# Which RASP tools have the strongest real-time attack blocking for financial services apps where regulatory requirements mean runtime protection is not optional?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For a roundup, I am exploring which RASP tools offer the strongest real-time attack blocking for financial services apps, where regulatory requirements make runtime protection non-optional. In finance, runtime blocking isn't just a preference; it's often a compliance line item, so the bar is real-time defense you can stand behind with auditors. The three that come up most for that combination are Dynatrace, Contrast Security, and OpenText Core Application Security, all from the <a class="a a--md" elv="true" href="https://www.g2.com/categories/runtime-application-self-protection-rasp-tools">Runtime Application Self-Protection (RASP) Tools</a> category.</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/dynatrace/reviews"><strong>Dynatrace</strong></a> (4.5 stars, 1,365 reviews) - it has heavy adoption in financial services and banking among reviewers, who value continuous, real-time visibility and anomaly detection across the stack, with runtime application security layered on through its Application Security module. Most reviews focus on observability, so we weigh the security module on its own merits.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/contrast-security-contrast-security/reviews"><strong>Contrast Security</strong></a> (4.5 stars, 49 reviews) - reviewers in fintech contexts specifically praise real-time protection, accurate runtime detection, and blocking attacks as requests come in, which is the core ask here. The IAST plus Protect combination gives auditors a clear runtime story.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/opentext-core-application-security/reviews"><strong>OpenText Core Application Security</strong></a> (4.1 stars, 34 reviews) - reviewers describe real-time control over sensitive data and protection that reduces the likelihood of cyberattacks, positioned within a broader, research-backed AppSec suite that regulated shops often already run.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/imperva-runtime-application-self-protection-rasp/reviews"><strong>Imperva Runtime Application Self-Protection (RASP)</strong></a> (5.0 stars, 2 reviews) - built around blocking attacks before exploitation with minimal performance impact, which fits the real-time requirement, though its very small review base means it rests more on documented capability than deep feedback.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Given the regulatory angle, do you need blocking that maps cleanly to a framework like PCI DSS, or broad OWASP-class coverage first? Are these apps mostly internal or customer-facing? And is anyone here running one of these specifically under a regulatory mandate?</p>

##### Post Metadata
- Posted at: 2 months ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;&lt;span style=&quot;color: rgb(0, 0, 0);&quot;&gt;For a regulated shop already running other pieces of that broader AppSec suite, OpenText Core Application Security is what I&#39;d want. Runtime protection sitting inside a platform the security team already trusts for other tooling should make the audit conversation easier than introducing a brand new vendor.&lt;/span&gt;&lt;/p&gt;

##### Comment Metadata
- Posted at: 12 days ago
- Author title: Marketing



### Comment 2

&lt;p&gt;Something worth surfacing about the regulatory angle: in finance the hard question isn&#39;t whether the tool can block, it&#39;s what blocking costs you when it&#39;s wrong. A false positive on a payment path is a failed customer transaction, and that carries its own reporting consequences, which is why plenty of regulated shops run RASP in monitor mode on critical flows and block only on the narrow set of rules they trust completely. So &quot;strongest real-time blocking&quot; in practice means highest precision plus a defensible record of every decision the engine made, including the ones where it allowed traffic through. The Contrast pairing of IAST with Protect is interesting on exactly that axis, because the runtime story an auditor wants is a record of decisions rather than a count of blocks.&lt;/p&gt;

##### Comment Metadata
- Posted at: 13 days ago
- Author title: Tech Consultant



### Comment 3

&lt;p&gt;For financial services, I’d care about both: broad OWASP-class blocking for day-to-day protection and controls that map cleanly to PCI DSS or internal regulatory requirements for auditability. Contrast feels especially relevant if the team needs runtime blocking evidence that is easy to explain to security and compliance reviewers.&lt;/p&gt;

##### Comment Metadata
- Posted at: 15 days ago
- Author title: Marketer



### Comment 4

&lt;p&gt;In a regulated context specifically, review depth stops being just a data-quality nuance and starts looking like audit evidence: Contrast&#39;s fintech-specific reviews are third-party proof you could actually point to if a regulator asked how the tool was validated, while Imperva&#39;s two reviews mean you&#39;re relying almost entirely on the vendor&#39;s own documentation for that same conversation. Dynatrace sits in an odd middle spot, since its huge review count proves out the observability side but says very little about the security module auditors would actually care about. That makes Contrast the one with the clearest paper trail here, not necessarily the strongest technical claim on its own. Has anyone actually had to produce vendor evidence like this during a PCI or SOX audit, and if so, which of these held up?&lt;/p&gt;

##### Comment Metadata
- Posted at: 2 months ago
- Author title: SEO Content Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


