cybersecuritycompanies.

THE ARENA / VENDOR DISCOVERY

Your challenges.
Your shortlist.

Choose what needs solving. Define what matters. Find vendors with the coverage to match.

Your shortlist 0

No vendor in mind? Start with the outcome.

START WITH THE OUTCOME

What does your identity problem look like?

Pick the challenges you recognize. We'll suggest requirements you can edit.

02 / EXPLORE ALTERNATIVES

Application security vendors for your brief

25 candidates in application security

Every must-have must be listed or documented. Optional preferences cannot fill a gap.

YOUR BRIEF, CONNECTED
YOUR MUST-HAVESMATCHING COVERAGE
Each connection is a capability listed in the directory.Click to explore ↗
25 alternativesMost requested capabilities listed first

Aqua Security

Product vendor · Boston, United States

Cloud-native application protection from code to runtime.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Atlant Security

MSSP / managed · Sofia, Bulgaria

Founder-led pentest, vCISO, and compliance consulting.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Bishop Fox

Consultancy / pentest · Phoenix, United States

Offensive security consultancy and Cosmos continuous pentest.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Cloudflare

Product vendor · San Francisco, United States

CDN, WAF, Zero Trust, and bot management on a global edge.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Conviso

Product vendor · Curitiba, Brazil

Application security management and secure development services.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

CyStack

Product vendor · Hanoi, Vietnam

Security testing and vulnerability management.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

GitGuardian

Product vendor · Paris, France

Secrets detection in git, tickets, and production.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Intigriti

Product vendor · Antwerp, Belgium

Bug bounty programs and crowdsourced security testing.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Jscrambler

Product vendor · Porto, Portugal

Client-side JavaScript protection and payment page monitoring.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Kasada

Product vendor · Sydney, Australia

Bot mitigation for websites and APIs.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Kratikal

Consultancy / pentest · Noida, India

Penetration testing and security compliance services.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Lakera

Product vendor · Zurich, Switzerland

Guardrails for LLM applications in production.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

NCC Group

Consultancy / pentest · Manchester, United Kingdom

Global pentest, research, and cyber resilience consultancy.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Penta Security

Product vendor · Seoul, South Korea

Web application protection and database encryption.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Pentest-Tools.com

Product vendor · Bucharest, Romania

Online penetration testing and vulnerability scanning tools.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Pradeo

Product vendor · Montpellier, France

Mobile threat defense and application security.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

SafeStack

Training · Auckland, New Zealand

Secure development training for software teams.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Secuna

Consultancy / pentest · Taguig, Philippines

Penetration testing and vulnerability disclosure programs.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Semgrep

Product vendor · Detroit, United States

Open-source SAST and a commercial code security platform.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Snyk

Product vendor · Boston, United States

Developer-first SCA, SAST, and container security.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Trail of Bits

Consultancy / pentest · New York, United States

High-assurance security engineering, audits, and research.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Wiz

Product vendor · New York, United States

Cloud security graph for code-to-cloud risk.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗

Zerocopter

Product vendor · Groningen, Netherlands

Coordinated vulnerability disclosure and ethical hacking.

Choose requirements to assess fit

Validate listed coverage for your deployment.

View company profile ↗
How vendors are matched +

Buyer tools feature vendors on Verified and Featured plans. All company listings remain available in the directory. Problem searches also include participating vendors in adjacent categories when they explicitly list a selected requirement. Provider type and location filters still apply.

“All must-haves” requires coverage for every mandatory requirement. Partial matches remain available in a separate view. Within equal must-have coverage, optional matches determine order, followed by alphabetical ties. A higher-priced plan does not improve a requirements match.

Integration and hosting requirements always need current evidence for a specific product, edition and deployment. Generic tags and headquarters do not establish support. Coverage for other capabilities comes from directory listings and linked vendor documentation. Documentation shows a vendor claim, not an independent product test. Different requirements may need different products or licenses from the same company. Unlisted means “confirm with vendor,” not “unsupported.”

Read the directory methodology ↗

03 / TAKE THE NEXT STEP

Your shortlist. Your next conversation.

Keep up to four vendors. Pick two to compare, or export your brief for the next demo.

SAVED IN THIS BROWSER
+
A good decision starts with a few good options.

Shortlist a vendor above to bring it here. Your brief and picks will be saved on this device.

Select two to compareSave to my account ↗

Keep named briefs and private evaluation notes across devices in Saved briefs. Account saving requires sign-in; browsing and exports remain available here.