Best Secure Code Review Software

How Many Secure Code Review Software Products Does G2 Track?

Total Products under this Category: 70

Category Stats (Sep 2026)

  • Average Rating: 4.52/5 (↑0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Greptile (+9.71%) - Among all products in this category, Greptile recorded the largest rating increase compared to last month

Last updated: September 05, 2026

How Does G2 Rank Secure Code Review Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,400+ Authentic Reviews
  • 70+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Secure Code Review Software

G2 Grid® for Secure Code Review Software plotting products by satisfaction and market presence

Highlighted products: GitHub, Aikido Security, GitGuardian, GitLab, Microsoft Defender for Cloud, SonarQube, Checkmarx, and Qodo.

Underlying data: [Grid® JSON](https://www.g2.com/categories/secure-code-review/grids.json?focus%5B%5D=github&focus%5B%5D=aikido-security&focus%5B%5D=gitguardian&focus%5B%5D=gitlab&focus%5B%5D=microsoft-defender-for-cloud&focus%5B%5D=sonarqube&focus%5B%5D=checkmarx&focus%5B%5D=qodo)

GitHub

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

Average Rating: 4.7/5.0

Total Reviews: 2,340

How Do G2 Users Rate GitHub?

  • Quality of Support: 8.7/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.9/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.0/10 (Category avg: 8.7/10)

Who Is the Company Behind GitHub?

  • Seller: GitHub
  • Year Founded: 2008
  • HQ Location: San Francisco, CA
  • Twitter: @github
    2,673,925 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,653 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 47% Small, 31% Medium

What Do G2 Reviewers Say About GitHub?

AI-generated summary from verified user reviews

Pros
  • Users value GitHub's seamless collaboration and powerful version control, enhancing project transparency and workflow management.
  • Users appreciate the ease of use of GitHub, enabling seamless collaboration and efficient version control.
  • Users value the seamless team collaboration on GitHub, enhancing code sharing and workflow management effectively.
  • Users value the seamless collaboration offered by GitHub, enhancing project transparency and team workflow management.
  • Users value GitHub for its seamless version control, enhancing collaboration and streamlining the development process.
Cons
  • Users find the complexity in advanced features of GitHub challenging, particularly for newcomers and managing large repositories.
  • Users find the learning curve challenging, especially when designing workflows and managing permissions effectively.
  • Users find the complexity for beginners challenging, especially with CI/CD workflows and permission management.
  • Users find learning GitHub challenging due to overwhelming settings and complexities, making navigation difficult for newcomers.
  • Users find the steep learning curve of GitHub challenging, especially in mastering workflows and managing permissions.

What Are Recent G2 Reviews of GitHub?

What Are G2 Users Discussing About GitHub?

Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

Average Rating: 4.6/5.0

Total Reviews: 262

How Do G2 Users Rate Aikido Security?

  • Quality of Support: 9.2/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.4/10 (Category avg: 8.7/10)

Who Is the Company Behind Aikido Security?

  • Seller: Aikido Security
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Ghent, Belgium
  • Twitter: @AikidoSecurity
    11,770 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    320 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Founder, CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 79% Small, 15% Medium

What Do G2 Reviewers Say About Aikido Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Aikido Security, thanks to its clear insights and seamless integration.
  • Users appreciate Aikido Security's robust security capabilities, providing a comprehensive and seamless integration in their workflow.
  • Users value the intuitive dashboard of Aikido Security, which simplifies security issue identification and management.
  • Users value the easy integrations of Aikido Security, enhancing workflows with seamless connections to existing GitLab repositories.
  • Users find Aikido's easy setup highly efficient, enabling quick implementation and immediate usability for security assessments.
Cons
  • Users note the lack of advanced features in Aikido Security, such as dark mode and in-depth analysis options.
  • Users find the pricing structure expensive for micro businesses, making upgrades difficult to justify.
  • Users note the limited features of Aikido Security, wishing for more customization and advanced options.
  • Users find the pricing issues challenging, especially for micro businesses, due to the steep upgrade costs.
  • Users feel Aikido Security is lacking features like advanced reporting and deeper compliance analysis compared to competitors.

What Are Recent G2 Reviews of Aikido Security?

GitGuardian

GitGuardian is an end-to-end Secrets and Non-Human Identity (NHI) Security platform designed to help organizations eliminate secrets sprawl, govern machine identities, and meet compliance requirements under PCI-DSS v4.0, DORA, NYDFS Part 500, and NIS 2. As attackers increasingly target NHIs like service accounts, service principals, AI agents, and applications, protecting the credentials they rely on has become critical. GitGuardian's platform is built on three pillars: Secrets Security, NHI Governance, and Developer Endpoint Protection. **Secrets Security** eliminates leaks across every environment. Internal Secrets Monitoring detects hardcoded credentials in source code, CI/CD pipelines, container images, and collaboration tools like Slack, Jira, and Confluence with 500+ purpose-built detectors and a false positive rate under 10%. Public Secrets Monitoring scans 1B+ public GitHub commits daily, alerting teams the moment a secret is exposed externally. Honeytokens deploy decoy credentials that trigger immediate alerts on unauthorized access attempts. **NHI Governance** provides a centralized inventory of machine identities, including those outside vaults, with ownership attribution, risk scoring, and compliance evidence to support access reviews and rotation policy configuration. **Developer Endpoint Protection** extends coverage to the credential layer that repo and CI scanning can't reach: developer laptops. GitGuardian scans project directories, .env files, cloud credential stores, AI agent configs, and shell history across the entire fleet, delivering a prioritized inventory of exposed secrets by machine and severity. Trusted by Snowflake, ING, BASF, Datadog, Webflow, Bouygues Telecom, and more, and the #1 most-installed security app on the GitHub Marketplace.

Average Rating: 4.8/5.0

Total Reviews: 282

How Do G2 Users Rate GitGuardian?

  • Quality of Support: 9.1/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.0/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.4/10 (Category avg: 8.7/10)

Who Is the Company Behind GitGuardian?

  • Seller: GitGuardian
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Paris, Île-de-France
  • Twitter: @GitGuardian
    6,055 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    208 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Software Developer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 85% Small, 12% Medium

What Do G2 Reviewers Say About GitGuardian?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time alert notifications from GitGuardian, ensuring quick detection of key leaks and issues.
  • Users value the automated security features of GitGuardian, ensuring quick detection of secrets throughout the development process.
  • Users love the automated vulnerability detection of GitGuardian, ensuring fast and efficient secret management after code pushes.
  • Users value the accuracy of GitGuardian, noting its swift detection of issues with precise actionable feedback.
  • Users value the immediate detection speed of GitGuardian, ensuring quick resolutions and minimal workflow interruptions.
Cons
  • Users face challenges with false positives, requiring time to adjust settings and improve user experience.
  • Users find the inefficient notifications overwhelming, leading to increased review time and a cluttered interface when managing alerts.
  • Users find limited customization in GitGuardian, hindering the adjustment of alerts and specific security policies.
  • Users find the confusing interface of GitGuardian complicates navigation and slows down incident resolution despite helpful alerting.
  • Users report feeling overwhelmed by the excessive notifications from GitGuardian, complicating workflow and alert management.

What Are Recent G2 Reviews of GitGuardian?

What Are G2 Users Discussing About GitGuardian?

GitLab

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

Average Rating: 4.5/5.0

Total Reviews: 885

How Do G2 Users Rate GitLab?

  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.8/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.7/10 (Category avg: 8.7/10)

Who Is the Company Behind GitLab?

  • Seller: GitLab Inc.
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @gitlab
    171,534 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,431 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 37% Medium, 37% Small

What Do G2 Reviewers Say About GitLab?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use in GitLab, enjoying its all-in-one DevOps capabilities and intuitive interface.
  • Users value the all-encompassing features of GitLab, which enhance collaboration and streamline the DevOps workflow.
  • Users love the seamless CI/CD integration of GitLab, simplifying automation and collaboration in DevOps workflows.
  • Users value the seamless integrations in GitLab, resulting in efficient workflows and streamlined management across multiple functions.
  • Users praise the seamless CI/CD integration in GitLab, enhancing automation and collaboration within their DevOps workflow.
Cons
  • Users find the complexity of GitLab's setup and management to be a significant barrier to efficient use.
  • Users find the difficult learning curve of GitLab challenging due to its complex interface and YAML syntax.
  • Users find the interface confusing due to clutter and slow performance with large repositories, complicating their navigation.
  • Users find the complex user interface challenging, especially with slow performance and difficulties in navigation and management.
  • Users find the learning curve steep, particularly for those new to DevOps and managing extensive features.

What Are Recent G2 Reviews of GitLab?

What Are G2 Users Discussing About GitLab?

Microsoft Defender for Cloud

Microsoft Defender for Cloud is a cloud native application protection platform for multicloud and hybrid environments with comprehensive security across the full lifecycle, from development to runtime.

Average Rating: 4.4/5.0

Total Reviews: 426

How Do G2 Users Rate Microsoft Defender for Cloud?

  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.5/10 (Category avg: 8.7/10)

Who Is the Company Behind Microsoft Defender for Cloud?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Who Uses This: Saas Consultant, Software Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 38% Medium, 35% Large

What Do G2 Reviewers Say About Microsoft Defender for Cloud?

AI-generated summary from verified user reviews

Pros
  • Users value the robust security features of Microsoft Defender for Cloud, effectively protecting against diverse cyber threats.
  • Users appreciate the comprehensive security of Microsoft Defender for Cloud, effectively protecting against various cyber threats.
  • Users praise the robust security features of Microsoft Defender for Cloud, enhancing threat detection and prevention effectively.
  • Users appreciate the security alerts from Microsoft Defender for Cloud, enhancing their overall cloud security experience.
  • Users value the effective threat detection of Microsoft Defender for Cloud, ensuring robust security for their cloud resources.
Cons
  • Users find the complexity of configuration in Microsoft Defender for Cloud challenging, affecting their overall experience.
  • Users note that while Microsoft Defender for Cloud is excellent, it can be expensive for small to medium businesses.
  • Users experience delayed detection with Microsoft Defender for Cloud, often missing suspicious threats and alerts.
  • Users experience false positives in Microsoft Defender for Cloud, leading to confusion over legitimate files being flagged.
  • Users find the complex interface and downtimes of Microsoft Defender for Cloud detracting from its overall usability.

What Are Recent G2 Reviews of Microsoft Defender for Cloud?

What Are G2 Users Discussing About Microsoft Defender for Cloud?

SonarQube

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

Average Rating: 4.4/5.0

Total Reviews: 152

How Do G2 Users Rate SonarQube?

  • Quality of Support: 8.1/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind SonarQube?

  • Seller: SonarSource Sàrl
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Geneva, Switzerland
  • Twitter: @SonarSource
    10,913 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    973 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: DevOps Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 42% Large, 40% Medium

What Do G2 Reviewers Say About SonarQube?

AI-generated summary from verified user reviews

Pros
  • Users value SonarQube for its ability to quickly flag code quality and security issues, ensuring a reliable codebase.
  • Users value the flexible issue filtering and prioritization features of SonarQube, enhancing team productivity and focus.
  • Users appreciate how SonarQube quickly flags code quality and security issues, ensuring a clean and reliable codebase.
  • Users appreciate the ease of use of SonarQube, finding integration and actionable feedback simple and effective.
  • Users appreciate the easy integrations with CI/CD tools, enhancing their workflow and improving code quality effectively.
Cons
  • Users face software bugs that lead to false positives, complicating the experience and requiring significant knowledge to manage.
  • Users find the complex configuration of SonarQube challenging, especially for beginners needing extensive knowledge.
  • Users encounter false positives that complicate usage, despite helpful tools for review and customization of analysis.
  • Users find SonarQube's complexity in configuration and excessive warnings can make it cumbersome to use.
  • Users find the complex setup of SonarQube time-consuming, requiring significant effort to configure and tune effectively.

What Are Recent G2 Reviews of SonarQube?

What Are G2 Users Discussing About SonarQube?

Qodo

Qodo is the AI Code Quality and Governance Platform that helps engineering teams maintain code quality as AI accelerates coding velocity. Qodo works across IDEs and Git platforms to catch bugs earlier, enforce standards automatically, and scale review to match faster coding output. Qodo combines deep codebase understanding with a self-learning rules system and multi-agent review to validate code logic, detect architectural drift, surface security issues, and enforce standards before merge. Qodo goes beyond pattern matching or static AI reviews by combining full codebase context, PR memory, and your rules to deliver high-signal feedback that aligns with your project's unique architecture and standards. Key capabilities include agentic pull request review with context-enriched code suggestions, local code review in your IDE, custom rules enforcement, and multi-repo codebase indexing.

Average Rating: 4.5/5.0

Total Reviews: 121

How Do G2 Users Rate Qodo?

  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.0/10 (Category avg: 8.7/10)

Who Is the Company Behind Qodo?

  • Seller: CodiumAI
  • Company Website:
  • Year Founded: 2022
  • HQ Location: Tel Aviv, IL
  • Twitter: @CodiumAI
    109 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    146 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 59% Small, 25% Medium

What Do G2 Reviewers Say About Qodo?

AI-generated summary from verified user reviews

Pros
  • Users find Qodo’s ease of use remarkable, ensuring effortless integration and intuitive functionality within their coding environment.
  • Users value the time-saving benefits of Qodo, enjoying faster test generation and improved code review processes.
  • Users appreciate the contextual understanding of Qodo, making coding and testing significantly easier and more efficient.
  • Users praise Qodo for its automation capabilities, seamlessly generating tests and enhancing productivity in coding tasks.
  • Users value the multifunctional capabilities of Qodo, excelling in code testing, suggestions, and project analysis.
Cons
  • Users find the slow performance of Qodo affects their workflow, with delayed suggestions and cumbersome test evaluations.
  • Users report testing issues with Qodo, noting that unit tests often require adjustments and don't run initially.
  • Users experience bug issues with Qodo, such as inaccurate suggestions and inconsistent functionality, requiring manual adjustments.
  • Users find the learning curve challenging, though tutorials can help simplify the process for better understanding.
  • Users find the poor UI design of Qodo confusing, often struggling to stay on topic during interactions.

What Are Recent G2 Reviews of Qodo?

Checkmarx

Checkmarx offers leading application security solutions that help organizations safeguard software development while enhancing efficiency and reducing costs. At the center is Checkmarx Fusion, the highest-fidelity scanning architecture in the industry. Most scanners force a choice: catch more, or get buried in noise and miss what matters. Fusion ends that trade-off — deterministic precision and frontier AI coverage fused into one verified result, with the Findings Analysis Engine validating and deduplicating every finding before a developer sees it. The result is an F1 score of 0.64 today by using the Checkmarx NG SAST vs. an industry average of ~0.20, and an astonishing market leading F1 score of 0.74 with Checkmarx Fusion. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as NG SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

Average Rating: 4.2/5.0

Total Reviews: 45

How Do G2 Users Rate Checkmarx?

  • Quality of Support: 8.4/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.2/10 (Category avg: 8.7/10)

Who Is the Company Behind Checkmarx?

  • Seller: Checkmarx
  • Company Website:
  • Year Founded: 2006
  • HQ Location: Paramus, NJ
  • Twitter: @Checkmarx
    7,284 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    997 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 57% Large, 22% Medium

What Do G2 Reviewers Say About Checkmarx?

AI-generated summary from verified user reviews

Pros
  • Users value the easy implementation of Checkmarx into existing repositories, enhancing their security review processes effortlessly.
  • Users praise the intuitive user interface of Checkmarx, making security reviews and integrations straightforward and user-friendly.
  • Users value the accuracy of results in Checkmarx, finding it effective for automated security reviews.
  • Users appreciate the automation testing capabilities of Checkmarx, making security reviews efficient and user-friendly.
  • Users praise the responsive customer support of Checkmarx, consistently providing help when challenges arise.
Cons
  • Users experience a significant number of false positives with Checkmarx, particularly for Kotlin projects, leading to frustration.
  • Users face challenges with limited support for Kotlin, experiencing many false positives compared to other languages like Java or Javascript.
  • Users experience missing features in Checkmarx, particularly with Kotlin support, leading to numerous false positives.
  • Users find the navigation poor in Checkmarx, citing issues with dashboard layout and display clarity.

What Are Recent G2 Reviews of Checkmarx?

What Are G2 Users Discussing About Checkmarx?

OX Security

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

Average Rating: 4.8/5.0

Total Reviews: 51

How Do G2 Users Rate OX Security?

  • Quality of Support: 9.6/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.7/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.0/10 (Category avg: 8.7/10)

Who Is the Company Behind OX Security?

Who Uses This Product?

  • Who Uses This: Security Engineer
  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 63% Medium, 25% Large

What Do G2 Reviewers Say About OX Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the intuitive dashboard of OX Security, enhancing issue management and streamlining security processes effectively.
  • Users value the collaboration features of OX Security, enhancing teamwork and integrating seamlessly with existing tools.
  • Users value the responsive and professional customer support of OX Security, enhancing their overall experience and efficiency.
  • Users value the seamless integrations of OX Security, enhancing workflow efficiency and security insights effortlessly.
  • Users appreciate the speed and efficiency of OX Security in identifying and addressing vulnerabilities promptly.
Cons
  • Users find the complexity of OX Security daunting, with inadequate documentation and a steep learning curve for new users.
  • Users find the interface overwhelming, facing a steep learning curve and lacking adequate documentation for ease of use.
  • Users find the complex setup of OX Security challenging, compounded by insufficient documentation and overwhelming UI.
  • Users experience limited dashboard functionality, impacting reporting on security enhancements and overall management effectiveness.
  • Users find the difficult learning curve challenging due to OX Security's complex interface and insufficient documentation.

What Are Recent G2 Reviews of OX Security?

Semgrep

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

Average Rating: 4.6/5.0

Total Reviews: 56

How Do G2 Users Rate Semgrep?

  • Quality of Support: 8.8/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.4/10 (Category avg: 8.7/10)

Who Is the Company Behind Semgrep?

  • Seller: Semgrep
  • Year Founded: 2017
  • HQ Location: San Francisco, US
  • Twitter: @semgrep
    4,433 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    268 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 45% Large, 43% Medium

What Do G2 Reviewers Say About Semgrep?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Semgrep, enabled by its intuitive syntax and smooth integration with CI/CD.
  • Users appreciate the flexibility and speed of Semgrep in enforcing coding standards and catching vulnerabilities effectively.
  • Users appreciate the effective vulnerability detection of Semgrep, facilitating quick identification and resolution of security issues.
  • Users appreciate the scanning efficiency of Semgrep, benefiting from rapid scans and streamlined CI/CD integration.
  • Users value Semgrep for its effective security vulnerability detection, enabling quick resolutions without hindering development speed.
Cons
  • Users find Semgrep not user-friendly due to a steep learning curve and complex initial setup requirements.
  • Users find the limited features of Semgrep restrict its usability and complicate effective vulnerability management.
  • Users find the difficult learning curve for Semgrep daunting, especially for creating advanced rules and setups.
  • Users express concerns about the lack of guidance in creating custom rules, complicating effective use of Semgrep.
  • Users note a steep learning curve for Semgrep's rule syntax, making it challenging for newcomers to master.

What Are Recent G2 Reviews of Semgrep?

Black Duck Polaris Platform

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Average Rating: 4.2/5.0

Total Reviews: 103

How Do G2 Users Rate Black Duck Polaris Platform?

  • Quality of Support: 8.5/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.4/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.4/10 (Category avg: 8.7/10)

Who Is the Company Behind Black Duck Polaris Platform?

  • Seller: Black Duck
  • Year Founded: 2024
  • HQ Location: Burlington, US
  • LinkedIn® Page: www.linkedin.com
    1,317 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 53% Large, 32% Medium

What Do G2 Reviewers Say About Black Duck Polaris Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the accuracy of findings from Black Duck SCA, highlighting its powerful engine and extensive knowledge base.
  • Users value the powerful identification of open source issues by Black Duck SCA, aided by extensive knowledge resources.
Cons
  • Users find that Black Duck SCA requires huge resources to deploy on-prem, which can be a significant drawback.

What Are Recent G2 Reviews of Black Duck Polaris Platform?

What Are G2 Users Discussing About Black Duck Polaris Platform?

DryRun Security

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

Average Rating: 4.9/5.0

Total Reviews: 20

How Do G2 Users Rate DryRun Security?

  • Quality of Support: 10.0/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 8.9/10)
  • Ease of Setup: 10.0/10 (Category avg: 8.7/10)

Who Is the Company Behind DryRun Security?

Who Uses This Product?

  • Top Industries: Computer & Network Security
  • Company Size: 40% Small, 30% Medium

What Do G2 Reviewers Say About DryRun Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the context-aware security feedback from DryRun Security, enabling efficient vulnerability mitigation in real-time.
  • Users appreciate the quick and context-aware vulnerability detection of DryRun Security, enhancing code security during development.
  • Users commend DryRun Security for its seamless integration and effective detections, enhancing code security and development efficiency.
  • Users appreciate the accuracy of DryRun Security, effectively identifying vulnerabilities in AI-generated code and traditional applications.
  • Users commend the easy setup of DryRun Security, providing seamless integration and efficient workflow for code scanning.
Cons
  • Users experience slow performance in the management portal, affecting usability and efficiency with linked repositories.
  • Users find the slow speed of the management portal frustrating, though improvements to the UI have been noted.
  • Users note a need for improved UX investment in DryRun Security to enhance the developer experience and engagement.
  • Users desire more customization options for tuning analyzers, indicating limited flexibility in current features.
  • Users feel that greater focus on workflow issues could enhance DryRun Security's adoption among developers.

What Are Recent G2 Reviews of DryRun Security?

Assembla

Assembla is the only managed cloud hosting provider for Perforce (Helix Core) and SVN, with project management built in. We provision, manage, and support your entire version control infrastructure so your team never has to touch a server. Teams running Perforce or SVN in the cloud come to Assembla because we are the only provider that handles everything: dedicated instances, automated backups, failovers, SOC 2 and GDPR compliance, and 24/5 DevOps support. No self-managed infrastructure. No custom integrations. No DevOps overhead. Perforce Cloud delivers managed Helix Core hosting on a shared, high-performance cloud environment with monthly licensing and the Perforce license included. Perforce Enterprise Cloud gives larger teams a dedicated single-tenant instance with custom architecture and unlimited users and storage. SVN Cloud Hosting brings the same managed approach to Subversion, with modern collaboration features like merge requests, locking, and code search that most SVN providers do not offer. More than 5,500 development teams worldwide trust Assembla to keep their most critical code available, secure, and compliant.

Average Rating: 4.2/5.0

Total Reviews: 146

How Do G2 Users Rate Assembla?

  • Quality of Support: 8.4/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.8/10 (Category avg: 8.7/10)

Who Is the Company Behind Assembla?

  • Seller: Assembla
  • Year Founded: 2005
  • HQ Location: San Antonio, TX
  • Twitter: @assembla
    3,818 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    20 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Product Manager
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 51% Small, 40% Medium

What Are Recent G2 Reviews of Assembla?

What Are G2 Users Discussing About Assembla?

Jit

Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empowers organizations to proactively manage security risks across the entire software development lifecycle.​ AI-Powered Agents Jit's AI Agents, such as SERA (Security Evaluation and Remediation Agent) and COTA (Communication, Ops, and Ticketing Agent), collaborate with your teams to automate vulnerability triage, risk assessment, and remediation processes, significantly reducing manual workloads. ​ Comprehensive Security Scanning Achieve full-stack security coverage with integrated scanners for SAST, DAST, SCA, IaC, CSPM, and more. Jit's platform ensures continuous monitoring and immediate feedback on code changes, facilitating rapid identification and resolution of security issues. ​ Developer-Centric Experience With integrations into popular IDEs and CI/CD pipelines, Jit provides developers with contextual security insights directly within their workflows, promoting a shift-left approach without disrupting productivity. ​ Agentic AI for AppSec Teams Risk-Based Prioritization Utilizing the Model Context Protocol (MCP), Jit evaluates vulnerabilities in the context of runtime environments, business impact, and compliance requirements, enabling teams to focus on the most critical risks. ​ Seamless Integrations Jit integrates with a wide array of tools, including GitHub, GitLab, AWS, Azure, GCP, Jira, Slack, and more, ensuring that security processes are embedded within your existing technology stack. ​

Average Rating: 4.5/5.0

Total Reviews: 43

How Do G2 Users Rate Jit?

  • Quality of Support: 9.3/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 8.9/10)
  • Ease of Setup: 9.2/10 (Category avg: 8.7/10)

Who Is the Company Behind Jit?

  • Seller: jit
  • Year Founded: 2021
  • HQ Location: Boston, MA
  • Twitter: @jit_io
    522 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Financial Services
  • Company Size: 44% Medium, 42% Small

What Do G2 Reviewers Say About Jit?

AI-generated summary from verified user reviews

Pros
  • Users value the seamless integration of security in Jit, enhancing efficiency without overwhelming the development process.
  • Users appreciate the ease of use of Jit, as it simplifies integration and enhances productivity without added complexity.
  • Users value the easy integrations of Jit, streamlining security into development without overwhelming workflows.
  • Users value the efficiency of Jit, noting significant waste reduction and streamlined processes that enhance overall productivity.
  • Users value Jit for its automation of security controls, streamlining workflows and reducing overhead for development teams.
Cons
  • Users note integration issues, as Jit may not support all enterprise environments and requires extra manual setup.
  • Users find the product has limited features, especially in customization and advanced analytics for complex environments.
  • Users express concerns about limited integration with enterprise environments and third-party tools, hindering overall usability.
  • Users find the documentation lacking for advanced configurations, making it difficult to fully utilize Jit.
  • Users find the complexity of Jit's advanced integrations and features overwhelming for beginners and experienced developers alike.

What Are Recent G2 Reviews of Jit?

Greptile

Greptile is an AI-powered code analysis tool designed to enhance software development workflows by providing intelligent code reviews, generating documentation, and facilitating codebase understanding. It integrates seamlessly with platforms like GitHub and GitLab, offering both cloud-based and self-hosted deployment options to accommodate various organizational needs.

Average Rating: 3.9/5.0

Total Reviews: 19

How Do G2 Users Rate Greptile?

  • Quality of Support: 7.4/10 (Category avg: 9.2/10)
  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 8.9/10)
  • Ease of Setup: 8.1/10 (Category avg: 8.7/10)

Who Is the Company Behind Greptile?

  • Seller: Greptile
  • Year Founded: 2021
  • HQ Location: San Francisco, California, United States
  • LinkedIn® Page: www.linkedin.com
    39 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 53% Small, 32% Medium

What Are Recent G2 Reviews of Greptile?

Adam Crivello
AC
Researched and written by Adam Crivello
Updated October 3, 2024