Best Software Supply Chain Security Solutions - Page 2

How Many Software Supply Chain Security Solutions Products Does G2 Track?

Total Products under this Category: 53

Category Stats (Sep 2026)

  • Average Rating: 4.52/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: JFrog (+0.26%) - Among all products in this category, JFrog recorded the largest rating increase compared to last month

Last updated: September 29, 2026

How Does G2 Rank Software Supply Chain Security Solutions Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,400+ Authentic Reviews
  • 53+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Software Supply Chain Security Solutions

G2 Grid® for Software Supply Chain Security Solutions plotting products by satisfaction and market presence

Highlighted products: Chainguard, Aikido Security, JFrog, Snyk, Mend.io, Harness Platform, Veracode Application Security Platform, and Sonatype Nexus Repository.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-supply-chain-security-tools/grids.json?focus%5B%5D=chainguard&focus%5B%5D=aikido-security&focus%5B%5D=jfrog-2024-03-28&focus%5B%5D=snyk&focus%5B%5D=mend-io&focus%5B%5D=harness-platform&focus%5B%5D=veracode-application-security-platform&focus%5B%5D=sonatype-nexus-repository)

Endor Labs

Endor Labs turns application security into a competitive advantage. At the core is AURI, the security harness for agentic development. It helps coding agents write secure code by default, automates PR security reviews, and gives agents deterministic context to fix what matters fast. At the core is our patented code context graph: a continuously updated model of application behavior across code, dependencies, secrets, and containers. The result: 83% fewer blocked PRs, 10x fewer security tickets, and 6x faster remediation at Atlassian, Cursor, Rubrik, and Snowflake.

Average Rating: 4.8/5.0

Total Reviews: 9

Who Is the Company Behind Endor Labs?

  • Seller: Endor Labs
  • Company Website:
  • Year Founded: 2021
  • HQ Location: Palo Alto, California, United States
  • Twitter: @EndorLabs
    592 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    207 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 78% Medium, 22% Large

What Do G2 Reviewers Say About Endor Labs?

AI-generated summary from verified user reviews

Pros
  • Users praise Endor Labs for its effective reachability analysis feature, enhancing accuracy and user experience in security management.
  • Users find Endor Labs' ease of use remarkable, allowing quick access to critical data and intuitive navigation.
  • Users highlight the high accuracy of findings from Endor Labs, enhancing vulnerability assessment and risk management significantly.
  • Users commend Endor Labs for their responsive customer support, consistently providing timely assistance and implementing feature requests.
  • Users value the responsive integration support from Endor Labs, enhancing ease of setup and overall user experience.
Cons
  • Users feel that the UI/UX needs improvement, particularly in API accessibility and clearer authentication displays.
  • Users find the API limitations restrictive, requesting more features to be accessible through the UI.
  • Users find the difficult setup of Endor Labs could be simplified to enhance the overall experience.
  • Users find integration issues challenging, particularly with Jira, though improvements are underway for a better experience.
  • Users note that the UI/UX lacks essential features, such as improved IdP authentication and default branch settings.

What Are Recent G2 Reviews of Endor Labs?

Cloudsmith

Cloudsmith is the modern artifact management and software supply chain security platform. It gives engineering teams a unified control layer for every package, container, binary, and ML model moving through their software supply chain – across 30+ formats, with built-in policy enforcement and continuous security monitoring. Modern engineering teams assemble software more than they author it and AI agents pull in open source dependencies at a pace that exceeds ad hoc governance. Cloudsmith functions as a private registry that sits between public sources and your builds; It is the first place every artifact lands and where policy enforcement occurs before anything enters your environment. Splitting artifact management and security across disconnected tools causes teams to lose the consistent visibility and control they need to move fast – and with confidence. Cloudsmith replaces that complexity with a unified platform that scales with your organization. Built for platform engineering teams, security leads, and the engineering leaders who support them, Cloudsmith reduces the operational burden of managing artifact infrastructure, enforces governance consistently across every team and format, and gives organizations full traceability across their supply chain.

Average Rating: 4.5/5.0

Total Reviews: 45

Who Is the Company Behind Cloudsmith?

  • Seller: Cloudsmith
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Belfast, Northern Ireland
  • Twitter: @cloudsmith
    1,094 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    162 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 38% Medium, 36% Small

What Do G2 Reviewers Say About Cloudsmith?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Cloudsmith, streamlining artifact management with simple integration and efficient support.
  • Users benefit greatly from Cloudsmith's seamless integrations, streamlining artifact management and enhancing overall DevOps efficiency.
  • Users value Cloudsmith's reliability, highlighting consistent performance and zero downtime during daily operations.
  • Users value the cloud-native integration of Cloudsmith, simplifying artifact management and enhancing software delivery efficiency.
  • Users appreciate the development efficiency of Cloudsmith, simplifying management and enhancing software delivery with comprehensive support.
Cons
  • Users often face difficult setup challenges with Cloudsmith, leading to confusion and a steep learning curve.
  • Users note the expensive pricing model of Cloudsmith, especially for teams with large artifacts and frequent downloads.
  • Users find integration issues with Cloudsmith frustrating, leading to concerns about onboarding and compatibility with existing systems.

What Are Recent G2 Reviews of Cloudsmith?

What Are G2 Users Discussing About Cloudsmith?

Jscrambler

Jscrambler is the leader in Client-Side Security for the modern, composable web. As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces. Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled according to enterprise policy at the point of creation — before they leave the client environment. Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.

Average Rating: 4.4/5.0

Total Reviews: 31

Who Is the Company Behind Jscrambler?

  • Seller: Jscrambler
  • Company Website:
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @Jscrambler
    1,161 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    88 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 35% Medium, 29% Small

What Do G2 Reviewers Say About Jscrambler?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Jscrambler, highlighting its intuitive navigation and user-friendly interface.
  • Users find Jscrambler's automation capabilities beneficial for seamless integration and enhanced security within development workflows.
  • Users commend the rapid and helpful customer support of Jscrambler, enhancing their overall experience significantly.
  • Users value the robust security features of Jscrambler, effectively safeguarding their intellectual property during deployment.
  • Users value the comprehensive overview of Jscrambler, enhancing security and performance while enabling features gradually.
Cons
  • Users experience slow performance with Jscrambler, requiring tuning and noting insufficient documentation for improvement.
  • Users suggest that the dashboard can be improved to display more detailed information from each installation.
  • Users experience a difficult initiation due to a complex setup process requiring substantial understanding of application deployment.
  • Users face challenges with obfuscated pages not working and project file limits in large applications.
  • Users struggle with limited guidance and often face issues when exporting reports, hindering their experience.

What Are Recent G2 Reviews of Jscrambler?

What Are G2 Users Discussing About Jscrambler?

DryRun Security

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

Average Rating: 4.9/5.0

Total Reviews: 20

Who Is the Company Behind DryRun Security?

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 40% Small, 30% Medium

What Do G2 Reviewers Say About DryRun Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the context-aware security feedback from DryRun Security, enabling efficient vulnerability mitigation in real-time.
  • Users appreciate the quick and context-aware vulnerability detection of DryRun Security, enhancing code security during development.
  • Users commend DryRun Security for its seamless integration and effective detections, enhancing code security and development efficiency.
  • Users appreciate the accuracy of DryRun Security, effectively identifying vulnerabilities in AI-generated code and traditional applications.
  • Users commend the easy setup of DryRun Security, providing seamless integration and efficient workflow for code scanning.
Cons
  • Users experience slow performance in the management portal, affecting usability and efficiency with linked repositories.
  • Users find the slow speed of the management portal frustrating, though improvements to the UI have been noted.
  • Users note a need for improved UX investment in DryRun Security to enhance the developer experience and engagement.
  • Users desire more customization options for tuning analyzers, indicating limited flexibility in current features.
  • Users feel that greater focus on workflow issues could enhance DryRun Security's adoption among developers.

What Are Recent G2 Reviews of DryRun Security?

Safeguard

Safeguard & Self-Heal your Software Supply Chain

Average Rating: 4.9/5.0

Total Reviews: 4

Who Is the Company Behind Safeguard?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Safeguard?

Xygeni

Xygeni: AI-Native ASPM for the Software Supply Chain Xygeni is an AI-native ASPM (Application Security Posture Management) platform that unifies native and third-party security findings into one prioritized view. Its own detection engines cover SAST, SCA, DAST, Secrets, IaC, Container, CI/CD, and Build Security, and it also ingests results from tools like Snyk, Veracode, and Checkmarx so teams don't have to abandon what they've already invested in. Every finding, regardless of source, gets scored by exploitability, reachability, and business impact through Xygeni's Dynamic Funnels, which is what drives its reported 90% cut in alert noise. Two AI systems sit underneath the platform. CoreAI acts as a correlation and reporting layer for security leaders, turning scattered findings into a single risk narrative. DevAI works earlier, inside the developer's IDE and AI coding assistants, catching problems in both human-written and AI-generated code and proposing fixes before a pull request is even opened. On the supply chain side, Xygeni's MEW engine (Malware Early Warning) is built to catch malicious open-source packages the moment they hit a public registry, ahead of when a formal malware signature would normally exist. Shield takes that enforcement to the developer's own machine, blocking unauthorized package downloads at the OS level before they reach disk. Xygeni also runs a dedicated Code Quality engine across ten languages, ranking maintainability and complexity issues alongside security findings in the same console, so a team can see when the messiest file is also the riskiest one. The platform connects to GitHub, GitLab, Bitbucket, Jenkins, and Azure DevOps, and deploys as SaaS, on-premises, or fully air-gapped. Xygeni was named Hot Company in ASPM and in GenAI Application Security at the 2026 Global InfoSec Awards.

Average Rating: 4.6/5.0

Total Reviews: 4

Who Is the Company Behind Xygeni?

  • Seller: Xygeni Security
  • Year Founded: 2021
  • HQ Location: Madrid, ES
  • Twitter: @xygeni
    178 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    31 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 40% Medium

What Do G2 Reviewers Say About Xygeni?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the comprehensive security features of Xygeni, fostering a secure development environment without hindering productivity.
  • Users value the effective prioritization of security issues in Xygeni, allowing teams to focus on critical threats quickly.
  • Users value the effective risk management of Xygeni, enhancing security without hindering software development processes.
  • Users appreciate the robust security features of Xygeni, enhancing their development process while ensuring compliance and risk management.
  • Users value the seamless CI/CD integration of Xygeni, enabling early vulnerability detection without impacting release schedules.
Cons
  • Users face difficult setup issues with Xygeni, especially when dealing with certain edge cases requiring manual adjustments.
  • Users find the learning curve challenging for newcomers despite a generally intuitive platform, requiring familiarity with AppSec practices.

What Are Recent G2 Reviews of Xygeni?

SCANOSS

SCANOSS is the industry-leading open source software intelligence provider, offering the largest database of open source information available. SCANOSS delivers cutting-edge tools and services that help businesses and developers detect, manage, and secure their open source components. By identifying license obligations, security vulnerabilities, and other risk concerns, SCANOSS ensures that organisations can harness the power of open source safely and securely throughout the development pipeline.

Average Rating: 4.3/5.0

Total Reviews: 2

Who Is the Company Behind SCANOSS?

  • Seller: SCANOSS
  • Year Founded: 2021
  • HQ Location: Madrid, ES
  • LinkedIn® Page: www.linkedin.com
    25 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of SCANOSS?

Cycode

Cycode’s AI-Native Application Security Platform unites security and development teams with actionable context from code to runtime to identify, prioritize, and fix the software risks that matter. Powered by proprietary scanners, third-party integrations, and the Context Intelligence Graph (CIG), Cycode delivers unified, correlated insight across the Software Factory. Its unique ability to sense, reason, and act with context in the AI-Era comes from its foundational convergence of AST, ASPM, and Software Supply Chain Security—purpose-built to secure both AI- and human-generated code.

Average Rating: 4.0/5.0

Total Reviews: 2

Who Is the Company Behind Cycode?

  • Seller: Cycode
  • Year Founded: 2019
  • HQ Location: New York, New York, United States
  • LinkedIn® Page: www.linkedin.com
    149 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Medium, 33% Large

What Are Recent G2 Reviews of Cycode?

ReversingLabs

ReversingLabs is the trusted name in file and software security. We provide the modern cybersecurity platform to verify and deliver safe binaries. Trusted by the Fortune 500 and leading cybersecurity vendors, RL Spectra Core powers the software supply chain and file security insights, tracking over 422 billion searchable files with the ability to deconstruct full software binaries in seconds to minutes. Only ReversingLabs provides that final exam to determine whether a single file or full software binary presents a risk to your organization and your customers.

Average Rating: 4.7/5.0

Total Reviews: 10

Who Is the Company Behind ReversingLabs?

  • Seller: ReversingLabs
  • Year Founded: 2009
  • HQ Location: Cambridge, US
  • Twitter: @ReversingLabs
    7,022 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    321 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 80% Small, 10% Medium

What Do G2 Reviewers Say About ReversingLabs?

AI-generated summary from verified user reviews

Pros
  • Users commend the accuracy of information offered by ReversingLabs, utilizing an extensive repository of files for effective risk management.
  • Users commend the excellent customer support from ReversingLabs, enhancing their onboarding and overall experience effectively.
  • Users commend the efficient onboarding process of ReversingLabs, facilitating a seamless and effective transition to their services.
  • Users appreciate the effective prioritization of risk management with ReversingLabs, enhancing their security processes significantly.
  • Users commend the high reliability of ReversingLabs, citing exceptional support and a vast repository of files.
Cons
  • Users find the endpoints for checking usage confusing, which complicates their overall experience with the product.
  • Users find the confusing interface for usage endpoints makes it difficult to navigate the product effectively.
  • Users find the navigation issues related to usage endpoints somewhat confusing, impacting their overall experience.
  • Users feel the UI could be nicer, yet it doesn't hinder the overall functionality of ReversingLabs.

What Are Recent G2 Reviews of ReversingLabs?

Sonatype Lifecycle

Continuously secure your software supply chain with Sonatype Nexus Lifecycle, a software composition analysis (SCA) solution. Nexus Lifecycle helps development, security, and compliance teams reduce open source risk without slowing delivery. It detects vulnerable or non-compliant components early, provides clear remediation guidance, and enforces the same policies from development through CI/CD and release - powered by Sonatype Nexus Intelligence. Choose safer components up front: A Chrome extension and IDE integrations surface vulnerability, license, and quality insights as developers browse public repositories or add dependencies. Fix issues fast where work happens: In Eclipse, IntelliJ, and Visual Studio, developers can see exactly what's wrong and upgrade to an approved version with a click - no guesswork. Automate remediation in source control: Integrations with GitHub, GitLab, and Atlassian Bitbucket can comment on pull/merge requests and identify the specific dependency change that introduces risk, along with recommended versions to resolve it. You can also generate automated pull requests to update components that violate policy. Enforce open source policies across the SDLC: Create security, license, and architectural policies tailored by application type, team, or organization, then apply them consistently in developer tools, CI/CD, and repositories to prevent risky components from reaching production. Generate SBOMs in minutes: Produce accurate Software Bills of Materials (SBOMs) per application to understand what components and transitive dependencies are in use and verify compliance. Prove progress with reporting: Track trends like Mean Time to Resolution (MTTR) and violation reduction over time to demonstrate measurable risk reduction to stakeholders. Nexus Lifecycle integrates with common developer, CI/CD, and repository tools including Nexus Repository, Artifactory, Jira, Jenkins, Azure DevOps, and more.

Average Rating: 4.2/5.0

Total Reviews: 3

Who Is the Company Behind Sonatype Lifecycle?

  • Seller: Sonatype
  • Year Founded: 2008
  • HQ Location: Fulton, US
  • Twitter: @sonatype
    10,589 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    567 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 75% Large, 25% Medium

What Are Recent G2 Reviews of Sonatype Lifecycle?

Sonatype Repository Firewall

Sonatype Repository Firewall helps protect your software supply chain by blocking open source malware and other high-risk components before they enter your artifact repositories and development workflows. Repository Firewall evaluates components at the point of download using automated analysis plus policy enforcement, so risky packages can be prevented (or quarantined) before they spread across builds, teams, and environments. Key capabilities: - Detect and block known and suspicious open source malware before it reaches developers - Enforce security, license, and quality policies early, at the repository perimeter - Identify risky or malicious components already present in repositories to support cleanup and response - Provide clear, auditable policy decisions and guidance so teams understand why a component was blocked and what to use instead - Integrate with common repository managers (including Nexus Repository and JFrog Artifactory) to add protection without slowing delivery Repository Firewall is ideal for organizations that depend heavily on public registries and want a preventative control to reduce supply chain attacks, lower rework, and keep development moving with trusted components.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Sonatype Repository Firewall?

  • Seller: Sonatype
  • Year Founded: 2008
  • HQ Location: Fulton, US
  • Twitter: @sonatype
    10,589 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    567 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Sonatype Repository Firewall?

AI-generated summary from verified user reviews

Pros
  • Users value the control over security that Sonatype Repository Firewall provides, preventing unapproved components from advancing applications.
  • Users value the network security benefits of Sonatype Repository Firewall, ensuring data safety and policy enforcement.
  • Users value the protection against malicious activities that Sonatype Repository Firewall provides, ensuring data security.
Cons
  • Users note a lack of technical support expertise, requiring knowledge of SDLC, DevOps, and Nexus Repository Manager.
  • Users face inadequate learning resources with Sonatype Repository Firewall, lacking proper support and understanding of key solutions.
  • Users face challenges with poor customer support, highlighting the need for knowledgeable assistance in technical issues.

What Are Recent G2 Reviews of Sonatype Repository Firewall?

ZeroPath

ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath's core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.

Average Rating: 4.5/5.0

Total Reviews: 11

Who Is the Company Behind ZeroPath?

  • Seller: ZeroPath
  • Company Website:
  • Year Founded: 2024
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    12 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 36% Small, 27% Medium

What Do G2 Reviewers Say About ZeroPath?

AI-generated summary from verified user reviews

Pros
  • Users value the high accuracy of ZeroPath, effectively identifying real security issues with minimal false alarms.
  • Users value the accuracy of findings from ZeroPath, as it effectively identifies real security issues with minimal false alarms.
  • Users commend ZeroPath for its high accuracy in security detection, minimizing false alarms and enhancing issue resolution.
  • Users commend ZeroPath for its highly accurate vulnerability detection, minimizing false alarms and enhancing security efforts.
  • Users commend ZeroPath for its accurate vulnerability identification, significantly reducing false alarms and enhancing security efforts.
Cons
  • Users report bug issues with ZeroPath, but the support team addresses them quickly and effectively.
  • Users experience some bugs with ZeroPath, but the support team quickly resolves them to improve functionality.
  • Users face some software bugs in ZeroPath, though the team is responsive in resolving them quickly.
  • Users feel that the pricing structure of ZeroPath is not currently suitable for their organization's budget.
  • Users experience bugs in the dashboard, though the ZeroPath team swiftly addresses these problems.

What Are Recent G2 Reviews of ZeroPath?

Apiiro

Apiiro is the leader in application security posture management (ASPM), unifying risk visibility, prioritization, and remediation with deep code analysis and runtime context. Get complete application and risk visibility: Apiiro takes a deep, code-based approach to ASPM. Its Cloud Application Security Platform analyzes source code and pulls in runtime context to build a continuous, graph-based inventory of application and software supply chain components. Prioritize with code-to-runtime context: With its proprietary Risk Graph™️, Apiiro contextualizes security alerts from third-party tools and native security solutions based on the likelihood and impact of risk to uniquely minimize alert backlogs and triage time by 95%. Fix faster and prevent risks that matter: By tying risks to code owners, providing LLM-enriched remediation guidance, and embedding risk-based guardrails directly into developer tools and workflows, Apiiro improves remediation times (MTTR) by up to 85%. Apiiro's native security solutions include API security testing in code, secrets detection and validation, software bill of materials (SBOM) generation, sensitive data exposure prevention, software composition analysis (SCA), and CI/CD and SCM security.

Average Rating: 4.8/5.0

Total Reviews: 2

Who Is the Company Behind Apiiro?

  • Seller: Apiiro
  • Year Founded: 2019
  • HQ Location: New York, New York, United States
  • Twitter: @apiiroSecurity
    7,397 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    135 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Apiiro?

What Are G2 Users Discussing About Apiiro?

Appsec360

AppSec360 is a platform for AI-driven software development to become Secure-by-Design.

Who Is the Company Behind Appsec360?

CleanStart Images

CleanStart Images are verified hardened container images built for secure software delivery and container image security. Each image is rebuilt from source using reproducible build pipelines and includes security evidence such as SBOMs, cryptographic signatures, and software provenance. Designed for Kubernetes and cloud-native environments, CleanStart Images help organizations reduce container vulnerabilities, minimize attack surface, and deploy trusted container foundations with confidence as part of a secure software supply chain.

Who Is the Company Behind CleanStart Images?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024