2026 Best Software Awards are here!See the list

DryRun Security Reviews & Product Details

Profile Status

This profile is currently managed by DryRun Security but has limited features.

Are you part of the DryRun Security team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

DryRun Security Integrations

(3)
Integration information sourced from real user reviews.

DryRun Security Media

DryRun Security Demo - AI-Native PR Security That Understands Your Code
Our Code Review Agent reviews every pull request in real time, stops risky merges, and teaches secure habits as developers work.
DryRun Security Demo - Risk Register
Your One Place to See and Act on Risk Across the Organization
DryRun Security Demo - DryRun Security Summary
DryRun Security will generate a summary describing the any security implications of the change. If there were any findings, they will be listed below the summary. Click a finding to expand the dropdown and view the finding details.
DryRun Security Demo - DryRun Security GitHub Checks Integration
DryRun posts security findings directly to GitHub Pull Request Checks, showing vulnerability type, explanation, affected file, and a direct link to the exact line of code so developers can review and fix issues before merge.
Product Avatar Image

Have you used DryRun Security before?

Answer a few questions to help the DryRun Security community

DryRun Security Reviews (17)

Reviews

DryRun Security Reviews (17)

4.9
17 reviews

Review Summary

Generated using AI from real user reviews
Users consistently praise the product for its ease of use and automated scans, which streamline security processes and integrate seamlessly into existing workflows. The ability to receive actionable feedback directly in pull requests enhances developer efficiency and helps maintain secure code practices. A common limitation noted is the sluggish UI, particularly when managing multiple repositories.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
FD
Lead AppSec Eng
Mid-Market (51-1000 emp.)
"Next Gen of SAST Tool That Has Cutting Edge Tech"
What do you like best about DryRun Security?

Very easy to set up and has takes in Github permissions making me worry less about what people have permission on. This SAST tool is a cutting edge and utilizes AI in a proper way allowing us to plug and play the tool into repo and get findings on it consistently across the repos we worry about. Chatting with the sec team + dev team we can see it provides value that other SAST tools haven't provided but also isn't noisy and high accurate letting find very critical bugs that have been missed in the past. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Nothing really. Had minor issues with missing common SAST features (dismissal, long PR comments) but Dry Run's team really steps up their game and take in customer feedback to consistently improve and make the product suit the customer as much as possible. Review collected by and hosted on G2.com.

JA
Director, Product Security Architecture
Enterprise (> 1000 emp.)
"Catches Logic and Authorization Flaws Traditional SAST Often Misses"
What do you like best about DryRun Security?

We use traditional SAST tools, but they mostly depend on rule-based static analysis. DryRun Security, by contrast, focuses on understanding code intent and logical flow, which makes it effective at finding authorization flaws, broken object-level authorization, insecure direct object reference, and insecure business logic. As AI assistants such as Cursor or ChatGPT-based tools become more widely adopted, we face new risks from AI-authored code. DryRun Security helps us focus specifically on the logic flaws that can show up in AI-generated code snippets—issues that traditional scanners often miss. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

This isn’t necessarily about the DryRun functionality itself, but it would be ideal to have DryRun Security available as a Marketplace offering in the cloud provider we use. That would make integration, renewal, and onboarding smoother and easier overall. Review collected by and hosted on G2.com.

Todd B.
TB
CISO
Small-Business (50 or fewer emp.)
"AppSec signal, not noise: DryRun catches the ‘Greeks in the horse’ PRs before they ship"
What do you like best about DryRun Security?

DryRun Security gives me high-signal visibility into the changes that actually matter. The out-of-the-box analyzers help me quickly spot unexpected or risky behavior in pull requests without having to manually comb through everything. It’s become a practical way to scale AppSec review when PR volume is high—especially for catching edge cases that could create real operational or compliance impact.

I also appreciate how quickly the team is iterating: they’re regularly adding meaningful functionality, improving false-positive handling, and behaving like thought leaders in the AppSec space rather than “just another scanner.” Their continued momentum toward/through GRC certifications is a strong indicator they’re building for serious organizations, not hobby deployments.

Getting it installed was SO simple. We didn't need to tweak much, but once we started it got even better!

If the citizens of Troy had used DryRun Security, the Greeks never would have made it in. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

I don’t have many dislikes. If I had to pick one, it would be that I’d love to see even more investment in the developer experience and day-to-day workflow fit—making it a tool developers want to use, not one that security has to continually champion. It’s already valuable, but increasing developer pull (UX, messaging in PRs, “why it matters” context, smoother adoption) would make it even stickier. Review collected by and hosted on G2.com.

Roger W.
RW
Expert Software Engineer
Enterprise (> 1000 emp.)
"Deep Scan Delivers Insightful, Low-Noise Findings for Massive Legacy Codebases"
What do you like best about DryRun Security?

The new Deep Scan feature, which performs a comprehensive review of our application, was incredibly helpful for identifying issues in a legacy application with millions of lines of code. Over the 20+ years of this application's lifespan, we've had several audits and 3rd-party reviews. DryRun's AI had a better grasp of the code's business intent and overall structure than most previous auditors. I expected a firehose of findings, most of which would be false positives or non-issues. However, the report listed 20 or so items to check, only one of which was a complete false positive. We're still tuning the engine for our uses, but the PR reviews have been helpful and insightful. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Their UI can be a bit sluggish, especially when there are many linked GitLab repositories. It's pretty clear they've been spending most of their time on the scanning engines, and the UI was a lower priority. However, that seems to be clearing up, as the UI has improved. Ideally, you shouldn't need to use it much once it's up and running; you can just let it work directly with your repo. Review collected by and hosted on G2.com.

DC
CTO
Small-Business (50 or fewer emp.)
"DryRun’s Context-Aware Scanning Beats Legacy SAST"
What do you like best about DryRun Security?

DryRun's use of LLMs and inclusion of context about the application makes it perform far better than traditional SAST tools. It is able to find "business logic" vulnerabilities that the legacy SAST scanners are simply unable to find and it better characterizes all of its results based on the application context it ingests. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Up until recently, you could only do pull request-level scans. Recently they added the ability to do full-repository scans so I'm excited to see how this capability evolves. Review collected by and hosted on G2.com.

Jonathan C.
JC
CTO
Small-Business (50 or fewer emp.)
"As a security company, we have come to rely on it"
What do you like best about DryRun Security?

I use it every day. We review anywhere from 5-50 PRs. Higher on a good day. We use any of the code review agents, but DryRun is the one we specifically rely on to review the security of the code Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

Until recently, we could only use it on a PR by PR basis. They've added a repo review (or rather an entire codebase review), but I haven't had a chance to test it yet. Review collected by and hosted on G2.com.

Brian J.
BJ
"Spearheading Secure Code Development with Innovative Analysis"
What do you like best about DryRun Security?

The team at DryRun Security has been wonderful to work with, and the technology is seamless to integrate. It provides valuable and ever-improving detections and allows us to accelerate secure code development, especially in the era of AI accelerating code creation. They are really innovating with agentic detections in software, not just static pattern matching like traditional SAST vendors, and can do multidimensional analysis across a wide range of contexts. This helps catch problems that would be otherwise impossible to detect with existing technology and makes our code even more secure against complex and emerging threats like prompt injection or IDOR. Additionally, integration with Impart Security's runtime protection platform is seamless, providing an end to end AI native solution. The initial setup of DryRun Security was very easy. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

I would love to see DryRun Security scan more of the codebase, not just pull requests. I believe they have recently launched a new feature called deepscan, and I would like the DryRun approach to be used in evaluating the entire repo so that I can get a sense of not just new code but also existing code security. Review collected by and hosted on G2.com.

Kyle R.
KR
"Efficient Code Review with Quick Feature Adaptations"
What do you like best about DryRun Security?

I use DryRun Security to identify issues for security review or improvement as our engineering team commits a lot of code. It helps me be aware of risky changes to the codebase and assists with code security reviews. My favorite thing about DryRun is that it allows me to focus on other tasks rather than reviewing code changes and PRs all the time. I appreciate that their team is fairly quick to make feature request changes and listens to customer feedback. The initial setup was very easy and smooth, and there's really nothing like it at the moment — it's great. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

I do somewhat wish there were more customization options for tuning the analyzers, but that seems to be in the works. Review collected by and hosted on G2.com.

Chenkai G.
CG
Security Engineer
Mid-Market (51-1000 emp.)
"One-Time Setup, Automatic Repo Scans, and Actionable PR Comments"
What do you like best about DryRun Security?

Setup is a one-time process, and any new repos are scanned automatically. Findings appear as PR comments, which makes them easy for developers to notice, review, and act on.

Deepscan feels like a step forward for establishing a baseline for repo security standards and for uncovering issues in legacy repos. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

The management portal is still slow to use, and the loading time is noticeably slow by modern standards. Review collected by and hosted on G2.com.

Josh S.
JS
CEO / CISO
Small-Business (50 or fewer emp.)
"Seamless Pipeline Integration with Near Real-Time Vulnerability Feedback"
What do you like best about DryRun Security?

DryRun Security easily integrates into our existing build pipeline so that scans happen automatically and our developers get near real-time feedback on vulnerabilities in their code. Review collected by and hosted on G2.com.

What do you dislike about DryRun Security?

There is nothing that I really dislike about DryRun Security. Even in situations where I've found what I believed to be a bug in the product, they were very quick to investigate and come back to me with a solution. Review collected by and hosted on G2.com.

No Discussions for This Product Yet

Be the first to ask a question and get answers from real users and experts.

Start a discussion
Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.

DryRun Security Features
Static Code Analysis
Code Analysis
Product Avatar Image
DryRun Security