# Best Software Composition Analysis Tools - Page 2

*By [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)*


Software composition analysis (SCA) tools enables users to analyze and manage the open-source elements of their applications. Companies and developers use SCA tools to verify licensing and assess vulnerabilities associated with each of their applications’ open-source components. More robust than [vulnerability scanner software](https://www.g2.com/categories/vulnerability-scanner), SCA tools automatically scan all open-source components to check for policy and license compliance, security risks, and version updates. SCA software also provides insights for remedying identified vulnerabilities, usually within the reports generated after a scan.

Companies and developers often use SCA tools in conjunction with [static code analysis software](https://www.g2.com/categories/static-code-analysis), which scans the code behind their applications as opposed to the open-source components.

To qualify for inclusion within the Software Composition Analysis (SCA) category, a product must:

- Automatically track and analyze an application’s open source-components
- Identify component vulnerabilities, licensing and compliance issues, and version updates
- Provide insight into vulnerability remediation





## Top Software Composition Analysis Tools at a Glance
| # | Product | Rating | Best For | What Users Say |
|---|---------|--------|----------|----------------|
| 1 | [Wiz](https://www.g2.com/products/wiz-wiz/reviews) | 4.7/5.0 (822 reviews) | Agentless code-to-cloud SCA with contextual risk prioritization | "[Excellent Cloud Risk Visibility and Fast Insights with Wiz](https://www.g2.com/survey_responses/wiz-review-12964571)" |
| 2 | [GitHub](https://www.g2.com/products/github/reviews) | 4.7/5.0 (2,315 reviews) | Dependency vulnerability tracking with CI/CD-integrated code review | "[Intuitive, Seamless GitHub Experience That Boosts Collaboration and Efficiency](https://www.g2.com/survey_responses/github-review-13064316)" |
| 3 | [Aikido Security](https://www.g2.com/products/aikido-security/reviews) | 4.6/5.0 (226 reviews) | Reachability-filtered dependency scanning with low-noise triage | "[Enterprise Security Without an Enterprise Security Team](https://www.g2.com/survey_responses/aikido-security-review-13108704)" |
| 4 | [Snyk](https://www.g2.com/products/snyk/reviews) | 4.5/5.0 (135 reviews) | Developer-native SCA with IDE-embedded remediation | "[Seamless Dev-First Security with Fast Scans and Actionable Fixes](https://www.g2.com/survey_responses/snyk-review-12676270)" |
| 5 | [GitLab](https://www.g2.com/products/gitlab/reviews) | 4.5/5.0 (881 reviews) | Pipeline-embedded dependency and vulnerability scanning | "[GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning](https://www.g2.com/survey_responses/gitlab-review-12864830)" |
| 6 | [Semgrep](https://www.g2.com/products/semgrep/reviews) | 4.6/5.0 (56 reviews) | Reachability-filtered SCA inside CI/CD pipelines | "[Streamlined Code Security with Semgrep](https://www.g2.com/survey_responses/semgrep-review-11971635)" |
| 7 | [Cortex Cloud](https://www.g2.com/products/cortex-cloud/reviews) | 4.1/5.0 (122 reviews) | Multi-cloud vulnerability detection with automated remediation | "[Cortex Cloud earned it&#39;s place before every release.](https://www.g2.com/survey_responses/cortex-cloud-review-13089470)" |
| 8 | [Mend.io](https://www.g2.com/products/mend-io/reviews) | 4.3/5.0 (109 reviews) | — | "[Great Tool for Managing 3rd party libraries](https://www.g2.com/survey_responses/mend-io-review-6728890)" |
| 9 | [JFrog](https://www.g2.com/products/jfrog-2024-03-28/reviews) | 4.2/5.0 (146 reviews) | Artifact-native SCA with supply chain traceability | "[JFrog Simplifies Artifact Management for Organized, Reliable Deployments](https://www.g2.com/survey_responses/jfrog-review-12870354)" |
| 10 | [OX Security](https://www.g2.com/products/ox-security/reviews) | 4.8/5.0 (51 reviews) | Consolidated open-source risk with SDLC-wide prioritization | "[A powerful and comprehensive tool that meets most best practices for web app security testing](https://www.g2.com/survey_responses/ox-security-review-10961361)" |


## G2 Grid® for Software Composition Analysis Tools
![G2 Grid® for Software Composition Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/software-composition-analysis/grids.png?focus%5B%5D=146504&focus%5B%5D=1392&focus%5B%5D=1259627&focus%5B%5D=36094&focus%5B%5D=19003&focus%5B%5D=1225549&focus%5B%5D=20461&focus%5B%5D=14032)
Highlighted products: Wiz, GitHub, Aikido Security, Snyk, GitLab, Semgrep, Cortex Cloud, and Mend.io.
Underlying data: [Grid® JSON](https://www.g2.com/categories/software-composition-analysis/grids.json?focus%5B%5D=wiz-wiz&amp;focus%5B%5D=github&amp;focus%5B%5D=aikido-security&amp;focus%5B%5D=snyk&amp;focus%5B%5D=gitlab&amp;focus%5B%5D=semgrep&amp;focus%5B%5D=cortex-cloud&amp;focus%5B%5D=mend-io)


## How Many Software Composition Analysis Tools Products Does G2 Track?
**Total Products under this Category:** 75

### Category Stats (Jul 2026)
- **Average Rating**: 4.48/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product**: Black Duck (+0.77%) - Among all products in this category, Black Duck recorded the largest rating increase compared to last month
*Last updated: July 19, 2026*


## How Does G2 Rank Software Composition Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 6,300+ Authentic Reviews
- 75+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.


## Which Software Composition Analysis Tools Is Best for Your Use Case?

- **Leader:** [Wiz](https://www.g2.com/products/wiz-wiz/reviews)
- **Highest Performer:** [SOOS](https://www.g2.com/products/soos/reviews)
- **Easiest to Use:** [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- **Top Trending:** [Aikido Security](https://www.g2.com/products/aikido-security/reviews)
- **Best Free Software:** [GitLab](https://www.g2.com/products/gitlab/reviews)


---

**Sponsored**

### JFrog

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry&#39;s most pressing trend: the rise of agentic software development and the hidden security risks of &quot;Shadow AI.&quot; In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization&#39;s ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.



[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&amp;secure%5Bad_slot%5D=category_product_list&amp;secure%5Bcategory_id%5D=2041&amp;secure%5Bchosen_at%5D=2026-07-20T00%3A32%3A46Z&amp;secure%5Bdisplayable_resource_id%5D=2041&amp;secure%5Bdisplayable_resource_type%5D=Category&amp;secure%5Bmedium%5D=sponsored&amp;secure%5Bplacement_reason%5D=page_category&amp;secure%5Bplacement_resource_ids%5D%5B%5D=2041&amp;secure%5Bprioritized%5D=false&amp;secure%5Bproduct_id%5D=143017&amp;secure%5Bresource_id%5D=2041&amp;secure%5Bresource_type%5D=Category&amp;secure%5Bsource_type%5D=category_page&amp;secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-composition-analysis%3Fopen_modal_url%3D%252Fproducts%252Fqwiet-ai%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fsoftware-composition-analysis%2526source%253Dcategory&amp;secure%5Btoken%5D=8d8be187156f5ab658fab31cee33d14c3b67c505ddb8c130596cb116b92513ca&amp;secure%5Burl%5D=https%3A%2F%2Fjfrog.com%2Fartifactory%2F%3Futm_source%3Dg2%26utm_medium%3Dcpc_social%26utm_campaign%3Dbrand_awareness_banner_ad%26utm_content%3Du-bin&amp;secure%5Burl_type%5D=custom_url)

---

## What Are the Top-Rated Software Composition Analysis Tools Products in 2026?
### 1. [DerScanner](https://www.g2.com/products/derscanner/reviews)
DerScanner is a complete application security testing solution to eliminate known and unknown code threats across Software Development Lifecycle. DerScanner static code analysis offers developers the support for 43 programming languages ensuring thorough security coverage for almost any application. DerScanner&#39;s SAST uniquely analyzes both source and binary files, revealing hidden vulnerabilities that are often missed in standard scans. This is especially crucial for legacy applications or when source code access is limited. DerScanner’s DAST feature mimics an external attacker, similar to penetration testing. This is vital for finding vulnerabilities that only appear when the application is operational. DAST in DerScanner enriches SAST findings by cross-checking and correlating vulnerabilities detected by both methods. With DerScanner Software Composition Analysis you can gain critical insights into open-source components and dependencies in your projects. It helps identify vulnerabilities early and ensures compliance with licensing terms, reducing legal risks. DerScanner&#39;s Supply Chain Security continuously monitors public repositories, evaluating the security posture of each package. This allows you to make informed decisions about using open-source components in your applications.


**Average Rating:** 5.0/5.0
**Total Reviews:** 8
**How Do G2 Users Rate DerScanner?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Language Support:** 10.0/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.2/10 (Category avg: 8.7/10)
- **Integration:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind DerScanner?**

- **Seller:** [DerSecur](https://www.g2.com/sellers/dersecur)
- **Year Founded:** 2011
- **HQ Location:** Dubai
- **LinkedIn® Page:** https://www.linkedin.com/company/dersecur/ (16 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 88% Small-Business, 63% Mid-Market



#### What Are Recent G2 Reviews of DerScanner?

**"[Making hidden issues visible - real eyes opener](https://www.g2.com/survey_responses/derscanner-review-8890905)"**

**Rating:** 5.0/5.0 stars
*— Jason C.*

[Read full review](https://www.g2.com/survey_responses/derscanner-review-8890905)

---

**"[Great resource that helps my platform stay up to date with needed security measures](https://www.g2.com/survey_responses/derscanner-review-8898184)"**

**Rating:** 5.0/5.0 stars
*— Yury S.*

[Read full review](https://www.g2.com/survey_responses/derscanner-review-8898184)

---



### 2. [ThreatWorx](https://www.g2.com/products/threatworx/reviews)
ThreatWorx is a next-gen proactive cybersecurity platform that protects servers, cloud, containers and source code from malware and vulnerabilities without scanner appliances or bulky agents. ThreatWorx serves multiple use cases including threat intelligence, DevSecOps, cloud security, vulnerability management and third party risk assessment.


**Average Rating:** 4.7/5.0
**Total Reviews:** 9
**How Do G2 Users Rate ThreatWorx?**

- **Quality of Support:** 9.8/10 (Category avg: 9.0/10)
- **Language Support:** 8.3/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.2/10 (Category avg: 8.7/10)
- **Integration:** 9.4/10 (Category avg: 8.8/10)

**Who Is the Company Behind ThreatWorx?**

- **Seller:** [Threatwatch](https://www.g2.com/sellers/threatwatch)
- **Year Founded:** 2016
- **HQ Location:** LOS GATOS, US
- **Twitter:** @threatwatch (100 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/threatwatch/ (5 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 40% Mid-Market, 40% Small-Business



#### What Are Recent G2 Reviews of ThreatWorx?

**"[Amazing security technology](https://www.g2.com/survey_responses/threatworx-review-4936116)"**

**Rating:** 5.0/5.0 stars
*— Parikshit S.*

[Read full review](https://www.g2.com/survey_responses/threatworx-review-4936116)

---

**"[very good product](https://www.g2.com/survey_responses/threatworx-review-6954316)"**

**Rating:** 4.5/5.0 stars
*— Yogesh S.*

[Read full review](https://www.g2.com/survey_responses/threatworx-review-6954316)

---


#### What Are G2 Users Discussing About ThreatWorx?

- [What is ThreatWorx used for?](https://www.g2.com/discussions/what-is-threatworx-used-for)

### 3. [Arnica](https://www.g2.com/products/arnica/reviews)
Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica&#39;s pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica&#39;s unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.


**Average Rating:** 4.9/5.0
**Total Reviews:** 8
**How Do G2 Users Rate Arnica?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Language Support:** 8.3/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 10.0/10 (Category avg: 8.7/10)
- **Integration:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Arnica?**

- **Seller:** [Arnica](https://www.g2.com/sellers/arnica)
- **Company Website:** https://www.arnica.io
- **Year Founded:** 2021
- **HQ Location:** Alpharetta, Georgia
- **Twitter:** @arnicaio (124 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/arnica-io/about (60 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 63% Enterprise, 25% Small-Business


#### What Are Arnica's Pros and Cons?

**Pros:**

- Accuracy of Findings (1 reviews)
- Actionable Recommendations (1 reviews)
- Ease of Use (1 reviews)
- Easy Setup (1 reviews)
- Remediation Solutions (1 reviews)

**Cons:**

- Paid Features (1 reviews)


### What Do G2 Reviewers Say About Arnica?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **accuracy of findings** from Arnica, which helps identify and minimize unnecessary elevated privileges.
- Users value the **actionable recommendations** provided by Arnica, facilitating effective management of elevated privileges in code repositories.
- Users love the **easy setup and administration** of Arnica, saving time while meeting their needs effectively.
- Users love the **easy setup** of Arnica, finding it quick and efficient for their needs.
- Users value Arnica for its ability to **simplify remediation of overprovisioning** and enhance security through effective privilege management.

**Cons:**

- Users note that **paid features** in Arnica restrict access for smaller teams, limiting comprehensive protections.

#### What Are Recent G2 Reviews of Arnica?

**"[Developer-friendly AppSec with a flexible policy engine](https://www.g2.com/survey_responses/arnica-review-12962349)"**

**Rating:** 5.0/5.0 stars
*— Thomas G.*

[Read full review](https://www.g2.com/survey_responses/arnica-review-12962349)

---

**"[Intuitive Dashboards and AI That Finds Real Issues](https://www.g2.com/survey_responses/arnica-review-12972680)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Computer Software*

[Read full review](https://www.g2.com/survey_responses/arnica-review-12972680)

---


#### What Are G2 Users Discussing About Arnica?

- [What is Arnica used for?](https://www.g2.com/discussions/what-is-arnica-used-for)

### 4. [Finite State](https://www.g2.com/products/finite-state/reviews)
Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes—connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed. Learn more at https://finitestate.io/


**Average Rating:** 4.3/5.0
**Total Reviews:** 12
**How Do G2 Users Rate Finite State?**

- **Quality of Support:** 9.2/10 (Category avg: 9.0/10)
- **Language Support:** 10.0/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.3/10 (Category avg: 8.7/10)
- **Integration:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Finite State?**

- **Seller:** [Finite State](https://www.g2.com/sellers/finite-state)
- **Company Website:** https://finitestate.io
- **Year Founded:** 2017
- **HQ Location:** Columbus, Ohio, United States
- **Twitter:** @FiniteStateInc (670 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/finitestate (78 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 50% Enterprise, 25% Mid-Market



#### What Are Recent G2 Reviews of Finite State?

**"[Deep Visibility Into Supply Chain Risks and CVEs—Boosting Product Security](https://www.g2.com/survey_responses/finite-state-review-12966722)"**

**Rating:** 5.0/5.0 stars
*— Suru S.*

[Read full review](https://www.g2.com/survey_responses/finite-state-review-12966722)

---

**"[Finite State Review: Firmware Security Simplified](https://www.g2.com/survey_responses/finite-state-review-12997919)"**

**Rating:** 5.0/5.0 stars
*— Prasanth B.*

[Read full review](https://www.g2.com/survey_responses/finite-state-review-12997919)

---



### 5. [GuardRails](https://www.g2.com/products/guardrails-guardrails/reviews)
GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted by hundreds of teams around the world to build safer apps, GuardRails integrates seamlessly into the developers’ workflow, quietly scans as they code, and shows how to fix security issues on the spot via Just-in-Time training. GuardRails commits to keeping the noise low and only reporting high-impact vulnerabilities that are relevant to your organization. GuardRails helps organizations shift security everywhere and build a strong DevSecOps pipeline, so they can go faster to market without risking security.


**Average Rating:** 4.3/5.0
**Total Reviews:** 29
**How Do G2 Users Rate GuardRails?**

- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Language Support:** 9.2/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 10.0/10 (Category avg: 8.7/10)
- **Integration:** 8.9/10 (Category avg: 8.8/10)

**Who Is the Company Behind GuardRails?**

- **Seller:** [GuardRails](https://www.g2.com/sellers/guardrails)
- **Year Founded:** 2017
- **HQ Location:** Singapore, Singapore
- **Twitter:** @guardrailsio (1,553 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/13599521 (13 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Financial Services
- **Company Size:** 52% Small-Business, 48% Mid-Market


#### What Are GuardRails's Pros and Cons?

**Pros:**

- Security (13 reviews)
- Vulnerability Detection (11 reviews)
- Ease of Use (9 reviews)
- Error Reduction (9 reviews)
- Threat Detection (9 reviews)

**Cons:**

- Missing Features (4 reviews)
- Time Management (3 reviews)
- Bug Issues (2 reviews)
- Dashboard Issues (2 reviews)
- False Positives (2 reviews)


### What Do G2 Reviewers Say About GuardRails?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **robust security features** of GuardRails, enabling better vulnerability management and compliance in development processes.
- Users value the **vulnerability detection** capabilities of GuardRails, ensuring quick and effective security for their code.
- Users find GuardRails **easy to use** , benefiting from seamless IDE integration and real-time security feedback.
- Users value the **error reduction** capabilities of GuardRails, which enhance security and improve overall development efficiency.
- Users commend the **effective threat detection** of GuardRails, ensuring robust security throughout the development process.

**Cons:**

- Users note the **missing features** in GuardRails, such as limited developer access and inadequate report generation capabilities.
- Users find **time management challenging** with GuardRails due to features being overwhelming and limited developer capacity.
- Users face **bug issues** with GuardRails, including code push failures and delays due to low-quality coding practices.
- Users experience **dashboard issues** , facing challenges with report generation and syncing new user dashboards.
- Users report **numerous false positives** in GuardRails, potentially complicating the vulnerability management process.

#### What Are Recent G2 Reviews of GuardRails?

**"[Security and Flexibility with GuardRails](https://www.g2.com/survey_responses/guardrails-review-8956655)"**

**Rating:** 4.0/5.0 stars
*— Muhammad S.*

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8956655)

---

**"[A must tool for security](https://www.g2.com/survey_responses/guardrails-review-8536638)"**

**Rating:** 4.0/5.0 stars
*— Sanjeev M.*

[Read full review](https://www.g2.com/survey_responses/guardrails-review-8536638)

---



### 6. [HCL AppScan](https://www.g2.com/products/hcl-appscan/reviews)
HCL AppScan is a comprehensive suite of market-leading application security testing solutions (SAST, DAST, IAST, SCA, API), available on-premises and on-cloud. These powerful DevSecOps tools pinpoint application vulnerabilities, allowing for quick remediation in every phase of the software development lifecycle. Fast and Accurate Scanning for Secure DevOps Developers and DevOps teams can quickly and accurately scan code, applications, and APIs for security vulnerabilities while applications are being developed. This allows companies to fix issues at the earliest stages of the software development lifecycle, when it is least costly to the business. Focus on the Fix Continuous monitoring with IAST, along with auto issue correlation with DAST and SAST scan results allows DevOps teams to group and prioritize findings for faster, more streamlined remediation. Enterprise Management for Security Teams Centralized, easy-to-use dashboards provide visibility and oversight of all security scanning and remediation, and allow users to set scan parameters and compliance policies.


**Average Rating:** 4.1/5.0
**Total Reviews:** 74
**How Do G2 Users Rate HCL AppScan?**

- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Language Support:** 8.8/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.8/10 (Category avg: 8.7/10)
- **Integration:** 8.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind HCL AppScan?**

- **Seller:** [HCL Technologies](https://www.g2.com/sellers/hcl-technologies)
- **Company Website:** https://hcl-software.com/
- **Year Founded:** 1999
- **HQ Location:** Noida, Uttar Pradesh
- **Twitter:** @hcltech (425,043 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/1756/ (246,058 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Computer &amp; Network Security
- **Company Size:** 54% Enterprise, 28% Small-Business



#### What Are Recent G2 Reviews of HCL AppScan?

**"[Easy to setup and powerful application security](https://www.g2.com/survey_responses/hcl-appscan-review-9387983)"**

**Rating:** 4.0/5.0 stars
*— chandramohan K.*

[Read full review](https://www.g2.com/survey_responses/hcl-appscan-review-9387983)

---

**"[A Testing Suite that packs quite a punch!](https://www.g2.com/survey_responses/hcl-appscan-review-9215302)"**

**Rating:** 5.0/5.0 stars
*— Pranav U.*

[Read full review](https://www.g2.com/survey_responses/hcl-appscan-review-9215302)

---


#### What Are G2 Users Discussing About HCL AppScan?

- [What is HCL AppScan used for?](https://www.g2.com/discussions/what-is-hcl-appscan-used-for)
- [What does HCL AppScan do?](https://www.g2.com/discussions/what-does-hcl-appscan-do)
- [Who owns AppScan?](https://www.g2.com/discussions/who-owns-appscan) - 1 comment
- [Is AppScan free?](https://www.g2.com/discussions/is-appscan-free) - 1 comment

### 7. [Vigiles](https://www.g2.com/products/vigiles/reviews)
Vigiles is a best-in-class vulnerability monitoring and remediation tool that combines a curated CVE database, continuous security feed based on your SBOM, powerful filtering, and easy triage tools so you don’t get blindsided by vulnerabilities.


**Average Rating:** 4.2/5.0
**Total Reviews:** 6
**How Do G2 Users Rate Vigiles?**

- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Language Support:** 8.9/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.9/10 (Category avg: 8.7/10)
- **Integration:** 7.8/10 (Category avg: 8.8/10)

**Who Is the Company Behind Vigiles?**

- **Seller:** [Timesys](https://www.g2.com/sellers/timesys)
- **Year Founded:** 1996
- **HQ Location:** Pittsburgh, US
- **Twitter:** @Timesys (540 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/timesys-corporation/ (52 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 83% Small-Business, 17% Mid-Market



#### What Are Recent G2 Reviews of Vigiles?

**"[A Revolutionary Security Solution for Peace of Mind](https://www.g2.com/survey_responses/vigiles-review-8284121)"**

**Rating:** 4.0/5.0 stars
*— Prashant  S.*

[Read full review](https://www.g2.com/survey_responses/vigiles-review-8284121)

---

**"[Vigiles review](https://www.g2.com/survey_responses/vigiles-review-8911852)"**

**Rating:** 4.0/5.0 stars
*— Tushar T.*

[Read full review](https://www.g2.com/survey_responses/vigiles-review-8911852)

---



### 8. [ZeroPath](https://www.g2.com/products/zeropath/reviews)
ZeroPath (YC S24) is the first AI-native application security platform that fundamentally reimagines how organizations find and fix vulnerabilities. Unlike deterministic SAST tools that bolt AI onto legacy rule engines, ZeroPath was built from the ground up to combine large language models with advanced program analysis (AST, data flow, taint tracking) by Ex-Tesla Red Team and Google Security engineers. ZeroPath&#39;s core differentiation is detecting critical vulnerabilities that pattern-matching SAST fundamentally cannot find. It catches IDORs, authorization bypasses, race conditions, and authentication bugs by reasoning about application behavior and developer intent. This capability achieved a 92% alert reduction when triaging findings from legacy tools. ZeroPath is best suited for enterprises and startups that want a complete appsec experience with: AI-powered SAST across 16+ languages, SCA with exploitability analysis (90% noise reduction by determining if dependency CVEs are actually reachable in your code), secrets detection with validation, IaC scanning for Terraform/CloudFormation/Kubernetes, and natural language security policies. Context-aware autopatch generation fixes 70% of vulnerabilities automatically with framework-specific patches that match your coding standards. To keep the developer experience seamless, ZeroPath integrates into existing workflows with zero configuration. It provides Sub-60-second PR scans on GitHub, GitLab, Bitbucket, and Azure DevOps to provide instant security feedback without blocking development. Developers receive clear explanations, one-click fixes, and can refine patches using natural language commands directly in PR comments. The platform automatically attributes vulnerabilities to responsible developers and syncs bidirectionally with Jira, Linear, and more. Overall, less noise, along with the breadth of integrations, has already made security teams faster in triaging and finding real vulnerabilities. Having been security engineers ourselves, we also understand how important visibility is for the evaluations. ZeroPath users get executive dashboards with real-time MTTR tracking, automated compliance reporting for SOC2 and ISO27001, and risk-based prioritization using CVSS 4.0 scoring. The platform provides complete visibility across organizational repositories, including security models, authentication patterns, and filtering logic, without manual configuration. Our research team dogfeeds our own technology and has discovered CVE-2025-61928 (critical account takeover in better-auth with 300k+ weekly downloads), identified 170+ verified bugs in curl, found 7 vulnerabilities in django-allauth enabling account impersonation, and discovered 0-days in production systems at Netflix, Hulu, and Salesforce. Currently trusted by 750+ companies running 200k+ scans monthly, ZeroPath delivers what security-conscious engineering teams need: more real vulnerabilities, dramatically less noise, and automated fixes that actually work.


**Average Rating:** 4.5/5.0
**Total Reviews:** 11
**How Do G2 Users Rate ZeroPath?**

- **Quality of Support:** 9.4/10 (Category avg: 9.0/10)
- **Integration:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind ZeroPath?**

- **Seller:** [ZeroPath](https://www.g2.com/sellers/zeropath)
- **Company Website:** https://zeropath.com
- **Year Founded:** 2024
- **HQ Location:** San Francisco, US
- **LinkedIn® Page:** https://www.linkedin.com/company/zeropathai/ (12 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 36% Small-Business, 27% Mid-Market


#### What Are ZeroPath's Pros and Cons?

**Pros:**

- Accuracy (6 reviews)
- Accuracy of Findings (6 reviews)
- Security (6 reviews)
- Vulnerability Detection (5 reviews)
- Vulnerability Identification (4 reviews)

**Cons:**

- Bug Issues (2 reviews)
- Bugs (2 reviews)
- Software Bugs (2 reviews)
- Cost Issues (1 reviews)
- Dashboard Issues (1 reviews)


### What Do G2 Reviewers Say About ZeroPath?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **high accuracy** of ZeroPath, effectively surfacing critical issues with minimal false alarms.
- Users value the **accuracy of findings** from ZeroPath, which effectively identifies real issues with minimal false alarms.
- Users value the **effective security identification** of ZeroPath, significantly reducing false alarms compared to other tools.
- Users value the **high accuracy in vulnerability detection** from ZeroPath, appreciating its low false positive rate.
- Users commend ZeroPath for its **accurate vulnerability identification** , significantly reducing false alarms and highlighting critical issues effectively.

**Cons:**

- Users experience **bug issues** with ZeroPath, but appreciate the team&#39;s quick response to resolve them.
- Users report **persistent bugs** in ZeroPath, but commend the team&#39;s quick response to resolve them.
- Users experience **software bugs** in ZeroPath, though the team resolves them quickly, enhancing user satisfaction.
- Users find the **pricing unclear** , making it a challenge for their organizations to justify the expense.
- Users face **dashboard issues** with bugs, although the Zeropath team promptly addresses these problems.

#### What Are Recent G2 Reviews of ZeroPath?

**"[Accurate Source-to-Sink Analysis with Surprisingly Reliable Auto-Patches](https://www.g2.com/survey_responses/zeropath-review-12564698)"**

**Rating:** 5.0/5.0 stars
*— Rohit J.*

[Read full review](https://www.g2.com/survey_responses/zeropath-review-12564698)

---

**"[ZeroPath: ease of use and results superior to the competition](https://www.g2.com/survey_responses/zeropath-review-12308821)"**

**Rating:** 4.0/5.0 stars
*— Maxime J.*

[Read full review](https://www.g2.com/survey_responses/zeropath-review-12308821)

---



### 9. [Debricked](https://www.g2.com/products/debricked/reviews)
Debricked&#39;s SCA-tool allows you to manage your open source in an easy, smart and efficient manner. Automatically find, fix and prevent vulnerabilities, avoid non compliant licenses and evaluate the health of your dependencies - all in one tool. Security - Your developers shouldn&#39;t have to be security experts in order to write secure code. Debricked helps your developers automate open source security in their own pipelines and generate fixes with a button click. License Compliance - Make open source compliance a non issue by automating the prevention of non compliant licenses. Set customizable pipeline rules and make sure to be ready for launch year round. Community Health - Help your developers make informed decisions when choosing what open source to use. Search for name or functionality and easily compare similar projects side by side on a set of health metrics.


**Average Rating:** 4.8/5.0
**Total Reviews:** 5
**How Do G2 Users Rate Debricked?**

- **Quality of Support:** 9.4/10 (Category avg: 9.0/10)
- **Language Support:** 6.7/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.3/10 (Category avg: 8.7/10)
- **Integration:** 9.4/10 (Category avg: 8.8/10)

**Who Is the Company Behind Debricked?**

- **Seller:** [Debricked](https://www.g2.com/sellers/debricked)
- **Year Founded:** 2018
- **HQ Location:** Malmö, SE
- **Twitter:** @debrickedab (473 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/debricked/ (6 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 60% Small-Business, 40% Mid-Market



#### What Are Recent G2 Reviews of Debricked?

**"[Developer-First SCA with Fast Scans, Auto Fix PRs, and Clear SBOM Visibility](https://www.g2.com/survey_responses/debricked-review-12483146)"**

**Rating:** 5.0/5.0 stars
*— Sagar S.*

[Read full review](https://www.g2.com/survey_responses/debricked-review-12483146)

---

**"[Powerful and easy to integrate](https://www.g2.com/survey_responses/debricked-review-7373046)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Renewables &amp; Environment*

[Read full review](https://www.g2.com/survey_responses/debricked-review-7373046)

---



### 10. [rezilion](https://www.g2.com/products/rezilion/reviews)
Rezilion&#39;s software attack surface management platform automatically secures the software you deliver to customers, giving teams time back to build. Rezilion works across your stack, helping you to know what software is in your environment, what is vulnerable, and what is actually exploitable, so you can focus on what matters and remediate automatically. KEY FEATURES: - Dynamic SBOM Create an instant inventory of all the software components in your environment - Vulnerability Validation Know which of your software vulnerabilities are exploitable, and which are not, through runtime analysis - Vulnerability Remediation Cluster vulnerabilities to eliminate multiple problems at once and automatically execute remediation work to save teams time. WITH REZILION, ACHIEVE: - 85% reduction in patching work after filtering out unexplainable vulnerabilities - 24/7 Continuous monitoring of your software attack surface -600% Faster time to remediate when you focus on what matters and patch automatically - 360-degree visibility across your entire DevSecOps stack -- not just in silos


**Average Rating:** 4.4/5.0
**Total Reviews:** 11
**How Do G2 Users Rate rezilion?**

- **Quality of Support:** 9.3/10 (Category avg: 9.0/10)
- **Language Support:** 8.9/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.9/10 (Category avg: 8.7/10)
- **Integration:** 7.2/10 (Category avg: 8.8/10)

**Who Is the Company Behind rezilion?**

- **Seller:** [rezilion](https://www.g2.com/sellers/rezilion)
- **Year Founded:** 2018
- **HQ Location:** Be&#39;er Sheva, Israel
- **Twitter:** @rezilion_ (198 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/18716043 (5 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 45% Mid-Market, 36% Enterprise



#### What Are Recent G2 Reviews of rezilion?

**"[A New Era of Software Supply Chain Security](https://www.g2.com/survey_responses/rezilion-review-8402929)"**

**Rating:** 5.0/5.0 stars
*— Jawahar A.*

[Read full review](https://www.g2.com/survey_responses/rezilion-review-8402929)

---

**"[Platform for Automated Software Supply Chain Security](https://www.g2.com/survey_responses/rezilion-review-8137689)"**

**Rating:** 4.0/5.0 stars
*— Dr. Rajesh V.*

[Read full review](https://www.g2.com/survey_responses/rezilion-review-8137689)

---



### 11. [Sonatype Nexus Repository](https://www.g2.com/products/sonatype-nexus-repository/reviews)
World’s #1 Repository Manager with Free and Pro versions - Single source of truth for all of your components, binaries, and build artifacts. - Efficiently distribute parts and containers to developers. - Used by more than 5 million developers globally. Centralize Give your teams a single source of truth for every component they use. Store Optimize build performance and reliability by caching proxies of remote repositories. Adapt Deliver universal coverage for all major package types and formats Scale Install on an unlimited amount of servers for an unlimited amount of users. Universal Support for all Popular Build Tools Store and distribute Maven/Java, npm, NuGet, Helm, Docker, P2, OBR, APT, GO, R, Conan components and more. Manage components from dev through delivery: binaries, containers, assemblies, and finished goods. Awesome support for the Java Virtual Machine (JVM) ecosystem, including Gradle, Ant, Maven, and Ivy. Compatible with popular tools like Eclipse, IntelliJ, Hudson, Jenkins, Puppet, Chef, Docker, and more. Enterprise Control of Binaries and Build Artifacts Deliver innovation 24x7x365 with high availability. A single source of truth for components used across your entire software development lifecycle including QA, staging, and operations. Easily integrate with existing user and access provisioning systems including LDAP, Atlassian Crowd, and more. SAML/SSO authentication for enhanced security and single sign-on experience. See the Health of Your Software Supply Chain Repository Health Check (RHC) provides up-to-date component intelligence, so your teams make informed decisions early on. View components in need of remediation, prioritized by the severity of vulnerability. Easily avoid known security and license issues for Maven/Java, npm, NuGet, and PyPI components. Modern Features for Continuous Innovation Deploy directly to a desired repository with your choice of build or deployment tool or directly via HTTP. Stage and manage releases with dedicated security and automated rule validation. Enhanced staging provides streamlined oversight and approval of workflows for release candidates. Share binaries, snapshots and releases between groups of developers or post a collection of related, staged artifacts which can be easily tested, promoted, or discarded.


**Average Rating:** 4.5/5.0
**Total Reviews:** 21
**How Do G2 Users Rate Sonatype Nexus Repository?**

- **Quality of Support:** 8.3/10 (Category avg: 9.0/10)

**Who Is the Company Behind Sonatype Nexus Repository?**

- **Seller:** [Sonatype](https://www.g2.com/sellers/sonatype)
- **Year Founded:** 2008
- **HQ Location:** Fulton, US
- **Twitter:** @sonatype (10,589 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/210324/ (551 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 43% Enterprise, 39% Mid-Market



#### What Are Recent G2 Reviews of Sonatype Nexus Repository?

**"[Perfect solution for artifact management](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9115886)"**

**Rating:** 4.0/5.0 stars
*— Juan Diego P.*

[Read full review](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9115886)

---

**"[Easy to use repository for sharing artifacts within team](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9407466)"**

**Rating:** 4.0/5.0 stars
*— Ardhiya C.*

[Read full review](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9407466)

---


#### What Are G2 Users Discussing About Sonatype Nexus Repository?

- [What does a repository manager do?](https://www.g2.com/discussions/nexus-repository-manager-what-does-a-repository-manager-do)
- [What does a repository manager do?](https://www.g2.com/discussions/what-does-a-repository-manager-do)
- [What is Nexus repository tool?](https://www.g2.com/discussions/what-is-nexus-repository-tool)
- [What is Nexus software used for?](https://www.g2.com/discussions/what-is-nexus-software-used-for) - 1 comment
- [What is Nexus repository manager used for?](https://www.g2.com/discussions/what-is-nexus-repository-manager-used-for)

### 12. [Dependency-Track](https://www.g2.com/products/dependency-track/reviews)
Dependency-Track is an intelligent Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). This approach provides capabilities that traditional Software Composition Analysis (SCA) solutions cannot achieve. Dependency-Track monitors component usage across all versions of every application in its portfolio in order to proactively identify risk across an organization. The platform has an API-first design and is ideal for use in Continuous Integration (CI) and Continuous Delivery (CD) environments.


**Average Rating:** 4.3/5.0
**Total Reviews:** 4
**How Do G2 Users Rate Dependency-Track?**

- **Quality of Support:** 6.7/10 (Category avg: 9.0/10)
- **Language Support:** 9.2/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 7.5/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind Dependency-Track?**

- **Seller:** [OWASP](https://www.g2.com/sellers/owasp)
- **Year Founded:** 2001
- **HQ Location:** Wakefield, US
- **Twitter:** @DependencyTrack (1,436 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/owasp (681 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 75% Enterprise, 25% Mid-Market


#### What Are Dependency-Track's Pros and Cons?

**Pros:**

- Ease of Use (1 reviews)
- Features (1 reviews)
- Risk Management (1 reviews)
- User Interface (1 reviews)

**Cons:**

- Limited Cloud Integration (1 reviews)


### What Do G2 Reviewers Say About Dependency-Track?
*AI-generated summary from verified user reviews*

**Pros:**

- Users praise the **neat UI and intuitive design** of Dependency-Track, enhancing their overall user experience.
- Users appreciate the **neat UI and ease of integration** in Dependency-Track, enhancing usability through illustrative dashboards.
- Users value the **neat UI** and illustrative design of Dependency-Track, enhancing overall risk management efficiency.
- Users appreciate the **neat UI with side nav bars and illustrative dashboards** for enhanced usability and integration.

**Cons:**

- Users find the **limited cloud integration** frustrating, resorting to manual data export methods for collaboration.

#### What Are Recent G2 Reviews of Dependency-Track?

**"[Dependency track](https://www.g2.com/survey_responses/dependency-track-review-6770857)"**

**Rating:** 4.0/5.0 stars
*— Suryansh G.*

[Read full review](https://www.g2.com/survey_responses/dependency-track-review-6770857)

---

**"[Full focus on vulnerabilities](https://www.g2.com/survey_responses/dependency-track-review-10750867)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Medical Devices*

[Read full review](https://www.g2.com/survey_responses/dependency-track-review-10750867)

---


#### What Are G2 Users Discussing About Dependency-Track?

- [What is Dependency-Track used for?](https://www.g2.com/discussions/what-is-dependency-track-used-for) - 1 comment

### 13. [Kiuwan Code Security &amp; Insights](https://www.g2.com/products/kiuwan-code-security-insights/reviews)
Fast, Flexible Code Security! Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. By integrating seamlessly into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. Top features: ✅ Extensive language support: Over 30 programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation. Kiuwan is now part of Sembi - a global portfolio of market-leading software brands focused on software quality, security, and developer productivity. Code Smarter. Secure Faster. Ship Sooner


**Average Rating:** 4.5/5.0
**Total Reviews:** 29
**How Do G2 Users Rate Kiuwan Code Security &amp; Insights?**

- **Quality of Support:** 8.9/10 (Category avg: 9.0/10)

**Who Is the Company Behind Kiuwan Code Security &amp; Insights?**

- **Seller:** [Sembi](https://www.g2.com/sellers/sembi)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** https://www.linkedin.com/company/sembi-inc/ (94 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services, Banking
- **Company Size:** 41% Enterprise, 35% Mid-Market


#### What Are Kiuwan Code Security &amp; Insights's Pros and Cons?

**Pros:**

- Accuracy (2 reviews)
- Accuracy of Findings (2 reviews)
- Customer Support (2 reviews)
- Ease of Use (2 reviews)
- Automation Testing (1 reviews)



### What Do G2 Reviewers Say About Kiuwan Code Security &amp; Insights?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend the **accuracy** of Kiuwan&#39;s code scans, ensuring reliable results and satisfaction with reporting capabilities.
- Users value the **accuracy of findings** from Kiuwan Code Security &amp; Insights, enhancing their confidence in code security.
- Users appreciate the **efficient customer support** of Kiuwan, enhancing their overall experience and satisfaction with the product.
- Users value the **user-friendly interface** of Kiuwan, enhancing their experience with efficient code scans and reporting.
- Users appreciate the **user-friendly interface** of Kiuwan Code Security &amp; Insights, making dashboard navigation easy and efficient.


#### What Are Recent G2 Reviews of Kiuwan Code Security &amp; Insights?

**"[Elevated our software security to the next level. Improved our code quality.](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)"**

**Rating:** 5.0/5.0 stars
*— Abdullah Enes K.*

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-11651809)

---

**"[Impeccable Security and Code Analysis, with Potential for Improvement in Customization](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)"**

**Rating:** 5.0/5.0 stars
*— Abelardo I.*

[Read full review](https://www.g2.com/survey_responses/kiuwan-code-security-insights-review-12676887)

---



### 14. [IriusRisk](https://www.g2.com/products/iriusrisk/reviews)
We make secure design the standard, scalable practice for all digital teams. IriusRisk makes secure design fast, reliable and accessible, even to non-security users, thanks to our automated and AI-augmented Threat Modeling Solution.


**Average Rating:** 4.7/5.0
**Total Reviews:** 3
**How Do G2 Users Rate IriusRisk?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Language Support:** 5.0/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 6.7/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind IriusRisk?**

- **Seller:** [IriusRisk](https://www.g2.com/sellers/iriusrisk)
- **HQ Location:** Huesca, Aragon, Spain
- **Twitter:** @IriusRisk (1,666 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/iriusrisk/ (181 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 33% Enterprise, 33% Mid-Market


#### What Are IriusRisk's Pros and Cons?

**Pros:**

- Useful (1 reviews)

**Cons:**

- Limited Cloud Integration (1 reviews)


### What Do G2 Reviewers Say About IriusRisk?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **threat library** of IriusRisk, finding it highly beneficial for risk assessment and management.

**Cons:**

- Users often face **limited cloud integration** , making it harder to connect with other tools and systems.

#### What Are Recent G2 Reviews of IriusRisk?

**"[In need of a threat modelling tool? Iriusrisk might be your friend indeed!!](https://www.g2.com/survey_responses/iriusrisk-review-7162460)"**

**Rating:** 4.5/5.0 stars
*— Gautam R.*

[Read full review](https://www.g2.com/survey_responses/iriusrisk-review-7162460)

---

**"[Secure By design using IriusRisk](https://www.g2.com/survey_responses/iriusrisk-review-11828166)"**

**Rating:** 5.0/5.0 stars
*— Lokesh T.*

[Read full review](https://www.g2.com/survey_responses/iriusrisk-review-11828166)

---



### 15. [Sonatype Lifecycle](https://www.g2.com/products/sonatype-lifecycle/reviews)
Continuously secure your software supply chain with Sonatype Nexus Lifecycle, a software composition analysis (SCA) solution. Nexus Lifecycle helps development, security, and compliance teams reduce open source risk without slowing delivery. It detects vulnerable or non-compliant components early, provides clear remediation guidance, and enforces the same policies from development through CI/CD and release - powered by Sonatype Nexus Intelligence. Choose safer components up front: A Chrome extension and IDE integrations surface vulnerability, license, and quality insights as developers browse public repositories or add dependencies. Fix issues fast where work happens: In Eclipse, IntelliJ, and Visual Studio, developers can see exactly what&#39;s wrong and upgrade to an approved version with a click - no guesswork. Automate remediation in source control: Integrations with GitHub, GitLab, and Atlassian Bitbucket can comment on pull/merge requests and identify the specific dependency change that introduces risk, along with recommended versions to resolve it. You can also generate automated pull requests to update components that violate policy. Enforce open source policies across the SDLC: Create security, license, and architectural policies tailored by application type, team, or organization, then apply them consistently in developer tools, CI/CD, and repositories to prevent risky components from reaching production. Generate SBOMs in minutes: Produce accurate Software Bills of Materials (SBOMs) per application to understand what components and transitive dependencies are in use and verify compliance. Prove progress with reporting: Track trends like Mean Time to Resolution (MTTR) and violation reduction over time to demonstrate measurable risk reduction to stakeholders. Nexus Lifecycle integrates with common developer, CI/CD, and repository tools including Nexus Repository, Artifactory, Jira, Jenkins, Azure DevOps, and more.


**Average Rating:** 4.2/5.0
**Total Reviews:** 3
**How Do G2 Users Rate Sonatype Lifecycle?**

- **Quality of Support:** 7.5/10 (Category avg: 9.0/10)

**Who Is the Company Behind Sonatype Lifecycle?**

- **Seller:** [Sonatype](https://www.g2.com/sellers/sonatype)
- **Year Founded:** 2008
- **HQ Location:** Fulton, US
- **Twitter:** @sonatype (10,589 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/210324/ (551 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 75% Enterprise, 25% Mid-Market



#### What Are Recent G2 Reviews of Sonatype Lifecycle?

**"[Best SCA tool in the market for Java, and .NET](https://www.g2.com/survey_responses/sonatype-lifecycle-review-6933703)"**

**Rating:** 5.0/5.0 stars
*— Vis C.*

[Read full review](https://www.g2.com/survey_responses/sonatype-lifecycle-review-6933703)

---

**"[So many features, easily configurable and wide support for a lot of languages](https://www.g2.com/survey_responses/sonatype-lifecycle-review-4165826)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Financial Services*

[Read full review](https://www.g2.com/survey_responses/sonatype-lifecycle-review-4165826)

---



### 16. [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)
Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.


**Average Rating:** 3.8/5.0
**Total Reviews:** 25
**How Do G2 Users Rate Veracode Application Security Platform?**

- **Quality of Support:** 8.0/10 (Category avg: 9.0/10)
- **Language Support:** 10.0/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 10.0/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

**Who Is the Company Behind Veracode Application Security Platform?**

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode (21,950 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/27845/ (502 employees on LinkedIn®)

**Who Uses This Product?**
- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Enterprise, 31% Mid-Market


#### What Are Veracode Application Security Platform's Pros and Cons?

**Pros:**

- Security (5 reviews)
- Vulnerability Detection (5 reviews)
- Automated Scanning (3 reviews)
- Detection (3 reviews)
- Ease of Use (3 reviews)

**Cons:**

- Expensive (2 reviews)
- Lack of Information (2 reviews)
- Licensing Issues (2 reviews)
- Poor Customer Support (2 reviews)
- Pricing Issues (2 reviews)


### What Do G2 Reviewers Say About Veracode Application Security Platform?
*AI-generated summary from verified user reviews*

**Pros:**

- Users appreciate the **comprehensive security analysis** offered by Veracode, effectively addressing vulnerabilities and streamlining development.
- Users value Veracode for its **effective vulnerability detection** , ensuring high-security standards and seamless integration into development processes.
- Users appreciate the **automated scanning** feature of Veracode, which effectively identifies vulnerabilities and enhances security standards.
- Users value the **effective detection capabilities** of Veracode, enabling thorough security checks and vulnerability identification.
- Users value the **ease of use** of Veracode, benefiting from seamless integration and comprehensive security analysis.

**Cons:**

- Users find the platform to be **expensive** , with rising costs and unjustifiable investment in customer success packages.
- Users face a **lack of information** regarding features and services, leading to confusion and unmet expectations.
- Users express concerns about **licensing issues** , citing high costs, complex models, and unmet feature expectations.
- Users report **poor customer support** , experiencing pressure from sales and challenges with feature delivery and documentation.
- Users express concerns over **pricing issues** , citing increased costs, complex licensing, and pressure from sales executives.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**"[Streamlined Security, Effortless Integration](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)"**

**Rating:** 5.0/5.0 stars
*— Bhanu Prakash M.*

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

---

**"[Clear, Unified View of Application Capabilities](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)"**

**Rating:** 4.5/5.0 stars
*— Christopher S.*

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

---


#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

### 17. [Xygeni](https://www.g2.com/products/xygeni/reviews)
Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage security risks while minimizing noise and overwhelming alerts. Our innovative technologies automatically detect malicious code in real-time upon new and updated components publication, immediately notifying customers and quarantining affected components to prevent potential breaches. With extensive coverage spanning the entire Software Supply Chain—including Open Source components, CI/CD processes and infrastructure, Anomaly detection, Secret leakage, Infrastructure as Code (IaC), and Container security—Xygeni ensures robust protection for your software applications. Trust Xygeni to protect your operations and empower your team to build and deliver with integrity and security.


**Average Rating:** 4.6/5.0
**Total Reviews:** 4
**How Do G2 Users Rate Xygeni?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Language Support:** 8.3/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 10.0/10 (Category avg: 8.7/10)
- **Integration:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Xygeni?**

- **Seller:** [Xygeni Security](https://www.g2.com/sellers/xygeni-security)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **Twitter:** @xygeni (178 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/xygeni/ (30 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 60% Small-Business, 40% Mid-Market


#### What Are Xygeni's Pros and Cons?

**Pros:**

- Comprehensive Security (2 reviews)
- Prioritization (2 reviews)
- Risk Management (2 reviews)
- Security (2 reviews)
- Cloud Integration (1 reviews)

**Cons:**

- Difficult Setup (1 reviews)
- Learning Curve (1 reviews)


### What Do G2 Reviewers Say About Xygeni?
*AI-generated summary from verified user reviews*

**Pros:**

- Users commend Xygeni for its **comprehensive security features** , enhancing protection while maintaining efficient software development processes.
- Users value the **contextual risk prioritization** of Xygeni, enabling focus on the most critical security issues efficiently.
- Users value the **effective risk management** of Xygeni, ensuring security without hindering development speed.
- Users praise the **robust security features** of Xygeni, ensuring efficient vulnerability management and compliance throughout development.
- Users value the **seamless CI/CD integration** of Xygeni, enhancing security without hindering development speed.

**Cons:**

- Users experience **difficult setup** with Xygeni due to manual adjustments needed for specific CI/CD configurations.
- Users find the **learning curve for first-time users** challenging, needing familiarity with AppSec best practices for deeper insights.

#### What Are Recent G2 Reviews of Xygeni?

**"[The essential tool for proactive security and confident development](https://www.g2.com/survey_responses/xygeni-review-11393516)"**

**Rating:** 4.5/5.0 stars
*— Marcos C.*

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11393516)

---

**"[Revolutionized Our Security Workflow with Unified, AI-Driven Efficiency](https://www.g2.com/survey_responses/xygeni-review-11998435)"**

**Rating:** 5.0/5.0 stars
*— Yerassyl K.*

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11998435)

---



### 18. [Bytesafe](https://www.g2.com/products/bytesafe/reviews)
Bytesafe is a platform for end-to-end software supply chain security - a firewall for your dependencies. The platform consists of: - Dependency Firewall - Package Management - Software Composition Analysis - License Compliance


**Average Rating:** 4.8/5.0
**Total Reviews:** 2
**How Do G2 Users Rate Bytesafe?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Language Support:** 6.7/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.3/10 (Category avg: 8.7/10)
- **Integration:** 9.2/10 (Category avg: 8.8/10)

**Who Is the Company Behind Bytesafe?**

- **Seller:** [Bytesafe](https://www.g2.com/sellers/bytesafe)
- **Year Founded:** 2018
- **HQ Location:** Stockholm, SE
- **Twitter:** @bytesafedev (479 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/bytesafe (3 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 100% Small-Business



#### What Are Recent G2 Reviews of Bytesafe?

**"[Overall great experience](https://www.g2.com/survey_responses/bytesafe-review-5007958)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Computer Software*

[Read full review](https://www.g2.com/survey_responses/bytesafe-review-5007958)

---

**"[Fully recommend Bytesafe](https://www.g2.com/survey_responses/bytesafe-review-5007590)"**

**Rating:** 4.5/5.0 stars
*— Bram H.*

[Read full review](https://www.g2.com/survey_responses/bytesafe-review-5007590)

---


#### What Are G2 Users Discussing About Bytesafe?

- [What is Bytesafe used for?](https://www.g2.com/discussions/what-is-bytesafe-used-for)

### 19. [FossID](https://www.g2.com/products/fossid-fossid/reviews)
FossID is a Software Composition Analysis (SCA) suite designed to give organizations clear, defensible insight into the software they build and ship. It helps teams understand exactly what third-party, open source, and commercial code exists in their products so they can manage license compliance, intellectual property risk, and security with confidence. Agentic SCA by FossID brings software supply chain integrity into the moment of code creation for continuous, real-time license and security compliance so you can move at AI-speed and eliminate reactive code rework. FossID is ideal for organizations that value accuracy, transparency, and control over their software supply chain. It is widely used by manufacturers of embedded systems and software-driven products in industries such as automotive, aerospace, medical devices, industrial automation, electronics, and telecom, where regulatory requirements and long product lifecycles demand a higher standard of software governance. FossID is also trusted by legal, compliance, and GRC teams that need reliable, auditable results, as well as by acquirers and investors conducting technical due diligence. FossID analyzes real source code rather than relying solely on declared dependencies. FossID identifies reused components and code snippets with high precision, detecting fragments as small as six lines of code. This approach delivers more accurate results in complex, mixed codebases, including legacy systems, embedded software, and environments influenced by AI-assisted development. Key differentiators include deep snippet-level detection that remains effective even when code has been modified or reformatted, a 200M+ component open source knowledge base covering more than 2,500 licenses, and strong identification of license and copyright obligations. FossID is deployed in a way that ensures that source code never leaves the organization, a critical requirement for security- and IP-sensitive teams. FossID supports software supply chain integrity across the entire development and release lifecycle. Engineers use it early to identify and resolve issues before code is merged. Legal and compliance teams rely on it to validate policy compliance, manage license obligations and produce accurate SBOMs. Governance, Risk, and Compliance leaders use FossID to demonstrate software supply chain transparency, reduce audit risk, and support regulatory compliance initiatives, including the EU Cyber Resilience Act. The primary value of FossID is confidence. Confidence in what is inside your software, confidence in your compliance posture, and confidence that your teams can move forward efficiently without introducing unnecessary risk.


**Average Rating:** 4.0/5.0
**Total Reviews:** 2
**How Do G2 Users Rate FossID?**

- **Quality of Support:** 7.5/10 (Category avg: 9.0/10)
- **Language Support:** 8.3/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 10.0/10 (Category avg: 8.7/10)
- **Integration:** 6.7/10 (Category avg: 8.8/10)

**Who Is the Company Behind FossID?**

- **Seller:** [FossID](https://www.g2.com/sellers/fossid-038ca491-2507-49c4-b6f1-2f965c09e84e)
- **Company Website:** https://www.fossid.com
- **Year Founded:** 2016
- **Twitter:** @FOSSID_AB (137 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/fossid-ab/ (1 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 50% Mid-Market, 50% Enterprise



#### What Are Recent G2 Reviews of FossID?

**"[Detects Code-Snippets reliable and has good usabiilty](https://www.g2.com/survey_responses/fossid-review-11298102)"**

**Rating:** 4.0/5.0 stars
*— Nikolaus F.*

[Read full review](https://www.g2.com/survey_responses/fossid-review-11298102)

---

**"[Powerful, Customizable Scanning with Accurate License Detection and Great Support](https://www.g2.com/survey_responses/fossid-review-12638783)"**

**Rating:** 4.0/5.0 stars
*— Jackie L.*

[Read full review](https://www.g2.com/survey_responses/fossid-review-12638783)

---



### 20. [Qwiet AI](https://www.g2.com/products/qwiet-ai/reviews)
Qwiet AI delivers comprehensive application security by combining agentic AI with advanced code analysis. In a single scan, the platform provides uniquely accurate SAST, SCA, SBOM, secrets detection, and container analysis that helps dev and security teams find and fix vulnerabilities faster. With its proprietary Code Property Graph (CPG) technology and AI/ML models, Qwiet AI achieves up to 95% reduction in false positives compared to traditional tools, while offering contextual AutoFix that understands the unique context of your code, even across complex enterprise applications. Q: What makes Qwiet AI different from other AppSec solutions? A: Qwiet AI stands out through its agentic AI approach, which enables autonomous vulnerability detection and remediation. The platform&#39;s Code Property Graph technology allows for deeper code analysis and more accurate vulnerability detection, resulting in dramatically fewer false positives than traditional tools. This advanced technology enables the platform to understand code relationships and context at a deeper level, leading to precise vuln detection and contextually appropriate fixes. Q: What security capabilities does the platform include? A: The platform provides comprehensive security coverage including: - Static Application Security Testing (SAST) using a patented CPG-based approach, for vuln detection that is objectively the fastest and most accurate available per the OWASP benchmark - Software Composition Analysis (SCA) for third-party dependency scanning and vulnerability detection in open source components - Automated SBOM generation for supply chain transparency and compliance requirements - Advanced secrets detection to prevent credential exposure and secure sensitive information - Container security analysis built in - AI-powered AutoFix for automated vulnerability remediation with contextually aware patches, powered by the CPG and a custom AI/ML engine with its own LLM - Custom rule creation capabilities for organization-specific security requirements Q: How does Qwiet AI improve development workflows? A: Qwiet AI integrates seamlessly into existing CI/CD pipelines and developer workflows. The platform&#39;s speed (up to 40x faster than traditional scanners) and accuracy mean developers spend less time investigating false positives and more time coding. The AutoFix capability helps developers resolve issues quickly with AI-generated patches that are contextually aware and tailored to your codebase. Additionally, the platform provides IDE integrations and pull request analysis to catch vulnerabilities early in the development process. Q: What do customers think? A: Qwiet AI provides enterprise-grade support with dedicated customer success representatives and technical account managers. The platform consistently receives high marks for customer support, with a 97% &quot;would recommend&quot; rate in Gartner&#39;s Voice of the Customer. Customers receive comprehensive onboarding assistance, ongoing technical support, and regular check-ins to ensure successful implementation and adoption. Q: How can I get started with Qwiet AI? A: Qwiet AI offers self-service access, self-guided demos, and AE-guided demos, depending on your needs. You can request a personalized demo through the company website at qwiet.ai to see how the platform addresses their specific security challenges. You can also sign up for self-service access through the web site, or access documentation and integration guides there.


**Average Rating:** 4.8/5.0
**Total Reviews:** 3
**How Do G2 Users Rate Qwiet AI?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)
- **Language Support:** 8.3/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 10.0/10 (Category avg: 8.7/10)
- **Integration:** 10.0/10 (Category avg: 8.8/10)

**Who Is the Company Behind Qwiet AI?**

- **Seller:** [Qwiet AI](https://www.g2.com/sellers/qwiet-ai)
- **HQ Location:** San Jose, California, United States
- **Twitter:** @ShiftLeftInc (1,164 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/qwiet (45 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 67% Enterprise, 33% Small-Business


#### What Are Qwiet AI's Pros and Cons?

**Pros:**

- Collaboration (1 reviews)
- Customer Support (1 reviews)
- Easy Integrations (1 reviews)
- Integration Support (1 reviews)
- Team Collaboration (1 reviews)

**Cons:**

- Command Line Difficulty (1 reviews)
- Limited Customization (1 reviews)
- Limited Features (1 reviews)
- UX Improvement (1 reviews)


### What Do G2 Reviewers Say About Qwiet AI?
*AI-generated summary from verified user reviews*

**Pros:**

- Users value the **responsive and collaborative support** from Qwiet AI, enhancing integration into their CI/CD pipelines.
- Users value the **highly responsive customer support** of Qwiet AI, which facilitates seamless integration processes.
- Users value the **easy integrations** of Qwiet AI, appreciating its thorough documentation for seamless CI/CD pipeline incorporation.
- Users value the **comprehensive documentation** from Qwiet AI, facilitating seamless integration into CI/CD pipelines.
- Users value the **effective team collaboration** fostered by Qwiet AI’s responsive support and thorough integration documentation.

**Cons:**

- Users find the lack of a graphical interface for policies frustrating, relying solely on the **command line interface**.
- Users find the **limited customization options** frustrating, as policy creation relies solely on the CLI without a user interface.
- Users find the **limited features** of Qwiet AI frustrating, lacking a user-friendly interface for policy creation.
- Users find the lack of a user interface for creating policies a significant **UX improvement** concern for Qwiet AI.

#### What Are Recent G2 Reviews of Qwiet AI?

**"[A great easy-to-use SAST Scanner](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Retail*

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-8626743)

---

**"[Seamless Integration with Responsive Support](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)"**

**Rating:** 5.0/5.0 stars
*— Brooks S.*

[Read full review](https://www.g2.com/survey_responses/qwiet-ai-review-10278075)

---



### 21. [Scanmycode.io](https://www.g2.com/products/scanmycode-io/reviews)
Code and Infra Security for Small and medium business A simple and powerful Cloudnative and Code Security and Compliance software for small businesses, agencies and startups


**Average Rating:** 5.0/5.0
**Total Reviews:** 2

**Who Is the Company Behind Scanmycode.io?**

- **Seller:** [Scanmycode.io](https://www.g2.com/sellers/scanmycode-io)
- **HQ Location:** Berlin, DE
- **LinkedIn® Page:** https://www.linkedin.com/company/betterscan-io/ (2 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 50% Mid-Market, 50% Small-Business



#### What Are Recent G2 Reviews of Scanmycode.io?

**"[Highly recommended](https://www.g2.com/survey_responses/scanmycode-io-review-6957519)"**

**Rating:** 5.0/5.0 stars
*— Stefano R.*

[Read full review](https://www.g2.com/survey_responses/scanmycode-io-review-6957519)

---

**"[handy &amp; fast security scanner](https://www.g2.com/survey_responses/scanmycode-io-review-6913723)"**

**Rating:** 5.0/5.0 stars
*— Verified User in Computer Software*

[Read full review](https://www.g2.com/survey_responses/scanmycode-io-review-6913723)

---



### 22. [SCANOSS](https://www.g2.com/products/scanoss/reviews)
SCANOSS is the industry-leading open source software intelligence provider, offering the largest database of open source information available. SCANOSS delivers cutting-edge tools and services that help businesses and developers detect, manage, and secure their open source components. By identifying license obligations, security vulnerabilities, and other risk concerns, SCANOSS ensures that organisations can harness the power of open source safely and securely throughout the development pipeline.


**Average Rating:** 4.3/5.0
**Total Reviews:** 2

**Who Is the Company Behind SCANOSS?**

- **Seller:** [SCANOSS](https://www.g2.com/sellers/scanoss)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **LinkedIn® Page:** https://www.linkedin.com/company/scanoss (24 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 100% Small-Business



#### What Are Recent G2 Reviews of SCANOSS?

**"[SCANOSS Open Source Inventorying Engine](https://www.g2.com/survey_responses/scanoss-review-7288704)"**

**Rating:** 4.5/5.0 stars
*— Joe H.*

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7288704)

---

**"[Great product with a valuable solution but the paid SaaS Tier might be a bit expensive for some](https://www.g2.com/survey_responses/scanoss-review-7283528)"**

**Rating:** 4.0/5.0 stars
*— Joe H.*

[Read full review](https://www.g2.com/survey_responses/scanoss-review-7283528)

---



### 23. [Apiiro](https://www.g2.com/products/apiiro/reviews)
Apiiro is the leader in application security posture management (ASPM), unifying risk visibility, prioritization, and remediation with deep code analysis and runtime context. Get complete application and risk visibility: Apiiro takes a deep, code-based approach to ASPM. Its Cloud Application Security Platform analyzes source code and pulls in runtime context to build a continuous, graph-based inventory of application and software supply chain components. Prioritize with code-to-runtime context: With its proprietary Risk Graph™️, Apiiro contextualizes security alerts from third-party tools and native security solutions based on the likelihood and impact of risk to uniquely minimize alert backlogs and triage time by 95%. Fix faster and prevent risks that matter: By tying risks to code owners, providing LLM-enriched remediation guidance, and embedding risk-based guardrails directly into developer tools and workflows, Apiiro improves remediation times (MTTR) by up to 85%. Apiiro&#39;s native security solutions include API security testing in code, secrets detection and validation, software bill of materials (SBOM) generation, sensitive data exposure prevention, software composition analysis (SCA), and CI/CD and SCM security.


**Average Rating:** 4.8/5.0
**Total Reviews:** 2
**How Do G2 Users Rate Apiiro?**

- **Quality of Support:** 10.0/10 (Category avg: 9.0/10)

**Who Is the Company Behind Apiiro?**

- **Seller:** [Apiiro](https://www.g2.com/sellers/apiiro)
- **Year Founded:** 2019
- **HQ Location:** New York, New York, United States
- **Twitter:** @apiiroSecurity (7,397 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/apiiro (120 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 100% Mid-Market



#### What Are Recent G2 Reviews of Apiiro?

**"[Awesome overall application security solution that just keeps getting better!](https://www.g2.com/survey_responses/apiiro-review-4945784)"**

**Rating:** 5.0/5.0 stars
*— Roy A.*

[Read full review](https://www.g2.com/survey_responses/apiiro-review-4945784)

---

**"[Great repo centric risk management and interrogation layer](https://www.g2.com/survey_responses/apiiro-review-5475193)"**

**Rating:** 4.5/5.0 stars
*— Adam S.*

[Read full review](https://www.g2.com/survey_responses/apiiro-review-5475193)

---


#### What Are G2 Users Discussing About Apiiro?

- [What is Apiiro used for?](https://www.g2.com/discussions/what-is-apiiro-used-for)

### 24. [CodeSentry](https://www.g2.com/products/codesentry/reviews)
CodeSentry is GrammaTech’s binary Software Composition Analysis (SCA) solution which achieves deep scalable analysis without the need for source code and is suitable for enterprise-wide adoption. By enabling developers to interrogate software at the binary level for both open-source software and the third-party software that is now so commonly used, GrammaTech CodeSentry provides visibility into component vulnerabilities after the build process to identify risk. This helps software developers solve challenging issues throughout the software development life cycle (SDLC), and protect mission-critical software and devices from failure and cyberattack. GrammaTech CodeSentry is a multi- programming language SCA solution supporting binary analysis across numerous formats such as endpoints, mobile devices, embedded systems, and firmware. CodeSentry uses multiple component matching algorithms that provide speed and accuracy of detection across different Instruction Set Architectures (ISAs), compilers, and interpretive languages such as JavaScript and Python. CodeSentry allows security professionals to measure and manage the risk associated with open-source vulnerabilities in third-party software quickly and easily, and generates detailed Software Bill of Materials (SBOM) for release support and compliance.


**Average Rating:** 4.5/5.0
**Total Reviews:** 1

**Who Is the Company Behind CodeSentry?**

- **Seller:** [CodeSecure](https://www.g2.com/sellers/codesecure)
- **Year Founded:** 1988
- **HQ Location:** Ithaca, NY
- **Twitter:** @GrammaTech (684 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/82321 (50 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 100% Mid-Market



#### What Are Recent G2 Reviews of CodeSentry?

**"[A powerful tool for coding.](https://www.g2.com/survey_responses/codesentry-review-7600064)"**

**Rating:** 4.5/5.0 stars
*— Netram M.*

[Read full review](https://www.g2.com/survey_responses/codesentry-review-7600064)

---



### 25. [DigiCert Software Trust Manager](https://www.g2.com/products/digicert-software-trust-manager/reviews)
Software Trust Manager code signing solution combines centralized governance of key and certificate management, granular team- and role-based access control, malware and vulnerability scanning, and SBOM management to create a policy-driven approach to securely signing, releasing and maintaining software.


**Average Rating:** 4.0/5.0
**Total Reviews:** 1

**Who Is the Company Behind DigiCert Software Trust Manager?**

- **Seller:** [digicert](https://www.g2.com/sellers/digicert)
- **Year Founded:** 2003
- **HQ Location:** Lehi, UT
- **Twitter:** @digicert (6,675 Twitter followers)
- **LinkedIn® Page:** https://www.linkedin.com/company/357882/ (1,901 employees on LinkedIn®)

**Who Uses This Product?**
- **Company Size:** 100% Mid-Market



#### What Are Recent G2 Reviews of DigiCert Software Trust Manager?

**"[Reliable Certificate Management](https://www.g2.com/survey_responses/digicert-software-trust-manager-review-8500766)"**

**Rating:** 4.0/5.0 stars
*— Verified User in Mechanical or Industrial Engineering*

[Read full review](https://www.g2.com/survey_responses/digicert-software-trust-manager-review-8500766)

---




## What Is Software Composition Analysis Tools?

[DevSecOps Software](https://www.g2.com/categories/devsecops)

## What Software Categories Are Similar to Software Composition Analysis Tools?

- [Vulnerability Scanner Software](https://www.g2.com/categories/vulnerability-scanner)
- [Static Application Security Testing (SAST) Software](https://www.g2.com/categories/static-application-security-testing-sast)
- [Secure Code Review Software](https://www.g2.com/categories/secure-code-review)


---

## How Do You Choose the Right Software Composition Analysis Tools?

### What You Should Know About Software Composition Analysis Software

### What is Software Composition Analysis Software?

Software composition analysis (SCA) refers to the management and evaluation of open source and third-party components within the development environment. Software developers and development teams use SCA to keep tabs on the hundreds of open source components incorporated in their builds. These components fall out of compliance and require version updates; if left unchecked they can pose major security risks. With so many components to track, developers lean on SCA to automatically manage issues. SCA tools scan for actionable items and alerts developers, allowing teams to focus on development rather than manually combing through a mess of software components.

In conjunction with tools such as [vulnerability scanner](https://www.g2.com/categories/vulnerability-scanner) and [dynamic application security testing (DAST) software](https://www.g2.com/categories/dynamic-application-security-testing-dast), software composition analysis integrates with the development environment to curate a secure DevOps workflow. The synergy between cybersecurity and DevOps, sometimes referred to as DevSecOps, answers an urgent call for developers to approach software development with a security-first mindset. For a long time, software developers have relied on open source and third-party components, leaving siloed cybersecurity professionals to clean up builds. This outdated standard often leaves large unresolved gaps in security for stretches of time. Software composition analysis presents a solution for ensuring secure compliance before the worst happens.

Key Benefits of Software Composition Analysis Software

- Help keep development secure
- Ease the workloads of developers
- Build a productive workflow across teams

### Why Use Software Composition Analysis Software?

Security best practices are a necessary staple in any DevOps environment. Beyond industry standards, secure development is increasingly important as issues such as API vulnerabilities come to the forefront of cybersecurity. There are often many open source and third-party components in a software build—ensuring components are constantly updated and secure is a task better left to software. Software composition analysis does the job and saves development teams significant time and energy.

**Peace of mind —** Software composition analysis software constantly evaluates open source components. This means developers and teams can focus on advancing their projects without worrying about a mess of unchecked components. In the event of any issues, SCA software alerts users and provides suggestions for remediation.

**Seamless security —** Most SCA software integrates with preexisting development environments, meaning users don’t have to navigate between windows to address vulnerabilities. Developers can receive important and relevant information about the open source and third-party components in their builds without detaching themselves from their workspace.

### Who Uses Software Composition Analysis Software?

DevOps teams that want to implement security best practices use SCA software as an integral part of the DevSecOps tool kit. SCA software empowers developers to proactively keep their open source and third-party components secure, rather than leave a mess of vulnerabilities for siloed cybersecurity team members to clean up. Tools like SCA software help break down the barriers between DevOps and cybersecurity practices, curating an integrated and agile workflow.

**Solo developers —** While SCA software does wonders for larger teams looking to marry their cybersecurity and DevOps processes, solo developers benefit from their own automated security watchdog. Developers working alone on personal projects can’t expect cybersecurity to be taken care of by someone else, so tools like SCA software help them manage their open source vulnerabilities without eating into their time and energy.

**Small development teams —** Similar to solo developers, small development teams often lack the assets to employ a full-time cybersecurity professional. SCA software also aids these teams, allowing them to focus their limited resources on building their project.

**Large DevOps teams —** Midsize and enterprise DevOps teams rely on SCA software to shape a secure and common sense DevSecOps workflow. Rather than isolate cybersecurity professionals from the DevOps process, companies use tools like SCA to integrate cybersecurity as a default standard for development. This practice mitigates stressors on both developers and IT teams by enabling a more agile environment.

### Software Composition Analysis Software Features

**Comprehensive insights —** SCA software gives users meaningful visibility into the open source and third-party components they use. These tools organize relevant and timely information and present developers with useful updates. This interface often requires some level of development knowledge, meaning the onus is on developers to act on any information presented by SCA tools. Version updates, compliance issues, and vulnerabilities are constantly evaluated so users can be alerted as soon as issues arise.

**Remediation information —** Beyond identifying issues with developers’ open source components, SCA software provides users with relevant documentation for remediation. These suggestions give knowledgeable developers a jumping off point so they can address vulnerabilities in a timely manner. These remediation suggestions typically require development knowledge to understand, but developers can often pass these remediation tasks to cybersecurity professionals on their team.

### Trends Related to Software Composition Analysis Software

**DevOps —** DevOps refers to the marriage of development and IT operations management to make unified software development pipelines. Teams have implemented DevOps best practices to build, test, and release software. SCA software’s seamless blending with integrated development environments (IDEs) means it fits right in with any DevOps cycle.

**Cybersecurity —** Calls for standardized cybersecurity best practices as part of DevOps philosophy, often referred to as DevSecOps, have shifted the responsibility for secure applications to developers. SCA software’s vulnerability detection and remediation features play a necessary role in establishing secure DevOps practices.

### Software and Services Related to Software Composition Analysis Software

[**Vulnerability scanner software**](https://www.g2.com/categories/vulnerability-scanner) **—** Vulnerability scanners constantly monitor applications and networks to identify vulnerabilities. These tools scan full applications and networks then test them against known vulnerabilities. All of these functions work in conjunction with SCA software to form a comprehensive security stack.

[**Static application security testing (SAST) software**](https://www.g2.com/categories/static-application-security-testing-sast) **—** SAST software inspects and analyzes an application’s code to discover security vulnerabilities without actually executing code. Similar to SCA software, these tools identify vulnerabilities and provide remediation suggestions. There is functional overlap with static code analysis software, but SAST software specifically focuses on security, while static code analysis software has a broader scope.

[**Dynamic application security testing (DAST) software**](https://www.g2.com/categories/dynamic-application-security-testing-dast) **—** DAST tools automate security tests for a variety of real-world threats. These tools run applications against simulated attacks and other cybersecurity scenarios using black box testing, or testing performed outside an application.

[**Static code analysis software**](https://www.g2.com/categories/static-code-analysis) **—** Static code analysis is a debugging and quality assurance method that inspects a computer program’s code without executing the program. Static code analysis software scans code to identify security vulnerabilities, catch bugs, and ensure the code adheres to industry standards. These tools help software developers automate the core aspects of program comprehension. While static code analysis is similar to static application security testing, this software covers a broader scope as opposed to focusing solely on security.




