What do you like best about OX Security?
Ox is a fantastic tool at the heart of our AppSec strategy. It’s easy to implement and provides an overwhelming volume of crucial, interrelated data that is vital to running a secure and effective SDLC.
The platform offers a wealth of features for use across your environment, gathering data from multiple stages of the SDLC and creating a top-down view to apply effective risk management strategies. Collected issues are contextually reassessed, and reprioritised severities help better organise and address findings efficiently.
We’ve integrated Ox scanning into our CI pipeline, enabling engineers to identify issues early in the development cycle—before code is merged—thanks to Ox’s pipeline rules. The variety of scans offered is impressive, accounting for numerous variables throughout the code journey.
Ox’s capabilities extend to our EKS clusters, validating image deployments and helping us better organize our registry. The data it provides on identified issues is invaluable for remediation planning, including the source of findings and associated code snippets. While the UI could be more intuitive and has a slight learning curve, it’s clear that all the necessary data is readily accessible within the platform. Administrators can also customise user views to hide irrelevant features, minimizing distractions for engineers.
The recent implementation of RBAC has further simplified our workflows, limiting users' visiblity scope and assigning the appropriate privileges. By dividing findings among the teams that own them and leveraging the application owner features, we can effectively delegate responsibilities and streamline remediation efforts.
Ox’s customer support has been excellent—attentive to our needs and super responsive to feedback. They convey professionalism and a genuine passion for their product and purpose, it shows.
Ox consistently delivers upgrades and new features, almost on a weekly basis. The new BOM capabilities, including Artifact BOM and Cloud BOM, provide unparalleled visibility into our cloud infrastructure and artifacts, helping us maintain control and avoid unvalidated components.
Overall, I highly recommend Ox Security. With their pace of innovation and commitment to excellence, I have no doubt they’ll be an industry leader in the coming years. Review collected by and hosted on G2.com.
What do you dislike about OX Security?
It's worth mentioning that the Ox team are aware of these points and are currently working to have the features implemented to support them shortly.
Issue metrics - Whilst there's great clarity on the issues that are open, it is harder to track what's been closed and why.
Jira integration - This is being developed, but our experience has shown that there is room for optimisation here, the integration at this stage simply creates tickets, it does not have the ability to close or add updates to the tickets through the lifecycle of the vulnerability remediation.
RBAC - This has been implemented and is great, but still requires some work to be a little more dynamic Review collected by and hosted on G2.com.