessible, and impossible to scale. Bito's AI Architect builds a knowledge graph from all of it, mapping services, dependencies, APIs, and operational history across every repository. That context powers every phase of the engineering workflow. Technical design and feasibility analysis in Jira, Linear, and Slack, before anyone writes code. Grounded code generation via MCP in Cursor, Claude Code, and Codex. Codebase aware code reviews in GitHub, GitLab, and Bitbucket. No code stored. No model trained on customer code. SOC 2 Type II certified.

Average Rating: 4.7/5.0

Total Reviews: 16

How Do G2 Users Rate Bito?

  • Quality of Support: 9.0/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.2/10 (Category avg: 8.7/10)

Who Is the Company Behind Bito?

  • Seller: Bito
  • Year Founded: 2021
  • HQ Location: Menlo Park, Ca
  • Twitter: @BitoHQ
    1,241 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    61 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 50% Small, 44% Medium

What Do G2 Reviewers Say About Bito?

AI-generated summary from verified user reviews

Pros
  • Users find Bito's ease of use impressive, facilitating quick coding, understanding, and seamless integration with VS Code.
  • Users value the coding assistance from Bito, which simplifies understanding and improves coding efficiency effectively.
  • Users love the easy integrations of Bito, enhancing collaboration and productivity through seamless connectivity with tools like Visual Studio Code.
  • Users value the enhanced efficiency of Bito, which streamlines code reviews and significantly boosts productivity.
  • Users appreciate the ease of use of Bito, praising its intuitive interface and seamless integration for efficiency.
Cons
  • Users find a steep learning curve with Bito, highlighting the need for better training and onboarding resources.
  • Users find Bito's pricing structure excessive, making it less accessible for small businesses and individuals.
  • Users feel that Bito has a high learning curve and lacks sufficient training resources for new users.
  • Users note that long responses can be overwhelming and suggest optimizing both content and UI for better clarity.
  • Users find the poor interface design of Bito challenging and believe it needs significant optimization for better experience.

What Are Recent G2 Reviews of Bito?

GuardRails

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

Average Rating: 4.3/5.0

Total Reviews: 29

How Do G2 Users Rate GuardRails?

  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind GuardRails?

  • Seller: GuardRails
  • Year Founded: 2017
  • HQ Location: Singapore, Singapore
  • Twitter: @guardrailsio
    1,553 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 52% Small, 48% Medium

What Do G2 Reviewers Say About GuardRails?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the robust security features of GuardRails, ensuring efficient code scans and vulnerability management in DevSecOps.
  • Users value the vulnerability detection capabilities of GuardRails, enhancing security with automated, comprehensive code scans.
  • Users find GuardRails easy to use, offering integrated feedback on security issues directly within their development environment.
  • Users value the error reduction capabilities of GuardRails, enabling early detection and swift resolution of security issues.
  • Users value the effective threat detection of GuardRails, ensuring secure code and timely vulnerability alerts during development.
Cons
  • Users note missing features in GuardRails, such as limited developer support and lack of report generation capabilities.
  • Users find time management challenging with GuardRails due to insufficient resources and requirement for constant supervision.
  • Users face bug issues with GuardRails, resulting in frequent bottlenecks and complications during code pushing.
  • Users face challenges with dashboard issues, including insufficient report generation and syncing difficulties for new users.
  • Users report false positives in GuardRails, which can complicate the vulnerability management process despite a helpful dashboard.

What Are Recent G2 Reviews of GuardRails?

DeepSource

DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software development cycle. - Guaranteed below 5% false-positive rate with highly accurate and fast static analyzers - Automated issue remediation with Autofix™️ - Code Issue and security reporting: OWASP Top 10, SANS Top 25, Code Coverage, and more - Self-hosted option with one-click installation and upgrades

Average Rating: 4.6/5.0

Total Reviews: 22

How Do G2 Users Rate DeepSource?

  • Quality of Support: 9.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.9/10)
  • Ease of Setup: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind DeepSource?

  • Seller: DeepSource
  • Year Founded: 2018
  • HQ Location: San Francisco, California
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 82% Small, 9% Large

What Are Recent G2 Reviews of DeepSource?

What Are G2 Users Discussing About DeepSource?

Veracode Application Security Platform

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

Average Rating: 3.8/5.0

Total Reviews: 25

How Do G2 Users Rate Veracode Application Security Platform?

  • Quality of Support: 8.0/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 7.9/10 (Category avg: 8.9/10)
  • Ease of Setup: 6.3/10 (Category avg: 8.7/10)

Who Is the Company Behind Veracode Application Security Platform?

  • Seller: VERACODE
  • Year Founded: 2006
  • HQ Location: Burlington, MA
  • Twitter: @Veracode
    21,950 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    500 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 69% Large, 31% Medium

What Do G2 Reviewers Say About Veracode Application Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the effective security vulnerability identification offered by Veracode, enhancing overall application safety and code integrity.
  • Users find Veracode's vulnerability detection excellent for identifying security issues and ensuring high application security standards.
  • Users value the automated scanning of Veracode, streamlining security checks and enhancing code quality effortlessly.
  • Users value the effective detection of security vulnerabilities, enabling robust protection and streamlined development processes.
  • Users appreciate the ease of integration with GitHub and CI/CD pipelines, streamlining their development process effectively.
Cons
  • Users find Veracode to be expensive, with high costs, complex licensing, and unfulfilled feature delivery.
  • Users face a lack of information due to mismatches in documentation and delayed notifications during uploads.
  • Users express concerns over licensing issues, including rising costs, complex models, and unequal feature availability.
  • Users report poor customer support with pushy account executives and difficulties in resolving issues efficiently.
  • Users express concerns about pricing issues, with rising costs and a complex licensing model affecting value perception.

What Are Recent G2 Reviews of Veracode Application Security Platform?

What Are G2 Users Discussing About Veracode Application Security Platform?

Amplify

Amplify is a comprehensive security platform designed to enhance the protection of digital assets for organizations of all sizes. It offers a suite of tools that integrate seamlessly to provide real-time threat detection, proactive risk management, and automated incident response. By leveraging advanced analytics and machine learning, Amplify identifies vulnerabilities and mitigates potential threats before they can impact operations. Its user-friendly interface ensures that security teams can efficiently monitor and manage their security posture, reducing the complexity often associated with cybersecurity solutions. Key Features and Functionality: - Real-Time Threat Detection: Continuously monitors network traffic and system activities to identify and alert on potential security incidents as they occur. - Automated Incident Response: Implements predefined protocols to swiftly address and neutralize threats, minimizing downtime and operational disruption. - Advanced Analytics and Machine Learning: Utilizes sophisticated algorithms to analyze patterns and predict potential vulnerabilities, enhancing proactive defense strategies. - Seamless Integration: Easily integrates with existing IT infrastructure, ensuring a smooth deployment without the need for extensive system overhauls. - User-Friendly Interface: Provides an intuitive dashboard that allows security teams to oversee and manage security operations effectively. Primary Value and Problem Solved: Amplify addresses the critical need for robust cybersecurity by offering a unified platform that simplifies threat detection and response. It empowers organizations to proactively manage risks, ensuring the safety of sensitive data and maintaining business continuity. By automating complex security processes and providing actionable insights, Amplify reduces the burden on IT teams and enhances overall operational efficiency.

Average Rating: 4.9/5.0

Total Reviews: 11

Who Is the Company Behind Amplify?

  • Seller: Amplify Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Boise, Idaho
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services

What Do G2 Reviewers Say About Amplify?

AI-generated summary from verified user reviews

Pros
  • Users value the seamless security integration of Amplify, enhancing code protection without overwhelming developers.
  • Users appreciate the speed and ease of use of Amplify, enabling quick results and minimal friction for teams.
  • Users appreciate the accuracy in security issue identification provided by Amplify, enhancing code quality and reducing noise.
  • Users commend the high-quality code remediation provided by Amplify, enhancing security and developer efficiency seamlessly.
  • Users find Amplify to be super easy to use, enabling faster results and reducing development friction significantly.
Cons
  • Users find the inadequate search functionality hinders their ability to efficiently find and access information.
  • Users note the missing features of Amplify, such as lack of export options and limited reporting capabilities.
  • Users find the complex setup of Amplify challenging, wishing for a simpler activation without file modifications.
  • Users report false positives with Amplify, leading to confusion and unnecessary alerts in their operations.

What Are Recent G2 Reviews of Amplify?

Baz AI Code Review

Baz AI Code Review is an AI-native code review platform designed to help engineering teams ship higher-quality code faster. Unlike traditional static analysis tools or AI reviewers that focus on style and syntax, Baz performs deep, behavior-aware code analysis to catch real bugs, breaking changes, and contract violations before they reach production. Baz understands how code works, not just how it looks. Deep, behavior-focused code analysis Baz analyzes AST diffs, control flow, APIs, and usage patterns to identify issues that matter in real systems. It detects breaking changes such as renamed or removed APIs, behavioral regressions, unsafe assumptions, and edge cases that are easy to miss during manual reviews. This allows teams to catch production-impacting issues early, without slowing development. Spec-aware reviews tied to real requirements Baz connects code changes directly to product intent. By validating changes against Linear tickets and specifications, Baz ensures that what was implemented matches what was requested. This reduces misalignment between product and engineering, shortens feedback cycles, and prevents incomplete or incorrect implementations from slipping through review. Customizable AI agents for every team Every engineering organization has its own conventions, architecture, and risk profile. Baz allows teams to define custom AI review agents that enforce internal coding standards, security policies, infrastructure rules, and domain-specific best practices. This makes Baz effective across multiple teams and disciplines, including backend, frontend, data engineering, and SRE. Faster reviews without human friction Baz significantly reduces code review time by automating repetitive and high-signal feedback. Because feedback comes from an AI reviewer rather than a teammate, it helps remove interpersonal friction while maintaining consistent standards across teams, locations, and seniority levels. Built for real-world engineering workflows Baz integrates directly into existing change workflows and scales to large, multi-file changes. Teams can tune sensitivity to reduce noise, focus on high-impact issues, and gradually expand coverage as their codebase evolves.

Average Rating: 4.9/5.0

Total Reviews: 9

How Do G2 Users Rate Baz AI Code Review?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Ease of Setup: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Baz AI Code Review?

  • Seller: Baz
  • Year Founded: 2023
  • HQ Location: Tel Aviv, IL
  • LinkedIn® Page: www.linkedin.com
    34 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 33% Medium, 11% Small

What Do G2 Reviewers Say About Baz AI Code Review?

AI-generated summary from verified user reviews

Pros
  • Users praise the exceptional code review quality of Baz AI Code Review, effectively identifying critical issues and enhancing productivity.
  • Users value the reliable performance of Baz AI Code Review, noting its quick insights and effective feedback adaptation.
  • Users appreciate the ease of use of Baz AI Code Review, benefiting from its quick setup and effective outcomes.
  • Users praise Baz AI Code Review for its high accuracy, efficiently identifying real issues and adapting to team needs.
  • Users praise the easy setup of Baz AI Code Review, enhancing their experience with seamless integration and configuration.
Cons
  • Users find the inefficient notifications can lead to spammy and noisy experiences during code reviews.
  • Users report experiencing false positives with Baz AI Code Review, leading to unnecessary alerts and confusion.
  • Users experience inefficiency when handling large changes across multiple files, despite the ongoing bug detection.
  • Users note that the Slack integration can be improved, which affects the overall experience with Baz AI Code Review.
  • Users find the missing features of Baz AI Code Review limiting, especially for enterprise-level applications.

What Are Recent G2 Reviews of Baz AI Code Review?

ZeroPath

ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath's core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.

Average Rating: 4.5/5.0

Total Reviews: 11

How Do G2 Users Rate ZeroPath?

  • Quality of Support: 9.4/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.0/10 (Category avg: 8.7/10)

Who Is the Company Behind ZeroPath?

  • Seller: ZeroPath
  • Company Website:
  • Year Founded: 2024
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Small, 27% Medium

What Do G2 Reviewers Say About ZeroPath?

AI-generated summary from verified user reviews

Pros
  • Users value the high accuracy of ZeroPath, effectively identifying real security issues with minimal false alarms.
  • Users value the accuracy of findings from ZeroPath, as it effectively identifies real security issues with minimal false alarms.
  • Users commend ZeroPath for its high accuracy in security detection, minimizing false alarms and enhancing issue resolution.
  • Users commend ZeroPath for its highly accurate vulnerability detection, minimizing false alarms and enhancing security efforts.
  • Users commend ZeroPath for its accurate vulnerability identification, significantly reducing false alarms and enhancing security efforts.
Cons
  • Users report bug issues with ZeroPath, but the support team addresses them quickly and effectively.
  • Users experience some bugs with ZeroPath, but the support team quickly resolves them to improve functionality.
  • Users face some software bugs in ZeroPath, though the team is responsive in resolving them quickly.
  • Users feel that the pricing structure of ZeroPath is not currently suitable for their organization's budget.
  • Users experience bugs in the dashboard, though the ZeroPath team swiftly addresses these problems.

What Are Recent G2 Reviews of ZeroPath?

Codeant AI Code Reviewer

CodeAnt AI reviews every pull request with the whole codebase and business logic behind it, not just the diff. It learns what your team accepts, rejects and argues about. Zero false positives, 70% fix acceptance, 80% less review time.

Average Rating: 4.7/5.0

Total Reviews: 7

How Do G2 Users Rate Codeant AI Code Reviewer?

  • Quality of Support: 8.8/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 6.7/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.7/10 (Category avg: 8.7/10)

Who Is the Company Behind Codeant AI Code Reviewer?

  • Seller: CodeAnt AI
  • Year Founded: 2023
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    22 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 57% Small, 43% Medium

What Do G2 Reviewers Say About Codeant AI Code Reviewer?

AI-generated summary from verified user reviews

Pros
  • Users value the exceptional code quality from Codeant AI Code Reviewer, benefiting from smart suggestions and custom rules.
  • Users appreciate the comprehensive all-in-one features of Codeant AI Code Reviewer, simplifying code reviews and security analysis.
  • Users appreciate the comprehensive coverage of Codeant AI Code Reviewer, simplifying code review and security processes.
  • Users value the custom rules feature for its tailored context and enhanced code review efficiency.
  • Users value the ease of use of Codeant AI Code Reviewer, appreciating its simple interface for comprehensive reviews.
Cons
  • Users find the difficult learning curve with Codeant AI Code Reviewer due to cautious suggestions and slow onboarding.
  • Users find the false positives from Codeant AI Code Reviewer often overly cautious, requiring manual adjustments during onboarding.
  • Users find the improvement needed as suggestions can be overly cautious and onboarding requires significant time.
  • Users find the inefficient notifications sometimes overly cautious and require manual adjustments, complicating the onboarding process.
  • Users find the lack of guidance frustrating, as suggestions may be overly cautious and require manual adjustments.

What Are Recent G2 Reviews of Codeant AI Code Reviewer?

CodeSonar

As a leading provider of static application security testing (SAST) solutions, CodeSecure helps software developers solve challenging issues throughout the software development life cycle (SDLC) to protect mission-critical software and devices from failure and cyberattack. By enabling developers to shift security testing left, CodeSecure CodeSonar seamlessly integrates into CI/CD and DevSecOps tools to assist developers in designing, developing, and deploying trusted software applications – meeting standards, minimizing risk and accelerating projects to gain a competitive advantage. CodeSecure CodeSonar is a multi-language static application security testing (SAST) solution supporting C, C++, C# and Java. CodeSonar provides deep static analysis to quickly find and fix defects impacting code quality, safety and security. With seamless integrations into developer tools such as GitHub, GitLab, Jenkins, Visual Studio and others, CodeSonar is easily adopted into developer workflows to efficiently and continuously test code to create higher quality, safer and more secure software.  

Average Rating: 4.3/5.0

Total Reviews: 13

How Do G2 Users Rate CodeSonar?

  • Quality of Support: 8.8/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 7.1/10 (Category avg: 8.7/10)

Who Is the Company Behind CodeSonar?

  • Seller: CodeSecure
  • Year Founded: 1988
  • HQ Location: Ithaca, NY
  • Twitter: @GrammaTech
    684 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 38% Medium, 31% Small

What Are Recent G2 Reviews of CodeSonar?

What Are G2 Users Discussing About CodeSonar?

NowSecure

NowSecure Inc., based in Oak Park, Illinois, was formed in 2009 with a mission to advance mobile security worldwide. We help secure mobile devices, enterprises and mobile apps.

Average Rating: 4.6/5.0

Total Reviews: 27

How Do G2 Users Rate NowSecure?

  • Quality of Support: 9.7/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.0/10 (Category avg: 8.7/10)

Who Is the Company Behind NowSecure?

  • Seller: NowSecure
  • Year Founded: 2009
  • HQ Location: Chicago, Illinois
  • Twitter: @nowsecuremobile
    6,372 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    101 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 41% Medium, 37% Large

What Are Recent G2 Reviews of NowSecure?

What Are G2 Users Discussing About NowSecure?

rezilion

Rezilion's software attack surface management platform automatically secures the software you deliver to customers, giving teams time back to build. Rezilion works across your stack, helping you to know what software is in your environment, what is vulnerable, and what is actually exploitable, so you can focus on what matters and remediate automatically. KEY FEATURES: - Dynamic SBOM Create an instant inventory of all the software components in your environment - Vulnerability Validation Know which of your software vulnerabilities are exploitable, and which are not, through runtime analysis - Vulnerability Remediation Cluster vulnerabilities to eliminate multiple problems at once and automatically execute remediation work to save teams time. WITH REZILION, ACHIEVE: - 85% reduction in patching work after filtering out unexplainable vulnerabilities - 24/7 Continuous monitoring of your software attack surface -600% Faster time to remediate when you focus on what matters and patch automatically - 360-degree visibility across your entire DevSecOps stack -- not just in silos

Average Rating: 4.4/5.0

Total Reviews: 11

How Do G2 Users Rate rezilion?

  • Quality of Support: 9.3/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 6.7/10 (Category avg: 8.7/10)

Who Is the Company Behind rezilion?

  • Seller: rezilion
  • Year Founded: 2018
  • HQ Location: Be'er Sheva, Israel
  • Twitter: @rezilion_
    198 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 45% Medium, 36% Large

What Are Recent G2 Reviews of rezilion?

Reviewpad

A platform that helps teams or individuals to manage their code review process more efficiently. It streamlines feedback, reduces context switching, and increases code quality. We can be used on GitHub private or public repositories. Build custom workflows or use pre-build ones that ensure compliance, security, and faster CI/CD cycles. Ensure you or your team focus on task that matters and leave repetitive meanless ones to be done by Reviewpad

Average Rating: 4.7/5.0

Total Reviews: 3

How Do G2 Users Rate Reviewpad?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.9/10)
  • Ease of Setup: 5.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Reviewpad?

  • Seller: Explore Dev
  • Year Founded: 2019
  • HQ Location: Boston, Massachusetts, United States
  • Twitter: @reviewpad
    4,069 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,322 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Reviewpad?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024