# Best Runtime Application Self-Protection (RASP) Tools

## How Many Runtime Application Self-Protection (RASP) Tools Products Does G2 Track?

**Total Products under this Category:** 30

### Category Stats (Aug 2026)

- **Average Rating:** 4.57/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Zimperium Mobile Application Protection Suite (MAPS) (+1.8%) - Among all products in this category, Zimperium Mobile Application Protection Suite (MAPS) recorded the largest rating increase compared to last month

_Last updated: August 15, 2026_

## How Does G2 Rank Runtime Application Self-Protection (RASP) Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,800+ Authentic Reviews
- 30+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Runtime Application Self-Protection (RASP) Tools
 ![G2 Grid® for Runtime Application Self-Protection (RASP) Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/runtime-application-self-protection-rasp-tools/grids.png?focus%5B%5D=118553&focus%5B%5D=56154&focus%5B%5D=2056&focus%5B%5D=70798&focus%5B%5D=32497&focus%5B%5D=5391&focus%5B%5D=56028&focus%5B%5D=56082)

Highlighted products: Appdome, Zimperium Mobile Application Protection Suite (MAPS), Dynatrace, APP SHIELDING, Contrast Security, Jscrambler, DexGuard, and PreEmptive.

Underlying data: [Grid® JSON](https://www.g2.com/categories/runtime-application-self-protection-rasp-tools/grids.json?focus%5B%5D=appdome&focus%5B%5D=zimperium-mobile-application-protection-suite-maps&focus%5B%5D=dynatrace&focus%5B%5D=app-shielding&focus%5B%5D=contrast-security-contrast-security&focus%5B%5D=jscrambler&focus%5B%5D=dexguard&focus%5B%5D=preemptive)

**Sponsored**

### cside

What is cside? cside is a browser-layer security platform that gives organisations complete visibility and control over the third-party JavaScript running on their websites. It intercepts every script before it reaches the user, captures the full payload, and analyses runtime behaviour in real time. Third-party scripts power modern websites. Analytics, chat, payments, advertising, and session replay tools all inject JavaScript that runs directly in your visitors' browsers. You didn't write that code. You don't control when it changes. And you have no idea what it does at runtime. That is the client-side blind spot. The three problems cside solves 1) Every third-party script is a blind spot. Analytics, chat, payments, ads: you didn't write it, you don't control it, and you have no idea what it does at runtime inside a real browser. 2) PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 are now enforced. Most companies have no idea how to meet them, and their existing vendors don't cover it. WAFs, CDNs, and tag managers were never built for this problem. 3) AI agents and bots are now targeting high-value web workflows including checkout, login, and form submission in ways that WAFs and CDN-layer tools were never designed to catch. The attack surface has moved into the browser. The tools haven't. What you get with cside 1) Visibility you have never had. Every script on every page, classified, behavioural-profiled, and monitored continuously. Not what a scanner saw on its last crawl. What actually ran in a real user's browser, in real time. 2) Compliance, done. 6.4.3 and 11.6.1 documentation generated automatically. Auditor-ready output without manual effort. QSA-validated. No CSV exports to fill in by hand. 3) Real-time blocking. Malicious or anomalous script behaviour stopped at the browser layer before data leaves the page. Not flagged for review after the fact. Stopped before exfiltration occurs. Why CSPs and crawlers cannot solve this A Content Security Policy tells the browser which domains are allowed to load scripts. It has no visibility into what those scripts execute. A script served from a trusted domain, after being compromised through a supply chain attack, passes every CSP check and still skims card data from your checkout page. Crawlers and scanners have a different problem. Bad actors detect them and serve clean content to the scanner, then flip to malicious for real users. What the scanner saw and what your customers experienced are two different things. WAFs and CDNs operate at the network layer. They cannot see inside the browser. They check what loads, not what executes. cside sits in the delivery path of every script. It captures what scripts actually do in real user sessions. Deployment: One script tag. Under ten minutes. No managed crawl setup, no session tokens, no captcha bypasses required. Pricing: Free tier available to see your script exposure before buying. Business and Enterprise tiers for teams managing compliance, multi-domain environments, and advanced governance. Transparent pricing. No contract required to prove compliance to your QSA before you commit. Frequently asked questions 1) What makes cside different from a Content Security Policy?: A CSP controls which domains scripts can load from. It cannot analyse what those scripts execute at runtime. cside captures the full payload of every script and analyses its behaviour inside real user browsers, giving you the runtime visibility that CSP was never designed to provide. 2) What PCI DSS requirements does cside address?: cside is built specifically around requirements 6.4.3 and 11.6.1 of PCI DSS 4.0.1. It generates the authorised script inventory required by 6.4.3 and provides the ongoing change detection and monitoring required by 11.6.1, with QSA-validated audit-ready output. 3) How is cside different from a WAF or CDN security feature?: WAFs and CDNs operate at the network or server layer and have no visibility into what JavaScript executes inside a user's browser. cside operates at the browser layer. It is a dedicated product for client-side security, not a feature bolted onto an existing network tool. 4) Does cside detect AI agents and bots?: Yes. cside detects AI agents and bots targeting high-value web workflows including checkout, login, and form submission, covering a threat class that network-layer tools were not designed to address.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1422&secure%5Bchosen_at%5D=2026-08-15T11%3A28%3A46Z&secure%5Bdisplayable_resource_id%5D=1452&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1452&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1447373&secure%5Bresource_id%5D=1422&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fruntime-application-self-protection-rasp-tools&secure%5Btoken%5D=1201f3e9815479490ee119267116243a82c76f19cf5ade29c8cae3208c53b808&secure%5Burl%5D=https%3A%2F%2Fcside.dev%2Fbook-demo&secure%5Burl_type%5D=book_demo)

### [Appdome](https://www.g2.com/de/products/appdome/reviews)

Appdome ist eine agentische Plattform, die mobile Apps und das mobile Geschäft in großem Maßstab schützt. Von Unternehmen weltweit vertraut, automatisiert Appdome die Sicherheit von mobilen Apps, Betrugsprävention, Bot-Abwehr sowie Bedrohungserkennung und -reaktion für Android- und iOS-Anwendungen. Im Gegensatz zu herkömmlichen SDK-basierten Ansätzen, die eine manuelle Implementierung und laufende Wartung erfordern, verwendet Appdome KI-Agenten, um Schutzmaßnahmen direkt in mobile Apps einzubetten, Bedrohungen in Echtzeit zu analysieren und Abwehrmaßnahmen kontinuierlich anzupassen, ohne Code oder komplexe Integration. Organisationen nutzen Appdome, um mobile Apps, APIs, Identitäten, Konten, Transaktionen und Benutzer vor Betrug, Bots, Malware, Kontoübernahme, Deepfakes und anderen Cyberbedrohungen zu schützen. Die agentische mobile Verteidigungsplattform von Appdome umfasst: Identitäts- und Reputationsschutz Betrugs- und Kontoübernahmeprävention (ATO) Bot- und API-Abwehr Sicherheit von mobilen Apps (RASP und App-Shielding) DevSecOps- und CI/CD-Integration Bedrohungsmanagement und -reaktion (einschließlich ThreatScope™ Mobile XDR, ThreatEvents™ und Threat Resolution Center™)

**Average Rating:** 4.8/5.0

**Total Reviews:** 92

#### Who Is the Company Behind Appdome?

- **Verkäufer:** [Appdome](https://www.g2.com/de/sellers/appdome)
- **Unternehmenswebsite:** www.appdome.com
- **Gründungsjahr:** 2012
- **Hauptsitz:** Redwood City, California, United States
- **Twitter:** @appdome  
2,107 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e96815550f91fcda1fc5c83b1e0150743d209e6e4a96929e4af0346d903767b7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fappdome%2F&secure%5Burl_type%5D=linkedin_company_website)  
173 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Bankwesen, Finanzdienstleistungen
- **Company Size:** 50% Large, 34% Medium

#### What Do G2 Reviewers Say About Appdome?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer loben den **proaktiven Kundensupport** von Appdome, der rechtzeitige Unterstützung und Lösung von Problemen gewährleistet.
- Benutzer schätzen die **überlegenen Sicherheitsvorkehrungen** , die von Appdome angeboten werden, und verbessern mühelos die Sicherheit ihrer Anwendungen.
- Benutzer schätzen die **Benutzerfreundlichkeit** von Appdome, ergänzt durch seine intuitive GUI und den reaktionsschnellen Support.
- Benutzer schätzen den **Laufzeitschutz von Anwendungen** von Appdome und die einfache Handhabung ohne Code-Anforderungen.
- Benutzer heben die **einfache Implementierung** mit Appdome hervor, profitieren von einer schnellen und effizienten No-Code-Integration.

##### Cons

- Benutzer bemerken, dass die Lizenzierung von Appdome **ziemlich teuer** ist, was es kleineren Unternehmen erschwert, sie sich vollständig leisten zu können.
- Benutzer finden die **überwältigende Komplexität** der Plattform herausfordernd aufgrund ihrer zahlreichen Funktionen und Konfigurationsmöglichkeiten.
- Benutzer finden die **anfängliche Lernkurve** herausfordernd aufgrund der überwältigenden Anzahl von Funktionen und Konfigurationen.
- Benutzer finden die **Lernschwierigkeit** herausfordernd aufgrund der komplexen Konfigurationen und der anfänglichen Einrichtung, die für Appdome erforderlich sind.
- Benutzer finden die **schlechte Dokumentation** von Appdome macht die Konfiguration und das Verständnis der Funktionen unnötig kompliziert.

#### What Are Recent G2 Reviews of Appdome?

**["Effizienz und Innovation in der mobilen Sicherheit mit Appdome"](https://www.g2.com/de/survey_responses/appdome-review-13122430)**

**Rating:** 5.0/5.0 stars

_— Adelmo A._

[Read full review](https://www.g2.com/de/survey_responses/appdome-review-13122430)

**["Appdome liefert schnelle, No-Code Mobile App-Sicherheit und ermöglicht sichere Veröffentlichungen."](https://www.g2.com/de/survey_responses/appdome-review-13218646)**

**Rating:** 5.0/5.0 stars

_— QP G._

[Read full review](https://www.g2.com/de/survey_responses/appdome-review-13218646)

### [Zimperium Mobile Application Protection Suite (MAPS)](https://www.g2.com/de/products/zimperium-mobile-application-protection-suite-maps/reviews)

Zimperium Mobile Application Protection Suite (MAPS)📱-- ist eine einheitliche mobile App-Sicherheitsplattform, die entwickelt wurde, um iOS- und Android-Apps über den gesamten Lebenszyklus hinweg zu schützen – von der Erstellung und dem Testen bis hin zur Bereitstellung, Laufzeit und Reaktion. Zimperium MAPS bietet mobile Bedrohungserkennung auf dem Gerät, Laufzeitschutz für Anwendungen (RASP), Anwendungs-Härtung und Schutz kryptografischer Schlüssel – alles integriert in ein leichtgewichtiges SDK, das sich problemlos in moderne DevSecOps-Workflows einfügt. Im Gegensatz zu cloud-abhängigen oder wrapper-basierten Tools bietet Zimperium MAPS Echtzeit-, verzögerungsfreien Schutz vor mobilen App-Bedrohungen wie Reverse Engineering, Code-Manipulation, Emulatoren, jailbroken/rooted Umgebungen und bösartigen Laufzeitverhalten. Zimperium MAPS umfasst vier integrierte Module: 📲 zScan – Mobile Application Security Testing (MAST): Scannen Sie iOS- oder Android-App-Binärdateien vor der Veröffentlichung, um Compliance-, Datenschutz- und Sicherheitsrisiken zu identifizieren, die in der Produktion ausgenutzt werden könnten. zScan ermöglicht sichere Release-Zyklen für stark regulierte Branchen. 📲 zShield – Anwendungsschutz für iOS- und Android-Apps: Schützen Sie Quellcode, App-Binärdateien und geistiges Eigentum mit fortschrittlicher Verschleierung, Manipulationsschutz und Verschlüsselung – blockieren Sie Reverse Engineering und Code-Änderungen. 📲 zDefend – Erweiterter Laufzeitschutz (RASP): Erkennt und reagiert in Echtzeit auf mobile Bedrohungen auf dem Gerät. zDefend schützt Apps vor Gerätekompromittierung, dynamischer Instrumentierung, Emulatoren und 0-Day-Angriffen – sogar ohne Internetverbindung. 📲 zKeyBox – Schutz kryptografischer Schlüssel: Sichern Sie Verschlüsselungsschlüssel und sensible Logik innerhalb der App mit White-Box-Kryptographie. zKeyBox verhindert, dass Angreifer Geheimnisse extrahieren – selbst auf gerooteten oder jailbroken Geräten. Warum Zimperium MAPS für den Schutz mobiler Apps wählen? 📱 + Einheitliche mobile Anwendungssicherheitsplattform - Schützen Sie iOS- und Android-Apps über den gesamten Lebenszyklus auf einer KI-gestützten Plattform. Optimieren Sie den Schutz, beschleunigen Sie Releases und reagieren Sie schneller auf mobile Bedrohungen. + End-to-End-Sicherheitstransparenz - Finden Sie Schwachstellen zur Build-Zeit, Compliance-Verstöße und reale Laufzeitbedrohungen in einer Ansicht. + Laufzeitschutz auf dem Gerät (RASP). Erkennen und blockieren Sie Zero-Day-Mobilbedrohungen, Jailbreak- und Root-Versuche sowie Repackaging-Angriffe in Echtzeit auf dem Gerät. Funktioniert offline ohne erforderliche Backend-Konnektivität. + Over-the-Air-Sicherheitsupdates - Schieben Sie neue mobile App-Schutzmaßnahmen in die Produktion, ohne eine App-Store-Veröffentlichung. Reagieren Sie auf aufkommende mobile Bedrohungen in Stunden, nicht in Sprints. + Low-Code- und No-Code-App-Schutz - Wenden Sie Code-Verschleierung, Manipulationsschutz und Schlüsselschutz mit minimalem technischen Aufwand an. Halten Sie die Release-Geschwindigkeit aufrecht, während Sie iOS- und Android-Apps härten. + Flexible Bereitstellung - Führen Sie MAPS vor Ort oder als SaaS aus, um Anforderungen an Datenresidenz, Datenschutz und regulatorische Compliance zu erfüllen. + KI-Mobil-App-Reaktionsagent - Ermöglicht SOC- und Betrugsanalysten, On-Demand-Untersuchungen auf jedem Gerät auszulösen, und innerhalb von Minuten bestimmt der Agent, ob ein Vorfall oder Betrug vorliegt.

**Average Rating:** 4.3/5.0

**Total Reviews:** 34

#### Who Is the Company Behind Zimperium Mobile Application Protection Suite (MAPS)?

- **Verkäufer:** [Zimperium](https://www.g2.com/de/sellers/zimperium)
- **Unternehmenswebsite:** www.zimperium.com
- **Gründungsjahr:** 2010
- **Hauptsitz:** Dallas, TX
- **Twitter:** @ZIMPERIUM  
10,785 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=841529b0e707f79e4f0c27e77982b55f15573543997f4904845542d71987ec3a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1630757%2F&secure%5Burl_type%5D=linkedin_company_website)  
285 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Finanzdienstleistungen, Informationstechnologie und Dienstleistungen
- **Company Size:** 42% Medium, 28% Large

#### What Are Recent G2 Reviews of Zimperium Mobile Application Protection Suite (MAPS)?

**["Umfassender Schutz für mobile Apps mit nahtloser Integration"](https://www.g2.com/de/survey_responses/zimperium-mobile-application-protection-suite-maps-review-13112346)**

**Rating:** 5.0/5.0 stars

_— Suraj Singh D._

[Read full review](https://www.g2.com/de/survey_responses/zimperium-mobile-application-protection-suite-maps-review-13112346)

**["Starke mobile Sicherheit mit hervorragender Leistung"](https://www.g2.com/de/survey_responses/zimperium-mobile-application-protection-suite-maps-review-13142410)**

**Rating:** 5.0/5.0 stars

_— Jomon J._

[Read full review](https://www.g2.com/de/survey_responses/zimperium-mobile-application-protection-suite-maps-review-13142410)

#### What Are G2 Users Discussing About Zimperium Mobile Application Protection Suite (MAPS)?

- [What is Zimperium Mobile Application Protection Suite (MAPS) used for?](https://www.g2.com/de/discussions/what-is-zimperium-mobile-application-protection-suite-maps-used-for)

### [Dynatrace](https://www.g2.com/de/products/dynatrace/reviews)

Dynatrace verbessert die Beobachtbarkeit für die heutigen digitalen Unternehmen und hilft dabei, die Komplexität moderner digitaler Ökosysteme in leistungsstarke Geschäftsressourcen zu verwandeln. Durch die Nutzung von KI-gestützten Erkenntnissen ermöglicht Dynatrace Organisationen, schneller zu analysieren, zu automatisieren und zu innovieren, um ihr Geschäft voranzutreiben. Erfahren Sie mehr unter www.dynatrace.com.

**Average Rating:** 4.5/5.0

**Total Reviews:** 1,234

#### Who Is the Company Behind Dynatrace?

- **Verkäufer:** [Dynatrace](https://www.g2.com/de/sellers/dynatrace)
- **Gründungsjahr:** 2005
- **Hauptsitz:** Boston, MA
- **Twitter:** @Dynatrace  
18,668 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=83c43c7495079d745f57a9f8c381cbe86f78689894d05ac3e6cb0ba76b16494d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F125999%2F&secure%5Burl_type%5D=linkedin_company_website)  
6,060 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** NYSE: DT

#### Who Uses This Product?

- **Who Uses This:** Software-Ingenieur, Senior Software Engineer
- **Top Industries:** Informationstechnologie und Dienstleistungen, Finanzdienstleistungen
- **Company Size:** 69% Large, 23% Medium

#### What Do G2 Reviewers Say About Dynatrace?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer loben die **Benutzerfreundlichkeit** von Dynatrace und heben die intuitive Navigation und den schnellen Installationsprozess hervor.
- Benutzer schätzen das **Echtzeit-Breakpoint-Feature** zur Fehlerbehebung von Code in der Produktion, was ihren Entwicklungsprozess verbessert.
- Benutzer loben die **schnelle Informationssammlung** von Dynatrace, was die Fehlererkennung und die allgemeine Debugging-Effizienz verbessert.
- Benutzer schätzen die **umfassenden Datenerfassungs** fähigkeiten von Dynatrace, die eine effiziente Fehlererkennung ohne Produktionsunterbrechungen ermöglichen.
- Benutzer finden **Überwachungs** fähigkeiten unschätzbar für schnelle Einblicke und rechtzeitige Warnungen bei Systemproblemen, was die Zuverlässigkeit erhöht.

##### Cons

- Benutzer finden die **Lernkurve steil** , mit Herausforderungen bei der Instrumentierung und dem effektiven Verständnis des Systems.
- Benutzer sind frustriert über **fehlende Funktionen** in Dynatrace, was die Datenextraktion und die allgemeine Benutzerfreundlichkeit beeinträchtigt.
- Benutzer finden, dass die **Komplexität der Instrumentierung** mit Dynatrace die effektive Problemuntersuchung und Benutzerfreundlichkeit behindern kann.
- Benutzer empfinden die **Benutzeroberfläche als zu überladen** , was die Navigation und das Anzeigen von Protokollen für Neulinge umständlich macht.
- Benutzer finden die **steile Lernkurve** von Dynatrace herausfordernd, was es schwierig macht, alle Funktionen vollständig zu nutzen.

#### What Are Recent G2 Reviews of Dynatrace?

**["Umfassende Beobachtbarkeit, hervorragende KI, aber komplexe Preisgestaltung"](https://www.g2.com/de/survey_responses/dynatrace-review-13111992)**

**Rating:** 4.0/5.0 stars

_— Vishnu Vardhan N._

[Read full review](https://www.g2.com/de/survey_responses/dynatrace-review-13111992)

**["Davis AI liefert klare Ursachenanalysen und Echtzeit-Benutzerüberwachung"](https://www.g2.com/de/survey_responses/dynatrace-review-12645823)**

**Rating:** 4.5/5.0 stars

_— Sabina K._

[Read full review](https://www.g2.com/de/survey_responses/dynatrace-review-12645823)

#### What Are G2 Users Discussing About Dynatrace?

- [Wofür wird Dynatrace verwendet?](https://www.g2.com/de/discussions/what-is-dynatrace-used-for) - 3 comments
- [How do you use Rookout?](https://www.g2.com/de/discussions/how-do-you-use-rookout)
- [What is the use of Rookout?](https://www.g2.com/de/discussions/what-is-the-use-of-rookout)
- [What is offline debugging?](https://www.g2.com/de/discussions/what-is-offline-debugging)
- [What does Rookout do?](https://www.g2.com/de/discussions/what-does-rookout-do) - 2 comments

### [APP SHIELDING](https://www.g2.com/de/products/app-shielding/reviews)

Vertrauen aufbauen und Wachstum fördern, indem Sie die Widerstandsfähigkeit Ihrer mobilen Apps gegen Eindringen, Manipulation und Reverse Engineering stärken.

**Average Rating:** 4.3/5.0

**Total Reviews:** 14

#### Who Is the Company Behind APP SHIELDING?

- **Verkäufer:** [OneSpan](https://www.g2.com/de/sellers/onespan)
- **Gründungsjahr:** 1991
- **Hauptsitz:** Boston, MA
- **Twitter:** @OneSpan  
3,374 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c0d4261655beb9bff5dc0dbf34613a5e4082a6885d794b62b18dbec0b349893f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fonespan%2F&secure%5Burl_type%5D=linkedin_company_website)  
665 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** OSPN

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen
- **Company Size:** 43% Small, 36% Medium

#### What Are Recent G2 Reviews of APP SHIELDING?

**["Beste Sicherheit für alle mobilen Anwendungen"](https://www.g2.com/de/survey_responses/app-shielding-review-8765545)**

**Rating:** 5.0/5.0 stars

_— Prashanth A._

[Read full review](https://www.g2.com/de/survey_responses/app-shielding-review-8765545)

**["Gegen potenzielle Bedrohungen geschützt"](https://www.g2.com/de/survey_responses/app-shielding-review-8715453)**

**Rating:** 5.0/5.0 stars

_— Lincoln H._

[Read full review](https://www.g2.com/de/survey_responses/app-shielding-review-8715453)

### [Contrast Security](https://www.g2.com/de/products/contrast-security-contrast-security/reviews)

Contrast Security ist der weltweit führende Anbieter von Application Detection and Response (ADR) und befähigt Organisationen, Angriffe auf Anwendungen und APIs in Echtzeit zu erkennen und zu stoppen. Contrast integriert patentierte Bedrohungssensoren direkt in die Software und bietet unvergleichliche Sichtbarkeit und Schutz. Mit kontinuierlicher, Echtzeit-Verteidigung deckt Contrast versteckte Risiken in der Anwendungsschicht auf, die traditionelle Lösungen übersehen. Die leistungsstarke Runtime-Sicherheitstechnologie von Contrast stattet Entwickler, AppSec-Teams und SecOps mit einer Plattform aus, die proaktiv Anwendungen und APIs gegen sich entwickelnde Bedrohungen schützt und verteidigt.

**Average Rating:** 4.5/5.0

**Total Reviews:** 49

#### Who Is the Company Behind Contrast Security?

- **Verkäufer:** [Contrast Security](https://www.g2.com/de/sellers/contrast-security)
- **Unternehmenswebsite:** contrastsecurity.com
- **Gründungsjahr:** 2014
- **Hauptsitz:** Pleasanton, CA
- **Twitter:** @contrastsec  
5,468 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=88d434bb9245c6db693a0f2f814fc8a26978bf92e8b8eba720e114bbee116763&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcontrast-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
196 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Versicherung, Informationstechnologie und Dienstleistungen
- **Company Size:** 67% Large, 20% Medium

#### What Do G2 Reviewers Say About Contrast Security?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Genauigkeit der Ergebnisse** von Contrast Security, was eine größere Präzision bei der Identifizierung von Schwachstellen gewährleistet.
- Benutzer schätzen die **Genauigkeit der Ergebnisse** von Contrast Security und profitieren von präziser Schwachstellenüberwachung und -analyse.
- Benutzer loben die **Echtzeit-Schwachstellenerkennung** von Contrast Security und schätzen das schnelle Feedback und die agile Unterstützung.

##### Cons

- Benutzer erlebten **Leistungsprobleme** mit Contrast Security, insbesondere bei Java-Anwendungen, fanden jedoch den Support hilfreich bei der Lösung dieser Probleme.

#### What Are Recent G2 Reviews of Contrast Security?

**["Shift-Smart mit Kontrast"](https://www.g2.com/de/survey_responses/contrast-security-review-8492224)**

**Rating:** 5.0/5.0 stars

_— Kiran S._

[Read full review](https://www.g2.com/de/survey_responses/contrast-security-review-8492224)

**["Contrast Security macht Anwendungssicherheit einfach"](https://www.g2.com/de/survey_responses/contrast-security-review-8516563)**

**Rating:** 5.0/5.0 stars

_— Verifizierter Benutzer in Höhere Bildung_

[Read full review](https://www.g2.com/de/survey_responses/contrast-security-review-8516563)

#### What Are G2 Users Discussing About Contrast Security?

- [What is contrast protect?](https://www.g2.com/de/discussions/what-is-contrast-protect)
- [Is Contrast security SaaS?](https://www.g2.com/de/discussions/is-contrast-security-saas)
- [What is Contrast security tool?](https://www.g2.com/de/discussions/what-is-contrast-security-tool)
- [What does contrast security do?](https://www.g2.com/de/discussions/what-does-contrast-security-do)

### [Jscrambler](https://www.g2.com/de/products/jscrambler/reviews)

Jscrambler ist der führende Anbieter von Client-Side-Sicherheit für das moderne, zusammensetzbare Web. Da Organisationen zunehmend digitale Erlebnisse durch Drittanbieter-Softwarelieferketten und KI-gestützte Agenten aufbauen, werden sensible Daten nun direkt im Browser erstellt – dem Punkt der Entstehung für digitale Interaktionen – was ihn zu einer der privilegiertesten, aber am wenigsten kontrollierten Angriffsflächen eines Unternehmens macht. Die Client-Side-Sicherheitsplattform von Jscrambler wird von einem Behavioral Enforcement Core angetrieben, der regelt, wie sich Anwendungs-Code, Drittanbieter-Skripte und sensible Daten zur Laufzeit verhalten. Durch die Durchsetzung von Software-Integrität und Daten-Governance direkt im Browser stellt die Plattform sicher, dass sensible Daten und KI-Eingaben gemäß der Unternehmensrichtlinie am Punkt der Entstehung kontrolliert werden – bevor sie die Client-Umgebung verlassen. Vertraut von führenden globalen Einzelhändlern, Fluggesellschaften, Finanzdienstleistern und Gesundheitsorganisationen bietet Jscrambler die Sichtbarkeit und Durchsetzung, die Organisationen benötigen, um Client-Side-Angriffe zu stoppen, Datenlecks zu verhindern und die Einhaltung von Vorschriften wie PCI DSS, GDPR, HIPAA, CCPA und dem EU AI Act zu gewährleisten.

**Average Rating:** 4.4/5.0

**Total Reviews:** 31

#### Who Is the Company Behind Jscrambler?

- **Verkäufer:** [Jscrambler](https://www.g2.com/de/sellers/jscrambler)
- **Unternehmenswebsite:** jscrambler.com
- **Gründungsjahr:** 2014
- **Hauptsitz:** San Francisco, California
- **Twitter:** @Jscrambler  
1,161 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1f232d3698f51e50cca5f27217404c5fdc451925ba67a491d9048732abcf939f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1005462%2F&secure%5Burl_type%5D=linkedin_company_website)  
90 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Company Size:** 35% Medium, 29% Small

#### What Do G2 Reviewers Say About Jscrambler?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **robusten Sicherheitsfunktionen** von Jscrambler, die sicherstellen, dass ihr geistiges Eigentum während der Bereitstellung gut geschützt ist.
- Benutzer schätzen die **Benutzerfreundlichkeit** von Jscrambler und finden die Oberfläche benutzerfreundlich und leicht zu navigieren.
- Benutzer loben die **benutzerfreundliche Oberfläche** von Jscrambler, was die Verwaltung und Implementierung einfach und effizient macht.
- Benutzer finden, dass sich die **Automatisierungsfähigkeiten** von Jscrambler nahtlos in CI/CD-Pipelines integrieren und die Sicherheit verbessern, ohne die Entwicklung zu stören.
- Benutzer schätzen den **umfassenden Überblick** von Jscrambler, der die Sicherheit und Leistung durch schrittweise Aktivierung von Funktionen verbessert.

##### Cons

- Benutzer erleben eine **schwierige Einführung** mit Jscrambler aufgrund seiner komplexen Installations- und Einrichtungsprozesse.
- Benutzer erleben **langsame Leistung** , die die Benutzererfahrung negativ beeinflusst, was zusätzliche Anpassungen erfordert und an ausreichender Dokumentation mangelt.
- Benutzer bemerken, dass das **Dashboard detailliertere Informationen** über jede Installation für bessere Einblicke bereitstellen könnte.
- Benutzer stehen oft vor **Verschleierungsproblemen** bei großen Anwendungen, was zu Funktionsproblemen und Herausforderungen mit Projektdateibeschränkungen führt.
- Benutzer stehen oft vor **begrenzter Anleitung** bei Jscrambler, was zu Herausforderungen beim effektiven Exportieren von Berichten führt.

#### What Are Recent G2 Reviews of Jscrambler?

**["Unvergleichlicher Code-Schutz mit Jscrambler"](https://www.g2.com/de/survey_responses/jscrambler-review-12607132)**

**Rating:** 5.0/5.0 stars

_— Bruno V._

[Read full review](https://www.g2.com/de/survey_responses/jscrambler-review-12607132)

**["Jscrambler integriert sich nahtlos in CI/CD für verbesserte Web-App-Sicherheit"](https://www.g2.com/de/survey_responses/jscrambler-review-11802189)**

**Rating:** 5.0/5.0 stars

_— Daniel G._

[Read full review](https://www.g2.com/de/survey_responses/jscrambler-review-11802189)

#### What Are G2 Users Discussing About Jscrambler?

- [Wofür wird Jscrambler verwendet?](https://www.g2.com/de/discussions/what-is-jscrambler-used-for)

### [PreEmptive](https://www.g2.com/de/products/preemptive/reviews)

PreEmptive sichert Apps gegen IP-Diebstahl, Hacking und Manipulation mit einem mehrschichtigen Schutz für .NET, Java und JavaScript. PreEmptive balanciert gekonnt Kosten, Komfort und Funktionalität, um Ihre Anwendungen zu sichern und sie widerstandsfähiger gegen Daten- und IP-Diebstahl, Hacking und Manipulation zu machen. Unsere schnell implementierbaren Premium-Lösungen bieten einen mehrschichtigen In-App-Schutz: Dotfuscator für .NET & Xamarin DashO für Java & Android JSDefender für JavaScript Unser mehrschichtiger Ansatz zum Schutz von Binärcode verwendet Verschleierung, Verschlüsselung, Root-Erkennung, Abschirmung und Manipulationssicherheit, um sich gegen Ausbeutung durch Menschen und Maschinen zu verteidigen. PreEmptive bietet passive und aktive Verteidigungsfähigkeiten, schützt Geschäftsgeheimnisse und geistiges Eigentum (IP), reduziert Piraterie und Fälschung und verhindert die Manipulation von Code und die Inspektion sensibler Daten. PreEmptive lässt sich einfach in .NET-, MAUI-, Java- und Android-Anwendungen integrieren und hilft Ihnen, Anwendungsrisiken zu managen und die Einhaltung von Vorschriften sicherzustellen. PreEmptive liefert erstklassigen Anwendungsschutz, der nahtlos in Ihren Entwicklungsablauf integriert wird, um Software zu sichern, Ihr Unternehmen zu schützen und Ihre Kunden zu sichern. Wählen Sie PreEmptive für umfassende, intelligente App-Sicherheit.

**Average Rating:** 4.6/5.0

**Total Reviews:** 49

#### Who Is the Company Behind PreEmptive?

- **Verkäufer:** [Sembi](https://www.g2.com/de/sellers/sembi)
- **Unternehmenswebsite:** www.sembi.com
- **Gründungsjahr:** 2023
- **Hauptsitz:** Austin, US
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7ed5860a727a31b32edfba64808a6ea32fccad50d052e993a08b626d675d5c69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsembi-inc%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computersoftware, Informationstechnologie und Dienstleistungen
- **Company Size:** 44% Small, 40% Medium

#### What Are Recent G2 Reviews of PreEmptive?

**["Hervorragender Support und mühelose Benutzerfreundlichkeit"](https://www.g2.com/de/survey_responses/preemptive-review-12175830)**

**Rating:** 5.0/5.0 stars

_— Verifizierter Benutzer in Militär_

[Read full review](https://www.g2.com/de/survey_responses/preemptive-review-12175830)

**["Einfache, praktische JavaScript-Schutzmaßnahmen, die nahtlos in meinen Arbeitsablauf passen"](https://www.g2.com/de/survey_responses/preemptive-review-12610744)**

**Rating:** 4.5/5.0 stars

_— Kodam S._

[Read full review](https://www.g2.com/de/survey_responses/preemptive-review-12610744)

#### What Are G2 Users Discussing About PreEmptive?

- [Wofür wird Dotfuscator – App-Schutz für .NET & Xamarin verwendet?](https://www.g2.com/de/discussions/what-is-dotfuscator-app-protection-for-net-xamarin-used-for)
- [Wofür wird DashO – App-Schutz für Android & Java verwendet?](https://www.g2.com/de/discussions/what-is-dasho-app-protection-for-android-java-used-for)
- [What is JSDefender – App Protection for JavaScript used for?](https://www.g2.com/de/discussions/what-is-jsdefender-app-protection-for-javascript-used-for) - 1 comment

### [DexGuard](https://www.g2.com/de/products/dexguard/reviews)

Umfassender Schutz für Android-Apps. Mit umfangreicher Android-App-Verschleierung und Sicherheitsprotokollen bietet DexGuard den umfassendsten mobilen App-Schutz, der verfügbar ist. Sichern Sie Ihre Android-Apps und SDKs durch mehrere Schichten der Code-Härtung und RASP. Das DexGuard NDK-Add-on erweitert den gesamten von DexGuard gebotenen Schutz — einschließlich mehrschichtiger Android-App-Code-Verschleierung, Datenverschleierung und RASP-Integration — auf enthaltene C/C++-Native-Bibliotheken. DexGuard erstellt einen Schutzbericht für jeden mobilen App-Build, der seine Schutzmaßnahmen integriert. Dieser Bericht validiert und bewertet die angewandten Schutzmaßnahmen, bewertet die Sicherheitskonfiguration Ihrer App in Bezug auf wichtige Risikokategorien, gibt weitere Empfehlungen zur Verbesserung der Sicherheitseffizienz und zeigt potenziell nützliche Funktionen zur Aktivierung auf. Beim Upgrade von ProGuard (oder R8) auf DexGuard können Sie Ihre bestehende ProGuard-Konfigurationsdatei wiederverwenden. Sie müssen lediglich die zusätzlichen Funktionen von DexGuard berücksichtigen, einschließlich seiner RASP- und Verschleierungsmöglichkeiten.

**Average Rating:** 4.2/5.0

**Total Reviews:** 21

#### Who Is the Company Behind DexGuard?

- **Verkäufer:** [GuardSquare NV](https://www.g2.com/de/sellers/guardsquare-nv)
- **Gründungsjahr:** 2014
- **Hauptsitz:** Leuven, Belgium
- **Twitter:** @GuardSquare  
4,049 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=42fc15e1baf9120344ce28a14377873e404d6db193eb805621a14cdfff7c5cd8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5012731&secure%5Burl_type%5D=linkedin_company_website)  
179 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen
- **Company Size:** 48% Small, 33% Medium

#### What Are Recent G2 Reviews of DexGuard?

**["Schutz auf Unternehmensniveau für mobile Apps und Laufzeitsicherheit für Android-Apps."](https://www.g2.com/de/survey_responses/dexguard-review-11364550)**

**Rating:** 4.5/5.0 stars

_— Rohith C._

[Read full review](https://www.g2.com/de/survey_responses/dexguard-review-11364550)

**["Robuster Schutz für mobile Apps mit soliden Anpassungsoptionen"](https://www.g2.com/de/survey_responses/dexguard-review-11438992)**

**Rating:** 4.5/5.0 stars

_— Ritwik P._

[Read full review](https://www.g2.com/de/survey_responses/dexguard-review-11438992)

#### What Are G2 Users Discussing About DexGuard?

- [Wofür wird DexGuard verwendet?](https://www.g2.com/de/discussions/what-is-dexguard-used-for)

### [OpenText Core Application Security](https://www.g2.com/de/products/opentext-core-application-security/reviews)

Fortify on Demand (FoD) ist eine vollständige Application Security as a Service-Lösung. Es bietet eine einfache Möglichkeit, zu beginnen, mit der Flexibilität zur Skalierung. Zusätzlich zu statischen und dynamischen Tests deckt Fortify on Demand umfassende Sicherheitsprüfungen für mobile Apps, Open-Source-Analyse und das Management der Anwendungssicherheit von Anbietern ab. Falsch positive Ergebnisse werden für jeden Test entfernt und Testergebnisse können manuell von Anwendungssicherheitsexperten überprüft werden.

**Average Rating:** 4.1/5.0

**Total Reviews:** 34

#### Who Is the Company Behind OpenText Core Application Security?

- **Verkäufer:** [OpenText](https://www.g2.com/de/sellers/opentext)
- **Gründungsjahr:** 1991
- **Hauptsitz:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Informationstechnologie und Dienstleistungen
- **Company Size:** 41% Large, 32% Small

#### What Are Recent G2 Reviews of OpenText Core Application Security?

**["Sichere und gesicherte Barriere"](https://www.g2.com/de/survey_responses/opentext-core-application-security-review-8819443)**

**Rating:** 4.5/5.0 stars

_— Ajinkya M._

[Read full review](https://www.g2.com/de/survey_responses/opentext-core-application-security-review-8819443)

**["Überprüfung von MicroFocus Application Defender"](https://www.g2.com/de/survey_responses/opentext-core-application-security-review-8781016)**

**Rating:** 4.5/5.0 stars

_— sohrab a._

[Read full review](https://www.g2.com/de/survey_responses/opentext-core-application-security-review-8781016)

#### What Are G2 Users Discussing About OpenText Core Application Security?

- [What are the main components of Fortify?](https://www.g2.com/de/discussions/micro-focus-fortify-on-demand-what-are-the-main-components-of-fortify)
- [How does Fortify on Demand work?](https://www.g2.com/de/discussions/how-does-fortify-on-demand-work)
- [What is Fortify software used for?](https://www.g2.com/de/discussions/micro-focus-fortify-on-demand-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify on Demand?](https://www.g2.com/de/discussions/what-is-micro-focus-fortify-on-demand)

### [DoveRunner](https://www.g2.com/de/products/doverunner/reviews)

DoveRunner, früher bekannt als AppSealing, ist eine umfassende Sicherheitsplattform für mobile Apps und Inhalte, die Unternehmen dabei unterstützt, sowohl ihre mobilen Anwendungen als auch Premium-Videoinhalte vor sich entwickelnden digitalen Bedrohungen zu schützen. Die Plattform kombiniert fortschrittliche Schutztechnologien für mobile Apps mit unternehmensgerechten Lösungen zum Schutz von Videoinhalten, wodurch Organisationen ihr digitales Ökosystem durch einen einheitlichen Sicherheitsansatz sichern können. DoveRunner bietet robuste Runtime Application Self-Protection (RASP)-Fähigkeiten für mobile Apps, die Unternehmen dabei helfen, ihr geistiges Eigentum zu schützen, ohne umfangreiche Codierung oder komplexe Integrationen zu erfordern. Eine der herausragenden Stärken von DoveRunner ist seine Fähigkeit, Anwendungen vor Manipulation, Reverse Engineering, Neuverpackung und unbefugten Änderungen zu schützen, während gleichzeitig Premium-Videoinhalte vor Piraterie und illegaler Verbreitung gesichert werden. Durch fortschrittliche Sicherheitsprotokolle erkennt und neutralisiert die Plattform aktiv Bedrohungen, die auf mobile Anwendungen und Streaming-Umgebungen abzielen, und gewährleistet die Integrität sowohl des App-Erlebnisses als auch der Content-Delivery-Pipeline. Der benutzerfreundliche Implementierungsprozess von DoveRunner ermöglicht es Unternehmen, leistungsstarke Sicherheitsfunktionen mit minimaler betrieblicher Komplexität in ihre bestehenden Anwendungen und Content-Workflows zu integrieren. Seine No-Code- und Low-Code-Bereitstellungsfähigkeiten ermöglichen es Organisationen, mobile Apps und Videodienste schnell zu sichern, ohne lange Entwicklungszyklen oder umfangreiche Infrastrukturanforderungen. Diese Kombination aus Benutzerfreundlichkeit, Skalierbarkeit und unternehmensgerechtem Schutz macht DoveRunner zur idealen Wahl für Unternehmen, die sowohl ihre mobile App-Sicherheit als auch ihre Strategien zum Schutz von Premium-Inhalten stärken möchten. Zusammenfassend bietet DoveRunner eine einheitliche Sicherheitsplattform, die die kritischen Herausforderungen moderner, app-gesteuerter und inhaltszentrierter Unternehmen adressiert. Durch die Bereitstellung fortschrittlicher Schutzmaßnahmen für mobile Apps neben robustem Schutz von Videoinhalten und Anti-Piraterie-Lösungen hilft DoveRunner Organisationen, ihre Anwendungen zu verteidigen, Premium-Inhalte zu schützen, Einnahmequellen zu bewahren und ein sichereres digitales Erlebnis für Nutzer weltweit zu schaffen.

**Average Rating:** 4.7/5.0

**Total Reviews:** 48

#### Who Is the Company Behind DoveRunner?

- **Verkäufer:** [DoveRunner](https://www.g2.com/de/sellers/doverunner)
- **Unternehmenswebsite:** doverunner.com
- **Gründungsjahr:** 2000
- **Hauptsitz:** San Jose, US
- **Twitter:** @doverunner\_inc  
12 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e9bfbfcf995136e1b15130d92b1574523882f53939da860a1409b58a9fe848fc&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdoverunner%2Fpeople%2F&secure%5Burl_type%5D=linkedin_company_website)  
60 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computersoftware, Informationstechnologie und Dienstleistungen
- **Company Size:** 46% Small, 42% Medium

#### What Do G2 Reviewers Say About DoveRunner?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **intuitive Benutzeroberfläche und die Echtzeit-Leistungsüberwachung** von DoveRunner, was das Datenmanagement effizient und vereinfacht macht.
- Benutzer lieben die **intuitive Benutzeroberfläche** von DoveRunner, die Datenverwaltung und -analyse effizient und unkompliziert macht.
- Benutzer schätzen die **saubere und intuitive Benutzeroberfläche** von DoveRunner, die die Effizienz bei der Datenverwaltung und -analyse verbessert.

##### Cons

- Benutzer finden die **steile Lernkurve** von DoveRunner herausfordernd und wünschen sich bessere Anleitungen und Tutorials für neue Benutzer.

#### What Are Recent G2 Reviews of DoveRunner?

**["Intuitive Benutzeroberfläche und Echtzeit-Tracking machen Datenmanagement mühelos"](https://www.g2.com/de/survey_responses/doverunner-review-12103203)**

**Rating:** 4.0/5.0 stars

_— Suraj C._

[Read full review](https://www.g2.com/de/survey_responses/doverunner-review-12103203)

**["DRM-Dienste mit Sicherheit"](https://www.g2.com/de/survey_responses/doverunner-review-9828507)**

**Rating:** 4.5/5.0 stars

_— Vikash R._

[Read full review](https://www.g2.com/de/survey_responses/doverunner-review-9828507)

#### What Are G2 Users Discussing About DoveRunner?

- [What is PallyCon used for?](https://www.g2.com/de/discussions/what-is-pallycon-used-for)
- [How do you use Appsealing?](https://www.g2.com/de/discussions/appsealing-how-do-you-use-appsealing)
- [How do you use Appsealing?](https://www.g2.com/de/discussions/how-do-you-use-appsealing)
- [What is application software security?](https://www.g2.com/de/discussions/appsealing-what-is-application-software-security)
- [What is application software security?](https://www.g2.com/de/discussions/what-is-application-software-security)

### [Waratek](https://www.g2.com/de/products/waratek-waratek/reviews)

Waratek ist die einzige Security-as-Code-Automatisierungsplattform, die Kontrolle durch Richtlinien ermöglicht, um Sicherheit mit moderner Entwicklung zu skalieren. Die größten Unternehmen der Welt vertrauen auf Waratek-Produkte, um Anwendungssicherheit in großem Maßstab zu liefern.

**Average Rating:** 4.7/5.0

**Total Reviews:** 11

#### Who Is the Company Behind Waratek?

- **Verkäufer:** [Waratek](https://www.g2.com/de/sellers/waratek)
- **Gründungsjahr:** 2009
- **Hauptsitz:** Dublin, County Dublin
- **Twitter:** @waratek  
749 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cb3b9353dc56044c01d1230648c2d7b2f2de325ceaec08034c940658c49150eb&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F519232&secure%5Burl_type%5D=linkedin_company_website)  
18 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Company Size:** 64% Large, 27% Medium

#### What Do G2 Reviewers Say About Waratek?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer loben die **einfache Konfiguration** mit Waratek, was es einfach macht, Anwendungen effektiv zu schützen.
- Benutzer schätzen Waratek für seine **effektive Anwendungssicherheit** , die den Schutz unsicherer Programme bei einfacher Handhabung verbessert.
- Benutzer schätzen die **benutzerfreundliche Oberfläche** von Waratek, die es einfach macht, Anwendungssicherheit zu implementieren und zu verwalten.
- Benutzer schätzen die **Anwendungssicherheit** , die von Waratek bereitgestellt wird, und loben ihre Benutzerfreundlichkeit und effektive Bedrohungsreaktion.
- Benutzer loben Waratek für seine **effektive Anwendungssicherheit** , die die Sicherheit verbessert, ohne dass Codeänderungen erforderlich sind.

#### What Are Recent G2 Reviews of Waratek?

**["Waratek Bewertung"](https://www.g2.com/de/survey_responses/waratek-review-8347973)**

**Rating:** 4.5/5.0 stars

_— Lincoln C._

[Read full review](https://www.g2.com/de/survey_responses/waratek-review-8347973)

**["Beste Software zur Bereitstellung sicherer Lösungen für Anwendungen"](https://www.g2.com/de/survey_responses/waratek-review-8730843)**

**Rating:** 5.0/5.0 stars

_— Riyaz K._

[Read full review](https://www.g2.com/de/survey_responses/waratek-review-8730843)

### [LIAPP](https://www.g2.com/de/products/liapp/reviews)

LIAPP ist eine spezialisierte Lösung für den Schutz mobiler Anwendungen und den Schutz zur Laufzeit (RASP), die entwickelt wurde, um Android- und iOS-Umgebungen vor unbefugtem Zugriff und Cyberbedrohungen zu sichern. Dieses Sicherheitstool ermöglicht es Entwicklern und Unternehmen, ihre mobilen Anwendungen zu schützen, indem robuste Sicherheitslagen auf das endgültige Anwendungs-Binary angewendet werden, um Schutz vor Manipulation und Reverse Engineering zu gewährleisten, ohne Änderungen am bestehenden Quellcode vornehmen zu müssen. Die Hauptfunktion von LIAPP besteht darin, die Integrität mobiler Anwendungen in risikoreichen Branchen wie Mobile Banking, Fintech und globalem Gaming zu wahren. Durch die Implementierung von LIAPP können Organisationen sich gegen verschiedene Angriffsvektoren wie Rooting, Jailbreaking, Debugging und Speicher-Manipulation verteidigen. Diese Lösung ist besonders effektiv für Unternehmen, die ihre mobilen Dienste mit internationalen Sicherheitsstandards und regionalen Finanzvorschriften in Einklang bringen müssen. Zusätzlich zu seinen Kernschutzfunktionen bietet die LOCKIN Company ergänzende Sicherheitsmodule an, die neben oder unabhängig von LIAPP implementiert werden können, um spezifische Schwachstellen zu adressieren: LISS (Bildschirmschutz): Eine dedizierte Lösung, die entwickelt wurde, um unbefugte Bildschirmaufnahmen, Bildschirmaufzeichnungen und Fernzugriffsversuche zu blockieren, um die Integrität visueller Daten zu schützen. LIKEY (Sicherheits-Tastatur): Eine spezialisierte virtuelle Tastatur, die sensible Benutzereingaben verschlüsselt und sichert, um Datenabfangversuche durch Keylogger und andere bösartige Methoden zu verhindern. Das Bereitstellungsmodell von LIAPP ist für eine schnelle Integration in den Entwicklungszyklus optimiert, um die technische Belastung der Ingenieurteams zu minimieren. Dies ermöglicht es Organisationen, ihre geplanten Veröffentlichungszyklen beizubehalten und gleichzeitig eine sichere Umgebung für ihre Endbenutzer bereitzustellen. Die Lösung bietet mehrere wichtige technische Vorteile: Umfassender App-Schutz: Verhindert unbefugte Modifikation und Neuverpackung der Anwendung, um sicherzustellen, dass die Software wie ursprünglich vorgesehen funktioniert. Dynamischer Laufzeitschutz: Erkennt und blockiert aktiv Sicherheitsbedrohungen während der Ausführung der Anwendung, um Datenverletzungen in Echtzeit zu verhindern. Modulare Sicherheitserweiterung: Ermöglicht es Benutzern, ihre Sicherheitslage zu verbessern, indem sie LISS für Bildschirmschutz oder LIKEY für sichere Dateneingabe basierend auf spezifischen betrieblichen Anforderungen hinzufügen. Unterstützung der Einhaltung von Vorschriften: Bietet die notwendige technische Infrastruktur, um Finanzinstitute bei der Erfüllung strenger Sicherheitsanforderungen für mobile Transaktionen und Betrugsprävention zu unterstützen. Durch seinen spezialisierten Fokus auf Anwendungsintegrität unterstützt LIAPP Benutzer bei der Verwaltung des Sicherheitslebenszyklus ihrer mobilen Produkte. Es bietet Überwachungsfunktionen und Bedrohungsinformationen, die es den Beteiligten ermöglichen, aufkommende Risiken zu identifizieren und eine widerstandsfähige mobile Präsenz aufrechtzuerhalten.

**Average Rating:** 4.8/5.0

**Total Reviews:** 20

#### Who Is the Company Behind LIAPP?

- **Verkäufer:** [Lockin Company](https://www.g2.com/de/sellers/lockin-company)
- **Gründungsjahr:** 2013
- **Hauptsitz:** Seongnam-si,Gyeonggi-do
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=661ca8fd8d6772bd2fdef82a1dad23690c275c49b4a2a3758914a9b83f9490b8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Flockin-company%2F&secure%5Burl_type%5D=linkedin_company_website)  
4 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computerspiele
- **Company Size:** 60% Medium, 35% Small

#### What Are Recent G2 Reviews of LIAPP?

**["Effiziente und leistungsstarke Sicherheitslösung LIAPP empfohlen!"](https://www.g2.com/de/survey_responses/liapp-review-6712420)**

**Rating:** 5.0/5.0 stars

_— Verifizierter Benutzer in Computerspiele_

[Read full review](https://www.g2.com/de/survey_responses/liapp-review-6712420)

**["Verteidigung gegen Hacking- und Fälschungsangriffe"](https://www.g2.com/de/survey_responses/liapp-review-8709178)**

**Rating:** 5.0/5.0 stars

_— Gary C._

[Read full review](https://www.g2.com/de/survey_responses/liapp-review-8709178)

#### What Are G2 Users Discussing About LIAPP?

- [Wofür wird LIAPP verwendet?](https://www.g2.com/de/discussions/what-is-liapp-used-for)

### [DexProtector](https://www.g2.com/de/products/dexprotector/reviews)

Mobile Anwendungen werden zunehmend von Angreifern ins Visier genommen, die versuchen, Code zu reverse-engineeren, Sicherheitskontrollen zu umgehen und das Verhalten von Apps zur Laufzeit zu manipulieren. DexProtector ist ein von EMVCo evaluiertes und genehmigtes Schutzwerkzeug für mobile Anwendungen, das Organisationen dabei hilft, ihre mobilen Apps in der freien Wildbahn zu schützen. Es sichert die Anwendungslogik, verhindert Manipulationen und erkennt kompromittierte Umgebungen, ohne dass Codeänderungen oder komplexe Integrationen erforderlich sind. Von Organisationen in mehr als 75 Ländern genutzt und Anwendungen auf über 500 Millionen Geräten schützend, wird DexProtector von Teams vertraut, die sichere mobile Banking-, Zahlungs- und andere Hochrisikoanwendungen entwickeln. Schützen Sie Apps, ohne Ihren Code zu ändern: DexProtector integriert sich direkt in Ihren Build-Prozess als CLI-, Gradle- oder CI/CD-Aufgabe. Schutzmaßnahmen werden automatisch auf Android- und iOS-Apps und SDKs (APKs, AABs, AARs, IPAs, Frameworks) angewendet, ohne SDKs, ohne Refactoring und ohne Unterbrechung der Entwicklungsabläufe. Verhindern Sie Reverse Engineering, Manipulationen und Laufzeitangriffe: DexProtector kombiniert mehrere Schutzschichten, um sowohl den Anwendungscode als auch das Laufzeitverhalten zu sichern. • Schützt Code mit fortschrittlicher Verschleierung und Verschlüsselung • Erkennt kompromittierte Umgebungen (gerootete, jailbroken und emulierte Geräte) • Verhindert Debugging, dynamische Instrumentierung und Laufzeitmanipulation • Erzwingt Anwendungsintegrität und Anti-Manipulationskontrollen Entwickelt für regulierte und Hochrisiko-Umgebungen: DexProtector wurde unter EMVCo SBMP (Software-Based Mobile Payments) als Software Protection Tool (SPT) evaluiert und genehmigt, was die Zertifizierung für Anwendungen und SDKs vereinfacht und die Einhaltung von Vorschriften in stark regulierten Branchen unterstützt. Erweitern Sie den Schutz mit Echtzeit-Bedrohungsinformationen: DexProtector kann mit Licel's Alice Threat and Device Intelligence-Lösung integriert werden, um Echtzeiteinblicke in Gerätrisiken, Bedrohungssignale und verdächtiges Verhalten zu bieten. Dies ermöglicht es Teams, Bedrohungen über die Anwendungsebene hinaus zu erkennen und darauf zu reagieren. Wichtige Fähigkeiten: • Verschlüsselung von Strings, Klassen und nativen Bibliotheken • Plattformübergreifender Schutz von Code (React Native, Flutter, Xamarin, etc.) • Erkennung von Root, Jailbreak und Emulatoren • Erkennung von Debugging und dynamischer Instrumentierung • Validierung von öffentlichen Schlüsselzertifikaten • White-Box-Kryptographie • Anti-Malware-Mechanismen • Schutz von mobilen APIs • Anti-Manipulations- und Integritätsdurchsetzung

**Average Rating:** 4.9/5.0

**Total Reviews:** 10

#### Who Is the Company Behind DexProtector?

- **Verkäufer:** [Licel](https://www.g2.com/de/sellers/licel)
- **Gründungsjahr:** 2011
- **Hauptsitz:** London, GB
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=4a83092c66723ece26b78be6ae36d5d36a8366f431a3b27fc7f5b6fd58bdeec5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Flicel%2F&secure%5Burl_type%5D=linkedin_company_website)  
33 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Company Size:** 36% Medium, 27% Large

#### What Are Recent G2 Reviews of DexProtector?

**["Eine der besten Lösungen zur Härtung und Sicherheit von mobilen Apps"](https://www.g2.com/de/survey_responses/dexprotector-review-13077554)**

**Rating:** 4.5/5.0 stars

_— Verifizierter Benutzer in Verbraucherdienste_

[Read full review](https://www.g2.com/de/survey_responses/dexprotector-review-13077554)

**["Sichern Sie Android-Apps mit kleineren Lizenzproblemen"](https://www.g2.com/de/survey_responses/dexprotector-review-12721294)**

**Rating:** 4.5/5.0 stars

_— Zafer ._

[Read full review](https://www.g2.com/de/survey_responses/dexprotector-review-12721294)

#### What Are G2 Users Discussing About DexProtector?

- [Wofür wird DexProtector verwendet?](https://www.g2.com/de/discussions/what-is-dexprotector-used-for)

### [Approov](https://www.g2.com/de/products/approov/reviews)

Approov bietet eine robuste Sicherheitslösung für mobile Apps und APIs, die entwickelt wurde, um unbefugten Zugriff, Betrug und API-Missbrauch zu verhindern. Indem sichergestellt wird, dass nur echte, unveränderte mobile Anwendungen mit Backend-Diensten kommunizieren können, schützt Approov Unternehmen in Branchen wie Finanzen, Gesundheitswesen, E-Commerce und vernetzte Fahrzeuge. Die Lösung kombiniert App-Attestierung und Laufzeitschutz (RASP), um Bedrohungen durch Skripte, Bots und modifizierte Apps in Echtzeit zu erkennen und zu blockieren. Approov sichert auch API-Schlüssel, Geheimnisse und Zertifikate zur Laufzeit, um Lecks und unbefugte Nutzung zu verhindern. Im Gegensatz zu traditionellen Sicherheitsmaßnahmen, die auf statischen Abwehrmechanismen basieren, passt sich Approov dynamisch an sich entwickelnde Bedrohungen an und bietet skalierbaren, entwicklerfreundlichen Schutz, ohne Fehlalarme zu erzeugen.

**Average Rating:** 4.8/5.0

**Total Reviews:** 5

#### Who Is the Company Behind Approov?

- **Verkäufer:** [Approov Limited](https://www.g2.com/de/sellers/approov-limited)
- **Gründungsjahr:** 2001
- **Hauptsitz:** Edinburgh, GB
- **Twitter:** @approov\_io  
1,200 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3608a290bc0f39985cc9108b103659b8ea497a7f76811aa6c1b720c63b99efa8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcriticalblue&secure%5Burl_type%5D=linkedin_company_website)  
23 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of Approov?

**["Ein Wendepunkt für die Sicherheit von mobilen APIs – Einfach zu implementieren & äußerst effektiv"](https://www.g2.com/de/survey_responses/approov-review-10829238)**

**Rating:** 5.0/5.0 stars

_— Mike W._

[Read full review](https://www.g2.com/de/survey_responses/approov-review-10829238)

**["Schnelle API-Sicherheitslösung mit Platz für weitere Attestierungsdaten"](https://www.g2.com/de/survey_responses/approov-review-11905215)**

**Rating:** 5.0/5.0 stars

_— Verifizierter Benutzer in Finanzdienstleistungen_

[Read full review](https://www.g2.com/de/survey_responses/approov-review-11905215)

### [Imperva Runtime Application Self-Protection (RASP)](https://www.g2.com/de/products/imperva-runtime-application-self-protection-rasp/reviews)

Da sich Cyber-Bedrohungen weiterentwickeln, benötigen Organisationen mehr als nur Perimeterverteidigungen, um ihre Anwendungen zu schützen. Imperva Runtime Application Self-Protection (RASP) hebt die Anwendungssicherheit auf die nächste Stufe, indem es den Schutz direkt in die Anwendung selbst einbettet. Im Gegensatz zu herkömmlichen Sicherheitslösungen überwacht und schützt RASP Anwendungen kontinuierlich von innen, identifiziert und blockiert Angriffe in Echtzeit, ohne die Leistung zu beeinträchtigen oder Änderungen am Anwendungscode zu erfordern. Imperva RASP bietet umfassenden Schutz gegen eine Vielzahl von Bedrohungen, einschließlich SQL-Injektionen, Cross-Site-Scripting und anderen OWASP Top 10-Schwachstellen. Durch die Analyse des Anwendungsverhaltens und das Verständnis des Kontexts jeder Anfrage kann RASP genau zwischen legitimen Aktivitäten und Angriffen unterscheiden, Fehlalarme reduzieren und legitimen Datenverkehr ungehindert fließen lassen. Diese Fähigkeit stellt sicher, dass Anwendungen sicher bleiben, ohne den Betrieb zu verlangsamen oder die Benutzererfahrung zu beeinträchtigen. Ein wesentlicher Vorteil von RASP ist seine Fähigkeit, neue und ältere Anwendungen sowie Drittanbieterkomponenten zu schützen, ohne teure und zeitaufwändige Codeänderungen zu benötigen. Dies macht es zu einer idealen Lösung für Organisationen, die ihre Sicherheitslage verbessern möchten, ohne ihre Entwicklungspipeline zu stören. Darüber hinaus integriert sich RASP nahtlos in DevOps-Workflows und gewährleistet kontinuierlichen Schutz auch in schnelllebigen Entwicklungsumgebungen. Imperva RASP wird durch kontinuierlich aktualisierte Bedrohungsinformationen unterstützt, die es ermöglichen, sich gegen Zero-Day-Angriffe und aufkommende Bedrohungen zu verteidigen, sobald sie auftreten. Mit RASP können Organisationen ihre Abhängigkeit von Perimeterverteidigungen verringern, die möglicherweise nicht ausreichen, um gegen ausgeklügelte, gezielte Angriffe zu schützen. Stattdessen bietet RASP Echtzeit-Sicherheit in der Anwendung, die Angriffe an der Quelle stoppt, um sicherzustellen, dass Ihre Anwendungen sicher bleiben und Ihr Unternehmen ohne Unterbrechung weiterarbeiten kann. Durch proaktive, Echtzeit-Abwehr mit minimalen betrieblichen Auswirkungen bietet Imperva RASP eine leistungsstarke Lösung zum Schutz kritischer Anwendungen in der heutigen dynamischen Bedrohungslandschaft.

**Average Rating:** 5.0/5.0

**Total Reviews:** 2

#### Who Is the Company Behind Imperva Runtime Application Self-Protection (RASP)?

- **Verkäufer:** [Thales Group](https://www.g2.com/de/sellers/thales-group)
- **Hauptsitz:** Austin, Texas
- **Twitter:** @ThalesCloudSec  
6,935 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6e2851e1a59f8d20bde4bcb61853df023b359c511759b122b0978397a41c6e7e&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fthalessoftwaremonetization%2F&secure%5Burl_type%5D=linkedin_company_website)  
46 Mitarbeiter\*innen auf LinkedIn®
- **Eigentum:** EPA:HO
- **Gesamterlös (USD Mio):** $15,854

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of Imperva Runtime Application Self-Protection (RASP)?

**["Schutz vor den heutigen Online-Bedrohungen."](https://www.g2.com/de/survey_responses/imperva-runtime-application-self-protection-rasp-review-10303490)**

**Rating:** 5.0/5.0 stars

_— Brian S._

[Read full review](https://www.g2.com/de/survey_responses/imperva-runtime-application-self-protection-rasp-review-10303490)

**["Verwenden Sie RASP in unserer Organisation als DDoS-Schutz und Bot-Schutz."](https://www.g2.com/de/survey_responses/imperva-runtime-application-self-protection-rasp-review-7558238)**

**Rating:** 5.0/5.0 stars

_— Nadav N._

[Read full review](https://www.g2.com/de/survey_responses/imperva-runtime-application-self-protection-rasp-review-7558238)

- &lsaquo; Prev ‹ Prev
- 1
- [2](/categories/runtime-application-self-protection-rasp-tools?order=g2_score&page=2#product-list)
- [Next &rsaquo; Next ›](/categories/runtime-application-self-protection-rasp-tools?order=g2_score&page=2#product-list)

Spotlight Categories

[Live Chat Software](https://www.g2.com/categories/live-chat)

[Contract Management Software](https://www.g2.com/categories/contract-management)

[Business Continuity Management (BCM) Software Solutions](https://www.g2.com/categories/business-continuity-management-software)

[Product Lifecycle Management (PLM) Software](https://www.g2.com/categories/product-lifecycle-management-plm)

[Electronic Data Interchange (EDI) Software](https://www.g2.com/categories/electronic-data-interchange-edi)

Similar Categories

- [Application Shielding](/categories/application-shielding)

- [SAP Security Software](/categories/sap-security-software)

[Browse Runtime Application Self-Protection (RASP) Tools Themes](/categories/runtime-application-self-protection-rasp-tools/themes)

 ![Lauren Worth](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Lauren Worth")
LW

Researched and written by [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)

Updated January 8, 2025

Runtime application self-protection (RASP) tools provide continuous attack protection and detection by integrating with, or being built within, an application’s runtime environment. An application runtime environment encompasses everything needed for an application to function, including hardware, software, and the operating system.

These tools are commonly utilized in industries like financial services, healthcare, e-commerce, and government, where protecting sensitive data is critical. RASP solutions monitor and control the application's runtime execution to detect and block threats in real time, enhancing performance and behavior analysis.

Traditionally, [static application security testing (SAST) software](https://www.g2.com/categories/static-application-security-testing-sast) and [dynamic application security testing (DAST) tools](https://www.g2.com/categories/dynamic-application-security-testing-dast) were the primary tools for identifying vulnerabilities in software. SAST software analyzes source code, while DAST tools test running applications. However, RASP tools provide real-time monitoring and protection, complementing SAST and DAST to create a more comprehensive approach to application security.

RASP software also differs from [application shielding software](https://www.g2.com/categories/application-shielding) as application shielding software proactively protects application code to prevent tampering but does not offer real-time attack monitoring and response. However, many application security products offer both sets of capabilities.

Developers use RASP tools to proactively identify vulnerabilities in production environments, while organizations can use them to prevent the exploitation of existing vulnerabilities in deployed applications. RASP solutions are often used alongside [web application firewalls](https://www.g2.com/categories/web-application-firewall-waf), [intrusion detection and prevention systems (IDPS)](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps), and other application security measures to add a layer of self-protection.

To qualify for inclusion in the Runtime Application Self-Protection (RASP) category, a product must:

- Control application runtime execution
- Monitor application performance and behavior
- Detect intrusions or abnormal behavior in real time
- Block common attacks such as SQL injection, cross-site scripting and request forgery, denial of service (DoS), and session hijacking

Show More

### Runtime Application Self-Protection (RASP) Tools Topics

- [What are runtime application self-protection (RASP) tools?](#what-are-runtime-application-self-protection-rasp-tools)
- [How does RASP work?](#how-does-rasp-work)
- [Features of RASP&nbsp;](#features-of-rasp)
- [Benefits of RASP&nbsp;](#benefits-of-rasp)
- [What is the difference between WAF and RASP?&nbsp;](#what-is-the-difference-between-waf-and-rasp)
- [Who uses RASP solutions?](#who-uses-rasp-solutions)
- [RASP security solutions pricing](#rasp-security-solutions-pricing)
- [Software and services related to runtime application self-protection tools](#software-and-services-related-to-runtime-application-self-protection-tools)
- [Challenges with RASP tools](#challenges-with-rasp-tools)
- [Which companies should buy RASP tools?](#which-companies-should-buy-rasp-tools)
- [How to choose the best RASP security solution](#how-to-choose-the-best-rasp-security-solution)
- [RASP implementation&nbsp;](#rasp-implementation)
- [Runtime application self-protection tool trends](#runtime-application-self-protection-tool-trends)

[
### Runtime Application Self-Protection (RASP) Tools Topics
 Expand/Collapse ](#)
- [What are runtime application self-protection (RASP) tools?](#what-are-runtime-application-self-protection-rasp-tools)
- [How does RASP work?](#how-does-rasp-work)
- [Features of RASP&nbsp;](#features-of-rasp)
- [Benefits of RASP&nbsp;](#benefits-of-rasp)
- [What is the difference between WAF and RASP?&nbsp;](#what-is-the-difference-between-waf-and-rasp)
- [Who uses RASP solutions?](#who-uses-rasp-solutions)
- [RASP security solutions pricing](#rasp-security-solutions-pricing)
- [Software and services related to runtime application self-protection tools](#software-and-services-related-to-runtime-application-self-protection-tools)
- [Challenges with RASP tools](#challenges-with-rasp-tools)
- [Which companies should buy RASP tools?](#which-companies-should-buy-rasp-tools)
- [How to choose the best RASP security solution](#how-to-choose-the-best-rasp-security-solution)
- [RASP implementation&nbsp;](#rasp-implementation)
- [Runtime application self-protection tool trends](#runtime-application-self-protection-tool-trends)

## Learn More About Runtime Application Self-Protection (RASP) Tools

Traditional security measures struggle to keep up with evolving threats in a fast-paced digital landscape. That's where Runtime Application Self-Protection (RASP) steps in. RASP empowers applications to defend themselves in real time. Explore how RASP software adapts to the ever-changing threat landscape, making it a crucial tool for safeguarding applications.

### What are runtime application self-protection (RASP) tools?
 

Runtime application self-protection software is a security technology designed to protect applications from cyber threats in real time. It operates by integrating directly into the application’s runtime environment, allowing it to monitor and respond to potential threats based on the application's internal state and behavior.

 

By doing so, RASP tools safeguard against[](https://www.g2.com/articles/data-breach)[data breaches](https://www.g2.com/articles/data-breach),[](https://www.g2.com/articles/malware)[malware](https://www.g2.com/articles/malware), and other threats, offering a proactive approach that strengthens application security.&nbsp;

 

RASP solutions analyze incoming requests and application usage to detect suspicious activity, like[](https://learn.g2.com/sql-injection)[SQL injection](https://learn.g2.com/sql-injection) attempts. When a potential threat is identified, RASP tools can take immediate action—like blocking malicious requests or restricting access—to prevent bot attacks and other vulnerabilities.&nbsp;

 

Advanced RASP tools can even predict potential threats, providing early warnings that further enhance security.

 

### How does RASP work?
 

RASP integrates into the application's runtime environment to monitor application behavior and fix issues when a security event occurs.&nbsp;

 

Unlike traditional security measures that rely on external defenses (like firewalls), RASP utilizes the context of the application’s operations to make informed decisions about potential threats within the application environment.&nbsp;

 

It continuously monitors data flow, execution pathways, and system calls and uses a combination of predefined security policies and dynamic analysis to establish a baseline of normal application behavior. This capability allows it to effectively differentiate between legitimate requests and malicious actions.

 

When deviations from this baseline occur, RASP triggers alerts or takes protective actions. These anomalies can be unauthorized access attempts or unusual system calls that might indicate[](https://www.g2.com/articles/cross-site-scripting)[cross-site scripting (XSS) attacks](https://www.g2.com/articles/cross-site-scripting), SQL injection attacks, or other malicious activity.&nbsp;

 

While stopping potential threats, RASP doesn't modify the application’s code but controls the app's behavior, allowing it to stop threats quickly before they cause significant damage. This real-time control makes RASP a proactive solution for safeguarding applications against evolving cyber threats.

 

In essence, RASP provides a comprehensive shield for applications, is constantly vigilant against evolving threats, and offers real-time protection without disrupting the development workflow.&nbsp;

 

### Features of RASP&nbsp;
 

RASP software offers several key features to enhance application security and protect against various threats:

 
- **Control runtime execution:** RASP enforces security policies within the application, analyzing requests, performing checks, and controlling access in real time to prevent breaches.
- **Monitor performance:** RASP monitors application performance during runtime, tracking metrics to identify abnormal activities that might indicate security threats.&nbsp;
- **Detect intrusions:** RASP analyzes application behavior to detect intrusions and suspicious patterns, including common attacks like SQL injection and unauthorized access attempts. This real-time detection helps mitigate security risks.
- **Automated actions:** Upon detecting suspicious activity, RASP automatically takes predefined actions, such as terminating user sessions, blocking malicious requests, or alerting security personnel. This automation helps in mitigating threats without requiring manual intervention.
- **Flexible deployment options:** RASP can be deployed in different modes, such as monitor mode (where it reports on attacks without blocking them) and protection mode (where it actively blocks malicious activities). This flexibility allows organizations to tailor their security approach based on their needs.
- **API security:** RASP software can secure communication between different parts of an application or between the application and external services through[](https://www.g2.com/articles/what-is-an-api)[Application programming interfaces](https://www.g2.com/articles/what-is-an-api) (APIs). It can detect unauthorized access attempts,[](https://www.g2.com/articles/data-manipulation)[data manipulation](https://www.g2.com/articles/data-manipulation), and other API-specific threats.
- **Protect mobile applications:** RASP technology can be implemented for mobile applications to safeguard against attacks that target mobile devices, such as jailbreaking, rooting, and reverse engineering. It can also protect against data breaches and unauthorized access on mobile platforms.
- **Integration with application code:** RASP is designed to be embedded within the application’s runtime environment. This is achieved through agent-based or library integrations, allowing security features to be implemented without extensive code rewrites. With this integration, RASP provides tailored security measures specific to each application’s needs without significant changes to the application code.&nbsp;

 

### Benefits of RASP&nbsp;

The benefits of RASP software are numerous and impactful:

- **Visibility into application-layer attacks:** With deep insight into the application layer, RASP tools can uncover a wide range of potential attacks and vulnerabilities that traditional methods might miss.
- **Zero-day protection:** RASP goes beyond signature-based detection. By analyzing anomalous behaviors, it can identify and block even[](https://www.g2.com/glossary/zero-day-attack-definition)[zero-day attacks](https://www.g2.com/glossary/zero-day-attack-definition).
- **Lower false positives** : By understanding an application's internals, RASP can accurately differentiate true threats from false alarms, freeing security teams to focus on genuine issues.
- **Enhanced user experience** : By minimizing false positives and responding swiftly to threats, RASP ensures smooth application performance with minimal interruptions to end users.
- **Lower CapEx and OpEx:** RASP's ease of deployment and effectiveness in protecting applications lead to lower upfront costs and ongoing maintenance compared to manual patching and traditional security measures like[](https://www.g2.com/categories/web-application-firewall-waf)WAFs.
- **Easy maintenance:** RASP operates based on application insight rather than traffic rules or blacklists, making it more reliable and resource-efficient for security teams.
- **Flexible deployment:** RASP solutions can adapt to various application architectures and standards, making them suitable for protecting a wide range of applications beyond just web applications.
- **Cloud support:** RASP software seamlessly integrates with cloud environments, allowing deployment wherever the protected on-premises or cloud-native applications run.
- **DevSecOps support:** RASP integrates into DevOps CI/[CD pipelines](https://learn.g2.com/ci-cd-pipeline), facilitating easy deployment and supporting DevSecOps practices by incorporating security throughout the development lifecycle.

### What is the difference between WAF and RASP?&nbsp;

While both RASP and WAF are crucial for application security, they take distinct approaches.

- A WAF sits at the perimeter of a network, acting as a gatekeeper to block or allow traffic based on predefined rules. In contrast, RASP is embedded within the application itself, providing internal protection by monitoring runtime behavior and taking immediate action on threats.
- WAFs focus on detecting and filtering known attack patterns like SQL injection or cross-site scripting using static rules. RASP, however, uses dynamic analysis to understand the application’s behavior, making it more effective against zero-day attacks and insider threats.
- While WAFs operate independently of the application’s code, RASP integrates with the application’s runtime environment, allowing it to control internal processes without extensive code changes.&nbsp;
- WAFs primarily block external threats, while RASP mitigates both internal and external threats in real time.

**Choosing the right tool:** The optimal choice hinges on specific needs. RASP excels for complex applications with unique security requirements or where protection against zero-day attacks is paramount. WAF is well-suited for broader web-facing applications with simpler architectures, offering a strong first line of defense.

For the most comprehensive application security, consider a layered approach that incorporates both RASP and WAF.

### Who uses RASP solutions?

Organizations of all sizes across various industries can benefit from implementing RASP as an additional layer of defense for their applications. This includes:

- **Large enterprises:** RASP strengthens security for complex applications, especially those handling sensitive data.
- **Small businesses:** RASP offers easy-to-use protection against common threats for web and mobile apps, even without a big security team.
- Software companies: Build-in security with RASP makes software more attractive to customers.
- **Financial institutions:** RASP helps protect online banking, payments, and other financial apps from cyberattacks.
- **Healthcare organizations:** Healthcare organizations benefit from RASP for safeguarding patient data in[](https://www.g2.com/categories/ehr)[electronic health record (EHR) systems](https://www.g2.com/categories/ehr), telemedicine platforms, and other healthcare applications.
- **Government agencies:** RASP helps secure web portals, citizen apps, and internal systems from cyber threats and breaches.
- **Tech companies:** RASP is used as part of the cybersecurity to boost the cloud or SaaS platform's security.

### RASP security solutions pricing

The cost of RASP solutions can vary depending on factors like the organization's size, deployment preferences, and required security features. Vendors often offer flexible pricing options, including annual subscriptions or multi-year contracts, to suit different needs.

Typically, RASP is available through perpetual licensing, allowing organizations to make a one-time purchase for full ownership. This enables easy on-site deployment and customization by in-house InfoSec teams. Additional charges may apply for ongoing maintenance and support services.

### Software and services related to runtime application self-protection tools

While there isn't a one-size-fits-all substitute for RASP, several complementary tools target various application security aspects, collaborating to establish a robust security framework. Here's an overview of alternative tools:

- [DevSecOps tools](https://www.g2.com/categories/devsecops):&nbsp; Integrate security practices within the software development lifecycle, with some incorporating RASP to provide runtime protection during deployment and beyond. This category includes tools that embed security controls directly into the CI/CD pipeline, ensuring proactive threat detection and response.
- [Web application firewall:](https://www.g2.com/categories/web-application-firewall-waf) Acts as a perimeter defense, filtering malicious traffic at the network level before it reaches applications. WAFs are essential for blocking common web-based attacks.
- [Static application security testing (SAST) software](https://www.g2.com/categories/static-application-security-testing-sast): Analyzes source code to identify vulnerabilities before deployment. SAST helps developers build secure applications from the ground up.
- [Dynamic application security testing (DAST) software](https://www.g2.com/categories/dynamic-application-security-testing-dast): Scans running applications to detect vulnerabilities after deployment. DAST complements RASP by identifying broader security weaknesses.
- [API security tools](https://www.g2.com/categories/api-security): Secure communication channels between applications and external components like databases by validating requests and responses.
- [Security information and event management (SIEM) software](https://www.g2.com/categories/security-information-and-event-management-siem): Aggregates security data from various sources, including RASP, to provide a centralized view of security threats and incidents.

### Challenges with RASP tools

RASP solutions, while effective in enhancing application security, face several challenges that organizations need to address:

- **False positives and negatives:** RASP tools can struggle with false positives (flagging harmless actions as threats) and false negatives (missing real threats). Fine-tuning configurations and leveraging[](https://www.g2.com/categories/threat-intelligence)[threat intelligence tools](https://www.g2.com/categories/threat-intelligence) are crucial to achieving optimal accuracy.
- **Performance overhead:** RASP monitoring adds processing overhead, potentially slowing down applications. Careful configuration and optimization are necessary to minimize performance degradation.
- **Limited support for legacy systems:** RASP solutions might not fully support older systems due to compatibility or instrumentation limitations. Organizations with legacy applications may need alternative security solutions or consider modernization efforts.
- **Evolving threat landscape:** The [cyber threat landscape](https://www.g2.com/articles/cyber-threats) is ever-changing. RASP needs consistent updates with the latest threat intelligence to combat evolving attack methods effectively.
- **Compliance issues:** Regulations in certain industries might impose specific security controls or reporting requirements. Organizations need to ensure their RASP system implementation aligns with relevant compliance standards.

### Which companies should buy RASP tools?

Companies that should consider investing in Runtime Application Self-Protection (RASP) software typically fall into industries where application security is critical to operations, compliance, or customer trust. This includes organizations that:&nbsp;

- **Face continuous threats:** Organizations facing constant security threats like[](https://www.g2.com/articles/cyber-attack)[cyberattacks](https://www.g2.com/articles/cyber-attack), data breaches, or vulnerability exploitation attempts benefit greatly from RASP's real-time protection within the application environment.
- **Store, handle, and/or process personally identifiable information (PII) or other sensitive data:** Companies that store, handle, or process sensitive data like[](https://www.g2.com/glossary/personally-identifiable-information-definition)[PII](https://www.g2.com/glossary/personally-identifiable-information-definition), financial information, healthcare records, or intellectual property require robust security. RASP helps safeguard this data by detecting and preventing unauthorized access, breaches, and other compromising incidents.
- **Develop and sell software-as-a-service (SaaS) and technology tools**: Software providers, SaaS companies, and tech firms dealing with continuous application development benefit from RASP’s integration with DevSecOps pipelines. RASP supports security throughout the software development lifecycle, identifying and blocking vulnerabilities instantly.
- **Need an additional layer of security:** Organizations prioritizing a layered security approach can leverage RASP alongside existing controls like firewalls, IDS, and[](https://www.g2.com/categories/antivirus)[antivirus software](https://www.g2.com/categories/antivirus). RASP complements these by offering application-level protection, strengthening defense-in-depth strategies, and reducing attack success rates.

### How to choose the best RASP security solution

Selecting the most suitable RASP tool requires carefully considering needs and environment. Here's a breakdown of critical factors to evaluate:

- **Identify vulnerabilities:** Begin by pinpointing the specific vulnerabilities to which applications are susceptible. Seek a RASP tool that mitigates these threats.
- **Choose certified solutions:** Prioritize RASP products endorsed by recognized security organizations like the Center for Internet Security (CIS) and Open Web Application Security Project (OWASP), ensuring their proven and reliable effectiveness.
- **Compare features and pricing:** Evaluate various vendors' RASP offerings, considering features, pricing models, and scalability to find the best fit.
- **Compatibility:** Opt for RASP solutions that are compatible with programming languages and existing hardware/software infrastructure to streamline integration and optimize performance.
- **Seamless integration** : Ensure smooth integration with the current security systems, such as SIEM and WAF, for centralized management and cohesive incident response capabilities. Consider RASP solutions bundled with WAF for a holistic security strategy.
- **Ease of deployment:** Look for RASP solutions that boast rapid deployment without requiring extensive rule creation or learning periods. This ensures swift implementation and minimal disruption to operations.

### RASP implementation&nbsp;

Here are some key steps for effectively implementing RASP software:

- **DevSecOps integration:** Integrate RASP into the[software development life cycle (SDLC)](https://learn.g2.com/software-development-life-cycle) alongside security testing and secure coding practices. This ensures applications are built with security in mind from the beginning.
- **Deployment flexibility:** RASP can be deployed through source code instrumentation, where libraries are added to the application code, or through agent-based deployment, where a lightweight agent is installed on the application server. Choose the method that best suits the development environment and expertise.&nbsp;Typically, agent-based deployment is often easier for legacy systems, while source code instrumentation is better suited for new or microservices-based applications.
- **Synergy with security systems:** Ensure RASP integrates smoothly with the existing security ecosystem, including WAFs,[](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps)[intrusion detection and prevention systems (IDPS)](https://www.g2.com/categories/intrusion-detection-and-prevention-systems-idps), and SIEM tools.&nbsp;Many RASP tools provide application programming interfaces (APIs) to enable better communication with other security systems, improving response coordination This fosters coordinated threat response and avoids conflicts between security controls.
- **Tune security policies:** Most RASP solutions allow customization of security policies. This helps to balance comprehensive protection with minimizing false positives that can disrupt application functionality.
- **Continuous monitoring and updates:** Keep the RASP solution updated with the latest security patches and signatures to ensure protection against evolving threats. Monitor RASP logs and security alerts to identify suspicious activity and potential attacks.

### Runtime application self-protection tool trends

- **Increasing demand for application security:** As cyber threats evolve, organizations increasingly turn to advanced security solutions like RASP. Traditional tools aren't enough anymore. RASP offers real-time threat detection within the application runtime, providing proactive defense against modern application attacks.
- **Focus on Zero Trust Architecture:** The adoption of [zero trust principles](https://www.g2.com/glossary/zero-trust-definition) is pushing RASP tools to offer deeper contextual security at the application level. RASP aligns well with zero trust by continuously validating user and device behaviors, ensuring that only authorized actions are allowed within applications.
- **Compliance awareness:** RASP software is gaining traction due to stricter regulations such as the[](https://www.g2.com/glossary/gdpr-definition)[General Data Protection Regulation](https://www.g2.com/glossary/gdpr-definition) (GDPR), [Payment Card Industry Data Security Standard](https://www.g2.com/glossary/pci-compliance-definition) (PCI DSS),[](https://www.g2.com/glossary/hipaa-definition)[Health Insurance Portability and Accountability Act](https://www.g2.com/glossary/hipaa-definition) (HIPAA) as it helps ensure compliance by offering real-time application security monitoring and protection.
- **Integration of AI and ML:** RASP solutions are incorporating artificial intelligence (AI) and[](https://www.g2.com/articles/machine-learning)[machine learning](https://www.g2.com/articles/machine-learning) (ML) technologies to enhance threat detection and prevention capabilities. These advanced technologies enable RASP solutions to learn from historical data and adapt to new and emerging real-time attacks, improving overall security effectiveness.
- **Adoption of cloud-based solutions:** Cloud-based RASP solutions are becoming popular for their scalability, flexibility, and easy deployment. These solutions provide centralized management and monitoring, appealing to organizations of any size.
- **Expansion of application scope:** RASP solutions are extending beyond web applications to include mobile apps and IoT devices. The need for robust application security becomes paramount with the increasing prevalence of mobile and IoT devices in both consumer and enterprise environments.&nbsp;

Researched and writted by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)