G2 takes pride in showing unbiased reviews on user satisfaction in our ratings and reports. We do not allow paid placements in any of our ratings, rankings, or reports. Learn about our scoring methodologies.
GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fort
The new ways of building software create the necessity to support new vulnerabilities and new remediation workflows. These needs have emerged so abruptly that they have given rise to a young and highl
GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab
CloudGuard Code Security, part of the CloudGuard Cloud Native Security platform (https://www.g2.com/products/cloudguard-cnapp/reviews) is developer-centric code security that seamlessly monitors, clas
Security should be an integral part of the software development process, not an afterthought. Founded by Neatsun Ziv and Lion Arzi, two former Check Point executives, OX is the first and only Active A
Jit is redefining application security by introducing the first Agentic AppSec Platform, seamlessly blending human expertise with AI-driven automation. Designed for modern development teams, Jit empow
Microsoft Defender for Cloud is a cloud native application protection platform for multicloud and hybrid environments with comprehensive security across the full lifecycle, from development to runtime
SonarQube helps developers continuously improve the quality and security of both AI-generated and human-written code. It addresses key areas including: - Code Quality: Ensuring all code meets high st
Checkmarx is constantly pushing the boundaries of Application Security (AppSec) Testing to make security seamless and simple for the world’s developers while giving CISOs the confidence and control th
Coverity® is a fast, accurate, and highly scalable static analysis (SAST) solution that helps development and security teams address security and quality defects early in the software development life
Semgrep is a highly customizable application security platform built for security engineers and developers. Semgrep scans first and third-party code to find security issues unique to an organization,
Kiuwan is a robust, end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composi
GuardRails is an end-to-end security platform that makes AppSec easier for both security and development teams. We scan, detect, and provide real-time guidance to fix vulnerabilities early. Trusted b
Klocwork is a static code analysis and SAST tool for C, C++, C#, Java, JavaScript, Python, and Kotlin that identifies software security, quality, and reliability issues helping to enforce compliance w
Assembla is the most secure version control and project collaboration platform in the world. We provide secure cloud hosting for Subversion, Perforce and Git repositories with integrated project manag
CodeScene is a code analysis, visualization, and reporting tool. Cross reference contextual factors such as code quality, team dynamics, and delivery output to get actionable insights to effectively r
Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a
DeepSource is an all-in-one code health platform that equips organizations with everything they need to build maintainable and secure software while elevating the velocity of their software developmen
Qodo is a quality-first generative AI coding platform that helps developers write, test, and review code within IDE and Git. It offers automated code reviews, contextual suggestions, and comprehensive
As a leading provider of static application security testing (SAST) solutions, CodeSecure helps software developers solve challenging issues throughout the software development life cycle (SDLC) to pr
NowSecure Inc., based in Oak Park, Illinois, was formed in 2009 with a mission to advance mobile security worldwide. We help secure mobile devices, enterprises and mobile apps.
Rezilion's software attack surface management platform automatically secures the software you deliver to customers, giving teams time back to build. Rezilion works across your stack, helping you to k
A platform that helps teams or individuals to manage their code review process more efficiently. It streamlines feedback, reduces context switching, and increases code quality. We can be used on GitHu
Symbiotic Security is an AI-powered cybersecurity startup putting code security directly into developers’ workflows. Backed by leading investors and co-founded by industry veterans, Symbiotic offers t
The Code Registry is the world's first AI-powered code intelligence and insights platform, designed to safeguard and optimize software assets for businesses. By providing an independent, secure replic
Apiiro is the leader in application security posture management (ASPM), unifying risk visibility, prioritization, and remediation with deep code analysis and runtime context. Get complete applicatio
BluBracket was forged by security industry veterans who’ve secured millions of assets for many of the world’s largest companies. During our time securing documents, one question kept coming up—can you
Embold supports developers and development teams by finding critical code issues before they become roadblocks. It is the perfect tool to analyze, diagnose, transform, and sustain your software effici
RhodeCode is an enterprise source code management platform for behind-the-firewall Mercurial, Git, and SVN. It is open source, secure, and provides centralized control over distributed code repositori
Code pre-review AI tool for pull requests based on static code analysis and LLMs. Pre-review your code, set instructions, let the auto-fix do its magic, then the engineer makes the final call.
CodeAnt AI reviews your code line by line, finds critical code quality issues and security vulnerabilities, explains their impact, and guides you on how to fix them. It’s SOC 2 and HIPAA compliant,
Cycode is the only end-to-end software supply chain (SSC) security solution to provide visibility, security, and integrity across all phases of the SDLC. Cycode integrates with all of your software de
Parasoft Jtest is an integrated Java testing tool for Application Software Development. Develop high-quality code within an Agile workflow. Jtest’s comprehensive set of Java testing tools ensures high
Trunk Check runs 100+ idiomatic code-checking tools for every language and technology, locally (CLI, VS Code Extension), on CI (CI, GitHub Bot), and in our web app. You're probably already running a f
Undraleu® is a code quality platform that embeds best practices into your data provisioning pipelines, Enterprise wide, in a consistent, simple and agile manner. Undraleu®’s intuitive design and power
Almanax is an AI-driven security platform designed to enhance the security of Web3 applications by identifying and addressing code vulnerabilities. By integrating advanced large language models (LLMs)
Axivion Static Code Analysis helps developers check standard compliance, security vulnerabilities, and code quality issues for C and C++ code. It performs automated analysis to identify violations of
Bearer helps modern teams ship trustworthy products with the help of our code security SAST solution built for security, privacy and engineering teams. We combine sensitive data context with static c
Codegrip is an automated code review SaaS platform that helps developers to save time in code reviews and to tackle technical debt efficiently.
esChecker combines many years of penetration testing experience with a unique dynamic engine simulating attack techniques, such as reverse-engineering or code tampering. No source code is needed, on
Greptile is an AI-powered code analysis tool designed to enhance software development workflows by providing intelligent code reviews, generating documentation, and facilitating codebase understanding
CodeEye's IRIS is a next-generation application security posture management (ASPM) platform, offers an all-in-one solution with real-time, AI-powered vulnerability and threat detection, correlation, p
Matter AI is redefining software development velocity with Engineering Intelligence™ platform. We supercharge your code reviews with AI-powered insights, enabling engineers to move faster, leaders to
NetSPI PTaaS solves the challenges of traditional pentesting, using a powerful combination of people, processes, and technology to deliver contextualized outcomes in real time on a single platform. Mo
OpenRefactory is a Silicon Valley startup based upon the state of the art technology developed by its Co-Founder, Dr. Munawar Hafiz. His Ph.D. from the University of Illinois (Urbana-Champaign) was a
Phylum defends applications at the perimeter of the open-source ecosystem and the tools used to build software. Its automated analysis engine scans third-party code as soon as it’s published into the
Designed for app development, Q-mast embeds security directly into your workflow to identify security, privacy, and compliance risks before the mobile app is released. With a design tailored for DevSe
Recurse ML is an advanced code review tool designed to identify bugs in pull requests that traditional static analysis tools often miss. By integrating seamlessly into the development workflow, it enh
Seal Apps is a comprehensive vulnerability remediation solution designed to secure open-source components by providing long-term support through standalone, remediated versions of security patches for
Albert Invent's Security & Developer Tools provide a robust, secure, and extensible platform tailored for the chemistry and materials science industries. These tools are designed to protect intell
Get 100% Security Design Review coverage without burning out your Security team Augment critical security talent by using Gen AI to automate manual AppSec workflows. Ship faster and save time, withou
Semgrep Code is a static application security testing (SAST) solution designed to help developers identify and remediate security vulnerabilities within their codebases. By integrating seamlessly into
Sigrid® - The Software Assurance Platform Sigrid, the software assurance platform from Software Improvement Group (SIG), provides actionable insights into your software portfolio and empowers your or
Vijil Trust Audit is a comprehensive assessment tool designed to evaluate and enhance the security and governance of Large Language Model (LLM) applications. By aligning with the OWASP Top 10 guidelin
Zendata's Code Scanner is a privacy-first development tool designed to integrate seamlessly into your software development lifecycle, ensuring that data privacy is embedded from the initial stages of