# Top Free Software Supply Chain Security Solutions

## How Many Software Supply Chain Security Solutions Products Does G2 Track?

**Total Products under this Category:** 43

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+1.29%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank Software Supply Chain Security Solutions Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,300+ Authentic Reviews
- 43+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Software Supply Chain Security Solutions
 ![G2 Grid® for Software Supply Chain Security Solutions plotting products by satisfaction and market presence](https://www.g2.com/categories/software-supply-chain-security-tools/grids.png?focus%5B%5D=1259627&focus%5B%5D=143017&focus%5B%5D=36094&focus%5B%5D=14032&focus%5B%5D=7362&focus%5B%5D=100655&focus%5B%5D=1312693&focus%5B%5D=108052)

Highlighted products: Aikido Security, JFrog, Snyk, Mend.io, Veracode Application Security Platform, Harness Platform, OX Security, and Sonatype Nexus Repository.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-supply-chain-security-tools/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=jfrog-2024-03-28&focus%5B%5D=snyk&focus%5B%5D=mend-io&focus%5B%5D=veracode-application-security-platform&focus%5B%5D=harness-platform&focus%5B%5D=ox-security&focus%5B%5D=sonatype-nexus-repository)

**Sponsored**

### Aikido Security

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1006186&secure%5Bchosen_at%5D=2026-08-02T05%3A12%3A07Z&secure%5Bdisplayable_resource_id%5D=1006186&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1006186&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=1259627&secure%5Bresource_id%5D=1006186&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-supply-chain-security-tools%2Ffree%3Fopen_modal_url%3D%252Fproducts%252Freversinglabs%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fsoftware-supply-chain-security-tools%25252Ffree%2526source%253Dcategory&secure%5Btoken%5D=30e7fb13d6ecfcf7ea477a8bad542fea031ddefac7108606f0ce65526094562a&secure%5Burl%5D=https%3A%2F%2Fwww.aikido.dev%2Fcode%2Fopen-source-dependency-scanning-sca%3Futm_source%3Dg2%26utm_campaign%3Dg2-promoted-listing-sca%26utm_medium%3Dcpc&secure%5Burl_type%5D=custom_url)

### [Aikido Security](https://www.g2.com/pt/products/aikido-security/reviews)

Aikido Security é a plataforma de segurança voltada para desenvolvedores que unifica código, nuvem, proteção e teste de ataques em um conjunto de produtos de classe mundial. Construída por desenvolvedores para desenvolvedores, a Aikido ajuda equipes de qualquer tamanho a lançar software seguro mais rapidamente, automatizar a proteção e simular ataques do mundo real com precisão impulsionada por IA. A IA proprietária da plataforma reduz o ruído em 95%, oferece correções com um clique e economiza mais de 10 horas por semana para os desenvolvedores. A Aikido Intel descobre proativamente vulnerabilidades em pacotes de código aberto antes da divulgação, ajudando a proteger mais de 50.000 organizações em todo o mundo, incluindo Revolut, Niantic, Visma, Montblanc e GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 254

#### Who Is the Company Behind Aikido Security?

- **Vendedor:** [Aikido Security](https://www.g2.com/pt/sellers/aikido-security)
- **Website da Empresa:** aikido.dev
- **Ano de Fundação:** 2022
- **Localização da Sede:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 seguidores no Twitter
- **Página do LinkedIn®:** [www.linkedin.com](https://www.g2.com/pt/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 funcionários no LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Fundador, Diretor de Tecnologia
- **Top Industries:** Software de Computador, Tecnologia da Informação e Serviços
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Os usuários apreciam a **facilidade de uso** do Aikido Security, beneficiando-se de seus insights claros e acionáveis e integração perfeita.
- Os usuários elogiam a Aikido Security por sua **rápida e amigável identificação de problemas de segurança** em bases de código, melhorando as práticas de desenvolvimento.
- Os usuários apreciam os **recursos robustos do Aikido Security** , valorizando sua usabilidade e eficácia em melhorar os fluxos de trabalho de segurança.
- Os usuários valorizam as **integrações fáceis** com o GitLab, permitindo um início rápido e um acompanhamento eficaz de problemas de segurança.
- Os usuários elogiam a **configuração fácil** do Aikido Security, simplificando a integração e melhorando significativamente o fluxo de trabalho de segurança.

##### Cons

- Os usuários observam as **funcionalidades ausentes** no Aikido Security, desejando mais integração e opções avançadas de configuração.
- Os usuários acham o **preço excessivo** , especialmente para startups, apesar de reconhecerem o valor do produto.
- Os usuários acham que o Aikido Security tem **recursos limitados** , especialmente em personalização avançada e relatórios para ambientes complexos.
- Os usuários acham que o **preço inicial** da Aikido Security é muito alto para startups, limitando a adoção e experimentação.
- Os usuários estão frustrados com a **falta de recursos** , especialmente com as limitações de escaneamento local e manuseio de ramificações.

#### What Are Recent G2 Reviews of Aikido Security?

**["Segurança Empresarial Sem uma Equipe de Segurança Empresarial"](https://www.g2.com/pt/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/pt/survey_responses/aikido-security-review-13108704)

**["Integração perfeita com o GitHub com descobertas de segurança sólidas e análise inteligente de falsos positivos"](https://www.g2.com/pt/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/pt/survey_responses/aikido-security-review-13109689)

### [JFrog](https://www.g2.com/pt/products/jfrog-2024-03-28/reviews)

A JFrog Ltd. (Nasdaq: FROG), criadora da plataforma unificada de DevOps, DevSecOps, DevGovOps e MLOps, está em uma missão para criar um mundo de software entregue sem atrito do desenvolvimento à produção. Impulsionada por uma visão de "Software Líquido" para manter o software fluindo continuamente, seguro e sempre atualizado, a Plataforma JFrog serve como o sistema definitivo de registro da cadeia de suprimentos de software. Ela é exclusivamente projetada para capacitar organizações a construir, gerenciar e distribuir software confiável com velocidade, segurança e escala sem precedentes em ambientes híbridos e multi-nuvem. À medida que a engenharia de software evolui na era da IA, as ofertas mais recentes da JFrog abordam a tendência mais urgente da indústria: o aumento do desenvolvimento de software agente e os riscos de segurança ocultos da "IA Sombra". Em resposta a atores de ameaças que cada vez mais visam fluxos de trabalho de desenvolvedores, incluindo um aumento maciço em modelos de IA de código aberto maliciosos e pacotes infectados; a JFrog expandiu as capacidades de sua plataforma para oferecer visibilidade absoluta de ponta a ponta e conformidade automatizada. As principais novas inovações incluem o JFrog AI Catalog, que permite às organizações centralizar, governar e controlar o ciclo de vida dos modelos de IA aprovados para uso empresarial. Para proteger ambientes de codificação autônomos, a JFrog introduziu o Universal MCP Registry e o Agent Skills Registry (desenvolvido junto com a NVIDIA). Essas novas soluções estabelecem a primeira camada de confiança de nível empresarial da indústria para gerenciar e armazenar com segurança habilidades de agentes de IA, monitorar conexões e bloquear instantaneamente ferramentas de desenvolvedor inseguras ou extensões de codificação maliciosas diretamente onde os desenvolvedores trabalham. Além disso, a integração de ferramentas avançadas de DevGovOps e Segurança em Tempo de Execução permite que as equipes substituam auditorias de conformidade lentas e manuais por uma aplicação contínua e em segundo plano de políticas. Ao deslocar a segurança para a esquerda diretamente no pipeline binário, a JFrog garante que o volume de código assistido por IA não ultrapasse a capacidade de uma organização de verificar sua segurança. Hoje, milhões de usuários e aproximadamente 6.600 organizações em todo o mundo, incluindo a maioria das empresas da Fortune 100, dependem da Plataforma universal JFrog para eliminar a fadiga de soluções pontuais, fechar a lacuna de governança e adotar com segurança a transformação digital. Saiba mais em www.jfrog.com ou siga-nos no X @JFrog.

**Average Rating:** 4.2/5.0

**Total Reviews:** 149

#### Who Is the Company Behind JFrog?

- **Vendedor:** [JFrog Ltd](https://www.g2.com/pt/sellers/jfrog-ltd)
- **Website da Empresa:** jfrog.com
- **Ano de Fundação:** 2008
- **Localização da Sede:** Sunnyvale, CA
- **Twitter:** @jfrog  
23,186 seguidores no Twitter
- **Página do LinkedIn®:** [www.linkedin.com](https://www.g2.com/pt/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9e9f01c1efeb3f3e7b4535b3aefc16344bbb21773bc11bf4ad186f193dbcaabf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjfrog-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,364 funcionários no LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Engenheiro de Software, Engenheiro de DevOps
- **Top Industries:** Tecnologia da Informação e Serviços, Software de Computador
- **Company Size:** 50% Large, 31% Medium

#### What Do G2 Reviewers Say About JFrog?

_AI-generated summary from verified user reviews_

##### Pros

- Os usuários apreciam a **integração abrangente e o suporte a múltiplos formatos** do JFrog, otimizando seus processos de DevOps de forma eficaz.
- Os usuários apreciam o **gerenciamento centralizado de artefatos** da JFrog, aumentando a eficiência no armazenamento e rastreamento de componentes em diferentes ambientes.
- Os usuários valorizam a **integração de implantação perfeita** do JFrog, melhorando efetivamente os pipelines de CI/CD e a gestão de segurança.
- Os usuários valorizam as **integrações perfeitas** do JFrog, aprimorando seus processos de CI/CD em vários formatos de pacotes.
- Os usuários valorizam as **integrações fáceis** do JFrog com várias ferramentas, melhorando seus fluxos de trabalho de CI/CD de forma contínua.

##### Cons

- Os usuários acham a plataforma da JFrog **excessivamente complexa** , exigindo treinamento significativo para navegar efetivamente por seus recursos extensos.
- Os usuários acham o JFrog **caro** , com custos que representam desafios para equipes menores e desenvolvedores individuais.
- Os usuários muitas vezes enfrentam uma **curva de aprendizado acentuada** com o JFrog, exigindo tempo significativo para dominar sua complexidade.
- Os usuários acham que a **curva de aprendizado difícil** do JFrog requer treinamento extensivo para navegar efetivamente em seus recursos complexos.
- Os usuários acham que o JFrog tem uma **curva de aprendizado acentuada** , exigindo tempo e esforço significativos para alcançar a proficiência.

#### What Are Recent G2 Reviews of JFrog?

**["Gestão de Artefatos Eficiente e Escalável que Simplifica o Ciclo de Vida de Entrega de Software"](https://www.g2.com/pt/survey_responses/jfrog-review-12788318)**

**Rating:** 4.0/5.0 stars

_— Arkajit D._

[Read full review](https://www.g2.com/pt/survey_responses/jfrog-review-12788318)

**["JFrog simplifica o gerenciamento de artefatos para implantações organizadas e confiáveis"](https://www.g2.com/pt/survey_responses/jfrog-review-12870354)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/pt/survey_responses/jfrog-review-12870354)

#### What Are G2 Users Discussing About JFrog?

- [Quais são os benefícios e desafios de usar o JFrog para gerenciar sua cadeia de suprimentos de software?](https://www.g2.com/pt/discussions/what-are-the-benefits-and-challenges-of-using-jfrog-for-managing-your-software-supply-chain)
- [What does Jfrog Platform do?](https://www.g2.com/pt/discussions/what-does-jfrog-platform-do)
- [What is difference between JFrog and Nexus?](https://www.g2.com/pt/discussions/what-is-difference-between-jfrog-and-nexus)
- [What is Artifactory software used for?](https://www.g2.com/pt/discussions/what-is-artifactory-software-used-for)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 114

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
257 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 35% Small, 33% Medium

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories.
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities.
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security.
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes.

##### Cons

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging.
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases.
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration.
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives.
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Great Tool for Managing 3rd party libraries"](https://www.g2.com/survey_responses/mend-io-review-6728890)**

**Rating:** 4.5/5.0 stars

_— Johannes B._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-6728890)

**["Effortless Integration with Budget-Friendly Scanning"](https://www.g2.com/survey_responses/mend-io-review-4261734)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/mend-io-review-4261734)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

### [Harness Platform](https://www.g2.com/de/products/harness-platform/reviews)

Vereinfachen Sie Ihr Entwicklererlebnis mit der weltweit ersten KI-unterstützten Software-Lieferplattform. Verbessern Sie Ihre Software-Lieferung mit den innovativen CI/CD-, Feature-Flags-, Infrastructure as Code Management- und Chaos-Engineering-Tools von Harness. Wir sind eine Software-Lieferplattform, die Entwicklern und Infrastruktur-Ingenieuren hilft, Code für Cloud- und On-Premise-Projekte zu erstellen und bereitzustellen. Wir automatisieren den Prozess der kontinuierlichen Integration und kontinuierlichen Lieferung (CI/CD), um Teams zu helfen, schneller zu entwickeln, häufiger zu liefern und Qualität, Effizienz und Governance zu verbessern. Wir helfen Unternehmen in vier Schlüsselbereichen: Erstens beschleunigen wir Innovation durch DevOps-Modernisierung. Wir bieten einen Ansatz für die Software-Lieferung, der Prozesse automatisiert, manuelle Eingriffe reduziert, Tools konsolidiert und die Markteinführungszeit für neue Produkte, Funktionen und Fehlerbehebungen beschleunigt. Zweitens verbessern wir das Entwicklererlebnis. Wir geben Ihnen die Möglichkeit, hochqualifizierte Ingenieurtalente anzuziehen, zu halten und einzuarbeiten, während wir eine Kultur der kontinuierlichen Innovation und Verbesserung fördern. Drittens sichern wir die Software-Lieferung. Wir geben Ihnen die Möglichkeit, Sicherheit in jede Phase des SDLC zu integrieren. Und zu guter Letzt optimieren wir die Cloud-Kosten. Wir geben Ihnen die Möglichkeit, Verschwendung zu eliminieren und sicherzustellen, dass geeignete Cloud-Ressourcen zur richtigen Zeit am richtigen Ort zugewiesen werden.

**Average Rating:** 4.6/5.0

**Total Reviews:** 301

#### Who Is the Company Behind Harness Platform?

- **Verkäufer:** [Harness](https://www.g2.com/de/sellers/harness-25016f40-e80f-4417-bea8-39412055d17a)
- **Unternehmenswebsite:** harness.io
- **Gründungsjahr:** 2018
- **Hauptsitz:** San Francisco
- **Twitter:** @HarnessWealth  
1,389 Twitter-Follower
- **LinkedIn®-Seite:** [www.linkedin.com](https://www.g2.com/de/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fbec562b1d7a892f3293de88d17cc0509949905a19856805c612616710bc3a7d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fharnessinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,701 Mitarbeiter\*innen auf LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software-Ingenieur, DevOps-Ingenieur
- **Top Industries:** Computersoftware, Finanzdienstleistungen
- **Company Size:** 43% Large, 37% Medium

#### What Do G2 Reviewers Say About Harness Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Benutzer schätzen die **Benutzerfreundlichkeit** der Harness-Plattform, wodurch Implementierung und Konfiguration nahtlos und effizient erfolgen.
- Benutzer schätzen die **Benutzerfreundlichkeit und Flexibilität** bei der Zielgruppenansprache innerhalb der Harness-Plattform.
- Benutzer schätzen die **benutzerfreundliche Oberfläche** der Harness-Plattform, um Feature-Flags einfach zu verwalten und bereitzustellen.
- Benutzer finden die **einfache Einrichtung** der Harness-Plattform schnell und effizient, was zu sofortigen Kosteneinsparungen und Zufriedenheit führt.
- Benutzer schätzen die **einfachen Integrationen** mit SSO und Tools, die die Softwarebereitstellung auf der Harness-Plattform optimieren.

##### Cons

- Benutzer bemerken einen **Mangel an mehreren Filtern** in der Harness-Plattform, was die Flexibilität für fortgeschrittene Anpassungen und Benutzerfreundlichkeit einschränkt.
- Benutzer stehen vor **Einschränkungen im Konfigurationsmanagement** , einschließlich Problemen beim Umbenennen und Löschen von Umschaltern, die die Benutzerfreundlichkeit erschweren.
- Benutzer bemerken einen **Mangel an mehreren Filtern** und fehlende Funktionen in der Harness-Plattform, was ihre Gesamtbenutzbarkeit einschränkt.
- Benutzer finden die **steile Lernkurve** herausfordernd, insbesondere aufgrund komplizierter Einstellungen und unzureichender Dokumentation.
- Benutzer finden die **Benutzeroberfläche komplex und umständlich** , was das gesamte Benutzererlebnis mit der Plattform komplizieren kann.

#### What Are Recent G2 Reviews of Harness Platform?

**["End-to-End DevOps-Automatisierung mit leistungsstarken, flexiblen CI/CD-Pipelines"](https://www.g2.com/de/survey_responses/harness-platform-review-13164505)**

**Rating:** 4.5/5.0 stars

_— Ravindra N._

[Read full review](https://www.g2.com/de/survey_responses/harness-platform-review-13164505)

**["Harness - Welt der Automatisierung"](https://www.g2.com/de/survey_responses/harness-platform-review-11792426)**

**Rating:** 4.5/5.0 stars

_— Sunil A._

[Read full review](https://www.g2.com/de/survey_responses/harness-platform-review-11792426)

#### What Are G2 Users Discussing About Harness Platform?

- [Wofür wird Harness Continuous Delivery verwendet?](https://www.g2.com/de/discussions/what-is-harness-continuous-delivery-used-for) - 1 comment
- [Wofür wird Propelo verwendet?](https://www.g2.com/de/discussions/what-is-propelo-used-for)
- [Wofür wird das Harness Cloud Cost Management verwendet?](https://www.g2.com/de/discussions/what-is-harness-cloud-cost-management-used-for)
- [Was ist der Unterschied zwischen Harness und Jenkins?](https://www.g2.com/de/discussions/what-is-the-difference-between-harness-and-jenkins) - 1 comment
- [Was ist Streaming Split IO?](https://www.g2.com/de/discussions/what-is-streaming-split-io) - 1 comment

### [OX Security](https://www.g2.com/pt/products/ox-security/reviews)

OX reconfigura seu programa de segurança para a Era do Mythos: a era em que a IA escreve o código, encadeia as explorações e se move mais rápido do que as defesas construídas por humanos podem acompanhar. OX é uma Plataforma de Proteção de Aplicações Nativas de IA (AINAPP) que unifica a segurança do Prompt ao Runtime. Ele move sua superfície de controle para o prompt, prevenindo e governando o risco na fonte em vez de persegui-lo a jusante no runtime. OX Mind e OX AI Context Lake conectam governança de usuários de IA, segurança de código, aplicação em nuvem e runtime, e pentesting agentico em um único sistema que compartilha contexto em todo o Ciclo de Vida de Desenvolvimento Agente (ADLC), substituindo ferramentas pontuais fragmentadas por uma única plataforma. A plataforma opera em quatro pilares conectados: OX VibeSec: Previne decisões inseguras de IA no ponto de criação e governa cada usuário de IA na organização, não apenas desenvolvedores usando assistentes de codificação. Visibilidade total sobre quais agentes, MCPs, habilidades e pacotes são executados, com quais permissões, contra quais dados. OX Code: Separa risco explorável do ruído teórico usando evidências de sua implantação real, modelo de ameaça e inteligência de ameaça. OX Cloud: Previne configurações incorretas e aplica limites de runtime que código e agentes não podem cruzar, observando o que realmente roda em produção. OX Agentic Pentester: Simula continuamente o comportamento de agentes adversários para provar caminhos de exploração de volta à sua fonte exata, alimentando o que encontra de volta no OX VibeSec para aprimorar a governança. OX conecta-se ao seu stack existente e rastreia cada descoberta de volta à sua origem (o prompt, o usuário de IA ou o endpoint que o criou), então corrige problemas na fonte em vez de sinalizá-los após o fato. Para novas implantações, OX consolida governança, segurança de código, aplicação em nuvem e pentesting em uma única plataforma. Para stacks existentes, OX sobrepõe governança e torna as ferramentas atuais mais inteligentes através de aprendizado contínuo, para que o mesmo problema nunca seja criado duas vezes. Visite https://ox.security para mais informações.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### Who Is the Company Behind OX Security?

- **Vendedor:** [OX Security](https://www.g2.com/pt/sellers/ox-security)
- **Ano de Fundação:** 2021
- **Localização da Sede:** New York, USA
- **Página do LinkedIn®:** [www.linkedin.com](https://www.g2.com/pt/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 funcionários no LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Engenheiro de Segurança
- **Top Industries:** Serviços Financeiros, Tecnologia da Informação e Serviços
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Os usuários valorizam o **painel intuitivo e a integração perfeita** do OX Security, melhorando sua gestão de segurança e eficiência de fluxo de trabalho.
- Os usuários valorizam a **colaboração perfeita** proporcionada pela OX Security, aumentando seu foco em tarefas críticas de desenvolvimento.
- Os usuários elogiam o **suporte ao cliente responsivo** da OX Security, aumentando sua eficiência operacional geral e satisfação.
- Os usuários valorizam as **integrações perfeitas** com ferramentas existentes, melhorando os fluxos de trabalho e aumentando a eficiência geral do desenvolvimento.
- Os usuários apreciam a **velocidade** da OX Security, permitindo uma remediação mais rápida de vulnerabilidades e configurações incorretas na nuvem.

##### Cons

- Os usuários acham a **complexidade** da OX Security intimidante, enfrentando uma curva de aprendizado acentuada e documentação inadequada.
- Os usuários acham a **interface opressiva** , com uma curva de aprendizado íngreme e documentação insuficiente para guiar novos usuários.
- Os usuários acham a **configuração complexa** desafiadora, especialmente devido à documentação inadequada e à interface de usuário esmagadora para novos usuários.
- Os usuários acham o **painel executivo limitante** , impactando a elaboração de relatórios eficazes sobre melhorias de segurança do produto para a gestão.
- Os usuários acham o **difícil curva de aprendizado** da OX Security desafiador, principalmente devido à sua interface complexa e à falta de documentação.

#### What Are Recent G2 Reviews of OX Security?

**["Solução de Segurança Holística com Integração Sem Costura"](https://www.g2.com/pt/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/pt/survey_responses/ox-security-review-10487561)

**["Uma ferramenta poderosa e abrangente que atende à maioria das melhores práticas para testes de segurança de aplicativos web."](https://www.g2.com/pt/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Usuário Verificado em Jogos e Cassinos_

[Read full review](https://www.g2.com/pt/survey_responses/ox-security-review-10961361)

### [Sonatype Nexus Repository](https://www.g2.com/products/sonatype-nexus-repository/reviews)

World’s #1 Repository Manager with Free and Pro versions - Single source of truth for all of your components, binaries, and build artifacts. - Efficiently distribute parts and containers to developers. - Used by more than 5 million developers globally. Centralize Give your teams a single source of truth for every component they use. Store Optimize build performance and reliability by caching proxies of remote repositories. Adapt Deliver universal coverage for all major package types and formats Scale Install on an unlimited amount of servers for an unlimited amount of users. Universal Support for all Popular Build Tools Store and distribute Maven/Java, npm, NuGet, Helm, Docker, P2, OBR, APT, GO, R, Conan components and more. Manage components from dev through delivery: binaries, containers, assemblies, and finished goods. Awesome support for the Java Virtual Machine (JVM) ecosystem, including Gradle, Ant, Maven, and Ivy. Compatible with popular tools like Eclipse, IntelliJ, Hudson, Jenkins, Puppet, Chef, Docker, and more. Enterprise Control of Binaries and Build Artifacts Deliver innovation 24x7x365 with high availability. A single source of truth for components used across your entire software development lifecycle including QA, staging, and operations. Easily integrate with existing user and access provisioning systems including LDAP, Atlassian Crowd, and more. SAML/SSO authentication for enhanced security and single sign-on experience. See the Health of Your Software Supply Chain Repository Health Check (RHC) provides up-to-date component intelligence, so your teams make informed decisions early on. View components in need of remediation, prioritized by the severity of vulnerability. Easily avoid known security and license issues for Maven/Java, npm, NuGet, and PyPI components. Modern Features for Continuous Innovation Deploy directly to a desired repository with your choice of build or deployment tool or directly via HTTP. Stage and manage releases with dedicated security and automated rule validation. Enhanced staging provides streamlined oversight and approval of workflows for release candidates. Share binaries, snapshots and releases between groups of developers or post a collection of related, staged artifacts which can be easily tested, promoted, or discarded.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### Who Is the Company Behind Sonatype Nexus Repository?

- **Seller:** [Sonatype](https://www.g2.com/sellers/sonatype)
- **Year Founded:** 2008
- **HQ Location:** Fulton, US
- **Twitter:** @sonatype  
10,589 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=dd965bcc74ef94929b9eb731aaa8ab372133c521cbfc49096fe776e20652458f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F210324%2F&secure%5Burl_type%5D=linkedin_company_website)  
551 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 43% Large, 39% Medium

#### What Are Recent G2 Reviews of Sonatype Nexus Repository?

**["Perfect solution for artifact management"](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9115886)**

**Rating:** 4.0/5.0 stars

_— Juan Diego P._

[Read full review](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9115886)

**["Easy to use repository for sharing artifacts within team"](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9407466)**

**Rating:** 4.0/5.0 stars

_— Ardhiya C._

[Read full review](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9407466)

#### What Are G2 Users Discussing About Sonatype Nexus Repository?

- [What does a repository manager do?](https://www.g2.com/discussions/nexus-repository-manager-what-does-a-repository-manager-do)
- [What does a repository manager do?](https://www.g2.com/discussions/what-does-a-repository-manager-do)
- [What is Nexus repository tool?](https://www.g2.com/discussions/what-is-nexus-repository-tool)
- [What is Nexus software used for?](https://www.g2.com/discussions/what-is-nexus-software-used-for) - 1 comment
- [What is Nexus repository manager used for?](https://www.g2.com/discussions/what-is-nexus-repository-manager-used-for)

### [SOOS](https://www.g2.com/products/soos/reviews)

SOOS is the complete application security posture management platform. Scan your software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license types, generate and manage Software Bill of Materials (SBOM), and fill out your compliance worksheets across all your teams. SOOS’s ASPM is a dynamic, comprehensive approach to safeguarding your application infrastructure from vulnerabilities across the Software Development Life Cycle (SDLC) and live deployments. Easy to integrate, all in one dashboard. SCA - Deep tree vulnerability scanning, license compliance, governance DAST - Automated Web & API vulnerability scanning Containers - Scan contents for vulnerabilities SAST - Analyze code for security vulnerabilities IaC - Cloud security coverage SBOMs - Create – monitor – manage

**Average Rating:** 4.6/5.0

**Total Reviews:** 42

#### Who Is the Company Behind SOOS?

- **Seller:** [SOOS](https://www.g2.com/sellers/soos)
- **Year Founded:** 2019
- **HQ Location:** Winooski, US
- **Twitter:** @soostech  
44 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=61bd56b45756b75fc0339880cc3369c6d2af3971839c773abcfbf38d4d05a283&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F53122310&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Medium, 43% Small

#### What Do G2 Reviewers Say About SOOS?

_AI-generated summary from verified user reviews_

##### Pros

- Users find SOOS to be **easy to use** , benefiting from user-friendly configurations and excellent support.
- Users praise the **awesome customer support** from SooS, ensuring a smooth onboarding and configuration process.
- Users commend SOOS for its **easy integrations** , enabling seamless workflows and efficient vulnerability management in development.
- Users value the **seamless integrations** of SOOS, enhancing workflow efficiency and simplifying vulnerability management.
- Users find the **easy setup** of SOOS to be intuitive and efficient, enhancing their overall experience.

##### Cons

- Users note a **lack of guidance** in documentation and processes, hindering onboarding and remediation efforts.
- Users find the **poor reporting** of SOOS limits their ability to analyze vulnerabilities effectively across projects.
- Users find the **dashboard issues** frustrating, particularly with limited reporting and filtering options that hinder analysis.
- Users find SOOS lacks **adequate reporting** , needing better customization and filtering options for effective analysis.
- Users find the **lack of features** in SOOS limits usability, especially with reporting and intuitive navigation.

#### What Are Recent G2 Reviews of SOOS?

**["Reliable continuous security assessment for our pipelines"](https://www.g2.com/survey_responses/soos-review-7744758)**

**Rating:** 4.0/5.0 stars

_— Brallan G._

[Read full review](https://www.g2.com/survey_responses/soos-review-7744758)

**["Awesome tool for detecting vulnerabilities within project dependecies"](https://www.g2.com/survey_responses/soos-review-7753830)**

**Rating:** 4.5/5.0 stars

_— Nayan C._

[Read full review](https://www.g2.com/survey_responses/soos-review-7753830)

### [Cybeats](https://www.g2.com/products/cybeats/reviews)

Cybeats is at the forefront of cybersecurity innovation and is focused explicitly on automating Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) management. Our platform has built-in support for HBOM and AIBOM. Our mission is to empower organizations to rapidly identify and address vulnerabilities, significantly reducing costs while enhancing the security posture of their products. With our focus on the vision of "Building trust in every layer of your technology," Cybeats provides a robust platform that ensures transparency and security throughout the technological stack. Core Offerings - SBOM Management & Continuous Monitoring Cybeats offers a scalable solution for managing and monitoring SBOMs. Our platform stores enriches and distributes SBOMs efficiently across the organization and the organization's customers. This continuous monitoring helps proactively identify and mitigate software component risks. - SBOM Inventory & Management We provide a centralized system for SBOM inventory management that ensures all software components are accounted for, up-to-date, and secure. This systematic approach helps maintain a clear overview of all software elements, facilitating easier management and compliance. - Vulnerability Lifecycle Management (VLM) Our VLM capabilities integrate Vulnerability Exploitability Exchange (VEX) and Vulnerability Disclosure Program (VDP) processes. This integration helps identify, assess, manage, and mitigate vulnerabilities throughout their lifecycle, ensuring continuous protection against potential software supply chain threats. - Regulatory Compliance Cybeats aligns with global regulatory requirements, assisting organizations in staying compliant with evolving cybersecurity standards. Our solution simplifies compliance management, reducing the complexity and resources required to meet legal and industry standards. With the introduction of regulatory requirements of the FDA pre-market and post-market, the EU CRA, PCI-SSF, and others, companies that develop software-based products must align with the SBOM and Vulnerability management requirements. - OSS and Comercial Licensing Risk Assessment Understanding and managing licensing risks associated with software components is crucial. Cybeats provides tools to assess these risks, helping organizations avoid legal and financial repercussions related to software licensing. - SBOM Sharing and Exchange We facilitate secure sharing and exchange of SBOMs within and across organizations. This capability ensures that all parties in the software supply chain have access to accurate and timely information, enhancing collaborative efforts toward secure software development.

**Average Rating:** 4.4/5.0

**Total Reviews:** 15

#### Who Is the Company Behind Cybeats?

- **Seller:** [CYBEATS](https://www.g2.com/sellers/cybeats)
- **Year Founded:** 2017
- **HQ Location:** Toronto, Ontario
- **Twitter:** @cybeatstech  
616 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2663143089be0432d313d1e538a94c0aa900c3536fc6ddc68eb338c35cf31f18&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcybeats%2F&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 47% Small, 33% Medium

#### What Are Recent G2 Reviews of Cybeats?

**["A safe and secure enterprise supply chain management system is created and enabled by Cybeats"](https://www.g2.com/survey_responses/cybeats-review-7468992)**

**Rating:** 4.5/5.0 stars

_— Karan C._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7468992)

**["Great Computer Security Service Solutin"](https://www.g2.com/survey_responses/cybeats-review-7160083)**

**Rating:** 4.5/5.0 stars

_— Patrícia P._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7160083)

### [Socket](https://www.g2.com/products/socket-socket/reviews)

Socket is the leading developer-first security platform that protects modern applications from malicious and vulnerable open source dependencies. By combining real-time package monitoring with AI-powered code analysis, Socket detects and blocks supply chain attacks within minutes of publication. With advanced reachability analysis, automated remediation, and license compliance features, Socket enables teams to focus on building software, while we keep their open source code secure.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### Who Is the Company Behind Socket?

- **Seller:** [Socket](https://www.g2.com/sellers/socket)
- **Year Founded:** 2020
- **HQ Location:** San Francisco, US
- **Twitter:** @SocketSecurity  
21,558 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=333fcd28dd311ff160a9395ac69327d82d0f595897ba65d2388e7b628c0687bf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsocketinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
115 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 40% Medium, 30% Large

#### What Do G2 Reviewers Say About Socket?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Socket's **exceptional security features** , particularly in monitoring and mitigating supply chain attacks effectively.
- Users praise Socket for its **effective open source security analysis** , streamlining package reviews and enhancing reliability.
- Users value the **accuracy of findings** from Socket, appreciating the thorough analysis it offers for open source security.
- Users value the **proactive alerts** from Socket, ensuring quick responses to potential supply chain threats.
- Users value the **comprehensive security** features of Socket, enhancing decision-making and risk management in software supply chains.

##### Cons

- Users find the **missing features** in Socket limit its ability to consolidate multiple use cases effectively.
- Users report experiencing **system slowness** , particularly noting the UI's slow loading times impacting their overall experience.

#### What Are Recent G2 Reviews of Socket?

**["Unique Approach to Supply Chain Security Problem and Does It Really Well"](https://www.g2.com/survey_responses/socket-review-12052484)**

**Rating:** 5.0/5.0 stars

_— Sindhoor H._

[Read full review](https://www.g2.com/survey_responses/socket-review-12052484)

**["Essential Tool for Application Security with Stellar MCP Feature"](https://www.g2.com/survey_responses/socket-review-12686360)**

**Rating:** 5.0/5.0 stars

_— Shreejal M._

[Read full review](https://www.g2.com/survey_responses/socket-review-12686360)

### [Arnica](https://www.g2.com/products/arnica/reviews)

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

**Average Rating:** 4.9/5.0

**Total Reviews:** 8

#### Who Is the Company Behind Arnica?

- **Seller:** [Arnica](https://www.g2.com/sellers/arnica)
- **Company Website:** www.arnica.io
- **Year Founded:** 2021
- **HQ Location:** Alpharetta, Georgia
- **Twitter:** @arnicaio  
124 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=35b6c80888a16d99de6aed67226d5eee0835f227fc79936eb37367fea6278187&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Farnica-io%2Fabout&secure%5Burl_type%5D=linkedin_company_website)  
60 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 63% Large, 25% Small

#### What Do G2 Reviewers Say About Arnica?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **accuracy of findings** from Arnica, which helps identify and minimize unnecessary elevated privileges.
- Users value the **actionable recommendations** provided by Arnica, facilitating effective management of elevated privileges in code repositories.
- Users love the **easy setup and administration** of Arnica, saving time while meeting their needs effectively.
- Users love the **easy setup** of Arnica, finding it quick and efficient for their needs.
- Users value Arnica for its ability to **simplify remediation of overprovisioning** and enhance security through effective privilege management.

##### Cons

- Users note that **paid features** in Arnica restrict access for smaller teams, limiting comprehensive protections.

#### What Are Recent G2 Reviews of Arnica?

**["Intuitive Dashboards and AI That Finds Real Issues"](https://www.g2.com/survey_responses/arnica-review-12972680)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/arnica-review-12972680)

**["Developer-friendly AppSec with a flexible policy engine"](https://www.g2.com/survey_responses/arnica-review-12962349)**

**Rating:** 5.0/5.0 stars

_— Thomas G._

[Read full review](https://www.g2.com/survey_responses/arnica-review-12962349)

#### What Are G2 Users Discussing About Arnica?

- [What is Arnica used for?](https://www.g2.com/discussions/what-is-arnica-used-for)

### [Jscrambler](https://www.g2.com/products/jscrambler/reviews)

Jscrambler is the leader in Client-Side Security for the modern, composable web. As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces. Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled according to enterprise policy at the point of creation — before they leave the client environment. Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.

**Average Rating:** 4.4/5.0

**Total Reviews:** 31

#### Who Is the Company Behind Jscrambler?

- **Seller:** [Jscrambler](https://www.g2.com/sellers/jscrambler)
- **Company Website:** jscrambler.com
- **Year Founded:** 2014
- **HQ Location:** San Francisco, California
- **Twitter:** @Jscrambler  
1,161 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1f232d3698f51e50cca5f27217404c5fdc451925ba67a491d9048732abcf939f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1005462%2F&secure%5Burl_type%5D=linkedin_company_website)  
89 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 35% Medium, 29% Small

#### What Do G2 Reviewers Say About Jscrambler?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **robust security features** of Jscrambler, ensuring their intellectual property is well-protected during deployment.
- Users appreciate the **ease of use** of Jscrambler, finding the interface user-friendly and easy to navigate.
- Users praise the **user-friendly interface** of Jscrambler, making management and implementation straightforward and efficient.
- Users find Jscrambler's **automation capabilities** seamlessly integrate into CI/CD pipelines, enhancing security without disrupting development.
- Users value the **comprehensive overview** of Jscrambler, enhancing security and performance with gradual feature activation.

##### Cons

- Users experience a **difficult initiation** with Jscrambler due to its complex installation and setup processes.
- Users experience **slow performance** that negatively affects user experience, requiring additional tuning and lacking adequate documentation.
- Users note that the **dashboard could provide more detailed information** about each installation for better insights.
- Users often face **obfuscation issues** with large applications, leading to functionality problems and project file limit challenges.
- Users often face **limited guidance** with Jscrambler, leading to challenges in exporting reports effectively.

#### What Are Recent G2 Reviews of Jscrambler?

**["Unmatched Code Protection with Jscrambler"](https://www.g2.com/survey_responses/jscrambler-review-12607132)**

**Rating:** 5.0/5.0 stars

_— Bruno V._

[Read full review](https://www.g2.com/survey_responses/jscrambler-review-12607132)

**["Jscrambler Integrates Seamlessly Into CI/CD for Enhanced Web App Security"](https://www.g2.com/survey_responses/jscrambler-review-11802189)**

**Rating:** 5.0/5.0 stars

_— Daniel G._

[Read full review](https://www.g2.com/survey_responses/jscrambler-review-11802189)

#### What Are G2 Users Discussing About Jscrambler?

- [What is Jscrambler used for?](https://www.g2.com/discussions/what-is-jscrambler-used-for)

### [Cloudsmith](https://www.g2.com/products/cloudsmith/reviews)

Cloudsmith is the modern artifact management and software supply chain security platform. It gives engineering teams a unified control layer for every package, container, binary, and ML model moving through their software supply chain – across 30+ formats, with built-in policy enforcement and continuous security monitoring. Modern engineering teams assemble software more than they author it and AI agents pull in open source dependencies at a pace that exceeds ad hoc governance. Cloudsmith functions as a private registry that sits between public sources and your builds; It is the first place every artifact lands and where policy enforcement occurs before anything enters your environment. Splitting artifact management and security across disconnected tools causes teams to lose the consistent visibility and control they need to move fast – and with confidence. Cloudsmith replaces that complexity with a unified platform that scales with your organization. Built for platform engineering teams, security leads, and the engineering leaders who support them, Cloudsmith reduces the operational burden of managing artifact infrastructure, enforces governance consistently across every team and format, and gives organizations full traceability across their supply chain.

**Average Rating:** 4.5/5.0

**Total Reviews:** 44

#### Who Is the Company Behind Cloudsmith?

- **Seller:** [Cloudsmith](https://www.g2.com/sellers/cloudsmith)
- **Company Website:** cloudsmith.com
- **Year Founded:** 2016
- **HQ Location:** Belfast, Northern Ireland
- **Twitter:** @cloudsmith  
1,094 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ed3ea9e062dddfc8e4cc06cf24ff5cad448805d24492bded400ddd53715bee83&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcloudsmith%2F&secure%5Burl_type%5D=linkedin_company_website)  
152 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 36% Medium, 36% Small

#### What Do G2 Reviewers Say About Cloudsmith?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Cloudsmith, enabling efficient artifact management without the complexity of multiple registries.
- Users appreciate the **seamless integrations** of Cloudsmith, enhancing efficiency and simplifying artifact management across various formats.
- Users value the **reliability** of Cloudsmith, with consistent performance and seamless integration into their workflows.
- Users praise Cloudsmith for its **comprehensive cloud integration** , streamlining artifact management and improving efficiency across multiple formats.
- Users value the **development efficiency** of Cloudsmith, streamlining artifact management and simplifying the software delivery process.

##### Cons

- Users find the **difficult setup** of Cloudsmith frustrating, experiencing issues with onboarding and native integrations.
- Users find Cloudsmith's pricing model **expensive** , especially for teams with high storage and bandwidth needs.
- Users face **integration issues** with Cloudsmith, leading to potential confusion during onboarding and high costs for large teams.

#### What Are Recent G2 Reviews of Cloudsmith?

**["Streamlined Artifact Management with Stellar Support"](https://www.g2.com/survey_responses/cloudsmith-review-12919092)**

**Rating:** 4.5/5.0 stars

_— Benjamin J._

[Read full review](https://www.g2.com/survey_responses/cloudsmith-review-12919092)

**["Exemplary Support and an Easy Web UI That Boosts Team Efficiency"](https://www.g2.com/survey_responses/cloudsmith-review-13174852)**

**Rating:** 5.0/5.0 stars

_— Dan M._

[Read full review](https://www.g2.com/survey_responses/cloudsmith-review-13174852)

#### What Are G2 Users Discussing About Cloudsmith?

- [What is Cloudsmith used for?](https://www.g2.com/discussions/what-is-cloudsmith-used-for) - 1 comment

### [DryRun Security](https://www.g2.com/products/dryrun-security/reviews)

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

**Average Rating:** 4.9/5.0

**Total Reviews:** 20

#### Who Is the Company Behind DryRun Security?

- **Seller:** [DryRun Security](https://www.g2.com/sellers/dryrun-security)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a05a774e1320fb12547e26ce7fe95d94335bc0c4be6317172500089b5b6db36&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdryrun-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 40% Small, 30% Medium

#### What Do G2 Reviewers Say About DryRun Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **context-aware security feedback** from DryRun Security, enhancing vulnerability mitigation during development in GitHub.
- Users appreciate the **quick and context-aware vulnerability detection** of DryRun Security, enhancing security during the development process.
- Users value the **seamless integration and advanced detections** of DryRun Security, enhancing code security and development efficiency.
- Users value the **accuracy of feedback** from DryRun Security, effectively minimizing false positives and identifying complex vulnerabilities.
- Users appreciate the **easy setup** of DryRun Security, enabling seamless integration and quick vulnerability detection.

##### Cons

- Users find the **slow performance** of DryRun Security's management portal frustrating, impacting their overall experience.
- Users experience **slow speed** issues with the management portal, impacting overall usability and efficiency.
- Users note the **sluggish UI** of DryRun Security, which hampers the overall developer experience during use.
- Users feel there are **limited customization options** for analyzers, though improvements may be forthcoming.
- Users feel that there are **workflow issues** that hinder the developer experience and adoption of DryRun Security.

#### What Are Recent G2 Reviews of DryRun Security?

**["Catches Logic and Authorization Flaws Traditional SAST Often Misses"](https://www.g2.com/survey_responses/dryrun-security-review-12357188)**

**Rating:** 5.0/5.0 stars

_— Jabez A._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12357188)

**["Next Gen of SAST Tool That Has Cutting Edge Tech"](https://www.g2.com/survey_responses/dryrun-security-review-12462338)**

**Rating:** 5.0/5.0 stars

_— Francis D._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12462338)

### [Xygeni](https://www.g2.com/products/xygeni/reviews)

Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage security risks while minimizing noise and overwhelming alerts. Our innovative technologies automatically detect malicious code in real-time upon new and updated components publication, immediately notifying customers and quarantining affected components to prevent potential breaches. With extensive coverage spanning the entire Software Supply Chain—including Open Source components, CI/CD processes and infrastructure, Anomaly detection, Secret leakage, Infrastructure as Code (IaC), and Container security—Xygeni ensures robust protection for your software applications. Trust Xygeni to protect your operations and empower your team to build and deliver with integrity and security.

**Average Rating:** 4.6/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Xygeni?

- **Seller:** [Xygeni Security](https://www.g2.com/sellers/xygeni-security)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **Twitter:** @xygeni  
178 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0302db05d62f71019af9c96a9c2a81cfa4c370ac1ddef2c863b931a5bb7be15a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fxygeni%2F&secure%5Burl_type%5D=linkedin_company_website)  
30 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Small, 40% Medium

#### What Do G2 Reviewers Say About Xygeni?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Xygeni for its **comprehensive security features** , enhancing protection while maintaining efficient software development processes.
- Users value the **contextual risk prioritization** of Xygeni, enabling focus on the most critical security issues efficiently.
- Users value the **effective risk management** of Xygeni, ensuring security without hindering development speed.
- Users praise the **robust security features** of Xygeni, ensuring efficient vulnerability management and compliance throughout development.
- Users value the **seamless CI/CD integration** of Xygeni, enhancing security without hindering development speed.

##### Cons

- Users experience **difficult setup** with Xygeni due to manual adjustments needed for specific CI/CD configurations.
- Users find the **learning curve for first-time users** challenging, needing familiarity with AppSec best practices for deeper insights.

#### What Are Recent G2 Reviews of Xygeni?

**["The essential tool for proactive security and confident development"](https://www.g2.com/survey_responses/xygeni-review-11393516)**

**Rating:** 4.5/5.0 stars

_— Marcos C._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11393516)

**["Revolutionized Our Security Workflow with Unified, AI-Driven Efficiency"](https://www.g2.com/survey_responses/xygeni-review-11998435)**

**Rating:** 5.0/5.0 stars

_— Yerassyl K._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11998435)

### [ReversingLabs](https://www.g2.com/products/reversinglabs/reviews)

ReversingLabs is the trusted name in file and software security. We provide the modern cybersecurity platform to verify and deliver safe binaries. Trusted by the Fortune 500 and leading cybersecurity vendors, RL Spectra Core powers the software supply chain and file security insights, tracking over 422 billion searchable files with the ability to deconstruct full software binaries in seconds to minutes. Only ReversingLabs provides that final exam to determine whether a single file or full software binary presents a risk to your organization and your customers.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### Who Is the Company Behind ReversingLabs?

- **Seller:** [ReversingLabs](https://www.g2.com/sellers/reversinglabs)
- **Year Founded:** 2009
- **HQ Location:** Cambridge, US
- **Twitter:** @ReversingLabs  
7,022 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a0adaa8657020403414851b990a81c3a6a6e60c4899834e4a7ca68c7abd667e5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freversinglabs%2F&secure%5Burl_type%5D=linkedin_company_website)  
321 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 80% Small, 10% Medium

#### What Do G2 Reviewers Say About ReversingLabs?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **accuracy of information** provided by ReversingLabs, ensuring effective risk management and resource utilization.
- Users appreciate the **excellent customer support** at ReversingLabs, highlighting their involvement and effectiveness in the onboarding process.
- Users praise ReversingLabs for its **efficiency** in onboarding and risk management, leading to a seamless user experience.
- Users commend the **effective prioritization** of risk management in ReversingLabs, enhancing their overall satisfaction and security.
- Users value the **high reliability** of ReversingLabs, appreciating its seamless onboarding and extensive file repository.

##### Cons

- Users find the **complex querying** for usage endpoints confusing, which can hinder their overall experience.
- Users find the **interface confusing** , particularly when it comes to checking usage endpoints.
- Users find the **navigation issues** of ReversingLabs challenging, leading to confusion in checking usage endpoints.
- Users feel the **UI could be improved** , although it doesn’t significantly block their overall experience.

#### What Are Recent G2 Reviews of ReversingLabs?

**["Deep File Reputation Intelligence with Excellent Format Coverage"](https://www.g2.com/survey_responses/reversinglabs-review-12547875)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/reversinglabs-review-12547875)

**["Very good, with small drawbacks in the interface"](https://www.g2.com/survey_responses/reversinglabs-review-12310983)**

**Rating:** 4.5/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/reversinglabs-review-12310983)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/software-supply-chain-security-tools/free?open_modal_url=%2Fproducts%2Freversinglabs%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsoftware-supply-chain-security-tools%252Ffree%26source%3Dcategory&order=g2_score&page=2#product-list)
- [Next &rsaquo;Next ›](/categories/software-supply-chain-security-tools/free?open_modal_url=%2Fproducts%2Freversinglabs%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsoftware-supply-chain-security-tools%252Ffree%26source%3Dcategory&order=g2_score&page=2#product-list)

Spotlight Categories

[Accounts Receivable Software](https://www.g2.com/categories/accounts-receivable)

[Purchasing Software](https://www.g2.com/categories/purchasing-software)

[Inbound Call Tracking Software](https://www.g2.com/categories/inbound-call-tracking)

[Accounts Payable Automation Software](https://www.g2.com/categories/ap-automation)

[Influencer Marketing Platforms](https://www.g2.com/categories/influencer-marketing-platforms)

Similar Categories

- [Cloud Platform as a Service (PaaS)](/categories/cloud-platform-as-a-service-paas)
- [Integrated Development Environments (IDE)](/categories/integrated-development-environments-ide)
- [Software Testing](/categories/software-testing)
- [Communication Platform as a Service (CPaaS)](/categories/communication-platform-as-a-service-cpaas)
- [Help Authoring Tool (HAT)](/categories/help-authoring-tool-hat)

- [Other Development](/categories/other-development)
- [AI Documentation Generators](/categories/ai-documentation-generators)
- [API Development](/categories/api-development)
- [API Documentation Management](/categories/api-documentation-management)
- [API Generation](/categories/api-generation)

- [API Management](/categories/api-management)
- [API Marketplace](/categories/api-marketplace)
- [API Mocking](/categories/api-mocking)
- [API Platforms](/categories/api-platforms)
- [Application Development](/categories/application-development)

[Browse Software Supply Chain Security Tools Themes](/categories/software-supply-chain-security-tools/themes)