Cybersecurity Companies

Categories · Certification

SOC 2

Companies that list a SOC 2 report (Type I or Type II). As listed — we do not audit the report.

39 companies. Search a country or city. Tick features, then apply once. Organic order is not for sale.

Indexorganic · newest first · page 1/2
CompanyWhat they sellFocus / ratingStatus

HiddenLayer

Austin, US · Product vendor

Security for machine-learning models and AI applications.

AI security

Cyera

New York, US · Product vendor

Data security posture management for cloud data stores.

Data protection · Cloud security

Proofpoint

Sunnyvale, US · Product vendor

Email security, threat protection, and human-risk controls.

Email & messaging · Human risk

Snyk

Boston, US · Product vendor

Developer-first SCA, SAST, and container security.

Application security · Cloud security

GitGuardian

Paris, FR · Product vendor

Secrets detection in git, tickets, and production.

Application security · Data protection

Lakera

Zurich, CH · Product vendor

Guardrails for LLM applications in production.

AI security · Application security

1Password

Toronto, CA · Product vendor

Password manager and secrets for people and machines.

Identity · Data protection

Darktrace

Cambridge, GB · Product vendor

AI-driven detection and response for enterprise networks.

Security operations · Email & messaging

Tines

Dublin, IE · Product vendor

No-code security automation and SOAR for lean teams.

Security operations

Abnormal Security

San Francisco, US · Product vendor

API-based email security against BEC and inbound phishing.

Email & messaging

Palo Alto Networks

Santa Clara, US · Product vendor

Network, cloud, and SOC platform spanning firewalls to Prisma Cloud.

Network security · Cloud security

Armis

San Francisco, US · Product vendor

Asset intelligence for IT, OT, IoT, and medical devices.

Cyber-physical · Network security

KnowBe4

Clearwater, US · Training

Security awareness training and simulated phishing.

Human risk

Zscaler

San Jose, US · Product vendor

Cloud-delivered ZTNA, SWG, and SSE for the internet-first workplace.

Network security · Identity

SentinelOne

Mountain View, US · Product vendor

Autonomous EDR and XDR for endpoints, identity, and cloud workloads.

Endpoint security · Security operations

Varonis

New York, US · Product vendor

Data security platform for identity, activity, and classification on unstructured data.

Data protection · Identity

Okta

San Francisco, US · Product vendor

Workforce and customer identity for SSO, MFA, and lifecycle.

Identity
Verified

CyberArk

Newton, US · Product vendor

Privileged access, secrets, and machine identity.

Identity

Arctic Wolf

Eden Prairie, US · MSSP / managed

Managed detection and response as a subscription.

Security operations

Tenable

Columbia, US · Product vendor

Exposure management and vulnerability scanning across IT, cloud, and OT.

Threat & vulnerability · Cyber-physical

Rapid7

Boston, US · Product vendor

SIEM, vulnerability management, and detection from InsightVM and InsightIDR.

Security operations · Threat & vulnerability

Semgrep

Detroit, US · Product vendor

Open-source SAST and a commercial code security platform.

Application security

Netskope

Santa Clara, US · Product vendor

SSE, CASB, and data protection delivered from a security cloud.

Network security · Data protection

SecurityScorecard

New York, US · Product vendor

Security ratings and vendor-risk monitoring.

GRC · Attack surface
Page 1 of 2Next
FAQ
What does SOC 2 mean on this index?

Companies that list SOC 2. Company attestations (ISO 27001, SOC 2) are held by the firm. Practitioner credentials (OSCP, GPEN) are held by people on staff. We do not audit certificates or invigilate exams.

Is the order paid?

No. Organic order is recency. Promoted shelves are labeled and separate. That is the opposite of buying a rank.

How do I get listed under SOC 2?

Submit a company and tick the certifications you actually hold. We review before anything is public. Paid plans buy a labeled shelf, not a silent bump in this list.

Why is a staff exam on a company directory?

Buyers shortlist pentest and training firms by who sits on the engagement. OSCP and GPEN are company filters here, not a people directory.