![Varun S.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Varun S.")
VS

Varun S.

Senior Application Security Engineer

Mid-Market (51-1000 emp.)

6/18/2026

"Fast, Transparent DAST with Excellent GraphQL Handling and Strong Support"

4/5

What do you like best about Escape?

Escape is built with a wide range of protocols in mind and shows a strong understanding of how they work. In particular, I really liked how it handles GraphQL operations. I’ve gotten better results than with traditional DASTs.

The UI/UX offers a lot of transparency into what the tool is doing and how it reports issues. Filtering is excellent, and it’s easy to adapt it to whatever prioritization matrix you use. Scans are also quick.

Escape comes with the baseline integrations you need from day one. It covers the same integrations you’d expect from other DAST platforms, and the team is quick to work with you on new ones when there’s enough interest and it improves the overall experience.

Support has been consistently strong: they typically respond within half a day and do a great job helping resolve issues. They’re also willing to jump on calls to debug and fix things together.

Escape's AI Copilot is great on its own, but if you want to extend it further, you can use Escape MCP with other AI tools to build your own triage pipelines with custom context and knowledge.

I was an early adopter of Escape, and their pricing has been fair since day one. Review collected by and hosted on G2.com.

What do you dislike about Escape?

I’m mostly going to nitpick here.

Escape could elevate the UX tremendously and connect its offerings more cohesively. It supports GraphQL schema files, but there’s no way to automate schema file updates. It would be a huge help if it had GitHub integration so it could automatically discover and pull schema files.

Similarly, Escape Copilot is great at reasoning with the information that’s available, but that alone isn’t enough for me to fully trust its reasoning when the goal is to reduce triage time.

Right now, I run custom pipelines via Escape’s MCP for triage agents, using my own code knowledge for correlation. If they introduce GitHub integration, they could leverage it to provide better triage outcomes.

They could also improve the UX around load times. The platform takes a while to load pages and profiles.

Lastly, Escape could improve their APIs & other component with customer side automations in mind. Escape generate good reports but there is no automated way to export those as PDFs. You have to manually fetch the data via API and format it where the escape insights and presentation is lost. Review collected by and hosted on G2.com.

What problems is Escape solving and how is that benefiting you?

I’m using Escape to close the gaps in our current DAST coverage as Sigma becomes more API-first and GraphQL-heavy. Previous tool was falling short for me on GraphQL support, authenticated and logic-aware testing, and CI/CD integration, which meant weaker coverage for issues like BOLA/IDOR and multi-step workflow flaws.

Escape helps me by giving me better coverage across the surfaces I actually care about - our GraphQL backends, APIs, and web apps - with native GraphQL discovery, authenticated and multi-user scanning, internal scanning through private locations, and more context-aware vulnerability detection.

The practical benefit to me is that I can get broader coverage, higher-fidelity findings, and better operational fit. I’m expecting fewer false positives, better signal for developers, and tighter integration with our existing workflows so security testing is less of a bottleneck. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerSource: G2 invite

See what 10 reviewers think of Escape

4.9 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/escape/reviews)