# Best Interactive Application Security Testing (IAST) Software

## How Many Interactive Application Security Testing (IAST) Software Products Does G2 Track?

**Total Products under this Category:** 19

### Category Stats (Aug 2026)

- **Average Rating:** 4.48/5 The average rating of products in this category, based on all submitted ratings

_Last updated: August 01, 2026_

## How Does G2 Rank Interactive Application Security Testing (IAST) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 400+ Authentic Reviews
- 19+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Interactive Application Security Testing (IAST) Software
 ![G2 Grid® for Interactive Application Security Testing (IAST) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/interactive-application-security-testing-iast/grids.png?focus%5B%5D=4475&focus%5B%5D=32484&focus%5B%5D=16946&focus%5B%5D=32497&focus%5B%5D=16944&focus%5B%5D=1225549&focus%5B%5D=7362)

Highlighted products: Checkmarx, Invicti (formerly Netsparker), HCL AppScan, Contrast Security, OpenText Core Application Security, Semgrep, and Veracode Application Security Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/interactive-application-security-testing-iast/grids.json?focus%5B%5D=checkmarx&focus%5B%5D=invicti-formerly-netsparker&focus%5B%5D=hcl-appscan&focus%5B%5D=contrast-security-contrast-security&focus%5B%5D=opentext-core-application-security&focus%5B%5D=semgrep&focus%5B%5D=veracode-application-security-platform)

**Sponsored**

### CAST Highlight

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2835&secure%5Bchosen_at%5D=2026-08-02T02%3A42%3A50Z&secure%5Bdisplayable_resource_id%5D=2041&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=2041&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=58553&secure%5Bresource_id%5D=2835&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Finteractive-application-security-testing-iast%3Fopen_modal_url%3D%252Fproducts%252Feschecker-mast-sast-dast-iast%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Finteractive-application-security-testing-iast%2526source%253Dcategory&secure%5Btoken%5D=ec6c264dba42cc2f2a66e03888819850d00b706f53acb1a5d6d5c7025db9976c&secure%5Burl%5D=https%3A%2F%2Fwww.castsoftware.com%2Ftryhighlight%3Futm_campaign%3Dg2_clicks_ads%26utm_source%3Dcast_highlight%26utm_medium%3Dtrial_request&secure%5Burl_type%5D=free_trial)

### [Checkmarx](https://www.g2.com/products/checkmarx/reviews)

Checkmarx is a type of application security solution designed to help organizations safeguard their software development processes while enhancing efficiency and reducing costs. The Checkmarx One platform stands out in the realm of enterprise-grade security, offering comprehensive protection that addresses the complexities of modern software development, including legacy systems and AI-generated code. By scanning trillions of lines of code annually, Checkmarx enables companies to significantly lower their vulnerability density, ensuring a robust defense against potential threats. The platform is particularly beneficial for software development teams, security professionals, and organizations that prioritize secure coding practices. With the increasing reliance on AI technologies and the rapid pace of software development, Checkmarx One provides essential tools to mitigate risks associated with both traditional and emerging programming languages. Its innovative architecture, powered by autonomous security agents and AI-native intelligence, allows organizations to integrate security seamlessly into their development workflows, thereby accelerating development velocity without compromising on safety. Key features of Checkmarx One include Triage Assist, which employs an autonomous AI agent to prioritize vulnerabilities based on real-world exploitability and contextual risk. This feature empowers teams to concentrate their efforts on the most critical issues rather than getting bogged down by static severity scores. Additionally, Remediation Assist generates review-ready fixes for validated vulnerabilities prior to code merges, streamlining the secure delivery process and minimizing the manual overhead typically associated with remediation tasks. Developer Assist is another notable feature, acting as a standalone security agent that identifies risks during the coding process. By providing safe, explainable, and verified fixes directly within the integrated development environment (IDE), it supports developers in maintaining a stable and rapid development pace. Furthermore, the platform includes AI Supply Chain Security, which offers centralized governance and visibility for AI components embedded in applications, ensuring that hidden AI assets are discovered and managed effectively. Lastly, Checkmarx One incorporates advanced analysis engines such as AI SAST and DAST for AI, which enhance security measures across various environments. The AI SAST feature expands detection capabilities to cover emerging and unsupported programming languages, while the DAST for AI strengthens runtime protection in continuous integration and deployment (CI/CD) settings. Together, these features position Checkmarx One as a comprehensive solution for organizations looking to fortify their software development lifecycle against evolving threats.

**Average Rating:** 4.2/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Checkmarx?

- **Ease of Use:** 8.5/10 (Category avg: 8.3/10)
- **Quality of Support:** 8.3/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 8.6/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.2/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Checkmarx?

- **Seller:** [Checkmarx](https://www.g2.com/sellers/checkmarx)
- **Company Website:** www.checkmarx.com
- **Year Founded:** 2006
- **HQ Location:** Paramus, NJ
- **Twitter:** @Checkmarx  
7,284 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=18f6741e77df71b112ecb3ec6620912d3a0f67666525358c0a4f3b1278b173df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcheckmarx&secure%5Burl_type%5D=linkedin_company_website)  
1,019 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 56% Large, 23% Medium

#### What Do G2 Reviewers Say About Checkmarx?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Checkmarx **easy to implement** , seamlessly integrating into existing repositories with a user-friendly interface.
- Users appreciate the **intuitive user interface** of Checkmarx, making security reviews simple and user-friendly.
- Users value the **accuracy of results** from Checkmarx, as it simplifies security reviews with detailed vulnerability insights.
- Users value the **automation testing capabilities** of Checkmarx, finding it easy to integrate and use effectively.
- Users praise the **exceptional customer support** at Checkmarx, ensuring prompt assistance for any unresolved issues.

##### Cons

- Users face a high number of **false positives** in Checkmarx when working with Kotlin projects, affecting accuracy and reliability.
- Users report **lacking feature support** for Kotlin, leading to numerous false positives not seen in Java or JavaScript.
- Users experience **missing features** in Checkmarx, specifically regarding poor support for Kotlin that leads to false positives.
- Users find the **poor navigation** in Checkmarx frustrating, as the dashboard layout and display need enhancement.

#### What Are Recent G2 Reviews of Checkmarx?

**["Centralized Source Code Security with Seamless CI/CD Integration"](https://www.g2.com/survey_responses/checkmarx-review-12980590)**

**Rating:** 5.0/5.0 stars

_— Aman M._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-12980590)

**["Checkmarx: Reliable SAST Solution for Strengthening Application Security"](https://www.g2.com/survey_responses/checkmarx-review-13085824)**

**Rating:** 4.0/5.0 stars

_— Naushad T._

[Read full review](https://www.g2.com/survey_responses/checkmarx-review-13085824)

#### What Are G2 Users Discussing About Checkmarx?

- [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) - 1 comment, 1 upvote
- [How much does Checkmarx cost?](https://www.g2.com/discussions/how-much-does-checkmarx-cost)
- [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) - 1 comment
- [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) - 1 comment
- [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) - 2 comments

### [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews)

Invicti (formerly known as Netsparker) is an enterprise application and API security testing platform that helps organizations secure thousands of web applications and APIs at scale while dramatically reducing the risk of attack. Combining advanced DAST and IAST capabilities in a single platform, Invicti enables security teams to continuously identify, prioritize, and remediate vulnerabilities across complex modern environments with confidence and automation. With Invicti, security teams can: - Automate application security testing workflows and save hundreds of hours every month - Discover and secure all web applications and APIs, including forgotten, unmanaged, and shadow assets - Deliver actionable, developer-friendly feedback that helps teams remediate vulnerabilities faster and build more secure code over time - Reduce false positives with proof-based scanning technology that validates exploitable vulnerabilities - Scale application security programs across large enterprises without slowing development teams - Integrate security seamlessly into existing DevSecOps and CI/CD workflows Built for organizations with the most demanding security requirements, Invicti empowers teams to confidently secure their entire attack surface with accuracy, scalability, and automation.

**Average Rating:** 4.5/5.0

**Total Reviews:** 69

#### How Do G2 Users Rate Invicti (formerly Netsparker)?

- **Ease of Use:** 9.1/10 (Category avg: 8.3/10)
- **Quality of Support:** 8.9/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **Ease of Admin:** 9.2/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Invicti (formerly Netsparker)?

- **Seller:** [Invicti Security](https://www.g2.com/sellers/invicti-security-04cb0d3d-fd96-45b2-83dc-2038fc9dac92)
- **Company Website:** www.invicti.com
- **Year Founded:** 2018
- **HQ Location:** Austin, Texas
- **Twitter:** @InvictiSecurity  
2,557 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=3c6c2278d6d9ef248056074aabb5416f9e0b5bf217ea8a7bfb87419d2894bc76&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Finvicti-security%2Fpeople%2F&secure%5Burl_type%5D=linkedin_company_website)  
335 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 46% Large, 29% Medium

#### What Do G2 Reviewers Say About Invicti (formerly Netsparker)?

_AI-generated summary from verified user reviews_

##### Pros

- Users highlight the **ease of use** of Invicti, appreciating its user-friendly setup and quick installation process.
- Users value the **efficient scanning technology** of Invicti, enhancing workflow with hassle-free monthly website tests.
- Users commend Invicti's **accurate vulnerability detection and excellent integration with DevOps tools** , enhancing their security testing efficiency.
- Users value the **high-quality reporting** of Invicti, making it ideal for certifications and simplifying compliance processes.
- Users value the **effective vulnerability detection** of Invicti, appreciating its ease of use and accurate reporting.

##### Cons

- Users find the **customer support lacking** , with slow responses and inadequate solutions for technical issues.
- Users experience **slow performance** during scans, setup, and upgrades, impacting the overall efficiency of Invicti.
- Users find that **slow scanning** can hinder efficiency, especially when setup is tricky and API scanning is limited.
- Users face **API issues** with Invicti, making it unsuitable for scanning purposes despite good support.
- Users find the **complex setup** challenging initially, impacting their experience before they can effectively utilize the product.

#### What Are Recent G2 Reviews of Invicti (formerly Netsparker)?

**["Efficient Scanning, Superb Usability"](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-13155895)**

**Rating:** 4.5/5.0 stars

_— Zach G._

[Read full review](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-13155895)

**["Scalable Enterprise Security: Deep Endpoint Coverage via Invicti"](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-12742667)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/invicti-formerly-netsparker-review-12742667)

#### What Are G2 Users Discussing About Invicti (formerly Netsparker)?

- [What is Invicti (formerly Netsparker) used for?](https://www.g2.com/discussions/what-is-invicti-formerly-netsparker-used-for) - 1 comment
- [What type of vulnerabilities Netsparker can automatically confirm?](https://www.g2.com/discussions/invicti-formerly-netsparker-what-type-of-vulnerabilities-netsparker-can-automatically-confirm)
- [What type of vulnerabilities Netsparker can automatically confirm?](https://www.g2.com/discussions/what-type-of-vulnerabilities-netsparker-can-automatically-confirm)
- [How much does Netsparker cost?](https://www.g2.com/discussions/invicti-formerly-netsparker-how-much-does-netsparker-cost-a1ecffa4-a216-4bcc-affd-40dc140f3e27)
- [How much does Netsparker cost?](https://www.g2.com/discussions/invicti-formerly-netsparker-how-much-does-netsparker-cost)

### [HCL AppScan](https://www.g2.com/products/hcl-appscan/reviews)

HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint application vulnerabilities, allowing for quick remediation in every phase of the software development lifecycle. Fast and Accurate Scanning for Secure DevOps Developers and DevOps teams can quickly and accurately scan code, applications, and APIs for security vulnerabilities while applications are being developed. This allows companies to fix issues at the earliest stages of the software development lifecycle, when it is least costly to the business. Focus on the Fix Continuous monitoring with IAST, along with auto issue correlation with DAST and SAST scan results allows DevOps teams to group and prioritize findings for faster, more streamlined remediation. Enterprise Management for Security Teams Centralized, easy-to-use dashboards provide visibility and oversight of all security scanning and remediation, and allow users to set scan parameters and compliance policies.

**Average Rating:** 4.1/5.0

**Total Reviews:** 74

#### How Do G2 Users Rate HCL AppScan?

- **Ease of Use:** 8.6/10 (Category avg: 8.3/10)
- **Quality of Support:** 8.5/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 8.8/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.6/10 (Category avg: 8.5/10)

#### Who Is the Company Behind HCL AppScan?

- **Seller:** [HCL Technologies](https://www.g2.com/sellers/hcl-technologies)
- **Company Website:** hcl-software.com
- **Year Founded:** 1999
- **HQ Location:** Noida, Uttar Pradesh
- **Twitter:** @hcltech  
425,043 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=956a02ad8dbfeae42d5674b0244526801e33ae7988583df05d94f7af84d4ede2&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1756%2F&secure%5Burl_type%5D=linkedin_company_website)  
246,058 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 54% Large, 28% Small

#### What Are Recent G2 Reviews of HCL AppScan?

**["Easy to setup and powerful application security"](https://www.g2.com/survey_responses/hcl-appscan-review-9387983)**

**Rating:** 4.0/5.0 stars

_— chandramohan K._

[Read full review](https://www.g2.com/survey_responses/hcl-appscan-review-9387983)

**["A Testing Suite that packs quite a punch!"](https://www.g2.com/survey_responses/hcl-appscan-review-9215302)**

**Rating:** 5.0/5.0 stars

_— Pranav U._

[Read full review](https://www.g2.com/survey_responses/hcl-appscan-review-9215302)

#### What Are G2 Users Discussing About HCL AppScan?

- [What is HCL AppScan used for?](https://www.g2.com/discussions/what-is-hcl-appscan-used-for)
- [What does HCL AppScan do?](https://www.g2.com/discussions/what-does-hcl-appscan-do)
- [Who owns AppScan?](https://www.g2.com/discussions/who-owns-appscan) - 1 comment
- [Is AppScan free?](https://www.g2.com/discussions/is-appscan-free) - 1 comment

### [Contrast Security](https://www.g2.com/products/contrast-security-contrast-security/reviews)

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

**Average Rating:** 4.5/5.0

**Total Reviews:** 49

#### How Do G2 Users Rate Contrast Security?

- **Ease of Use:** 8.6/10 (Category avg: 8.3/10)
- **Quality of Support:** 9.3/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Contrast Security?

- **Seller:** [Contrast Security](https://www.g2.com/sellers/contrast-security)
- **Company Website:** contrastsecurity.com
- **Year Founded:** 2014
- **HQ Location:** Pleasanton, CA
- **Twitter:** @contrastsec  
5,468 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=88d434bb9245c6db693a0f2f814fc8a26978bf92e8b8eba720e114bbee116763&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcontrast-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
196 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Insurance, Information Technology and Services
- **Company Size:** 67% Large, 20% Medium

#### What Do G2 Reviewers Say About Contrast Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **accuracy of findings** from Contrast Security, ensuring greater precision in identifying vulnerabilities.
- Users value the **accuracy of results** from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
- Users commend the **real-time vulnerability detection** of Contrast Security, appreciating its quick feedback and agile support.

##### Cons

- Users experienced **performance issues** with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

#### What Are Recent G2 Reviews of Contrast Security?

**["Shift-Smart with Contrast"](https://www.g2.com/survey_responses/contrast-security-review-8492224)**

**Rating:** 5.0/5.0 stars

_— Kiran S._

[Read full review](https://www.g2.com/survey_responses/contrast-security-review-8492224)

**["Contrast Security makes application security simple"](https://www.g2.com/survey_responses/contrast-security-review-8516563)**

**Rating:** 5.0/5.0 stars

_— Verified User in Higher Education_

[Read full review](https://www.g2.com/survey_responses/contrast-security-review-8516563)

#### What Are G2 Users Discussing About Contrast Security?

- [What is contrast protect?](https://www.g2.com/discussions/what-is-contrast-protect)
- [Is Contrast security SaaS?](https://www.g2.com/discussions/is-contrast-security-saas)
- [What is Contrast security tool?](https://www.g2.com/discussions/what-is-contrast-security-tool)
- [What does contrast security do?](https://www.g2.com/discussions/what-does-contrast-security-do)

### [OpenText Core Application Security](https://www.g2.com/products/opentext-core-application-security/reviews)

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

**Average Rating:** 4.1/5.0

**Total Reviews:** 34

#### How Do G2 Users Rate OpenText Core Application Security?

- **Ease of Use:** 8.2/10 (Category avg: 8.3/10)
- **Quality of Support:** 7.9/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.0/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.9/10 (Category avg: 8.5/10)

#### Who Is the Company Behind OpenText Core Application Security?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 41% Large, 32% Small

#### What Are Recent G2 Reviews of OpenText Core Application Security?

**["Safe and Secured Barrier"](https://www.g2.com/survey_responses/opentext-core-application-security-review-8819443)**

**Rating:** 4.5/5.0 stars

_— Ajinkya M._

[Read full review](https://www.g2.com/survey_responses/opentext-core-application-security-review-8819443)

**["Review of MicroFocus Application Defender"](https://www.g2.com/survey_responses/opentext-core-application-security-review-8781016)**

**Rating:** 4.5/5.0 stars

_— sohrab a._

[Read full review](https://www.g2.com/survey_responses/opentext-core-application-security-review-8781016)

#### What Are G2 Users Discussing About OpenText Core Application Security?

- [What are the main components of Fortify?](https://www.g2.com/discussions/micro-focus-fortify-on-demand-what-are-the-main-components-of-fortify)
- [How does Fortify on Demand work?](https://www.g2.com/discussions/how-does-fortify-on-demand-work)
- [What is Fortify software used for?](https://www.g2.com/discussions/micro-focus-fortify-on-demand-what-is-fortify-software-used-for)
- [What is Micro Focus Fortify on Demand?](https://www.g2.com/discussions/what-is-micro-focus-fortify-on-demand)

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### How Do G2 Users Rate Semgrep?

- **Ease of Use:** 9.1/10 (Category avg: 8.3/10)
- **Quality of Support:** 8.8/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.6/10 (Category avg: 9.2/10)
- **Ease of Admin:** 9.1/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Company Website:** semgrep.dev
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Semgrep, praising its intuitive syntax and smooth CI/CD integration.
- Users appreciate the **intuitive pattern-matching syntax** of Semgrep, enabling effective custom rules for various programming languages.
- Users appreciate Semgrep's **effective vulnerability detection** , enabling quick identification of security issues with low false positives.
- Users value the **scanning efficiency** of Semgrep, benefiting from rapid scans and seamless CI/CD integration.
- Users appreciate the **robust security features** of Semgrep, enabling effective identification and remediation of vulnerabilities effortlessly.

##### Cons

- Users find Semgrep **not user-friendly** , citing a steep learning curve and challenges in initial setup and customization.
- Users note the **limited features** of Semgrep, making categorization and comprehensive analysis more challenging.
- Users find the **difficult learning** curve for custom rules in Semgrep challenging, impacting new user experiences and efficiency.
- Users face a **lack of guidance** in mastering rule creation and initial setup, impacting effective tool utilization.
- Users find the **learning curve steep** for rule writing, especially for those new to static analysis tools.

#### What Are Recent G2 Reviews of Semgrep?

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

### [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

**Average Rating:** 3.8/5.0

**Total Reviews:** 25

#### How Do G2 Users Rate Veracode Application Security Platform?

- **Ease of Use:** 7.3/10 (Category avg: 8.3/10)
- **Quality of Support:** 8.0/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 7.9/10 (Category avg: 9.2/10)
- **Ease of Admin:** 7.4/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Veracode Application Security Platform?

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode  
21,950 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d799a3c2e821841d648bc54266ea8fb1c07039938aa9c79b60d2cf275f0dcf34&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F27845%2F&secure%5Burl_type%5D=linkedin_company_website)  
502 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Large, 31% Medium

#### What Do G2 Reviewers Say About Veracode Application Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive security analysis** offered by Veracode, effectively addressing vulnerabilities and streamlining development.
- Users value Veracode for its **effective vulnerability detection** , ensuring high-security standards and seamless integration into development processes.
- Users appreciate the **automated scanning** feature of Veracode, which effectively identifies vulnerabilities and enhances security standards.
- Users value the **effective detection capabilities** of Veracode, enabling thorough security checks and vulnerability identification.
- Users value the **ease of use** of Veracode, benefiting from seamless integration and comprehensive security analysis.

##### Cons

- Users find the platform to be **expensive** , with rising costs and unjustifiable investment in customer success packages.
- Users face a **lack of information** regarding features and services, leading to confusion and unmet expectations.
- Users express concerns about **licensing issues** , citing high costs, complex models, and unmet feature expectations.
- Users report **poor customer support** , experiencing pressure from sales and challenges with feature delivery and documentation.
- Users express concerns over **pricing issues** , citing increased costs, complex licensing, and pressure from sales executives.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**["Streamlined Security, Effortless Integration"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)**

**Rating:** 5.0/5.0 stars

_— Bhanu Prakash M._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

**["Clear, Unified View of Application Capabilities"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)**

**Rating:** 4.5/5.0 stars

_— Christopher S._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

### [Akto API Security Platform](https://www.g2.com/products/akto-api-security-platform/reviews)

Akto is a trusted platform for application security and product security teams to build an enterprise-grade API security program throughout their DevSecOps pipeline. Our industry-leading suite of — API discovery, API security posture management, sensitive data exposure, and API security testing solutions enables organizations to gain visibility in their API security posture. 1,000+ Application Security teams globally trust Akto for their API security needs. Akto use cases: 1. API Discovery 2. API Security Testing in CI/CD 3. API Security Posture Management 4. Authentication and Authorization Testing 5. Sensitive data Exposure 6. Shift left in DevSecOps

**Average Rating:** 4.5/5.0

**Total Reviews:** 54

#### How Do G2 Users Rate Akto API Security Platform?

- **Ease of Use:** 8.6/10 (Category avg: 8.3/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.1/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.4/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Akto API Security Platform?

- **Seller:** [Akto.io](https://www.g2.com/sellers/akto-io)
- **Company Website:** www.akto.io
- **Year Founded:** 2022
- **HQ Location:** San Francisco, California
- **Twitter:** @Aktodotio  
1,357 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=687d485b663f00a21d08f272ed345b1b5caabdc4b03654caa8fd2040afc76f56&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fakto-io%2F&secure%5Burl_type%5D=linkedin_company_website)  
29 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 44% Medium, 40% Small

#### What Do G2 Reviewers Say About Akto API Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate Akto's **automated security testing** for APIs, enhancing their security practices seamlessly within their CI/CD pipeline.
- Users admire the **efficient autonomous AI agents** of Akto, enhancing API security with seamless integration and scalability.
- Users appreciate the **ease of use** of Akto API Security Platform, highlighting its intuitive dashboard and seamless integration.
- Users value the **seamless integration and efficiency** of Akto API Security, enhancing their CI/CD security processes effortlessly.
- Users appreciate the **seamless integration of automation testing** within Akto, enhancing their CI/CD workflows effortlessly.

##### Cons

- Users face a **complex initial setup** with Akto API Security Platform, requiring significant understanding and improved documentation.
- Users face **complex initial setup** challenges with Akto, often struggling with poor documentation and steep learning curves.
- Users face a steep **learning curve** with Akto API Security Platform, making initial setup and understanding challenging.
- Users find the **learning curve steep** for Akto API Security Platform, affecting new users' onboarding and configuration experience.
- Users find the **difficult configuration** of Akto API Security Platform challenging, especially for newcomers navigating its complexities.

#### What Are Recent G2 Reviews of Akto API Security Platform?

**["Easy to Use API Security Tool That Helps Save Time"](https://www.g2.com/survey_responses/akto-api-security-platform-review-11240428)**

**Rating:** 4.5/5.0 stars

_— ashish d._

[Read full review](https://www.g2.com/survey_responses/akto-api-security-platform-review-11240428)

**["Easy to Implement, Clear API Security Visibility, and Responsive Support"](https://www.g2.com/survey_responses/akto-api-security-platform-review-12272742)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/akto-api-security-platform-review-12272742)

### [NowSecure](https://www.g2.com/products/nowsecure/reviews)

NowSecure Inc., based in Oak Park, Illinois, was formed in 2009 with a mission to advance mobile security worldwide. We help secure mobile devices, enterprises and mobile apps.

**Average Rating:** 4.6/5.0

**Total Reviews:** 27

#### How Do G2 Users Rate NowSecure?

- **Ease of Use:** 8.2/10 (Category avg: 8.3/10)
- **Quality of Support:** 9.7/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.3/10 (Category avg: 9.2/10)
- **Ease of Admin:** 9.0/10 (Category avg: 8.5/10)

#### Who Is the Company Behind NowSecure?

- **Seller:** [NowSecure](https://www.g2.com/sellers/nowsecure)
- **Year Founded:** 2009
- **HQ Location:** Chicago, Illinois
- **Twitter:** @nowsecuremobile  
6,372 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e0cc25f0b9ffcadbc4e3260142f1c5c081f73e87791b3aaa10260e9d42e8cd81&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnowsecure&secure%5Burl_type%5D=linkedin_company_website)  
102 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 41% Medium, 37% Large

#### What Are Recent G2 Reviews of NowSecure?

**["NowSecure has proven to be an invaluable asset to our mobile application security testing process."](https://www.g2.com/survey_responses/nowsecure-review-8741524)**

**Rating:** 5.0/5.0 stars

_— Sam S._

[Read full review](https://www.g2.com/survey_responses/nowsecure-review-8741524)

**["Unmatched efficiency and Expertise in Mobile App Security"](https://www.g2.com/survey_responses/nowsecure-review-8901553)**

**Rating:** 5.0/5.0 stars

_— Diego T._

[Read full review](https://www.g2.com/survey_responses/nowsecure-review-8901553)

#### What Are G2 Users Discussing About NowSecure?

- [What is NowSecure used for?](https://www.g2.com/discussions/what-is-nowsecure-used-for)

### [GuardRails](https://www.g2.com/products/guardrails-guardrails/reviews)

GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.

**Average Rating:** 4.3/5.0

**Total Reviews:** 29

#### How Do G2 Users Rate GuardRails?

- **Ease of Use:** 8.3/10 (Category avg: 8.3/10)
- **Quality of Support:** 8.5/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.7/10 (Category avg: 8.5/10)

#### Who Is the Company Behind GuardRails?

- **Seller:** [GuardRails](https://www.g2.com/sellers/guardrails)
- **Year Founded:** 2017
- **HQ Location:** Singapore, Singapore
- **Twitter:** @guardrailsio  
1,553 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6be090277f6c8c141e1d2ae05a89f7c1ee759f1313bdebe23b0a48edda8ba158&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F13599521&secure%5Burl_type%5D=linkedin_company_website)  
13 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 52% Small, 48% Medium

#### What Do G2 Reviewers Say About GuardRails?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **robust security features** of GuardRails, enabling better vulnerability management and compliance in development processes.
- Users value the **vulnerability detection** capabilities of GuardRails, ensuring quick and effective security for their code.
- Users find GuardRails **easy to use** , benefiting from seamless IDE integration and real-time security feedback.
- Users value the **error reduction** capabilities of GuardRails, which enhance security and improve overall development efficiency.
- Users commend the **effective threat detection** of GuardRails, ensuring robust security throughout the development process.

##### Cons

- Users note the **missing features** in GuardRails, such as limited developer access and inadequate report generation capabilities.
- Users find **time management challenging** with GuardRails due to features being overwhelming and limited developer capacity.
- Users face **bug issues** with GuardRails, including code push failures and delays due to low-quality coding practices.
- Users experience **dashboard issues** , facing challenges with report generation and syncing new user dashboards.
- Users report **numerous false positives** in GuardRails, potentially complicating the vulnerability management process.

#### What Are Recent G2 Reviews of GuardRails?

**["A must tool for security"](https://www.g2.com/survey_responses/guardrails-review-8536638)**

**Rating:** 4.0/5.0 stars

_— Sanjeev M._

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8536638)

**["Security and Flexibility with GuardRails"](https://www.g2.com/survey_responses/guardrails-review-8956655)**

**Rating:** 4.0/5.0 stars

_— Muhammad S._

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8956655)

### [Black Duck Seeker Interactive](https://www.g2.com/products/black-duck-seeker-interactive/reviews)

Accurate, automated security testing for your web applications. The industrys first IAST solution with active verification and sensitive-data tracking for web-based applications.

**Average Rating:** 4.8/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate Black Duck Seeker Interactive?

- **Ease of Use:** 8.3/10 (Category avg: 8.3/10)
- **Quality of Support:** 9.2/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 8.3/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Black Duck Seeker Interactive?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,345 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Medium, 50% Small

#### What Are Recent G2 Reviews of Black Duck Seeker Interactive?

**["Seeker for IAST"](https://www.g2.com/survey_responses/black-duck-seeker-interactive-review-10739440)**

**Rating:** 4.5/5.0 stars

_— Verified User in Consulting_

[Read full review](https://www.g2.com/survey_responses/black-duck-seeker-interactive-review-10739440)

**["Best Product In Market"](https://www.g2.com/survey_responses/black-duck-seeker-interactive-review-9514371)**

**Rating:** 5.0/5.0 stars

_— Shriram B._

[Read full review](https://www.g2.com/survey_responses/black-duck-seeker-interactive-review-9514371)

### [PT Application Inspector](https://www.g2.com/products/pt-application-inspector/reviews)

PT Application Inspector™ (PT AI™) is a comprehensive source code analysis tool that offers protection for web applications of any scale. Its holistic approach combines the advantages of static, dynamic, and interactive analysis to maintain application security throughout every stage of development—from the very first line of code to the go-live.

**Average Rating:** 5.0/5.0

**Total Reviews:** 2

#### How Do G2 Users Rate PT Application Inspector?

- **Ease of Use:** 10.0/10 (Category avg: 8.3/10)
- **Quality of Support:** 10.0/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.2/10)
- **Ease of Admin:** 10.0/10 (Category avg: 8.5/10)

#### Who Is the Company Behind PT Application Inspector?

- **Seller:** [Positive Technologies](https://www.g2.com/sellers/positive-technologies)
- **HQ Location:** N/A
- **Twitter:** @PTsecurity\_UK  
6 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=72d1f72f1158c4fa727ba2e5c23b6cdf81412fcdbe1d7abe21c044b6641c9991&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fpositivetechnologies%2F&secure%5Burl_type%5D=linkedin_company_website)  
776 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 67% Large, 33% Small

#### What Are Recent G2 Reviews of PT Application Inspector?

**["We chose PT AI for SDL"](https://www.g2.com/survey_responses/pt-application-inspector-review-3356602)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/pt-application-inspector-review-3356602)

**["Nice source code analyzer "](https://www.g2.com/survey_responses/pt-application-inspector-review-3394127)**

**Rating:** 5.0/5.0 stars

_— Verified User in Banking_

[Read full review](https://www.g2.com/survey_responses/pt-application-inspector-review-3394127)

#### What Are G2 Users Discussing About PT Application Inspector?

- [What is PT Application Inspector used for?](https://www.g2.com/discussions/what-is-pt-application-inspector-used-for)

### [ZeroThreat](https://www.g2.com/products/zerothreat/reviews)

ZeroThreat is an AI-powered web application and API penetration testing platform designed to identify real, exploitable vulnerabilities, not just surface-level findings. Built for modern engineering teams, it combines Agentic AI pentesting with a high-performance scanning engine to deliver up to 10× faster, deeply validated security testing. Unlike traditional DAST tools that rely on static signatures and generate excessive noise, ZeroThreat executes adaptive, attacker-style workflows that evolve based on application behavior. Its interpreter-driven vulnerability intelligence continuously ingests emerging threats and newly disclosed CVEs, enabling near real-time detection updates and rapid CVE-to-exploit mapping. The platform supports over 100,000 vulnerability checks, including native Nuclei template execution, and extends beyond known issues with zero-day detection through behavioral pattern analysis. It validates every finding through live exploit execution, ensuring only real, impactful vulnerabilities are reported, with clear proof of risk and exposed data.

**Average Rating:** 4.8/5.0

**Total Reviews:** 10

#### How Do G2 Users Rate ZeroThreat?

- **Ease of Use:** 8.7/10 (Category avg: 8.3/10)
- **Quality of Support:** 9.4/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 9.4/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.8/10 (Category avg: 8.5/10)

#### Who Is the Company Behind ZeroThreat?

- **Seller:** [ZeroThreat](https://www.g2.com/sellers/zerothreat)
- **HQ Location:** Delaware, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ecb8cc3ed2572bb5109733f408d1d0c525c9b841e160809adf022667c76dc1df&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fzerothreat&secure%5Burl_type%5D=linkedin_company_website)  
4 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 50% Large, 30% Medium

#### What Do G2 Reviewers Say About ZeroThreat?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of ZeroThreat, noting its seamless integration and quick, clear setup and scans.
- Users praise the **accuracy of vulnerability detection** in ZeroThreat, significantly enhancing efficiency in security assessments.
- Users commend the **accuracy of results** from ZeroThreat, minimizing false positives and enhancing efficiency in identifying issues.
- Users find the **setup effortless** with ZeroThreat, enabling quick scans and seamless integration into development pipelines.
- Users find the **easy setup** of ZeroThreat to be effortless, enhancing efficiency in security scanning and issue resolution.

##### Cons

- Users find the **inefficient filtering** in ZeroThreat's reporting section makes retrieving specific data unnecessarily time-consuming.
- Users experience **integration issues** with ZeroThreat, facing challenges with CI/CD and compatibility across different platforms.
- Users find the **limited integration** options with other tools to be a drawback for a smoother experience.
- Users experience **slow performance** with ZeroThreat, as some features lag and loading times can be time-consuming.
- Users find the **UX improvement** necessary due to slow navigation and limited filtering options impacting usability.

#### What Are Recent G2 Reviews of ZeroThreat?

**["Accurate Scans Without All the False Alarms"](https://www.g2.com/survey_responses/zerothreat-review-11864576)**

**Rating:** 4.5/5.0 stars

_— Aiden M._

[Read full review](https://www.g2.com/survey_responses/zerothreat-review-11864576)

**["Continuous Testing & Early Fixes"](https://www.g2.com/survey_responses/zerothreat-review-11927050)**

**Rating:** 5.0/5.0 stars

_— Ethan H._

[Read full review](https://www.g2.com/survey_responses/zerothreat-review-11927050)

### [Staris](https://www.g2.com/products/staris/reviews)

Staris is an AI-powered application security validation platform that continuously discovers, proves, and remediates exploitable vulnerabilities in running applications — in hours, not weeks. Traditional security scanners generate thousands of potential vulnerabilities, forcing teams to rely on expensive, slow manual pentesting to determine which ones are actually exploitable. Staris replaces that bottleneck by combining SAST, DAST, and context-rich whitebox testing to validate real attack paths in your running applications, delivering zero false positives with proof of exploitability for every finding. Staris is purpose-built for application security leaders, DevSecOps teams, and engineering organizations that need to move fast without compromising security. The platform ingests your documentation, policies, and source code to understand your unique application context, then continuously tests for vulnerabilities that matter — not hypothetical risks. Key capabilities: Proves exploitable vulnerabilities with evidence, not just flags them Delivers results in ~4 hours vs. the ~40 hours a typical expert requires (40:1 efficiency) Closed-loop AI-driven remediation that fixes issues and verifies the fix Integrates into CI/CD pipelines for continuous security validation Zero false positives — every finding is proven exploitable Staris is ideal for organizations that are tired of triaging thousands of scanner alerts, waiting weeks for pentest results, or shipping code without knowing whether their applications are actually secure.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate Staris?

- **Ease of Use:** 8.3/10 (Category avg: 8.3/10)
- **Quality of Support:** 10.0/10 (Category avg: 8.9/10)
- **Has the product been a good partner in doing business?:** 10.0/10 (Category avg: 9.2/10)
- **Ease of Admin:** 8.3/10 (Category avg: 8.5/10)

#### Who Is the Company Behind Staris?

- **Seller:** [Staris AI](https://www.g2.com/sellers/staris-ai)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e18cebffbced5e0febfb7acb38ac9297e2e5a94d28551434d9eddc49a2e06ac7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fstaris-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
2 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of Staris?

**["Phenomenal Product - Accurate, Exploitable Findings in Hours"](https://www.g2.com/survey_responses/staris-review-12657690)**

**Rating:** 5.0/5.0 stars

_— Verified User in Accounting_

[Read full review](https://www.g2.com/survey_responses/staris-review-12657690)

### [Data Theorem](https://www.g2.com/products/data-theorem-data-theorem/reviews)

RamQuest’s solutions include our fully integrated closing, escrow accounting, imaging, transaction management, esigning, and digital marketplace solutions and are available on-premise or in a hosted environment

**Average Rating:** 4.0/5.0

**Total Reviews:** 1

#### Who Is the Company Behind Data Theorem?

- **Seller:** [Data Theorem](https://www.g2.com/sellers/data-theorem)
- **Year Founded:** 2013
- **HQ Location:** Palo Alto, California, United States
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c836473aa2fe1cc435daa555c1a9f9a99908c73b766d1c711f4d460a97e3d98d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdatatheorem%2F&secure%5Burl_type%5D=linkedin_company_website)  
94 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Are Recent G2 Reviews of Data Theorem?

**["Convenient AppSec"](https://www.g2.com/survey_responses/data-theorem-review-5226382)**

**Rating:** 4.0/5.0 stars

_— Verified User in Transportation/Trucking/Railroad_

[Read full review](https://www.g2.com/survey_responses/data-theorem-review-5226382)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/interactive-application-security-testing-iast?order=g2_score&page=2#product-list)
- [Next &rsaquo;Next ›](/categories/interactive-application-security-testing-iast?order=g2_score&page=2#product-list)

Spotlight Categories

[Payroll Software](https://www.g2.com/categories/payroll)

[ETL Tools](https://www.g2.com/categories/etl-tools)

[Corporate Performance Management (CPM) Software](https://www.g2.com/categories/corporate-performance-management-cpm)

[Online Reputation Management Software](https://www.g2.com/categories/online-reputation-management)

[Talent Assessment Software](https://www.g2.com/categories/talent-assessment-software)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Log Analysis](/categories/log-analysis)

- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Interactive Application Security Testing (IAST) Themes](/categories/interactive-application-security-testing-iast/themes)

 ![Lauren Worth](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Lauren Worth")
LW

Researched and written by [Lauren Worth](https://research.g2.com/insights/author/lauren-worth)

Updated October 3, 2024

Interactive application security testing (IAST) software inspects and analyzes an application’s code from within to discover security vulnerabilities while the application is running. This testing method differs from both [static application security testing (SAST)](https://www.g2.com/categories/static-application-security-testing-sast), which runs without actually executing an application’s code, and [dynamic application security testing (DAST)](https://www.g2.com/categories/dynamic-application-security-testing-dast), which uses a black-box testing method to perform tests from outside the application. IAST is a faster method for testing code than SAST, which can make it more desirable for teams looking to enhance their [continuous delivery](https://www.g2.com/categories/continuous-delivery) practices. However, IAST software’s real-time speed comes with a comparatively less thorough scanning technique. Unlike SAST software, which analyzes the entire codebase, IAST only executes at specific tester-defined points. IAST software notifies testers when vulnerabilities are discovered and offers remediation suggestions to help teams resolve the issue.

To qualify for inclusion in the interactive application security testing (IAST) category, a product must:

- Test applications as they are running
- Perform predefined tests from within the application 
- Notify teams of vulnerabilities in real time and offer remediation suggestions

Show More