# Best Software Bill of Materials (SBOM) Software

## How Many Software Bill of Materials (SBOM) Software Products Does G2 Track?

**Total Products under this Category:** 34

### Category Stats (Sep 2026)

- **Average Rating:** 4.51/5 (↑0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** JFrog (+0.17%) - Among all products in this category, JFrog recorded the largest rating increase compared to last month

_Last updated: September 01, 2026_

## How Does G2 Rank Software Bill of Materials (SBOM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 900+ Authentic Reviews
- 34+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

**Sponsored**

### CAST Highlight

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1008169&secure%5Bchosen_at%5D=2026-09-01T08%3A58%3A52Z&secure%5Bdisplayable_resource_id%5D=1008169&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1008169&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=58553&secure%5Bresource_id%5D=1008169&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-bill-of-materials-sbom&secure%5Btoken%5D=f6b1ba766d5e31da49fbf4da00a1a6559beb25ddb4e2d4b965f6c2d866543dcd&secure%5Burl%5D=https%3A%2F%2Fwww.castsoftware.com%2Ftryhighlight%3Futm_campaign%3Dg2_clicks_ads%26utm_source%3Dcast_highlight%26utm_medium%3Dtrial_request&secure%5Burl_type%5D=free_trial)

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **intuitive dashboard** of OX Security, enhancing issue management and streamlining security processes effectively.
- Users value the **collaboration features** of OX Security, enhancing teamwork and integrating seamlessly with existing tools.
- Users value the **responsive and professional customer support** of OX Security, enhancing their overall experience and efficiency.
- Users value the **seamless integrations** of OX Security, enhancing workflow efficiency and security insights effortlessly.
- Users appreciate the **speed and efficiency** of OX Security in identifying and addressing vulnerabilities promptly.

##### Cons

- Users find the **complexity** of OX Security daunting, with inadequate documentation and a steep learning curve for new users.
- Users find the **interface overwhelming** , facing a steep learning curve and lacking adequate documentation for ease of use.
- Users find the **complex setup** of OX Security challenging, compounded by insufficient documentation and overwhelming UI.
- Users experience **limited dashboard functionality** , impacting reporting on security enhancements and overall management effectiveness.
- Users find the **difficult learning** curve challenging due to OX Security's complex interface and insufficient documentation.

#### What Are Recent G2 Reviews of OX Security?

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

### [Cybeats](https://www.g2.com/products/cybeats/reviews)

Cybeats is at the forefront of cybersecurity innovation and is focused explicitly on automating Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) management. Our platform has built-in support for HBOM and AIBOM. Our mission is to empower organizations to rapidly identify and address vulnerabilities, significantly reducing costs while enhancing the security posture of their products. With our focus on the vision of "Building trust in every layer of your technology," Cybeats provides a robust platform that ensures transparency and security throughout the technological stack. Core Offerings - SBOM Management & Continuous Monitoring Cybeats offers a scalable solution for managing and monitoring SBOMs. Our platform stores enriches and distributes SBOMs efficiently across the organization and the organization's customers. This continuous monitoring helps proactively identify and mitigate software component risks. - SBOM Inventory & Management We provide a centralized system for SBOM inventory management that ensures all software components are accounted for, up-to-date, and secure. This systematic approach helps maintain a clear overview of all software elements, facilitating easier management and compliance. - Vulnerability Lifecycle Management (VLM) Our VLM capabilities integrate Vulnerability Exploitability Exchange (VEX) and Vulnerability Disclosure Program (VDP) processes. This integration helps identify, assess, manage, and mitigate vulnerabilities throughout their lifecycle, ensuring continuous protection against potential software supply chain threats. - Regulatory Compliance Cybeats aligns with global regulatory requirements, assisting organizations in staying compliant with evolving cybersecurity standards. Our solution simplifies compliance management, reducing the complexity and resources required to meet legal and industry standards. With the introduction of regulatory requirements of the FDA pre-market and post-market, the EU CRA, PCI-SSF, and others, companies that develop software-based products must align with the SBOM and Vulnerability management requirements. - OSS and Comercial Licensing Risk Assessment Understanding and managing licensing risks associated with software components is crucial. Cybeats provides tools to assess these risks, helping organizations avoid legal and financial repercussions related to software licensing. - SBOM Sharing and Exchange We facilitate secure sharing and exchange of SBOMs within and across organizations. This capability ensures that all parties in the software supply chain have access to accurate and timely information, enhancing collaborative efforts toward secure software development.

**Average Rating:** 4.4/5.0

**Total Reviews:** 15

#### Who Is the Company Behind Cybeats?

- **Seller:** [CYBEATS](https://www.g2.com/sellers/cybeats)
- **Year Founded:** 2017
- **HQ Location:** Toronto, Ontario
- **Twitter:** @cybeatstech  
616 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2663143089be0432d313d1e538a94c0aa900c3536fc6ddc68eb338c35cf31f18&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcybeats%2F&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 47% Small, 33% Medium

#### What Are Recent G2 Reviews of Cybeats?

**["A safe and secure enterprise supply chain management system is created and enabled by Cybeats"](https://www.g2.com/survey_responses/cybeats-review-7468992)**

**Rating:** 4.5/5.0 stars

_— Karan C._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7468992)

**["Great Computer Security Service Solutin"](https://www.g2.com/survey_responses/cybeats-review-7160083)**

**Rating:** 4.5/5.0 stars

_— Patrícia P._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7160083)

### [Aqua Security](https://www.g2.com/products/aqua-security/reviews)

Aqua Security sees and stops attacks across the entire cloud native application lifecycle in a single, integrated platform. From software supply chain security for developers to cloud security and runtime protection for security teams, Aqua helps customers reduce risk while building the future of their businesses. The Aqua Platform is the industry’s most comprehensive Cloud Native Application Protection Platform (CNAPP). Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL with Fortune 1000 customers in over 40 countries.

**Average Rating:** 4.2/5.0

**Total Reviews:** 57

#### Who Is the Company Behind Aqua Security?

- **Seller:** [Aqua Security Software Ltd](https://www.g2.com/sellers/aqua-security-software-ltd)
- **Year Founded:** 2015
- **HQ Location:** Burlington, US
- **Twitter:** @AquaSecTeam  
7,673 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f4eb23edc8b5f10ebd17fc968083bd004165393cf169f8e925d190834d97d836&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faquasecteam%2F&secure%5Burl_type%5D=linkedin_company_website)  
466 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 56% Large, 39% Medium

#### What Do G2 Reviewers Say About Aqua Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **robust security features** of Aqua Security, effectively managing vulnerabilities and ensuring compliance.
- Users highlight the **ease of use** of Aqua Security, noting its intuitive design and straightforward implementation process.
- Users appreciate the **intuitive setup** of Aqua Security, finding deployment and scanning straightforward and manageable.
- Users appreciate the **effective detection capabilities** of Aqua Security, simplifying the management of container security challenges.
- Users value Aqua Security for its **effective vulnerability identification** , simplifying management of container security and compliance.

##### Cons

- Users find **missing features** in Aqua Security, like inadequate dashboards and minimal reporting, hinder their experience.
- Users find the **lack of features** frustrating, particularly with inadequate APIs and ineffective dashboards for analysis.
- Users find Aqua Security has **limited features** , lacking support for various applications and essential reporting options.
- Users find the **difficult navigation** of Aqua Security’s UI complicates data identification and overall experience.
- Users find **improvement needed** in Aqua Security's dashboards and reporting features, causing delays in necessary enhancements.

#### What Are Recent G2 Reviews of Aqua Security?

**["Allows us to monitor security of or platforms and scan images easily."](https://www.g2.com/survey_responses/aqua-security-review-10502217)**

**Rating:** 5.0/5.0 stars

_— Mitchell M._

[Read full review](https://www.g2.com/survey_responses/aqua-security-review-10502217)

**["AquaSec have been very efficient and user friendly."](https://www.g2.com/survey_responses/aqua-security-review-7802942)**

**Rating:** 5.0/5.0 stars

_— Adefolarin B._

[Read full review](https://www.g2.com/survey_responses/aqua-security-review-7802942)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 118

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
259 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 35% Small, 33% Large

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **scanning efficiency** of Mend.io, enabling quick and accurate scans across multiple repositories seamlessly.
- Users appreciate the **ease of use** of Mend.io, made simpler by effective integrations and an attractive interface.
- Users value the **easy integrations** of Mend.io, allowing seamless scanning across multiple repositories and CI/CD platforms.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, benefiting from a range of integrations.
- Users value the **automated vulnerability detection** of Mend.io, enhancing efficiency in identifying and addressing issues seamlessly.

##### Cons

- Users face **integration issues** with Mend.io, finding it difficult to connect on-premise tools and features like Jira.
- Users express concern over **limited features** in Mend.io, necessitating workarounds for optimal functionality and integration.
- Users find the **missing features** in Mend.io cumbersome, often resorting to workarounds for integration and functionality.
- Users face **complex implementation** , with challenging integration and frequent false positives affecting their experience.
- Users find the **confusing interface** challenging due to the awkward transitions between different portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Mend.io Makes Vulnerability Scanning and Prioritization Easy"](https://www.g2.com/survey_responses/mend-io-review-13187391)**

**Rating:** 4.5/5.0 stars

_— Ratna P._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-13187391)

**["Great Tool for Managing 3rd party libraries"](https://www.g2.com/survey_responses/mend-io-review-6728890)**

**Rating:** 4.5/5.0 stars

_— Johannes B._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-6728890)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

### [Arnica](https://www.g2.com/products/arnica/reviews)

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

**Average Rating:** 4.9/5.0

**Total Reviews:** 8

#### Who Is the Company Behind Arnica?

- **Seller:** [Arnica](https://www.g2.com/sellers/arnica)
- **Company Website:** www.arnica.io
- **Year Founded:** 2021
- **HQ Location:** Alpharetta, Georgia
- **Twitter:** @arnicaio  
124 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=35b6c80888a16d99de6aed67226d5eee0835f227fc79936eb37367fea6278187&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Farnica-io%2Fabout&secure%5Burl_type%5D=linkedin_company_website)  
60 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 63% Large, 25% Small

#### What Do G2 Reviewers Say About Arnica?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **accuracy of findings** from Arnica, enhancing security through effective management of privileges.
- Users value Arnica for its **actionable recommendations** , simplifying the management of elevated privileges in source code repositories.
- Users appreciate the **easy setup and administration** of Arnica, which saves valuable time and effort.
- Users love the **easy setup** of Arnica, making administration a quick and efficient process.
- Users value Arnica for its ability to **reduce attack surface** by identifying and rectifying excessive privileged access efficiently.

##### Cons

- Users find the **paid features limited** for smaller teams, restricting access to crucial protections in Arnica.

#### What Are Recent G2 Reviews of Arnica?

**["Intuitive Dashboards and AI That Finds Real Issues"](https://www.g2.com/survey_responses/arnica-review-12972680)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/arnica-review-12972680)

**["Developer-friendly AppSec with a flexible policy engine"](https://www.g2.com/survey_responses/arnica-review-12962349)**

**Rating:** 5.0/5.0 stars

_— Thomas G._

[Read full review](https://www.g2.com/survey_responses/arnica-review-12962349)

#### What Are G2 Users Discussing About Arnica?

- [What is Arnica used for?](https://www.g2.com/discussions/what-is-arnica-used-for)

### [Finite State](https://www.g2.com/products/finite-state/reviews)

Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes—connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed. Learn more at https://finitestate.io/

**Average Rating:** 4.3/5.0

**Total Reviews:** 12

#### Who Is the Company Behind Finite State?

- **Seller:** [Finite State](https://www.g2.com/sellers/finite-state)
- **Company Website:** finitestate.io
- **Year Founded:** 2017
- **HQ Location:** Columbus, Ohio, United States
- **Twitter:** @FiniteStateInc  
670 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c0fe50fa8a0e0ed8412dfd69616147ad626de06ff8e7521a186e1f519fbfdf94&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ffinitestate&secure%5Burl_type%5D=linkedin_company_website)  
78 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Large, 25% Medium

#### What Are Recent G2 Reviews of Finite State?

**["Deep Visibility Into Supply Chain Risks and CVEs—Boosting Product Security"](https://www.g2.com/survey_responses/finite-state-review-12966722)**

**Rating:** 5.0/5.0 stars

_— Suru S._

[Read full review](https://www.g2.com/survey_responses/finite-state-review-12966722)

**["Finite State Review: Firmware Security Simplified"](https://www.g2.com/survey_responses/finite-state-review-12997919)**

**Rating:** 5.0/5.0 stars

_— Prasanth B._

[Read full review](https://www.g2.com/survey_responses/finite-state-review-12997919)

### [Socket](https://www.g2.com/products/socket-socket/reviews)

Socket is the leading developer-first security platform that protects modern applications from malicious and vulnerable open source dependencies. By combining real-time package monitoring with AI-powered code analysis, Socket detects and blocks supply chain attacks within minutes of publication. With advanced reachability analysis, automated remediation, and license compliance features, Socket enables teams to focus on building software, while we keep their open source code secure.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### Who Is the Company Behind Socket?

- **Seller:** [Socket](https://www.g2.com/sellers/socket)
- **Year Founded:** 2020
- **HQ Location:** San Francisco, US
- **Twitter:** @SocketSecurity  
21,558 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=333fcd28dd311ff160a9395ac69327d82d0f595897ba65d2388e7b628c0687bf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsocketinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
115 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 40% Medium, 30% Large

#### What Do G2 Reviewers Say About Socket?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **robust security features** of Socket, particularly its effectiveness in monitoring supply chain attacks.
- Users value Socket's **effective open source security analysis** , which simplifies package evaluation and enhances overall efficiency.
- Users commend the **accuracy of findings** from Socket, appreciating its unique analysis methods and time-saving capabilities.
- Users value Socket's **proactive alerts** for supply chain attacks, enhancing security and customer support responsiveness.
- Users value the **comprehensive security** that Socket provides, enhancing decision-making in software supply-chain management.

##### Cons

- Users feel the **missing features** in Socket hinder its ability to consolidate tools for diverse use cases.
- Users report experiencing **system slowness** with Socket, particularly noting delays in UI loading times.

#### What Are Recent G2 Reviews of Socket?

**["Unique Approach to Supply Chain Security Problem and Does It Really Well"](https://www.g2.com/survey_responses/socket-review-12052484)**

**Rating:** 5.0/5.0 stars

_— Sindhoor H._

[Read full review](https://www.g2.com/survey_responses/socket-review-12052484)

**["Essential Tool for Application Security with Stellar MCP Feature"](https://www.g2.com/survey_responses/socket-review-12686360)**

**Rating:** 5.0/5.0 stars

_— Shreejal M._

[Read full review](https://www.g2.com/survey_responses/socket-review-12686360)

### [SOOS](https://www.g2.com/products/soos/reviews)

SOOS is the complete application security posture management platform. Scan your software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license types, generate and manage Software Bill of Materials (SBOM), and fill out your compliance worksheets across all your teams. SOOS’s ASPM is a dynamic, comprehensive approach to safeguarding your application infrastructure from vulnerabilities across the Software Development Life Cycle (SDLC) and live deployments. Easy to integrate, all in one dashboard. SCA - Deep tree vulnerability scanning, license compliance, governance DAST - Automated Web & API vulnerability scanning Containers - Scan contents for vulnerabilities SAST - Analyze code for security vulnerabilities IaC - Cloud security coverage SBOMs - Create – monitor – manage

**Average Rating:** 4.6/5.0

**Total Reviews:** 42

#### Who Is the Company Behind SOOS?

- **Seller:** [SOOS](https://www.g2.com/sellers/soos)
- **Year Founded:** 2019
- **HQ Location:** Winooski, US
- **Twitter:** @soostech  
44 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=61bd56b45756b75fc0339880cc3369c6d2af3971839c773abcfbf38d4d05a283&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F53122310&secure%5Burl_type%5D=linkedin_company_website)  
23 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Medium, 43% Small

#### What Do G2 Reviewers Say About SOOS?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **ease of use** of SOOS, highlighting its user-friendly setup and supportive onboarding process.
- Users highlight the **awesome customer support** from SOOS, enhancing the overall user experience during onboarding.
- Users value the **easy integrations** of SOOS, enhancing workflow without hindering developer efficiency.
- Users appreciate the **easy integrations** of SOOS, enhancing workflow without hindering development processes.
- Users find the **easy setup** of SOOS intuitive, enabling quick integration and effective use with minimal effort.

##### Cons

- Users express concern over the **lack of guidance** in documentation and actionable recommendations for vulnerability remediation.
- Users highlight **poor reporting** in SOOS, seeking better filtering and display options for vulnerability analysis.
- Users find the **dashboard issues** frustrating, as richer reporting and filtering options are lacking.
- Users note the need for **inadequate reporting** features, highlighting a lack of customization and richer options for analysis.
- Users find SOOS to be **lacking features** , particularly in reporting and user interface intuitiveness.

#### What Are Recent G2 Reviews of SOOS?

**["Reliable continuous security assessment for our pipelines"](https://www.g2.com/survey_responses/soos-review-7744758)**

**Rating:** 4.0/5.0 stars

_— Brallan G._

[Read full review](https://www.g2.com/survey_responses/soos-review-7744758)

**["Awesome tool for detecting vulnerabilities within project dependecies"](https://www.g2.com/survey_responses/soos-review-7753830)**

**Rating:** 4.5/5.0 stars

_— Nayan C._

[Read full review](https://www.g2.com/survey_responses/soos-review-7753830)

### [CAST Highlight](https://www.g2.com/products/cast-highlight/reviews)

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

**Average Rating:** 4.5/5.0

**Total Reviews:** 86

#### Who Is the Company Behind CAST Highlight?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Company Website:** www.castsoftware.com
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 57% Large, 24% Small

#### What Do G2 Reviewers Say About CAST Highlight?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of CAST Highlight, noting its quick setup and straightforward functionality for assessments.
- Users find the **easy setup** of CAST Highlight highly beneficial, enabling quick integration and efficient use with enterprise tools.
- Users value CAST Highlight for its **insights into cloud migration and technical debt assessment** , enhancing software health evaluation.
- Users appreciate the **efficient analysis** offered by CAST Highlight, enabling fast insights and effective modernization strategies.
- Users value the **speed and simplicity** of CAST Highlight, enabling quick, actionable insights for portfolio analysis.

##### Cons

- Users find the **complex navigation** of CAST Highlight challenging, making it harder to efficiently use the tool.
- Users find **dashboard issues** prevalent, including lack of depth and customization challenges for specific organizational needs.
- Users find that the **delayed detection** of issues may hinder timely responses and overall effectiveness of CAST Highlight.
- Users find the **difficulty in initial configuration** and metric interpretation a barrier for new teams using CAST Highlight.
- Users find the **high price** of CAST Highlight a barrier for broader adoption in larger companies.

#### What Are Recent G2 Reviews of CAST Highlight?

**["Portfolio Insights in One Place with CAST Highlight"](https://www.g2.com/survey_responses/cast-highlight-review-12977472)**

**Rating:** 4.5/5.0 stars

_— Verified User in Government Administration_

[Read full review](https://www.g2.com/survey_responses/cast-highlight-review-12977472)

**["Cast Highlight App Review"](https://www.g2.com/survey_responses/cast-highlight-review-8335236)**

**Rating:** 4.0/5.0 stars

_— Silviu Constantin S._

[Read full review](https://www.g2.com/survey_responses/cast-highlight-review-8335236)

#### What Are G2 Users Discussing About CAST Highlight?

- [What is cast imaging?](https://www.g2.com/discussions/what-is-cast-imaging) - 1 comment
- [How does a cast tool work?](https://www.g2.com/discussions/how-does-a-cast-tool-work)
- [What is CAST software tool?](https://www.g2.com/discussions/what-is-cast-software-tool) - 1 comment
- [What does cast highlight do?](https://www.g2.com/discussions/what-does-cast-highlight-do) - 1 comment

### [Manifest](https://www.g2.com/products/manifest-cyber-manifest/reviews)

Manifest helps organizations understand and reduce the cybersecurity risk in the technology they produce and procure. The Manifest platform operationalizes software bills of materials (SBOMs), artificial intelligence bills of materials (AIBOMs), and Vulnerability Exploitability eXchange (VEX) documents so organizations can analyze and action the risk in internal or third-party tools. Manifest manages the entire SBOM lifecycle for customers in critical industries like enterprise technology, aerospace, defense contracting, healthcare, manufacturing & logistics, financial services, and the federal government.

**Average Rating:** 5.0/5.0

**Total Reviews:** 3

#### Who Is the Company Behind Manifest?

- **Seller:** [Manifest Cyber](https://www.g2.com/sellers/manifest-cyber)
- **HQ Location:** Connecticut, USA
- **Twitter:** @manifestcyber  
89 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=54e6ef840d28ede463596f51619097fd992e89b81825043f5a51847ef091dd2f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmanifestcyber%2F&secure%5Burl_type%5D=linkedin_company_website)  
14 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Medium, 33% Small

#### What Do G2 Reviewers Say About Manifest?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Manifest, simplifying SBOM generation and integration into existing workflows.
- Users value the **automation capabilities** of Manifest, enhancing efficiency and security in managing software supply chains.
- Users value the **real-time monitoring** of software dependencies in Manifest, enhancing security and efficiency in their workflows.
- Users value the **authentication security** of Manifest, enhancing the safety of their software supply chain.
- Users value the **exceptional customer support** from Manifest, noting their commitment to user satisfaction and assistance.

##### Cons

- Users find that the **integration process is time-consuming** as they seek to enhance the product's functionality.

#### What Are Recent G2 Reviews of Manifest?

**["Real “Continuous Compliance”"](https://www.g2.com/survey_responses/manifest-review-9130056)**

**Rating:** 5.0/5.0 stars

_— Peter Z._

[Read full review](https://www.g2.com/survey_responses/manifest-review-9130056)

**["Cutting-Edge Tool Enables Complete Lifecycle Management of your Software Bill of Materials"](https://www.g2.com/survey_responses/manifest-review-9139664)**

**Rating:** 5.0/5.0 stars

_— Shaun M._

[Read full review](https://www.g2.com/survey_responses/manifest-review-9139664)

### [Snyk](https://www.g2.com/products/snyk/reviews)

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

**Average Rating:** 4.5/5.0

**Total Reviews:** 135

#### Who Is the Company Behind Snyk?

- **Seller:** [Snyk](https://www.g2.com/sellers/snyk)
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @snyksec  
21,057 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=53ae05ab7bc9d48691ba96e338012b66175e75679973854c2a6c213b21fab33f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10043614%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,370 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 44% Medium, 35% Small

#### What Do G2 Reviewers Say About Snyk?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Snyk's **quick vulnerability detection** , significantly improving efficiency in code security and remediation processes.
- Users appreciate Snyk for its **efficient vulnerability identification** , significantly aiding in maintaining secure code and streamlining DevOps processes.
- Users value the **easy integration setup** of Snyk, enhancing vulnerability detection in their development workflows.
- Users appreciate the **easy setup** of Snyk, seamlessly integrating with GitHub for efficient vulnerability management.
- Users benefit from Snyk's **intuitive GUI and customizable features** , facilitating effective vulnerability management and developer organization.

##### Cons

- Users experience **false positives** in Snyk, which can hinder efficiency and slow down the scanning process.
- Users find the **poor interface design** of Snyk cumbersome, impacting their overall experience with the product.
- Users note that **pricing issues** can arise, especially when accessing all features of Snyk, impacting affordability.
- Users report experiencing **false positives and slow scan times** , affecting their efficiency and integration within the Snyk product.
- Users experience **false positives and slow scans** , complicating overall use and requiring additional tools for code quality.

#### What Are Recent G2 Reviews of Snyk?

**["Developer-Friendly Security with Clear, Automated Fixes"](https://www.g2.com/survey_responses/snyk-review-12974957)**

**Rating:** 4.5/5.0 stars

_— Hemanth K._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12974957)

**["Seamless Dev-First Security with Fast Scans and Actionable Fixes"](https://www.g2.com/survey_responses/snyk-review-12676270)**

**Rating:** 4.5/5.0 stars

_— Prateek J._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12676270)

#### What Are G2 Users Discussing About Snyk?

- [What is Snyk scanning?](https://www.g2.com/discussions/what-is-snyk-scanning) - 2 comments, 2 upvotes
- [Is Snyk a SaaS?](https://www.g2.com/discussions/is-snyk-a-saas) - 2 comments
- [How good is Snyk?](https://www.g2.com/discussions/how-good-is-snyk) - 2 comments
- [What is Snyk used for?](https://www.g2.com/discussions/what-is-snyk-used-for)

### [Anchore](https://www.g2.com/products/anchore/reviews)

Anchore, Inc., based in Santa Barbara, CA, was founded in 2016 by Saïd Ziouani and Daniel Nurmi to help organizations implement secure container-based workflows without compromising velocity. Anchore Enterprise is a complete container security workflow solution for professional teams. Integrating seamlessly with a wide variety of development tools and platforms, it allows teams to adhere to defined industry security standards. The Anchore Enterprise user interface provides visibility to security teams, allowing them to audit and verify compliance throughout the organization. It can be deployed in air-gapped and public cloud environments and is built for large scale. Anchore Enterprise is based on Anchore Engine, an open-source tool for deep image inspection and vulnerability scanning.

**Average Rating:** 4.4/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Anchore?

- **Seller:** [Anchore](https://www.g2.com/sellers/anchore)
- **Year Founded:** 2016
- **HQ Location:** Santa Barbara, California, United States
- **Twitter:** @anchore  
2,797 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=80a88822f136760cc3ade8de797d9fe334aca48666cbbdf6ff6e665fe7e55a0a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fanchore%2F&secure%5Burl_type%5D=linkedin_company_website)  
91 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Large, 50% Medium

#### What Do G2 Reviewers Say About Anchore?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **seamless cloud integration** of Anchore, enhancing workflows with tools like DefectDojo and Jira.
- Users appreciate the **clean and user-friendly interface** of Anchore, enhancing integration and workflow management effectively.
- Users appreciate the **easy integrations** of Anchore, enabling seamless workflows with tools like DefectDojo and Jira.
- Users appreciate the **clean interface and seamless integration** with tools like DefectDojo and Jira for effective workflows.
- Users find the **user-friendly interface** of Anchore facilitates seamless integration and effective issue management in security workflows.

#### What Are Recent G2 Reviews of Anchore?

**["Love the intuitive interface and dashboard to assess security posture in a single place"](https://www.g2.com/survey_responses/anchore-review-11048224)**

**Rating:** 4.0/5.0 stars

_— Raja A._

[Read full review](https://www.g2.com/survey_responses/anchore-review-11048224)

**["Anchore: Essential Tool for Container Security and Compliance"](https://www.g2.com/survey_responses/anchore-review-10025756)**

**Rating:** 4.0/5.0 stars

_— Dr habeeb M._

[Read full review](https://www.g2.com/survey_responses/anchore-review-10025756)

#### What Are G2 Users Discussing About Anchore?

- [What is Anchore used for?](https://www.g2.com/discussions/what-is-anchore-used-for)

### [JFrog](https://www.g2.com/products/jfrog-2024-03-28/reviews)

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry's most pressing trend: the rise of agentic software development and the hidden security risks of "Shadow AI." In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization's ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.

**Average Rating:** 4.2/5.0

**Total Reviews:** 159

#### Who Is the Company Behind JFrog?

- **Seller:** [JFrog Ltd](https://www.g2.com/sellers/jfrog-ltd)
- **Company Website:** jfrog.com
- **Year Founded:** 2008
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @jfrog  
23,186 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9e9f01c1efeb3f3e7b4535b3aefc16344bbb21773bc11bf4ad186f193dbcaabf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjfrog-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,364 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Large, 30% Medium

#### What Do G2 Reviewers Say About JFrog?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **unified support for various package formats** that simplifies DevOps management and integration.
- Users praise JFrog for its **efficient repository management** , streamlining the storage and tracking of artifacts in DevOps workflows.
- Users value the **seamless integration** of JFrog with CI/CD tools, enhancing efficiency in artifact management and security.
- Users value the **seamless integrations** of JFrog with various tools, enhancing their CI/CD workflows significantly.
- Users appreciate the **easy integrations** of JFrog, enhancing CI/CD processes and supporting various package formats seamlessly.

##### Cons

- Users find the **complexity** of JFrog overwhelming, often needing extensive training to use all features effectively.
- Users often find JFrog to be **expensive** , especially challenging for smaller teams and individual developers to afford.
- Users find the **steep learning curve** of JFrog challenging, requiring significant time and investment to master.
- Users note the **difficult learning** curve with JFrog, requiring extensive training to navigate its complex features effectively.
- Users find the **learning difficulty** of JFrog challenging, requiring significant time investment to master its features.

#### What Are Recent G2 Reviews of JFrog?

**["Streamlines CI/CD with Efficient Artifact Management"](https://www.g2.com/survey_responses/jfrog-review-13224726)**

**Rating:** 5.0/5.0 stars

_— Nameera S._

[Read full review](https://www.g2.com/survey_responses/jfrog-review-13224726)

**["JFrog Simplifies Artifact Management for Organized, Reliable Deployments"](https://www.g2.com/survey_responses/jfrog-review-12870354)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/survey_responses/jfrog-review-12870354)

#### What Are G2 Users Discussing About JFrog?

- [What are the benefits and challenges of using JFrog for managing your software supply chain?](https://www.g2.com/discussions/what-are-the-benefits-and-challenges-of-using-jfrog-for-managing-your-software-supply-chain)
- [What does Jfrog Platform do?](https://www.g2.com/discussions/what-does-jfrog-platform-do)
- [What is difference between JFrog and Nexus?](https://www.g2.com/discussions/what-is-difference-between-jfrog-and-nexus)
- [What is Artifactory software used for?](https://www.g2.com/discussions/what-is-artifactory-software-used-for)

### [1Exiger Platform](https://www.g2.com/products/1exiger-platform/reviews)

Exiger’s award-winning, purpose-built technology platform, 1Exiger, is the only open-source, third-party and supply chain management software that helps companies and government agencies achieve cost savings, resilience, and compliance in real time. Created and launched in collaboration with our 550+ customers, the platform makes supply chain management simple, intuitive and accessible. The 1Exiger user experience is housed in an integrated suite that is scalable and secure. Using our powerful AI technology, you can uncover risks and reveal insights that enable confident decision-making.

**Average Rating:** 4.5/5.0

**Total Reviews:** 17

#### Who Is the Company Behind 1Exiger Platform?

- **Seller:** [Exiger](https://www.g2.com/sellers/exiger)
- **Company Website:** www.exiger.com
- **HQ Location:** New York, NY
- **Twitter:** @exigerllc  
1,851 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d8f8d5b35d2f0f783ea827e1c0fec1989f724128ef381ae2b943d92db3f63084&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fexiger&secure%5Burl_type%5D=linkedin_company_website)  
800 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 53% Large, 47% Medium

#### What Do G2 Reviewers Say About 1Exiger Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **AI-driven risk intelligence** of the 1Exiger Platform, enhancing compliance workflows and simplifying management.
- Users find the **ease of use** of 1Exiger Platform simplifies risk management for any organization efficiently.
- Users appreciate the **automation efficiency** of the 1Exiger Platform, streamlining complex compliance workflows for better decision-making.
- Users appreciate the **centralized compliance management** of the 1Exiger Platform, streamlining processes and enhancing risk visibility.
- Users find the **comprehensive coverage** of the 1Exiger Platform invaluable for effective risk management and support.

##### Cons

- Users find the **customization options limited** , which hinders effective use, especially on mobile devices.
- Users find the **limited functionality** of the 1Exiger Platform restricts customization and mobile accessibility.
- Users find the **difficult usability** of the 1Exiger Platform hampers their experience, particularly for new or mobile users.
- Users find the **customization options limited** , especially on mobile, affecting their ability to work flexibly.
- Users find **navigation challenging** , causing confusion and slowing down their ability to effectively utilize the platform.

#### What Are Recent G2 Reviews of 1Exiger Platform?

**["Easy-to-Use Platform That Centralizes Risk & Compliance Data and Saves Time"](https://www.g2.com/survey_responses/1exiger-platform-review-10545189)**

**Rating:** 4.5/5.0 stars

_— Verified User in Package/Freight Delivery_

[Read full review](https://www.g2.com/survey_responses/1exiger-platform-review-10545189)

**["Great Visibility Into HQ Practices for Remote Teams"](https://www.g2.com/survey_responses/1exiger-platform-review-12726616)**

**Rating:** 4.0/5.0 stars

_— carl l._

[Read full review](https://www.g2.com/survey_responses/1exiger-platform-review-12726616)

#### What Are G2 Users Discussing About 1Exiger Platform?

- [What is DDIQ used for?](https://www.g2.com/discussions/what-is-ddiq-used-for)

### [CipherScan](https://www.g2.com/products/cipherscan/reviews)

CipherScan by QuantumGenie is an AI-native cryptographic discovery platform that inventories cryptographic assets across source code, cloud infrastructure, certificates, keys, databases, and endpoints, generating a Cryptographic Bill of Materials (CBOM) to identify classical and quantum-vulnerable cryptography ahead of post-quantum migration. CipherScan performs one-time or continuous cryptographic discovery through QuantumGenie's numerous integrations across enterprise environments. QuantumGenie supports integration across Microsoft Azure, Amazon Web Services, Google Cloud, GitHub, Bitbucket, GitLab, MongoDB, PostgreSQL, MySQL, Jenkins, Thales, Splunk, CrowdStrike, IBM Cloud, ServiceNow, Datadog, Redis, and other infrastructure and data platforms. Therefore, CipherScan by QuantumGenie is a pioneer in post-quantum cryptography. CipherScan by QuantumGenie has also recently launched on Microsoft Marketplace, arriving alongside the validation by Google Cloud Marketplace Solution. CipherScan is also available on Visual Studio Code Marketplace and is soon coming on AWS Marketplace and Splunk Cloud Marketplace.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### Who Is the Company Behind CipherScan?

- **Seller:** [QuantumGenie](https://www.g2.com/sellers/quantumgenie)
- **Year Founded:** 2024
- **HQ Location:** Westlake Village, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9a73b7e8e233496390af8a7e80849cdbfd42cdad81f753880e46d80b475d7121&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fquantumgenie&secure%5Burl_type%5D=linkedin_company_website)  
12 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of CipherScan?

**["CipherScan: Comprehensive Self-Serve Cryptographic Discovery with Powerful PQC Remediation"](https://www.g2.com/survey_responses/cipherscan-review-13234764)**

**Rating:** 5.0/5.0 stars

_— Srijan D._

[Read full review](https://www.g2.com/survey_responses/cipherscan-review-13234764)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/software-bill-of-materials-sbom?order=popular&page=2#product-list)
- [3](/categories/software-bill-of-materials-sbom?order=popular&page=3#product-list)
- [Next &rsaquo; Next ›](/categories/software-bill-of-materials-sbom?order=popular&page=2#product-list)

Spotlight Categories

[Quality Management Systems (QMS)](https://www.g2.com/categories/quality-management-qms)

[Experience Management Software](https://www.g2.com/categories/experience-management)

[Media Monitoring Software](https://www.g2.com/categories/media-monitoring)

[Employer of Record (EOR) Software](https://www.g2.com/categories/employer-of-record-eor)

[Electronic Data Interchange (EDI) Software](https://www.g2.com/categories/electronic-data-interchange-edi)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Bill of Materials (SBOM) Themes](/categories/software-bill-of-materials-sbom/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Software bill of materials (SBOM) solutions generate, ingest, manage, and monitor a machine-readable inventory of the components within software supply chains. The components covered include libraries, packages, modules, associated licenses, and more. Companies and developers use SBOM software to deliver and annotate comprehensive SBOMs for their software’s third party and open source components .

These solutions allow users to comply with government mandates that require the provision of a minimum SBOM. Maintaining and monitoring SBOMs also helps companies perform continuous risk assessments, though vulnerability remediation is not the primary focus of such tools. [software composition analysis (SCA) tools](https://www.g2.com/categories/software-composition-analysis) scan software supply chains’ components and dependencies at the code level to identify and remediate security vulnerabilities, whereas SBOM software automates the standardized presentation of those elements for transparency, observability, and compliance.

To qualify for inclusion in the Software Bill of Materials (SBOM) category, a product must:

- Automatically ingest and generate SBOMs in standard formats like CycloneDX and SPDX
- Continuously monitor and update SBOMs based on component versions, associated licenses, dependencies, and more
- Alert users of non-compliant elements in their software supply chain
- Allow users to annotate SBOMs
- Facilitate compliance with government regulations

Show More