![Thomas G.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Thomas G.")
TG

Thomas G.

Senior DevSecOps Engineer

Enterprise (\> 1000 emp.)

6/15/2026

"Developer-friendly AppSec with a flexible policy engine"

5/5

What do you like best about Arnica?

I deployed Arnica to replace Checkmarx at a previous company, and I have brought it with me to several startups I support since then. I still use it in my current role, in a somewhat different capacity than the full enterprise program I originally ran.

The policy engine was the primary reason we selected it after evaluating multiple products, since none of the other vendors we tested could offer comparable granularity at the time. It deployed fast across GitHub and Azure DevOps through SCM integration, with no CI rework to start getting value, and our first blocking policy was live within 90 days.

We were able to create granular PR policies on severity, EPSS, finding type, direct versus transitive and prod versus dev dependencies, and package reputation, which let us stage enforcement from annotations into blocking and turn rollout into measurable maturity milestones.

It also strengthened our Security Champions program, since we could empower champions to review dismissals for their own teams. Developer experience improved because people handled findings in code they were already changing instead of years of historical debt.

Customer success has been a genuine strength, responsive and willing to help with rollout, and several requests we raised shipped faster than I expected.

The SBOM explorer experience is also something I personally appreciate, I use it regularly to check exposure across the organizations I support whenever another large supply chain attack hits the news.

My use of the AI review features is still early, more proof of concept than a rollout. I feel positive about the direction, since reviewing AI-generated code is a real challenge and having policy enforcement meet it at the source is the right place to solve it.

On cost, it was priced competitively against the other vendors we evaluated and the per-identity model scaled sensibly as the team grew. Review collected by and hosted on G2.com.

What do you dislike about Arnica?

Dashboard and reporting could be smoother, especially for executive or audit reporting, though I did not find it better in Checkmarx, Snyk, or GitHub Advanced Security. The API was accessible and well-documented enough that our vulnerability management aggregation platform built an integration to it, and we separately pulled findings into our own reporting.

We had some early challenges with SAST rule quality for older, non-web languages, C++ in particular, where SAST quality tends to be inconsistent industry-wide. We worked with Arnica on custom rules and coverage has improved since.

No DAST, which was a lower priority given our focus on pre-production risk, but runtime-heavy teams should weigh that.

The per-identity pricing model also made direct comparison against other vendors trickier, since most of them price differently, and it took some work to walk our finance stakeholders through it before a deal could move forward, though we concluded the pricing was fair once we normalized the comparison. Review collected by and hosted on G2.com.

What problems is Arnica solving and how is that benefiting you?

The goal was to get more traction from existing application security coverage across SCA, SAST, secrets detection, and SBOM, without slowing engineering down on GitHub and Azure DevOps. In a previous deployment we selected it because we were not seeing consistent, organization-wide reduction in findings, largely because of how findings were delivered, and we wanted a tool that would let us run a focused, prioritized reduction process.

Delivering findings at the SCM layer meant developers mostly dealt with issues in the code they were actively changing rather than a backlog of historical debt they had no context for, which is what finally moved the needle on reduction.

The policy engine flexibility gave us a concrete way to prioritize in a common way across our other product security programs, since we could place emphasis on issues with demonstrated impact that came through bug bounty and red team work, and further tie that back to how Security Champions reviewed and drove remediation on their teams. That pulled four programs into a shared product security effort with a common incentive.

The other ongoing benefit is supply-chain visibility, when a major dependency compromise hits the news, I can check exposure across the organizations I support quickly. Review collected by and hosted on G2.com.

Show More

Response from Anna Daugherty of Arnica

[Editedit](https://www.g2.com/survey_responses/arnica-review-12962349/official_response/edit)

Thank you so much for your feedback, Thomas. We appreciate the detailed review, and are always looking to improve our features and capabilities. We can't wait to share exciting new updates at Arnica with you!

Validated ReviewerSource: Organic Review from User Profile

See what 8 reviewers think of Arnica

4.9 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/arnica/reviews)