# Best Application Security Posture Management (ASPM) Software

## How Many Application Security Posture Management (ASPM) Software Products Does G2 Track?

**Total Products under this Category:** 37

### Category Stats (Jul 2026)

- **Average Rating:** 4.55/5 (↓0.01 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Mend.io (+0.25%) - Among all products in this category, Mend.io recorded the largest rating increase compared to last month

_Last updated: July 27, 2026_

## How Does G2 Rank Application Security Posture Management (ASPM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,100+ Authentic Reviews
- 37+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Application Security Posture Management (ASPM) Software
 ![G2 Grid® for Application Security Posture Management (ASPM) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/application-security-posture-management-aspm/grids.png?focus%5B%5D=1259627&focus%5B%5D=151443&focus%5B%5D=1312693&focus%5B%5D=7775&focus%5B%5D=1186242&focus%5B%5D=7336&focus%5B%5D=32484&focus%5B%5D=148651)

Highlighted products: Aikido Security, CrowdStrike Falcon Cloud Security, OX Security, SonarQube, Jit, Carbon Black App Control, Invicti (formerly Netsparker), and APPCHECK.

Underlying data: [Grid® JSON](https://www.g2.com/categories/application-security-posture-management-aspm/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=ox-security&focus%5B%5D=sonarqube&focus%5B%5D=jit&focus%5B%5D=carbon-black-app-control&focus%5B%5D=invicti-formerly-netsparker&focus%5B%5D=appcheck)

**Sponsored**

### Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list&secure%5Bcategory_id%5D=1008070&secure%5Bchosen_at%5D=2026-07-29T05%3A24%3A03Z&secure%5Bdisplayable_resource_id%5D=1423&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1423&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=27706&secure%5Bresource_id%5D=1008070&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fapplication-security-posture-management-aspm%3Fopen_modal_url%3D%252Fproducts%252Factivestate%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fapplication-security-posture-management-aspm%2526source%253Dcategory&secure%5Btoken%5D=bfa9c7f7bc04cbedead72eeebcce2a4a25248addf1986956aa1d7b49923c6631&secure%5Burl%5D=https%3A%2F%2Fwww.intruder.io%2F%3Futm_source%3Dg2%26utm_medium%3Dp_referral%26utm_campaign%3Dglobal%7Cfixed%7Cg2_clicks_2025&secure%5Burl_type%5D=free_trial)

[
Aikido Security
](https://www.g2.com/products/aikido-security/reviews)

By [Aikido Security](https://www.g2.com/sellers/aikido-security)

[

4.6/5(252)

](https://www.g2.com/products/aikido-security/reviews)

What do users say?

Users consistently praise the ease of use and intuitive interface of Aikido Security, highlighting how it simplifies vulnerability management and integrates seamlessly into existing workflows. The pla

Pros and Cons

[
Ease of Use (78)
](https://www.g2.com/products/aikido-security/reviews?qs=pros-and-cons)[
Missing Features (19)
](https://www.g2.com/products/aikido-security/reviews?qs=pros-and-cons)

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 250

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

[
CrowdStrike Falcon Cloud...
](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews)

By [CrowdStrike](https://www.g2.com/sellers/crowdstrike)

[

4.5/5(161)

](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews)

What do users say?

Users consistently praise real-time threat detection and comprehensive visibility provided by CrowdStrike Falcon Cloud Security, which enhances their ability to manage cloud security effectively. The

Pros and Cons

[
Security (49)
](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews?qs=pros-and-cons)[
Expensive (17)
](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews?qs=pros-and-cons)

### [CrowdStrike Falcon Cloud Security](https://www.g2.com/products/crowdstrike-falcon-cloud-security/reviews)

Crowdstrike Falcon Cloud Security is the only CNAPP to stop breaches in the cloud Built for today’s hybrid and multi-cloud environments, Falcon Cloud Security protects the entire cloud attack surface - from code to runtime - by combining continuous agentless visibility with real-time detection and response. At runtime, Falcon Cloud Security delivers best-in-class cloud workload protection and real-time cloud detection and response (CDR) to stop active threats across hybrid environments. Integrated with the CrowdStrike Falcon platform, it correlates signals across endpoint, identity, and cloud to detect sophisticated cross-domain attacks that point solutions miss—enabling teams to respond faster and stop breaches in progress. To reduce risk before attacks occur, Falcon Cloud Security also delivers agentless-driven posture management that proactively shrinks the cloud attack surface. Unlike typical solutions, Crowdstrike enriches cloud risk detections with adversary intelligence and graph-based context, enabling security teams to prioritize exploitable exposures and prevent breaches before they happen. Customers using Falcon Cloud Security consistently see measurable results: 89% faster cloud detection and response 100x reduction in false positives by prioritizing exploitable, business-critical risk 83% reduction in cloud security licenses due to elimination of redundant tools

**Average Rating:** 4.5/5.0

**Total Reviews:** 152

#### Who Is the Company Behind CrowdStrike Falcon Cloud Security?

- **Seller:** [CrowdStrike](https://www.g2.com/sellers/crowdstrike)
- **Company Website:** www.crowdstrike.com
- **Year Founded:** 2011
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @CrowdStrike  
110,809 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f13dce0bc1628ccb762ed9d5acb4e0f0998a717639b903c3d3a271ef1da6ad7b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2497653%2F&secure%5Burl_type%5D=linkedin_company_website)  
11,343 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 53% Large, 33% Medium

#### What Do G2 Reviewers Say About CrowdStrike Falcon Cloud Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **complete protection** from code to cloud offered by CrowdStrike Falcon Cloud Security, enhancing security efficiently.
- Users appreciate the **strong security and compliance features** of CrowdStrike Falcon Cloud Security, enhancing visibility and threat intelligence.
- Users commend the **detection efficiency** of CrowdStrike Falcon Cloud Security, ensuring robust protection with minimal false positives.
- Users value the **complete protection and efficient vulnerability detection** offered by CrowdStrike Falcon Cloud Security for all organization sizes.
- Users appreciate the **user-friendly interface** of CrowdStrike Falcon Cloud Security, making it easy to navigate and investigate alerts.

##### Cons

- Users note that the pricing of CrowdStrike Falcon Cloud Security is **expensive** , making it hard for smaller organizations to afford.
- Users suggest that **improvements are needed** for better uptime and user experience in CrowdStrike Falcon Cloud Security.
- Users note that **improvement is needed** in uptime and user experience during enrollment for CrowdStrike Falcon Cloud Security.
- Users find the **feature complexity** of CrowdStrike Falcon Cloud Security overwhelming, requiring a significant learning curve to navigate.
- Users face a **steep learning curve** with CrowdStrike Falcon Cloud Security, complicating the onboarding process for new users.

#### What Are Recent G2 Reviews of CrowdStrike Falcon Cloud Security?

**["Real-Time Cloud Protection with eBPF and Unified Telemetry"](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13173504)**

**Rating:** 4.0/5.0 stars

_— Aswindev P._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13173504)

**["CrowdStrike Falcon Cloud Security: Unified Console and Smart Prioritization That Keeps Us Focused"](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13138386)**

**Rating:** 4.0/5.0 stars

_— Tamanna T._

[Read full review](https://www.g2.com/survey_responses/crowdstrike-falcon-cloud-security-review-13138386)

[
OX Security
](https://www.g2.com/products/ox-security/reviews)

By [OX Security](https://www.g2.com/sellers/ox-security)

[

4.8/5(51)

](https://www.g2.com/products/ox-security/reviews)

What do users say?

Users consistently praise the intuitive interface and seamless integration with existing tools, which simplify security management and enhance productivity. The platform's ability to provide comprehen

Pros and Cons

[
Features (8)
](https://www.g2.com/products/ox-security/reviews?qs=pros-and-cons)[
Complexity (5)
](https://www.g2.com/products/ox-security/reviews?qs=pros-and-cons)

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **intuitive dashboard and seamless integration** of OX Security, enhancing their security management and workflow efficiency.
- Users value the **seamless collaboration** enabled by OX Security, enhancing their focus on critical development tasks.
- Users commend the **responsive customer support** of OX Security, enhancing their overall operational efficiency and satisfaction.
- Users value the **seamless integrations** with existing tools, enhancing workflows and boosting overall development efficiency.
- Users appreciate the **speed** of OX Security, enabling faster remediation of vulnerabilities and cloud misconfigurations.

##### Cons

- Users find the **complexity** of OX Security daunting, facing a steep learning curve and inadequate documentation.
- Users find the **interface overwhelming** , with a steep learning curve and insufficient documentation to guide new users.
- Users find the **complex setup** challenging, especially due to inadequate documentation and overwhelming UI for new users.
- Users find the **executive dashboard limiting** , impacting effective reporting on product security enhancements to management.
- Users find OX Security's **difficult learning curve** challenging, particularly due to its complex interface and lacking documentation.

#### What Are Recent G2 Reviews of OX Security?

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

[
SonarQube
](https://www.g2.com/products/sonarqube/reviews)

By [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)

[

4.4/5(155)

](https://www.g2.com/products/sonarqube/reviews)

What do users say?

Users consistently praise SonarQube for its automated code quality checks and seamless CI/CD integration, which significantly enhance development workflows and reduce reliance on manual reviews. The t

Pros and Cons

[
Code Quality (24)
](https://www.g2.com/products/sonarqube/reviews?qs=pros-and-cons)[
Software Bugs (12)
](https://www.g2.com/products/sonarqube/reviews?qs=pros-and-cons)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

[
Jit
](https://www.g2.com/products/jit/reviews)

By [jit](https://www.g2.com/sellers/jit)

[

4.5/5(43)

](https://www.g2.com/products/jit/reviews)

What do users say?

Users consistently praise Jit for its ease of integration and automated security checks, which streamline the development workflow without adding complexity. The platform's ability to provide clear vi

Pros and Cons

[
Security (10)
](https://www.g2.com/products/jit/reviews?qs=pros-and-cons)[
Integration Issues (4)
](https://www.g2.com/products/jit/reviews?qs=pros-and-cons)

### [Jit](https://www.g2.com/products/jit/reviews)

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

**Average Rating:** 4.5/5.0

**Total Reviews:** 43

#### Who Is the Company Behind Jit?

- **Seller:** [jit](https://www.g2.com/sellers/jit)
- **Year Founded:** 2021
- **HQ Location:** Boston, MA
- **Twitter:** @jit\_io  
522 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c12301146938a4e9885aeef608ceac690a4eb5c023d31e5d2df099a15cbff3c7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjit%2F&secure%5Burl_type%5D=linkedin_company_website)  
150 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 44% Medium, 42% Small

#### What Do G2 Reviewers Say About Jit?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **seamless integration of security into development workflows** , highlighting efficiency and centralized management.
- Users find Jit to be **very easy to use** , streamlining integration of security into development workflows effectively.
- Users love the **easy integrations** of Jit, streamlining security within their development workflows effortlessly.
- Users appreciate the **efficiency** of Jit, which reduces waste and streamlines processes, enhancing overall productivity.
- Users value the **automation of security controls** in Jit, streamlining workflows and enhancing efficiency in development processes.

##### Cons

- Users face **integration issues** with Jit, particularly in enterprise environments and with certain CI tools requiring extra setup.
- Users find the **limited features** of Jit restrict complex setups and hinder comprehensive analytics and reporting.
- Users feel the **limited integration** with enterprise environments restricts Jit's full potential and usability.
- Users find the **documentation lacking** , particularly for advanced configurations, impacting their overall experience with Jit.
- Users find the **complexity** of Jit challenging, particularly with advanced integrations and configuration for newcomers.

#### What Are Recent G2 Reviews of Jit?

**["Exploring jit a personal review"](https://www.g2.com/survey_responses/jit-review-11751139)**

**Rating:** 4.0/5.0 stars

_— Mohamed A._

[Read full review](https://www.g2.com/survey_responses/jit-review-11751139)

**["Helpful Tool for Integrating Security in Mobile App Development"](https://www.g2.com/survey_responses/jit-review-11750234)**

**Rating:** 4.0/5.0 stars

_— Ali A._

[Read full review](https://www.g2.com/survey_responses/jit-review-11750234)

[
CB Protection
](https://www.g2.com/products/carbon-black-app-control/reviews)

By [Broadcom](https://www.g2.com/sellers/broadcom-ab3091cd-4724-46a8-ac89-219d6bc8e166)

[

4.6/5(45)

](https://www.g2.com/products/carbon-black-app-control/reviews)

What do users say?

Users consistently praise the product for its granular control over application installations, which enhances security and compliance. The intuitive interface and ease of implementation allow organiza

Pros and Cons

[
Security (2)
](https://www.g2.com/products/carbon-black-app-control/reviews?qs=pros-and-cons)[
False Positives (2)
](https://www.g2.com/products/carbon-black-app-control/reviews?qs=pros-and-cons)

### [Carbon Black App Control](https://www.g2.com/products/carbon-black-app-control/reviews)

With the rise of security threats and malware, organizations need technologies to combat these risks. Unplanned downtime and performance degradation from security breaches impact productivity and reputation. As IT and security shift to the cloud, it's crucial to stay vigilant about security gaps. Many companies still rely on air-gapped servers or outdated operating systems (EOL OS) for critical systems and data storage. Carbon Black App Control offers proactive security for data centers, AWS, Azure, GCP, or hosted private clouds. App Control ensures trusted software runs, monitors file integrity, controls devices, protects memory and registry keys on Windows.

**Average Rating:** 4.6/5.0

**Total Reviews:** 44

#### Who Is the Company Behind Carbon Black App Control?

- **Seller:** [Broadcom](https://www.g2.com/sellers/broadcom-ab3091cd-4724-46a8-ac89-219d6bc8e166)
- **Year Founded:** 1991
- **HQ Location:** San Jose, CA
- **Twitter:** @broadcom  
63,909 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=093adce8015fea9ef126312884b465dc8e3c20e17dcb12fbb77a7bd82577e7a5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fbroadcom%2F&secure%5Burl_type%5D=linkedin_company_website)  
55,094 employees on LinkedIn®
- **Ownership:** NASDAQ: CA

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 64% Large, 33% Medium

#### What Do G2 Reviewers Say About Carbon Black App Control?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **enhanced security** of Carbon Black App Control, successfully preventing unauthorized applications and reducing attack surfaces.
- Users admire the **excellent customer support** of Carbon Black App Control, enhancing security confidence and compliance effectively.
- Users value the **ease of use and implementation** of Carbon Black App Control, enhancing their security confidence.
- Users appreciate the **easy implementation** of Carbon Black App Control, which enhances security and compliance seamlessly.
- Users highlight the **easy integrations** of Carbon Black App Control, enhancing security with minimal implementation effort.

##### Cons

- Users sometimes face **false positives** with Carbon Black App Control, which can lead to unnecessary alerts and complications.
- Users note that the pricing can be **on the higher side** for smaller organizations, impacting accessibility.
- Users often experience **high CPU usage** with Carbon Black App Control, leading to performance concerns and false alerts.
- Users often face **memory issues** with Carbon Black due to high CPU and memory utilization, along with false alerts.
- Users face **slow performance** due to high CPU and memory usage, leading to frustration with false alerts.

#### What Are Recent G2 Reviews of Carbon Black App Control?

**["Powerful Application Control enabling Enhanced Security"](https://www.g2.com/survey_responses/carbon-black-app-control-review-10387482)**

**Rating:** 4.5/5.0 stars

_— Prajwal V._

[Read full review](https://www.g2.com/survey_responses/carbon-black-app-control-review-10387482)

**["Carbon Black Review"](https://www.g2.com/survey_responses/carbon-black-app-control-review-9186031)**

**Rating:** 4.0/5.0 stars

_— Abhiuday M._

[Read full review](https://www.g2.com/survey_responses/carbon-black-app-control-review-9186031)

#### What Are G2 Users Discussing About Carbon Black App Control?

- [Does Carbon Black do file integrity monitoring?](https://www.g2.com/discussions/does-carbon-black-do-file-integrity-monitoring)
- [How does Carbon Black EDR work?](https://www.g2.com/discussions/how-does-carbon-black-edr-work)
- [What are the benefits of VMware carbon black to organizations?](https://www.g2.com/discussions/what-are-the-benefits-of-vmware-carbon-black-to-organizations)
- [What does Carbon Black App Control do?](https://www.g2.com/discussions/what-does-carbon-black-app-control-do)

[
Invicti (formerly Netsparker)
](https://www.g2.com/products/invicti-formerly-netsparker/reviews)

By [Invicti Security](https://www.g2.com/sellers/invicti-security-04cb0d3d-fd96-45b2-83dc-2038fc9dac92)

[

4.5/5(72)

](https://www.g2.com/products/invicti-formerly-netsparker/reviews)

What do users say?

Users consistently praise the product for its accuracy and ease of use, noting that it effectively identifies real vulnerabilities without generating excessive false positives. The integration with CI

Pros and Cons

[
Ease of Use (9)
](https://www.g2.com/products/invicti-formerly-netsparker/reviews?qs=pros-and-cons)[
Poor Customer Support (3)
](https://www.g2.com/products/invicti-formerly-netsparker/reviews?qs=pros-and-cons)

### [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews)

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

**Average Rating:** 4.5/5.0

**Total Reviews:** 69

#### Who Is the Company Behind Invicti (formerly Netsparker)?

- **Seller:** [Invicti Security](https://www.g2.com/sellers/invicti-security-04cb0d3d-fd96-45b2-83dc-2038fc9dac92)
- **Company Website:** www.invicti.com
- **Year Founded:** 2018
- **HQ Location:** Austin, Texas
- **Twitter:** @InvictiSecurity  
2,557 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3c6c2278d6d9ef248056074aabb5416f9e0b5bf217ea8a7bfb87419d2894bc76&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Finvicti-security%2Fpeople%2F&secure%5Burl_type%5D=linkedin_company_website)  
335 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 46% Large, 29% Medium

#### What Do G2 Reviewers Say About Invicti (formerly Netsparker)?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of Invicti, appreciating its user-friendly setup and quick installation process.
- Users value the **efficient scanning technology** of Invicti, enhancing workflow with hassle-free monthly website tests.
- Users commend Invicti's **accurate vulnerability detection and excellent integration with DevOps tools** , enhancing their security testing efficiency.
- Users value the **high-quality reporting** of Invicti, making it ideal for certifications and simplifying compliance processes.
- Users value the **effective vulnerability detection** of Invicti, appreciating its ease of use and accurate reporting.

##### Cons

- Users find the **customer support lacking** , with slow responses and inadequate solutions for technical issues.
- Users experience **slow performance** during scans, setup, and upgrades, impacting the overall efficiency of Invicti.
- Users find that **slow scanning** can hinder efficiency, especially when setup is tricky and API scanning is limited.
- Users face **API issues** with Invicti, making it unsuitable for scanning purposes despite good support.
- Users find the **complex setup** challenging initially, impacting their experience before they can effectively utilize the product.

#### What Are Recent G2 Reviews of Invicti (formerly Netsparker)?

**["Efficient Scanning, Superb Usability"](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-13155895)**

**Rating:** 4.5/5.0 stars

_— Zach G._

[Read full review](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-13155895)

**["Scalable Enterprise Security: Deep Endpoint Coverage via Invicti"](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-12742667)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-12742667)

#### What Are G2 Users Discussing About Invicti (formerly Netsparker)?

- [What is Invicti (formerly Netsparker) used for?](https://www.g2.com/discussions/what-is-invicti-formerly-netsparker-used-for) - 1 comment
- [What type of vulnerabilities Netsparker can automatically confirm?](https://www.g2.com/discussions/invicti-formerly-netsparker-what-type-of-vulnerabilities-netsparker-can-automatically-confirm)
- [What type of vulnerabilities Netsparker can automatically confirm?](https://www.g2.com/discussions/what-type-of-vulnerabilities-netsparker-can-automatically-confirm)
- [How much does Netsparker cost?](https://www.g2.com/discussions/invicti-formerly-netsparker-how-much-does-netsparker-cost-a1ecffa4-a216-4bcc-affd-40dc140f3e27)
- [How much does Netsparker cost?](https://www.g2.com/discussions/invicti-formerly-netsparker-how-much-does-netsparker-cost)

[
APPCHECK
](https://www.g2.com/products/appcheck/reviews)

By [APPCHECK](https://www.g2.com/sellers/appcheck)

[

4.6/5(67)

](https://www.g2.com/products/appcheck/reviews)

What do users say?

Users consistently praise the ease of use and thorough vulnerability scanning provided by AppCheck, which simplifies the complex process of security testing. Many appreciate the responsive support tea

Pros and Cons

[
Vulnerability Detection (7)
](https://www.g2.com/products/appcheck/reviews?qs=pros-and-cons)[
Poor Customer Support (2)
](https://www.g2.com/products/appcheck/reviews?qs=pros-and-cons)

### [APPCHECK](https://www.g2.com/products/appcheck/reviews)

AppCheck is a Dynamic Application Security Testing (DAST) and network vulnerability testing solution, developed and supported by experienced penetration testers. We approach security testing as a hacker would, leveraging multiple proprietary crawling engines to analyse target behaviour across both modern and traditional technologies, including Single Page Applications (SPAs), APIs, and complex authentication flows such as SSO, 2FA, and TOTP. Organisations can conduct unlimited security assessments across Web Applications, SPAs, APIs, cloud services, networks, across internal or external assets. Supporting production and UAT testing, AppCheck also helps organisations ‘shift left’ by integrating with CI/CD pipelines and build servers, including ADO, GitHub, Jenkins, TeamCity, CircleCI, TravisCI, Bamboo, and GitLab CI/CD. Allowing automated security testing throughout development, identifying risks as soon as changes are introduced. AppCheck are proud to be part of the CVE Numbering Authority (CNA), contributing to global security research

**Average Rating:** 4.6/5.0

**Total Reviews:** 67

#### Who Is the Company Behind APPCHECK?

- **Seller:** [APPCHECK](https://www.g2.com/sellers/appcheck)
- **Company Website:** www.appcheck-ng.com
- **Year Founded:** 2014
- **HQ Location:** Leeds, GB
- **Twitter:** @AppcheckNG  
649 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=549c2b4af47894c058c47c213d419ff9cf92c7465ec55dd23e8a822f291b824c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fappcheck-ng-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
106 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 49% Medium, 30% Small

#### What Do G2 Reviewers Say About APPCHECK?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **effective vulnerability detection** of AppCheck, which outshines competitors in thoroughness and ease of use.
- Users find the **ease of use** of AppCheck invaluable, simplifying complex security processes effectively and efficiently.
- Users appreciate the **excellent pricing and functionality** of AppCheck, enhancing their vulnerability management and reporting capabilities.
- Users commend AppCheck for its **exceptional pentesting efficiency** , significantly enhancing vulnerability detection and streamlining security processes.
- Users appreciate the **automated scanning** of AppCheck, benefiting from detailed reports and seamless integration with CI/CD pipelines.

##### Cons

- Users find the **poor customer support** frustrating, as they must submit tickets for simple changes.
- Users feel that **UX improvement** is necessary, particularly in scoring systems, customization, and starting points for scans.
- Users find the **API endpoint changes cumbersome** , relying on service requests instead of having direct control.
- Users find **difficult customization** options in AppCheck, limiting the ability to tailor reports and vulnerability scoring.
- Users note a significant **difficult learning curve** with Appcheck, which can hinder initial usability and efficiency.

#### What Are Recent G2 Reviews of APPCHECK?

**["Effortless Vulnerability Management with APPCHECK"](https://www.g2.com/survey_responses/appcheck-review-12463853)**

**Rating:** 5.0/5.0 stars

_— Aaron H._

[Read full review](https://www.g2.com/survey_responses/appcheck-review-12463853)

**["Great onboarding experience and trial"](https://www.g2.com/survey_responses/appcheck-review-11771398)**

**Rating:** 4.0/5.0 stars

_— Tyler S._

[Read full review](https://www.g2.com/survey_responses/appcheck-review-11771398)

[
Strobes Security
](https://www.g2.com/products/strobes-security/reviews)

By [Strobes Security Inc](https://www.g2.com/sellers/strobes-security-inc)

[

4.6/5(35)

](https://www.g2.com/products/strobes-security/reviews)

What do users say?

Users consistently praise the platform for its ease of use and streamlined vulnerability management, which simplifies the process of identifying and addressing security issues. The intuitive interface

Pros and Cons

[
Vulnerability Identification (14)
](https://www.g2.com/products/strobes-security/reviews?qs=pros-and-cons)[
Inadequate Reporting (4)
](https://www.g2.com/products/strobes-security/reviews?qs=pros-and-cons)

### [Strobes Security](https://www.g2.com/products/strobes-security/reviews)

Strobes is an AI-driven exposure management platform designed to help organizations streamline their security operations by unifying various security methodologies, including Attack Surface Management (ASM), Application Security Posture Management (ASPM), Risk-Based Vulnerability Management (RBVM), and Penetration Testing as a Service (PTaaS). This comprehensive solution provides users with a holistic view of their security posture, enabling them to identify, assess, and respond to potential risks and vulnerabilities effectively. Targeted primarily at security teams and IT professionals, Strobes caters to organizations of all sizes that require a robust approach to managing their security exposure. The platform is particularly beneficial for those who need to navigate the complexities of modern security environments, where multiple tools and processes can lead to fragmented insights. By consolidating various security functions into a single workflow, Strobes empowers users to make informed decisions based on a complete understanding of their risk landscape. One of the key features of Strobes is its extensive integration capabilities, boasting over 120 integrations with existing security tools and systems. This allows organizations to pull findings from disparate sources into a single view, enriching data with contextual information that enhances the relevance of insights. The platform's advanced correlation capabilities help identify relationships between different vulnerabilities and risks, enabling security teams to prioritize their remediation efforts effectively. The user-friendly dashboards in Strobes serve as a central hub for monitoring security activities, encompassing everything from asset discovery and vulnerability insights to Service Level Agreement (SLA) tracking and ticketing. This comprehensive visibility supports continuous prioritization and fix validation, allowing teams to address the most critical issues first. By automating triage processes, Strobes ensures that real risks and exposures are highlighted, facilitating a more efficient response to potential threats. Overall, Strobes stands out in the exposure management landscape by providing a cohesive and intelligent approach to security management. Its ability to unify various methodologies, coupled with powerful automation and integration features, positions it as a valuable tool for organizations seeking to enhance their security posture and effectively manage their exposure to risks.

**Average Rating:** 4.6/5.0

**Total Reviews:** 34

#### Who Is the Company Behind Strobes Security?

- **Seller:** [Strobes Security Inc](https://www.g2.com/sellers/strobes-security-inc)
- **Company Website:** www.strobes.co
- **Year Founded:** 2019
- **HQ Location:** Plano, US
- **Twitter:** @StrobesHQ  
218 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=f9bd3984d9a343de887a22a2403ea2381378c1c59707d61385d0ce4e66687075&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fstrobeshq&secure%5Burl_type%5D=linkedin_company_website)  
97 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 37% Large, 37% Medium

#### What Do G2 Reviewers Say About Strobes Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **thorough vulnerability identification** by Strobes, appreciating detailed insights and actionable remediation suggestions.
- Users commend Strobes Security for its **robust vulnerability detection** , providing precise fixes that enhance security efficiency.
- Users value the **comprehensive security insights** provided by Strobes, enhancing vulnerability management and productivity significantly.
- Users value the **proactive customer support** of Strobes Security, noting quick responses and detailed follow-ups for issues.
- Users find Strobes Security's **ease of use** refreshing, with a clean interface streamlining vulnerability management effectively.

##### Cons

- Users criticize the **inadequate reporting** of Strobes Security, highlighting the need for improved transparency and customization options.
- Users find the **limited customization options** of Strobes Security challenging, affecting initial setup and usability.
- Users find Strobes Security's **poor usability** frustrating, noting a steep learning curve and difficulty in navigating features.
- Users find the **reporting issues** in Strobes Security frustrating, lacking transparency and flexibility for effective data management.
- Users find the **UI complex** , noting a learning curve for customization and slow loading for advanced features.

#### What Are Recent G2 Reviews of Strobes Security?

**["Valuable Security Assessments with Practical Findings"](https://www.g2.com/survey_responses/strobes-security-review-12795666)**

**Rating:** 4.5/5.0 stars

_— Apoorva J._

[Read full review](https://www.g2.com/survey_responses/strobes-security-review-12795666)

**["Comprehensive and Reliable Attack Surface Management Solution"](https://www.g2.com/survey_responses/strobes-security-review-12638010)**

**Rating:** 5.0/5.0 stars

_— Divya D._

[Read full review](https://www.g2.com/survey_responses/strobes-security-review-12638010)

[
ActiveState
](https://www.g2.com/products/activestate/reviews)

By [ActiveState](https://www.g2.com/sellers/activestate-fd82e7c7-dea3-4ff5-9e96-cc5cd7d39a87)

[

4.1/5(35)

](https://www.g2.com/products/activestate/reviews)

What do users say?

Users consistently praise the platform for its ease of use and collaboration features, making it a valuable tool for managing open-source projects and dependencies. Many appreciate the time-saving cap

### [ActiveState](https://www.g2.com/products/activestate/reviews)

ActiveState provides the world's largest library of secure open source: 79 million (Java, Javascript, Python, R, Go, etc.) vetted components across all major language ecosystems, including transitive dependencies and OS-level libraries—built from source to ensure every component is verified, vulnerability-free, and continuously updated. Software teams improve security posture while accelerating development velocity. We deliver five critical outcomes. Counter Supply Chain Risks at Their Source Significantly reduce the possibility of inheriting malicious code from pre-built binaries. Replace risky, unvetted public components with secure, verifiable packages built directly from source. Gain provenance over your artifacts, ensuring bad actors and malware never reach your environment. - Protection from compromised package ecosystems and build systems - Mitigate high-profile malware attacks such as the npm Shai-Hulud attack and other future threats Continuous Remediation for Your Open Source Inventory Shift from reactive patching to proactive immunity. Maintain a hardened security posture with safe-by-default open source and continuous remediation across your inventory. ActiveState artifacts reduce your attack surface and evolve to help close vulnerabilities before they become incidents. - Up to 99% reduction in CVEs compared to community open source artifacts - Achieve up to 90% reduction in MTTR for future vulnerabilities Apply Frictionless Security Policies Embed governance directly into developer workflows without impeding engineering or adding costly CI/CD bloat. ActiveState solutions slot seamlessly into existing tools and AI coding assistants, transforming security policy from a blocker into an enabler that reduces open source approval workflows from weeks and days to just hours and minutes. - Reduce open source approval workflows from weeks and days to hours and minutes Audit Ready Compliance, Always Achieve continuous compliance with instant, granular visibility into components, licenses, and dependencies across your organization. ActiveState delivers comprehensive SBOMs and metadata by default, ensuring you can meet complex standards and minimizing the scramble of audit preparation. - Full visibility into your open source usage, including transitive and OS level dependencies Reclaim Developer Velocity and Focus Minimize high-value engineering hours on dependency conflicts, environment setup, research and remediation. ActiveState components and artifacts are fully managed to ensure they are always up to date and safe to use so your team can focus entirely on shipping revenue-generating features. - Free up 4-8 developer hours per CVE - 68% reduction in scanner noise from false positives

**Average Rating:** 4.1/5.0

**Total Reviews:** 32

#### Who Is the Company Behind ActiveState?

- **Seller:** [ActiveState](https://www.g2.com/sellers/activestate-fd82e7c7-dea3-4ff5-9e96-cc5cd7d39a87)
- **Company Website:** www.activestate.com
- **Year Founded:** 1997
- **HQ Location:** Vancouver, BC
- **Twitter:** @ActiveState  
4,014 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=54ce0d1abc2408eca9f1dd938d649e059c97258b26b72553b4fa8dd7d56aee88&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5052%2F&secure%5Burl_type%5D=linkedin_company_website)  
74 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Computer & Network Security
- **Company Size:** 51% Small, 29% Medium

#### What Are Recent G2 Reviews of ActiveState?

**["Very easy to use and very helpful"](https://www.g2.com/survey_responses/activestate-review-6964391)**

**Rating:** 5.0/5.0 stars

_— Saurav S._

[Read full review](https://www.g2.com/survey_responses/activestate-review-6964391)

**["Super easy to use platform, makes building code way less of a hassle"](https://www.g2.com/survey_responses/activestate-review-6961997)**

**Rating:** 5.0/5.0 stars

_— Alexander H._

[Read full review](https://www.g2.com/survey_responses/activestate-review-6961997)

#### What Are G2 Users Discussing About ActiveState?

- [What is ActivePerl used for?](https://www.g2.com/discussions/what-is-activeperl-used-for)
- [What is the difference between Python and ActivePython?](https://www.g2.com/discussions/what-is-the-difference-between-python-and-activepython) - 1 comment
- [What is ActiveState platform?](https://www.g2.com/discussions/what-is-activestate-platform)

[
Edgescan
](https://www.g2.com/products/edgescan/reviews)

By [Edgescan](https://www.g2.com/sellers/edgescan)

[

4.6/5(59)

](https://www.g2.com/products/edgescan/reviews)

What do users say?

Users consistently praise the product for its human-validated results and ease of use, which enhance the accuracy of vulnerability management. The combination of automated scanning with expert review

Pros and Cons

[
Ease of Use (25)
](https://www.g2.com/products/edgescan/reviews?qs=pros-and-cons)[
Complex UI (5)
](https://www.g2.com/products/edgescan/reviews?qs=pros-and-cons)

### [Edgescan](https://www.g2.com/products/edgescan/reviews)

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

**Average Rating:** 4.6/5.0

**Total Reviews:** 57

#### Who Is the Company Behind Edgescan?

- **Seller:** [Edgescan](https://www.g2.com/sellers/edgescan)
- **Company Website:** www.edgescan.com
- **Year Founded:** 2017
- **HQ Location:** Dublin, Dublin
- **Twitter:** @edgescan  
2,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=51edeb949934c6f870f2d6720fefabf6632464f3895af4d8276b3c60c0fe37db&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2928425%2F&secure%5Burl_type%5D=linkedin_company_website)  
89 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 37% Large, 29% Medium

#### What Do G2 Reviewers Say About Edgescan?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate Edgescan's **ease of use** , enjoying its intuitive interface and streamlined navigation for effective vulnerability management.
- Users value the **automated vulnerability detection** with intuitive reports, timely alerts, and effective risk management features.
- Users value the **excellent customer support** from Edgescan, praising the team's responsiveness and proactive assistance.
- Users value the **thorough vulnerability identification** features of Edgescan, enhancing risk management and resolution efficiency.
- Users value the **robust features** of Edgescan, which streamline security assessments and enhance ease of use.

##### Cons

- Users find the **complex UI** challenging initially, with navigation issues and a need for improved dashboard functionality.
- Users highlight **limited customization** options in Edgescan, particularly regarding filtering and admin functionalities.
- Users find the **poor interface design** of Edgescan challenging, affecting usability and data accessibility.
- Users report experiencing **slow performance** as scans can take longer due to manual review processes.
- Users find the **UI not user friendly** , lacking intuitiveness and advanced features for better navigation and data accessibility.

#### What Are Recent G2 Reviews of Edgescan?

**["Efficient Vulnerability Scanning with Easy Navigation"](https://www.g2.com/survey_responses/edgescan-review-12218850)**

**Rating:** 5.0/5.0 stars

_— Simon L._

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12218850)

**["Edgescan: Easy Setup, Clear Insights, and Expert Security Support"](https://www.g2.com/survey_responses/edgescan-review-12224347)**

**Rating:** 5.0/5.0 stars

_— Matt W._

[Read full review](https://www.g2.com/survey_responses/edgescan-review-12224347)

#### What Are G2 Users Discussing About Edgescan?

- [What is edgescan used for?](https://www.g2.com/discussions/what-is-edgescan-used-for) - 1 comment

[
Mend.io
](https://www.g2.com/products/mend-io/reviews)

By [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)

[

4.3/5(116)

](https://www.g2.com/products/mend-io/reviews)

What do users say?

Users consistently praise the product for its ease of use and effective integration with CI/CD pipelines, which simplifies vulnerability management and dependency tracking. Many appreciate the compreh

Pros and Cons

[
Scanning Efficiency (8)
](https://www.g2.com/products/mend-io/reviews?qs=pros-and-cons)[
Integration Issues (6)
](https://www.g2.com/products/mend-io/reviews?qs=pros-and-cons)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 110

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
257 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 36% Small, 34% Medium

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories.
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities.
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security.
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes.

##### Cons

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging.
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases.
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration.
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives.
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Great Tool for Managing 3rd party libraries"](https://www.g2.com/survey_responses/mend-io-review-6728890)**

**Rating:** 4.5/5.0 stars

_— Johannes B._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-6728890)

**["Effortless Integration with Budget-Friendly Scanning"](https://www.g2.com/survey_responses/mend-io-review-4261734)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/mend-io-review-4261734)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

[
Whitespots Security Portal
](https://www.g2.com/products/whitespots-security-portal/reviews)

By [Whitespots](https://www.g2.com/sellers/whitespots)

[

5/5(10)

](https://www.g2.com/products/whitespots-security-portal/reviews)

What do users say?

Users consistently praise the intuitive UI and automation features of Whitespots Security Portal, which streamline vulnerability management and enhance overall security monitoring. The platform integr

Pros and Cons

[
Easy Setup (4)
](https://www.g2.com/products/whitespots-security-portal/reviews?qs=pros-and-cons)[
Poor Analytics (1)
](https://www.g2.com/products/whitespots-security-portal/reviews?qs=pros-and-cons)

### [Whitespots Security Portal](https://www.g2.com/products/whitespots-security-portal/reviews)

Vulnerability management tool on steroids 📈 Measure and control your application security state; 🔎 Scan your code, containers, web and mobile applications using ANY tool; 🔥 Remove duplicates, validate results, comment merge requests and create Jira tasks in seconds; 🕜 Save your engineers time and automate your processes; ✅ Self-hosted

**Average Rating:** 5.0/5.0

**Total Reviews:** 10

#### Who Is the Company Behind Whitespots Security Portal?

- **Seller:** [Whitespots](https://www.g2.com/sellers/whitespots)
- **Year Founded:** 2020
- **HQ Location:** Tallinn, EE
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=20ff2385668cb267298f8b1a9b9c650a8ad039ecadc164b9c55ed735283f717d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fwhitespots%2F&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Medium, 20% Small

#### What Do G2 Reviewers Say About Whitespots Security Portal?

_AI-generated summary from verified user reviews_

##### Pros

- Users find the **easy setup** of Whitespots Security Portal effortless, enhancing workflow and minimizing complications.
- Users praise the **seamless integration** of Whitespots Security Portal into workflows, enhancing productivity and monitoring efficiency.
- Users love the **effortless integration** of Whitespots Security Portal, enhancing their workflow and saving time on security tasks.
- Users appreciate the **intuitive UI** of Whitespots Security Portal, facilitating quick monitoring and efficient task management.
- Users value the **enhanced vulnerability monitoring** of Whitespots Security Portal, significantly improving overall security and efficiency.

##### Cons

- Users mention **poor analytics** , noting it lacks specialized reports for managerial needs but request potential improvements.
- Users find the **poor documentation** challenging, particularly for advanced features and initial configuration, impacting usability.
- Users find the interface not always **user-friendly** , but appreciate that issues are resolved upon request.

#### What Are Recent G2 Reviews of Whitespots Security Portal?

**["Simple, Reliable for Everyday Security Needs"](https://www.g2.com/survey_responses/whitespots-security-portal-review-11191394)**

**Rating:** 5.0/5.0 stars

_— Daniil M._

[Read full review](https://www.g2.com/survey_responses/whitespots-security-portal-review-11191394)

**["A reliable and intuitive security management platform"](https://www.g2.com/survey_responses/whitespots-security-portal-review-11178920)**

**Rating:** 5.0/5.0 stars

_— Shohrukh A._

[Read full review](https://www.g2.com/survey_responses/whitespots-security-portal-review-11178920)

[
Flyingduck
](https://www.g2.com/products/flyingduck/reviews)

By [Flyingduck](https://www.g2.com/sellers/flyingduck)

[

5/5(4)

](https://www.g2.com/products/flyingduck/reviews)

Product Description

Flyingduck is a Comprehensive Code security Intelligence platform that identifies and remediates security vulnerabilities in the code base. Key modules are SBOM Compliance, SCA, SAST, Secrets Analysis

### [Flyingduck](https://www.g2.com/products/flyingduck/reviews)

Flyingduck is a Comprehensive Code security Intelligence platform that identifies and remediates security vulnerabilities in the code base. Key modules are SBOM Compliance, SCA, SAST, Secrets Analysis. We also identify Business Logic Issues in the code such as OTP Bypass, Transaction Manipulation type issues with our Deep Logic Analysis AI engine.

**Average Rating:** 5.0/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Flyingduck?

- **Seller:** [Flyingduck](https://www.g2.com/sellers/flyingduck)
- **Year Founded:** 2024
- **HQ Location:** Hyderabad, IN
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9a551d88df8db9021dbdf960c481cf5649749b8acee083c43b633ed0cf9cdb4b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fflyingduck-cyber-security-genai-shiftleftsecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
11 employees on LinkedIn®
- **Ownership:** Sarat Lingamallu
- **Phone:** +919550681242

#### Who Uses This Product?

- **Company Size:** 75% Medium, 25% Small

#### What Are Recent G2 Reviews of Flyingduck?

**["Continuous Security Insights with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/flyingduck-review-12174073)**

**Rating:** 5.0/5.0 stars

_— Naveen P._

[Read full review](https://www.g2.com/survey_responses/flyingduck-review-12174073)

**["Centralized Security Scans Made Effortless and Effective"](https://www.g2.com/survey_responses/flyingduck-review-12081490)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/flyingduck-review-12081490)

[
AccuKnox
](https://www.g2.com/products/accuknox/reviews)

By [Accuknox](https://www.g2.com/sellers/accuknox)

[

4.4/5(13)

](https://www.g2.com/products/accuknox/reviews)

What do users say?

Users consistently praise the product for its user-friendly interface and robust security features, highlighting its effectiveness in providing continuous compliance and runtime protection. Many appre

Pros and Cons

[
Comprehensive Security (5)
](https://www.g2.com/products/accuknox/reviews?qs=pros-and-cons)[
Difficult Learning (3)
](https://www.g2.com/products/accuknox/reviews?qs=pros-and-cons)

### [AccuKnox](https://www.g2.com/products/accuknox/reviews)

AccuKnox Zero Trust CNAPP cloud security protects public and private clouds, Kubernetes and VMs. AccuKnox is a AI-powered Zero Trust Cloud Native Security Platform that helps organizations comply with various frameworks and over 33+ compliance controls, including MITRE, NIST, STIG, CIS, PCI-DSS, GDPR, and SOC2. AccuKnox enhances InfraSec and DevSecOps teams by enabling them to detect, prioritize, prevent and protect against advanced and sophisticated cloud attacks. Key Benefits 1. Code to Cloud Security 2. Easy Deployment 3. Extensive Coverage. 4. Preemptive Attack Mitigation 5. Open Source and Innovative Key Differentiators - Inline Preemptive Security (as opposed to Post-attack mitigation) - Secures modern workloads (Kubernetes) and traditional workloads (VMs) - Multi-Cloud, Private, Air-gapped, and Hybrid Cloud Security - IaC – Infrastructure As Code scanning - Secures AI/ML workloads like Jupyter Notebooks Features - Automated Zero Trust Cloud Security (Public, Private, Hybrid, Air-gapped) - Vulnerability Management & Prioritization - Run-time security, Micro-segmentation - Application Firewalling, Kernel Hardening - Drift Detection & Audit Trail - Continuous Diagnostics & Mitigation - GRC – CIS, HIPAA, GDPR, SOC2, STIG, MITRE, NIST - Securing Mission-Critical Workloads like Vault - Securing AI workbenches like Jupyter Notebooks - Cryptojacking and TNTBotinger Attacks With over 15+ patents, we're proud to offer an OpenSource, DevSecOps-led delivery model. To top it off, we have an ongoing R&D partnership with the esteemed SRI International. We deliver both Static and Runtime Security, anchored on innovations in Cloud Security and AI/ML-based Anomaly Detection. Static Code Analysis - Deeply analyze your code for vulnerabilities and weaknesses. CI/CD Pipelines Scanning - Continuously scan your pipelines for security flaws and risks. Container Security - Fortify your containers with robust security measures. Kubernetes Orchestration - Seamlessly manage and secure your Kubernetes environments. Secret Scanning - Detect and protect sensitive information from unauthorized access.

**Average Rating:** 4.4/5.0

**Total Reviews:** 12

#### Who Is the Company Behind AccuKnox?

- **Seller:** [Accuknox](https://www.g2.com/sellers/accuknox)
- **Year Founded:** 2020
- **HQ Location:** California, USA
- **Twitter:** @AccuKnox  
341 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c15a1a00305354f8e770c469c551b7cc7aead95829f7289e088c2caa17c4a6e3&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faccuknox&secure%5Burl_type%5D=linkedin_company_website)  
180 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 46% Large, 31% Medium

#### What Do G2 Reviewers Say About AccuKnox?

_AI-generated summary from verified user reviews_

##### Pros

- Users highly value the **comprehensive security** offered by AccuKnox, effectively managing tools across various platforms.
- Users value the **high security level** of AccuKnox, effectively enhancing protection across their cloud environments and tools.
- Users value the **seamless cloud integration** of AccuKnox, enhancing security and compliance effortlessly across platforms.
- Users value the **seamless compliance management** of AccuKnox, enhancing security across cloud workloads and integrations.
- Users commend the **exceptional customer support** from AccuKnox, praising their responsiveness and deep product knowledge.

##### Cons

- Users find the **difficult learning curve** challenging, especially with complex setup and Kubernetes knowledge required.
- Users find the **complex setup** challenging, particularly for those with limited security expertise in their organizations.
- Users find the solution **cost prohibitive** , making it a potential barrier for many customers.
- Users find the **poor customer support** frustrating, as response times are slow and require follow-ups.
- Users find the **complex setup** of AccuKnox challenging, particularly for those with limited security knowledge.

#### What Are Recent G2 Reviews of AccuKnox?

**["Having performed PoC with the product and involved with discussions with the team - excellent!"](https://www.g2.com/survey_responses/accuknox-review-10934962)**

**Rating:** 5.0/5.0 stars

_— Ashleigh W._

[Read full review](https://www.g2.com/survey_responses/accuknox-review-10934962)

**["Right set of Solution building blocks to address complex CloudSec challenges"](https://www.g2.com/survey_responses/accuknox-review-10731493)**

**Rating:** 5.0/5.0 stars

_— Dinakar R._

[Read full review](https://www.g2.com/survey_responses/accuknox-review-10731493)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/application-security-posture-management-aspm?order=g2_score&page=2#product-list)
- [3](/categories/application-security-posture-management-aspm?order=g2_score&page=3#product-list)
- [Next &rsaquo;Next ›](/categories/application-security-posture-management-aspm?order=g2_score&page=2#product-list)

Spotlight Categories

[Expense Management Software](https://www.g2.com/categories/expense-management)

[Quality Management Systems (QMS)](https://www.g2.com/categories/quality-management-qms)

[Compensation Management Software](https://www.g2.com/categories/compensation-management)

[Customer Service Automation Software](https://www.g2.com/categories/customer-service-automation)

[Applicant Tracking Systems (ATS)](https://www.g2.com/categories/applicant-tracking-systems-ats)

Similar Categories

- [API Security](/categories/api-security)
- [Cloud Compliance](/categories/cloud-compliance)
- [Cloud Data Security](/categories/cloud-data-security)
- [Cloud Detection and Response (CDR)](/categories/cloud-detection-and-response-cdr)
- [Cloud Edge Security](/categories/cloud-edge-security)

- [Cloud File Security](/categories/cloud-file-security)
- [Cloud Infrastructure Entitlement Management (CIEM)](/categories/cloud-infrastructure-entitlement-management-ciem)
- [Cloud-Native Application Protection Platform (CNAPP)](/categories/cloud-native-application-protection-platform-cnapp)
- [Cloud Security Monitoring and Analytics](/categories/cloud-security-monitoring-and-analytics)
- [Cloud Security Posture Management (CSPM)](/categories/cloud-security-posture-management-cspm)

- [Cloud Workload Protection Platforms](/categories/cloud-workload-protection-platforms)
- [Extended Detection and Response (XDR) Platforms](/categories/extended-detection-and-response-xdr-platforms)
- [SaaS Security Posture Management (SSPM) Solutions](/categories/saas-security-posture-management-sspm-solutions)
- [Secure Access Service Edge (SASE) Platforms](/categories/secure-access-service-edge-sase-platforms)
- [Secure Service Edge (SSE) Solutions](/categories/secure-service-edge-sse-solutions)

[Browse Application Security Posture Management (ASPM) Themes](/categories/application-security-posture-management-aspm/themes)

 ![Lauren Worth](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Lauren Worth")
LW

Researched and written by [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)

Updated October 3, 2024

Application security posture management (ASPM) is a comprehensive cybersecurity solution that focuses on safeguarding software applications from potential threats. The process involves continuously assessing, monitoring, and enhancing an organization's application security posture. ASPM encompasses various technologies to identify and mitigate security risks in software applications. It helps companies with visibility, risk identification, and remediation recommendations. This software aids security teams, DevOps, and IT administration to manage compliance, prioritize risks, and handle vulnerabilities.

Application security posture management (ASPM) solutions offer unique capabilities that distinguish them from other cybersecurity tools like [security information and event management (SIEM) systems](https://www.g2.com/categories/security-information-and-event-management-siem) and vulnerability scanners. Unlike these tools, which identify, assess, and mitigate security risks, ASPM is specifically tailored to the security of software applications. It provides a holistic picture of application security health and integrates with the development lifecycle for proactive security measures.

To qualify for inclusion in the ASPM category, a product must:

- Help prioritize and address the most critical security issues and recommend how to remediate vulnerabilities and weaknesses
- Scan and analyze software applications to identify vulnerabilities, misconfigurations, and weaknesses in the code, libraries, and configurations
- Actively monitor applications for signs of malicious activity and potential security breaches, using techniques such as behavioral analysis and anomaly detection
- Help organizations ensure that their applications adhere to industry standards and compliance requirements by assessing and reporting on security posture against these benchmarks

Show More