Best Software Supply Chain Security Solutions - Page 3

How Many Software Supply Chain Security Solutions Products Does G2 Track?

Total Products under this Category: 53

Category Stats (Sep 2026)

  • Average Rating: 4.52/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: JFrog (+0.26%) - Among all products in this category, JFrog recorded the largest rating increase compared to last month

Last updated: September 29, 2026

How Does G2 Rank Software Supply Chain Security Solutions Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,400+ Authentic Reviews
  • 53+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Software Supply Chain Security Solutions

G2 Grid® for Software Supply Chain Security Solutions plotting products by satisfaction and market presence

Highlighted products: Chainguard, Aikido Security, JFrog, Snyk, Mend.io, Harness Platform, Veracode Application Security Platform, and Sonatype Nexus Repository.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-supply-chain-security-tools/grids.json?focus%5B%5D=chainguard&focus%5B%5D=aikido-security&focus%5B%5D=jfrog-2024-03-28&focus%5B%5D=snyk&focus%5B%5D=mend-io&focus%5B%5D=harness-platform&focus%5B%5D=veracode-application-security-platform&focus%5B%5D=sonatype-nexus-repository)

Conviso

The Conviso Platform is a complete Application Security Posture Management (ASPM) solution that centralizes visibility, correlation, and prioritization of vulnerabilities across the software development lifecycle. It integrates with your existing SAST, DAST, SCA, IaC, and CI/CD tools, automates triage, and provides a unified view of risk — helping security and development teams work together to reduce complexity and strengthen AppSec maturity.

Who Is the Company Behind Conviso?

CVDPortal

CVD Portal is a compliance platform for the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847). It helps manufacturers of hardware and software products with digital elements meet every CRA obligation from one product record, from classification to Article 14 vulnerability reporting. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the national CSIRT, with a 24 hour early warning, a 72 hour notification and a final report. From 11 December 2027, the full regulation applies, including the Annex I essential requirements, the technical documentation, the EU Declaration of Conformity and CE marking. What CVD Portal does: - Product classification. A free classifier resolves each product to default, important Class I, important Class II or critical under Annex III and Annex IV, and derives the Article 32 conformity route. - Coordinated vulnerability disclosure. A free whitelabel disclosure portal under your own brand, with a hosted RFC 9116 security.txt, PGP support and 48 hour acknowledgment tracking. - Article 14 reporting. Timers for the 24 hour, 72 hour and final report deadlines, and filing packages prepared for the ENISA Single Reporting Platform. The final submission to the authority stays a human action. - Risk assessment. A STRIDE risk assessment per product, with likelihood and impact scoring, mapped to the Annex I requirements it makes applicable. - Annex I and technical documentation. An applicability decision for every Annex I requirement, with evidence or a justification, and the Annex VII technical file, the EU Declaration of Conformity and the simplified declaration generated from the same record. - SBOM and advisories. SBOM import in SPDX 2.3 and CycloneDX 1.6, component vulnerability matching, and CSAF 2.0 advisories with VEX. - Audit trail. A hash-chained audit log and point-in-time snapshots of the technical file for each release. - Cross-framework evidence. Controls mapped to ISO 27001, NIS2, DORA and NIST CSF 2.0, so evidence is collected once. Who uses it: product security, compliance and engineering teams at manufacturers that place connected devices, industrial equipment or software on the EU market, and the consultants who support them. Data residency: customer data, analytics and logs stay in the European Union on every plan. CVD Portal is built by Porta Regulus B.V. in Amsterdam. Pricing: the Free plan costs €0 per month and covers the disclosure portal. Reporting is €99 per month and Compliance is €299 per month. Enterprise pricing is on request. New accounts get a 14 day free trial of the paid features.

Who Is the Company Behind CVDPortal?

DevArmor

Who Is the Company Behind DevArmor?

  • Seller: DevArmor
  • Year Founded: 2025
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    13 employees on LinkedIn®

Gauntlet

Gauntlet mitigates risks like security breaches, data theft, and compliance violations with Generative AI (GenAI), enhancing efficiency by accelerating time-to-fix by 60%. Its core pillars include Cloud Security Posture Management (CSPM) for proactive vulnerability remediation, Software Supply Chain Security (SBOM) for component transparency, Secrets Scanning to safeguard sensitive credentials, and AI Security Posture Management (AISPM) to secure cloud-based AI services. Gauntlet ensures seamless compliance with over 20 global standards, including HIPAA, FDA, and GDPR, making regulatory adherence effortless for organizations. This powerful platform reduces human error and optimizes operational security at every level. Visit https://www.gauntlet.security for more information.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Gauntlet?

Who Uses This Product?

  • Company Size: 100% Small

What Do G2 Reviewers Say About Gauntlet?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the clear information and guidance provided by Gauntlet, enhancing their overall experience and understanding.
  • Users appreciate the clear and precise remediation guidance from Gauntlet, enhancing their understanding and response efforts.
  • Users value Gauntlet for its clear reporting, offering easy-to-read summaries and precise remediation guidance.
Cons
  • Users wish the inefficient alert system would proactively address urgent and easily fixable issues for better support.

What Are Recent G2 Reviews of Gauntlet?

Guardian

Enable enterprise level enforcement and management of model security to block unsafe models from entering your environment.

Who Is the Company Behind Guardian?

  • Seller: Palo Alto Networks
  • Year Founded: 2005
  • HQ Location: Santa Clara, CA
  • Twitter: @PaloAltoNtwks
    128,951 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,492 employees on LinkedIn®
  • Ownership: NYSE: PANW

IRIS

CodeEye's IRIS is a next-generation application security posture management (ASPM) platform, offers an all-in-one solution with real-time, AI-powered vulnerability and threat detection, correlation, prioritization, and remediation, easing the tension between time-to-market and risk mitigation. How it Works? Unlike traditional ASPM Solutions, IRIS detects vulnerabilities within the product development lifecycle and application infrastructure, while simultaneously providing continuous penetration testing and attack surface management to production environments. IRIS detects, correlates, provides risk-based analysis, and prioritizes application security findings in real time with automated workflows for remediation – all within one platform. IRIS seamlessly integrates with your tools, pipelines, and workflows, and supports your favourite languages. Unlock the Benefits: 1) Centralize detection, prioritization, and remediation of application threats and vulnerabilities. 2) Real-time actionable insights. 3) Establish resilient DevSecOps processes based on risk management. 4) Implement automated workflows to accelerate the identification and resolution of application risks. 5) Adopt a straightforward licensing model. 6) Ability to measure the effectiveness of your application security program. 7) Deploy within 24 hours with simplicity and ease of operation. 8) Built-in policy compliance measures. Next-Gen ASPM Managed Service In today's digital landscape, organizations grapple with deciphering and prioritizing the criticality of code and application related threats and vulnerabilities. The scarcity and expense of specialized talent capable of bridging the gap between DevOps and SecOps exacerbates this challenge. CodeEye's expertise in Application Security provides a Continuous AppSec Partner, accelerating program maturity with expert guidance and advanced technology. Our IRIS Managed Service centralizes application risk management, helping you define compliance measures and policies for prioritization and remediation, ensuring you grasp and address program risk in real-time. Key Features - Static Application Security Testing (SAST): Scans your source code for security risks before an issue goes to production. - Software Composition Analysis (SCA): Continuously monitors your code for known vulnerabilities and other security risks. - Container Scanning: Scans your container in real time for packages that contain security threats and vulnerabilities. - Dynamic Application Security Testing (DAST): Dynamically tests your production applications for vulnerabilities through simulated attacks. - Attack Surface Management (ASM): Continuously identifies, monitors, and manages external internet-connected assets for potential attack vectors and exposures. - Risk and Compliance: Continuously evaluates regulatory and internal security policy compliance using real-time and historical reporting. Vendor of Record Award CodeEye's IRIS is recognized as a Vendor of Record by the Ministry of Government and Consumer Services for IT Security Products In 2024, NIST updated its Cyber Security Framework (CSF) with significant implications for security by design and secure SDLC. Our Risk and Compliance module supports compliance with NIST CSF 2.0 throughout the software development lifecycle. Gain a comprehensive view of various scanning modules aligned with the CSF's five core functions: Identify, Protect, Detect, Respond, and Recover. Our Difference: An all-in-one platform with straight forward licensing and seamless integration. Your Results: A tool that works with your existing tools and workflows, providing security without hidden costs or complexities. Our Difference: Continuous penetration testing and attack surface management. Your Results: Identify and close gaps before an attacker exploits them across your ever-changing attack surface. Our Difference: Quick and Easy Deployment Your Results: Security monitoring and testing within 24 hours, without extensive setup or training. Our difference: Built-in risk and compliance policy module Your Results: Ensure regulatory and internal compliance with built-in policy measures aligned with industry standards like NIST CSF 2.0. Our Difference: Automated Workflows for remediation. Your Results: Rapid risk mitigation, reducing the time, effort and cost of finding and fixing vulnerabilities to ensure continuous protection. Our Difference: Real-Time, AI-powered vulnerability Your Results: Immediately identify and address security threats with precise, actionable intelligence. Our Difference: Threat and vulnerability detection, correlation, and risk-based analysis. Your Results: Simplified security operations where critical vulnerabilities are addressed first.

Who Is the Company Behind IRIS?

  • Seller: CodeEye
  • Year Founded: 2015
  • HQ Location: Toronto, CA
  • Twitter: @CodeEyeAI
    6 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Legit Security

Legit Security provides an application security posture management platform that secures application delivery from code to cloud and protects an organization's software supply chain from attacks. The platform’s unified application security control plane and automated SDLC discovery and analysis capabilities provide visibility and security control over rapidly changing environments and prioritize security issues based on context and business criticality to improve security team efficiency and effectiveness.

Who Is the Company Behind Legit Security?

Listen.dev

Proactive monitoring and Threat Detection for GitHub CI Workflows

Who Is the Company Behind Listen.dev?

NetRise

Who Is the Company Behind NetRise?

  • Seller: NetRise
  • Year Founded: 2020
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    57 employees on LinkedIn®

NPMscan

NPMSCan is a security analysis platform for JavaScript and Node.js ecosystems that helps developers and teams identify supply chain risks in npm packages. The platform scans npm dependencies to detect potentially malicious behavior such as suspicious install scripts, dependency takeovers, obfuscated code patterns, and abnormal package metadata changes. It is designed to complement traditional vulnerability scanners by focusing on supply chain and behavior-based risks rather than only CVE databases. NPMSCan is used by developers, security engineers, and organizations that want deeper visibility into third-party package risks before installing or deploying dependencies in production environments.

Who Is the Company Behind NPMscan?

OSPulse

OSPulse, a supply-chain monitor that flags compromised and abandoned dependencies before a CVE exists, with the evidence behind every alert rather than a bare score. It also produces the EU Cyber Resilience Act Article 14 reporting pack, filled in ready to send.

Who Is the Company Behind OSPulse?

Ossprey

Stop malicious code, not engineers. We detect malware hiding in open source code

Who Is the Company Behind Ossprey?

  • Seller: Ossprey
  • Year Founded: 2024
  • HQ Location: London, GB
  • LinkedIn® Page: www.linkedin.com
    6 employees on LinkedIn®
Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024