Security Tool Directory
Every security tool. One map.
The security market is noisy. We mapped it so you don't have to.
AI & LLM Security
Start here if you're evaluating AI security. We've mapped the vendors across AI-SPM, AI runtime, agentic SOC and prompt-injection defense, laid out by where they actually sit in your stack.
Curated lens · Updated monthly
1,139 vendors
the pioneering GenAI bug bounty platform designed to safeguard the future of artificial intelligence
Agentless privileged access for every identity.
Led by seasoned security and technology executives, 1Password provides trusted access for people and AI agents. We unlock productivity by making security and privacy simple for every person and organization.
360 Privacy was founded to reduce the critical gap between cybersecurity and real-world protection, securing personal data that puts high-profile people, families, and companies at risk.
42Crunch is a SaaS API security platform focused on securing APIs from design time through runtime. It uses OpenAPI Specification (OAS v2 and later) to audit API definitions, scan live endpoints for contract drift and common API vulnerabilities, and generate API firewall policies for protection. The platform is aimed at teams that want security controls embedded in API development and CI/CD workflows, especially enterprises with distributed development and multiple API stacks. Adjacent governance and inventory functions exist, but the core value is contract-driven API security testing and enforcement.
7AI is the foundational AI security company. Founded in 2024 by Cybereason co-founders Lior Div and Yonatan Striem-Amit, 7AI came out of stealth in February 2025 to take on the non-human work of the SOC, with AI agents that detect, investigate, respond, and hunt, and humans on the loop.
A10 Networks delivers secure, high-performance networking solutions that protect and scale critical applications across core, cloud, and edge environments
An AI-Native Company Dedicated to Cybersecurity. Built by AI insiders with an outsider's perspective: Behavior is the future of cyber defense.
Behavioral AI that protects email, identity, and AI, and stops insider threats.
AI-native insider risk workflows for detecting, investigating, and preventing threats before they escalate.
Absolute Security’s endpoint product line centers on **Absolute Secure Endpoint**, which uses a firmware-embedded Persistence agent to keep a durable connection to managed devices even after reimaging or software tampering. Within EDR, it is better understood as an endpoint visibility, control, and recovery platform than a pure malware-detection engine. It is best for enterprises that need continuous endpoint reachability, remote containment, and fleet-wide remediation across laptops and other managed devices, especially in distributed workforces.
Abstract, founded in 2023, has built a revolutionary platform to redefine security operations, launching the world's first AI-Gen Composable SIEM.
AbuseIPDB provides high-fidelity IP reputation data and a massive crowd-sourced database of reported malicious infrastructure. It offers a high-performance API and on-premises feeds used for real-time traffic analysis, automated enrichment in SOC workflows, and blocking of known bad actors. This platform complements SIEM and SOAR systems by providing the contextual intelligence needed to identify botnets, scanners, and brute-force actors before they breach the network.
Abusix is the essential solution in today's network security landscape, enabling fast and reliable mitigation of network abuse and cyber threats.
Acalvio is the leader in autonomous cyber deception, defending against APTs, insider threats, and ransomware. Its AI-powered Preemptive Cybersecurity Platform, protected by 25 patents, delivers threat detection across IT, OT, and cloud environments and advances Identity Threat Detection and Response (ITDR) with Honeytoken-driven Zero Trust security.
Identity governance built where your business already runs, natively on the ServiceNow Platform.
Acronis is a global cyber protection company delivering the only natively integrated cybersecurity, data protection, and infrastructure management platform for managed service providers and IT departments. Acronis solutions are designed to identify, protect, detect, respond, recover and govern IT deployments, ensuring data integrity and business continuity.
Action1 is an autonomous endpoint management platform trusted by many Fortune 500 companies. Cloud-native, infinitely scalable, highly secure, and configurable in 5 minutes, it just works and is always free for the first 200 endpoints, with no functional limits. Pioneering autonomous OS and third-party patching with peer-to-peer patch distribution and real-time vulnerability assessment, no VPN required.
ActiveState is a DevSecOps vendor focused on securing open source dependencies and language runtimes used in software delivery pipelines. Its platform scans code repositories, containers, and build inputs to identify vulnerable components, then supports remediation by rebuilding packages from source and managing dependency changes. The company is positioned around automated vulnerability management and software supply chain security rather than broad application security testing. It is best suited for engineering and security teams that need governed open source usage, deterministic builds, and faster patching without relying only on upstream package updates.
Action-Centric Cloud Security
ActTrident™ is a United Kingdom cybersecurity company building a focused platform across human-centered security, AI security, quantum-oriented security planning, and governance-led product lines.
The Invicti Web + API (formerly Acunetix) legacy is built on runtime accuracy, speed, and proof your team can trust. We pioneered the DAST market 20+ years ago and continue to drive AppSec forward with innovations in AI, code-to-runtime correlation, and vulnerability management.
Adaptiva, the autonomous endpoint management company, delivers the fastest way to patch and manage endpoints at scale.
Unified security awareness training, email security, and AI governance built for the AI era.
Adaptive Shield is primarily known for SaaS Security Posture Management, but in a cloud security/CSPM evaluation it is not a native fit and should be treated as an adjacent vendor rather than a core CSPM platform. The public material provided focuses on SaaS configuration monitoring, identity-related SaaS controls, and remediation workflows across applications such as Google Workspace and Microsoft 365. For a buyer specifically seeking cloud posture management, the useful takeaway is that Adaptive Shield’s model is agentless and configuration-centric, but its disclosed capabilities do not map cleanly to AWS, Azure, GCP, or Kubernetes CSPM requirements. Best suited for organizations prioritizing SaaS configuration governance over IaaS posture management.
Admin By Request is a privileged access management vendor focused on removing standing local administrator rights while allowing controlled elevation when needed. Its PAM offering is centered on endpoint privilege elevation, request/approval workflows, session auditing, and policy-based control of elevated activity. The product is best suited for Windows, macOS, and Linux environments where IT teams want to reduce local admin exposure without blocking legitimate software installs or support tasks. It also integrates with ServiceNow for request handling, but its core scope is endpoint PAM rather than vault-centric secrets management.
Our AI-native culture drives continuous reinvention and bold innovation. We embrace change, push to stay ahead of adversaries, and collaborate without ego, all while fiercely securing our customers' data as the foundation of their trust.
Our vision is to provide a digital world where every business can safely build its applications by inherently trusting how they connect to partners, customers, and foundational services. The result: You can build, deliver and maintain better applications that support and empower your customers, without the frustration and exposure risks that come with boldly crossing borders.
The same identity foundation, extended to the new workforce: AI agents. Identity-native governance for everything that acts on your systems.
The secure hub for agent identity, governance, and visibility. Control what your agents can access and do, for every user.
AhnLab provides endpoint security products centered on Windows endpoint protection and centralized management. Its V3 Endpoint Security line uses anti-malware scanning, URL and DNS protection, device control, and cloud-assisted detection through Smart Defense. AhnLab Endpoint PLUS consolidates endpoint controls into a single management console, and the vendor also offers EDR and OT endpoint security adjacent to the core endpoint portfolio. It is best suited for enterprises that want endpoint prevention and response from a vendor with long-standing experience in anti-virus and endpoint control, especially in Windows-heavy environments.
Your Control Plane for Secure AI
All the security tools we used were slow, confusing, overpriced and noisy. So we built better ones.
Aim Security provides AI security posture management and runtime protection for enterprise GenAI deployments. Acquired by Cato Networks in 2025, Aim is being integrated into the Cato SASE Cloud platform to bring AI discovery, data protection and policy enforcement to network-delivered security. Best suited for organizations that want a single SASE-delivered control plane covering shadow AI discovery, GenAI DLP, prompt injection defence and governance over copilots and homegrown AI apps without standing up a separate AI security stack.
Airlock Digital was founded in Adelaide, Australia, by cybersecurity professionals determined to build the most effective and scalable application control technology in the world.
We're passionate about delivering awesome detection and response to security teams of all sizes.
The Agentic OS for the enterprise. Redefining how organizations run cybersecurity, IT, and business operations in the agentic era, by making intelligence native, not bolted on. Today’s enterprises are overwhelmed by fragmented point tools and shallow, bolt-on AI that can summarize information but can’t reason, decide, or act. Airrived was built to change that. Our platform enables enterprises to fine-tune models, compose deep-reasoning agents, and orchestrate intelligence across systems, without requiring AI expertise. I
AAIR secures every AI add-on before it becomes part of your enterprise. From discovery and continuous vetting to governance and runtime protection, AIR enables organizations to adopt AI safely. Air provides four solutions as a complete agentic security platform: - Air Control - Governance and control of agents across the enterprise, shadow ai discovery, posture management of agents configuration and connectivity - Air Defend - Runtime protection of agents behavior in real time. Visibility of every agent prompt and action, detection and response to dangerous and malicious behavior, runtime guardrails for agent behavior in realtime - Air Filter - Governing all agent add-ons which exist in the enterprise, continuously vetting of them, and detect and response to supply chain incidents. - Air Marketplace - Secured-by-default marketplace of pre-vetted add-ons, both external from open source and internally built, as a single source of truth for all enterprise usage
Autonomous AI penetration testing, source-code audits plus white-box and black-box pentests with validated findings.
The AI-native security operations platform built for enterprise. Preemptive, autonomous, and continuously self-improving.
aisy helps security teams move from isolated vulnerability tickets to the threats they actually care about. We build context from an offensive security perspective ahead of time, clean up findings, and feed the recurring patterns into their coding agent as they build - so every finding makes the next one less likely.
We make life better for billions of people, trillions of times a day
Cloud-Native SaaS platform built to secure and manage every identity through a single pane of glass.
The Enterprise Platform for AI Security & Governance
We make data answerable and actionable, for people and agents.
AlgoSec provides a security policy management platform that automates the orchestration of connectivity and security policies across hybrid cloud and on-premise environments. It provides deep visibility into complex network topologies, enabling automated risk analysis and firewall rule changes without manual intervention. The platform replaces manual CLI-based firewall management and integrates with ITSM tools to streamline security operations.
Keeping communicative tech safe, secure, and reliable.
AT&T Cybersecurity AlienVault USM Anywhere is a cloud-hosted SIEM platform that unifies asset discovery, vulnerability assessment, intrusion detection, behavioral monitoring, and incident response for on-premises, cloud, and hybrid environments. It correlates security events from logs, network traffic, and cloud APIs like AWS CloudTrail and CloudWatch, retaining data for 90 days. Integrated with OTX threat intelligence and AlienLabs feeds, it targets SMBs and resource-constrained teams needing all-in-one threat detection without separate tools. OSSIM offers a limited open-source alternative for single-server on-premises use.
Alpha Level is a next-generation cybersecurity company transforming how Security Operations Centers (SOCs) detect and respond to threats. Alpha Level combines statistical modeling, anomaly detection, and agentic AI to filter out non-actionable alerts, surface rare and high-risk behaviors, and provide contextualized evidence for investigation. The result is a data-driven, behavior-based detection system that improves signal quality while reducing cost.
alphaMountain.ai provides AI-driven domain and IP threat intelligence focuses on web reputation and content classification. Utilizing proprietary machine learning, it offers real-time detection of malicious sites, phishing domains, and risky infrastructure through high-speed APIs and feeds. It is typically integrated into web gateways, SIEMs, and firewalls to provide a dynamic layer of categorization and risk assessment for internet-bound traffic.
ALT Security is an agentic penetration testing and red team product that claims to find “every critical attack chain” in an environment and prioritize them continuously. In the penetration testing and red team category, it appears aimed at teams that want repeatable offensive testing with automated attack-path discovery rather than a one-off manual assessment. Based on its public messaging, it is best suited for security teams that need ongoing validation of exposed paths across infrastructure and want findings organized by exploitability and impact. Adjacent products are not clearly disclosed on the homepage.
Anchorage Digital is a global crypto platform that enables institutions to participate in digital assets through custody, staking, trading, governance, settlement, and the industry's leading security infrastructure.
Anchore is creating a more secure software supply chain for priceless peace of mind.
We don't replace human talent and intelligence. We empower cybersecurity teams to make critical decisions, assess threats, respond immediately, reduce risk, and focus on prevention.
We're Anecdotes, and we're transforming how enterprise teams manage governance, risk, and compliance. We built the world's first enterprise agentic GRC platform to fundamentally change what's possible in GRC, and empower teams to focus on what matters.
Anomali ThreatStream is a threat intelligence platform that aggregates IOCs and IOAs from hundreds of global sources including Anomali Labs curated feeds, OSINT, premium feeds, and ISACs. It enriches telemetry via automated correlation, campaign analysis, and ML-based scoring for confidence and severity. The Next-Gen version integrates agentic AI for natural language queries via Anomali Copilot, MITRE ATT&CK mapping, and pushes high-confidence intelligence into SIEM, SOAR, EDR, and firewall workflows. Trusted by enterprises and governments for over a decade, it accelerates investigations 300x faster, ideal for CTI and SOC teams operationalizing intelligence at scale.
Anvilogic is a threat detection and hunting platform that works alongside existing data platforms (Snowflake, Databricks, Splunk) rather than replacing them. It provides a library of pre-built detection rules, a detection-as-code workflow, and multi-platform hunt capabilities. Popular with teams who want to improve detection quality without migrating their data infrastructure, Anvilogic helps detection engineers measure and close MITRE ATT&CK coverage gaps while standardising rules across heterogeneous data lakes and SIEM stacks.
AnyInsight.ai is a Zero Trust platform designed to secure the deployment of GenAI agents within the enterprise. It focuses on preventing shadow AI, data leakage (DLP for AI), and minimizing hallucinations through built-in security agents. This platform complements existing IAM and DLP solutions by extending their capabilities to the unique risks associated with autonomous AI agents and large language model interactions.
ANY.RUN helps security teams detect malware and phishing earlier and respond with confidence. It combines real-time interactive analysis with threat intelligence from live attacks, delivering immediate visibility into behavior, indicators, and active campaigns. This helps SOCs and MSSPs assess risk faster, reduce uncertainty, and act without delays. ANY.RUN fits into SOC workflows across monitoring, triage, incident response, and threat hunting.
Apiiro provides supply chain security capabilities as part of its application security platform, with a focus on inventorying software components, tracing code-to-runtime relationships, and detecting supply chain risk across SCM repositories and CI/CD pipelines. It is positioned for AppSec and platform security teams that need continuous visibility into dependencies, build activity, commit changes, and artifact provenance, rather than point-in-time scans. Apiiro also ties supply chain findings to code owners and policy workflows, and it offers adjacent ASPM and application inventory features, which are not the focus of this profile.
Apono is a cloud access management vendor positioned in IAM around just-in-time and least-privilege access for human and non-human identities. Its platform replaces standing privileges with access created at request time, enforced with policy guardrails, and revoked automatically. Apono is best suited for cloud-first teams that need granular control across AWS, Azure, GCP, Kubernetes, databases, and SaaS-connected environments, especially where privileged access and access review must be tightly managed.
Appdome provides no-code mobile app security for Android and iOS, delivered as build-time and runtime protections inside the mobile CI/CD pipeline. In the Mobile Security category, it focuses on app shielding, communication protection, anti-tampering controls, and device-integrity checks such as root and jailbreak detection. It is suited for mobile teams in banking, healthcare, government, and consumer apps that need to add protections without embedding and maintaining security SDK code. Appdome also offers adjacent fraud and mobile threat defense capabilities, but the core mobile security scope centers on protecting the app binary, runtime, and network sessions.
Appgate provides a high-performance Zero Trust Network Access (ZTNA) solution designed for complex hybrid and multi-cloud environments. The platform utilizes a Software-Defined Perimeter (SDP) architecture to create 1-to-1 encrypted tunnels, replacing legacy VPNs and hardware-based firewalls with identity-centric access controls. It features 'direct-routed' architecture to eliminate cloud latency bottlenecks and supports granular, attribute-based access control (ABAC) for both users and machine-to-machine communications.
AppOmni is positioned as a SaaS Security Posture Management (SSPM) platform, not a traditional multi-cloud CSPM vendor. The search results consistently clarify that AppOmni focuses on SaaS application security posture (Salesforce, Microsoft 365, ServiceNow, Google Workspace, Workday) rather than cloud infrastructure (AWS, Azure, GCP). While AppOmni uses CSPM terminology in legacy marketing, it does not compete in the infrastructure CSPM category. For cloud infrastructure posture management, AppOmni integrates with true CSPM solutions like Wiz. Organizations seeking multi-cloud IaC scanning, drift detection, and infrastructure misconfiguration remediation should evaluate dedicated CSPM vendors, not AppOmni.
AppRiver is an email security vendor now operating under OpenText Cybersecurity after its acquisition by Zix and then OpenText. In the email-security scope, it is known for cloud-delivered filtering, phishing and malware blocking, and encrypted message delivery for organizations that want to protect Microsoft 365 and other email environments without deploying on-premises appliances. Its portfolio also includes adjacent compliance functions such as archiving and continuity, but the core buyer is typically a small-to-mid-sized business or managed service provider looking for managed email protection and encryption.
AppSentinels is a comprehensive API security platform that focuses on protecting the entire API lifecycle from development to runtime. It utilizes stateful API modeling and workflow analysis to identify sophisticated business logic attacks and data exfiltration that traditional WAFs often miss. The platform provides deep visibility into API discovery, vulnerability assessment, and real-time threat protection for REST, GraphQL, and AI-driven API endpoints.
AppViewX is an automated Certificate Lifecycle Management (CLM) and Public Key Infrastructure (PKI) platform designed to prevent service outages caused by expired certificates. It provides centralized visibility and control over machine identities across multi-cloud and on-premises environments, enabling crypto-agility and rapid modernization of cryptographic standards. The solution complements existing HSMs and CAs by orchestrating the end-to-end process of certificate issuance, renewal, and installation.
Apricorn offers an extensive line of keypad-authenticated, 256-bit XTS hardware-encrypted USB external storage devices that protect your data at the highest levels. Available in a number of useful form factors from flash keys, to mid sized portables, to high capacity desktop models, in both HDD and SSD. Being hardware-encrypted, there is no software involved in the authentication or encryption processes, making them completely compatible with any operating system.
APX Labs appears to operate in application security testing, but the available public results do not identify a distinct APX Labs DAST/SAST product page or a clear commercial profile. Based on the surrounding AppSec sources, the relevant scope would be runtime DAST-style scanning of web applications and APIs, with SAST only if APX Labs also analyzes source code or binaries. Because the company’s product details are not well documented in the provided results, buyer fit, feature depth, and market position cannot be confirmed with high confidence.
AQtive Guard by SandboxAQ is a specialized security platform focusing on cryptographic discovery and AI risk management in the face of quantum computing threats. It provides deep visibility into an organization's cryptographic footprint (Agile Cryptography) and enforces real-time guardrails for AI agents and LLM deployments. The tool is designed to help CISOs transition to Post-Quantum Cryptography (PQC) while managing the immediate risks of 'shadow AI' and non-compliant code.
Aqua Security’s CSPM offering is a multi-cloud posture management product that uses cloud API access and agentless checks to inventory resources, detect misconfigurations, and map findings to compliance requirements. It is positioned for organizations operating AWS, Azure, Google Cloud, and Oracle Cloud that want continuous visibility into cloud configuration drift and prioritization of high-risk issues. Aqua also emphasizes real-time context and correlation of findings to reduce alert noise. The company sells a broader cloud security platform, but this profile is limited to its CSPM capabilities.
Aquila I offers an AI-native cyber defense platform that centralizes security telemetry in a lakehouse architecture. It leverages specialized AI agents and an AI Analyst Workbench to perform continuous detection, intelligent triage, and accelerated investigations. The platform unifies threat exposure management, AI system security, and continuous defense validation within a single system for in-house SOC teams.
Arcanna.ai provides a Decision Intelligence AI platform for SOC and NOC environments, framing investigations as classification problems using hybrid models with convolutional layers and Long Short-Term Memory units. It ingests analyst-labeled alerts to train models for autonomous triage, prioritization, enrichment, and incident management, incorporating human feedback for continuous learning. Patented grounding and governance ensure auditable, explainable decisions under human oversight. Best suited for SOC teams seeking agentic workflows to reduce noise and accelerate routine alert handling while maintaining control over complex threats.
Arch0 is an AI-native security operations platform that uses a knowledge graph and autonomous agents to provide context-aware incident analysis and remediation. It moves beyond traditional alert-based SIEM/SOAR models by using a 'swarm' of specialized AI agents to evaluate security signals based on real business impact and organizational context. The platform automates the investigation cycle, performing root-cause analysis and auto-remediation to reduce the load on security analysts.
Archer, formerly RSA Archer and now independent after RSA Security divestiture, provides an integrated GRC platform for enterprise governance, risk, and compliance management. It centralizes data aggregation from multiple sources, supports risk assessments, policy management, audit workflows, incident tracking, and business continuity planning. The configurable platform enables automated compliance monitoring for regulations like GDPR and HIPAA, with modules for controls testing and reporting. Widely adopted by large organizations and governments like Virginia Commonwealth, Archer serves enterprises needing holistic risk visibility across IT, operational, and third-party domains.
Archestra.AI is an open source security and governance layer positioned between large language models, AI agents, and enterprise data systems. The platform enforces a deterministic control layer so that access rules for agents stay fixed and predictable, independent of model judgment or prompt wording. It includes a private registry for Model Context Protocol (MCP) servers that governs which tools agents can reach, a retrieval augmented generation stack that runs inside the customer's own infrastructure, and a Kubernetes native orchestrator for multi-team deployments. The product is self-hostable and targets organizations connecting AI agents to systems such as HR platforms, email, and internal communication tools. Archestra.AI is a London based, early stage, seed funded company.
ARCON PAM is an enterprise-class privileged access management solution designed for hybrid, multi-cloud, and distributed datacenter environments. The platform centralizes control of privileged accounts across heterogeneous IT infrastructure through a unified admin console and secure gateway server. ARCON PAM targets IT security, risk, and compliance teams managing complex privilege lifecycles in organizations with DevOps and cloud-native workloads requiring fine-grained access controls and comprehensive audit trails.
Arctic EWS provides a comprehensive and international early warning service for distributed organizations, expanding on the scope of services available from the government. Our service lets you split your organization into areas of responsibility, and automatically routes the security warnings to the right people. Our monitoring can also cover your suppliers.
Arctic Wolf provides managed security operations via the Aurora Platform, an Open-XDR framework that ingests unlimited security telemetry from endpoints, networks, cloud workloads, SaaS applications, and identity systems. It applies correlation engines with predefined rules, behavioral models, machine learning analytics, and Arctic Wolf Labs threat intelligence for anomaly detection and threat identification. Unlike standalone SIEM, it pairs automated analysis with 24x7 human SOC review, Concierge Security Teams for posture assessments, and integrated MDR. Best for organizations seeking outsourced SOC capabilities with rapid 30-day onboarding and flat-fee log retention up to 10 years, avoiding traditional SIEM complexity.
Cloudflare started as a simple application to find the source of email spam. From there it grew into a service that protects websites from all manner of attacks, while simultaneously optimizing performance.
Making Salesforce the safest place for enterprise data.
Arista Networks is an industry leader in data-driven, client to cloud networking for large data center/AI, campus and routing environments. Arista's award-winning platforms deliver availability, agility, automation, analytics and security through an advanced network operating stack.
Arkose Labs provides fraud detection and prevention focused on account fraud, bot abuse, credential stuffing, fake account creation, and automated abuse across web and mobile touchpoints. Its platform combines real-time risk scoring with challenge-response enforcement to distinguish legitimate users from suspicious sessions and to raise the cost of abuse. The product is best suited for consumer-facing digital businesses such as ecommerce, financial services, and online platforms that need to stop automated and human-operated fraud without blocking valid traffic. Arkose also advertises AI-agent policy enforcement, but its core value in this category is adaptive fraud deterrence and step-up authentication.
Armis provides agentless IoT security for unmanaged and hard-to-agent devices across enterprise, healthcare, industrial, and critical infrastructure environments. Its Centrix platform uses passive network sensing to discover connected assets, identify device type and behavior, and flag risk from unsupported operating systems, weak configurations, and suspicious communications. In this category, Armis is best suited for organizations that need visibility into IoT, OT, IIoT, and medical devices without installing agents or actively scanning devices that may be fragile or unavailable for software deployment. Adjacent exposure-management features exist, but the IoT security value centers on discovery, monitoring, and response for connected devices.
Zero-day and every day protection for your cloud applications with the first runtime behavioral Cloud Application Detection and Response (CADR) solution. A fully explainable & traceable runtime security story spanning the entire cloud technology stack.
ArmorCode is redefining security governance in the AI era as the agentic control plane for Unified Exposure Management.
ArmorPoint is a cloud-native managed security operations platform built for midsize enterprises and the partners who serve them. The platform brings detection, response, risk, and compliance together within a shared operations environment where customers, partners, and ArmorPoint's 24/7 U.S.-based SOC work side by side.
Arnica powers the most effective application security programs in the world.
Artemis is a specialized AI Security Posture Management (AI-SPM) platform focused on discovering, inventorying, and securing AI models, datasets, and notebooks across cloud environments. It provides continuous visibility into AI misconfigurations, exposure risks, and training-data classification, while mapping findings to OWASP LLM/ML Top 10. Artemis detects leaked AI credentials and assesses AI-BOM and supply-chain risks in ML pipelines. The vendor targets mid-to-large enterprises actively scaling AI adoption and needing operational governance without added headcount. Artemis also offers adjacent runtime security products, but its AI-SPM suite remains distinct for posture-focused buyers.
Artiphishell is a privately held cybersecurity vendor spun out of the Shellphish research team, but its public materials describe an AI-native application security platform rather than a classic penetration testing service. In the penetration testing and red team context, it is best understood as an autonomous vulnerability discovery and validation system that reproduces exploitable issues, reduces false positives, and generates proof-of-concept artifacts and patches. It appears best suited for security research, AppSec, and advanced validation workflows rather than outsourced human-led red teaming.
HPE Aruba Networking ClearPass Policy Manager is an on-premises Network Access Control (NAC) platform providing role- and device-based secure access across multi-vendor wired, wireless, and VPN infrastructures. It delivers device profiling via DHCP and TCP fingerprinting, posture assessment through OnGuard persistent and dissolvable agents, guest management with self-service portals, and automated enforcement using RADIUS, TACACS+, and OnConnect. ClearPass supports Zero Trust with real-time visibility, integrates with 150+ third-party systems including SIEM and MDM, and serves over 10,000 customers in healthcare, finance, education, and government for compliance and IoT security.
We're Making it Possible for Everyone to Proactively Secure Complex Cloud Environments.
A Security appears to be a vendor profile request for a penetration testing and red team offering, but the search results provided do not identify a product or company named exactly “A Security.” The available sources define the category rather than this vendor, describing red teaming as an adversary simulation with specific mission objectives, focused on testing detection, response, and control effectiveness rather than exhaustive vulnerability discovery. Based on that category framing, a buyer would expect services for organizations that need realistic attack-path validation, SOC exercise support, and executive-level evidence of defensive gaps.
Proof-Based Exposure Security
Discover, secure, and deploy AI agents responsibly across the enterprise
Atera is an all-in-one IT management platform that helps IT teams and MSPs monitor, manage, and secure their environments from a single interface. It combines RMM, helpdesk, automation, and Robin by Atera, our patented AI agent, solves issues autonomously, streamlines workflows, and lets your people get back to work. With real-time insights and proactive alerts, Atera reduces manual tasks, boosts efficiency, and helps teams scale support effortlessly.
Atsign is a cryptographic identity and secure communications platform built around the atProtocol, with keys generated at the edge and encrypted data exchanged only between authorized Atsigns. In the Encryption & Key Management scope, its main value is non-custodial, peer-to-peer key handling: private keys stay on sender and receiver devices, and the infrastructure operator cannot decrypt customer data. It is best suited for IoT, distributed systems, and agentic AI teams that want end-to-end encrypted messaging without centralized key custody or exposed inbound ports. Atsign also offers adjacent secure remote access tooling, but the core security model is protocol-level encryption.
The leading platform for Adversarial Exposure Validation (AEV) We help security teams make better decisions by continuously measuring how adversaries can exploit gaps across people, processes, and technology.
Attaxion builds on decades of joint cybersecurity expertise from our founders, team members, and advisors. We stand at the forefront of cybersecurity innovation and offer attack surface management solutions with #1 asset coverage and laser-focused, actionable intelligence.
AT&T Business offers **Security Operations Center (SOC)** services that combine managed monitoring, correlation, alerting, and incident response for enterprise networks and applications. In this category, it is positioned as a telecom-scale managed security provider that operationalizes security processes around AT&T network visibility and service management. The offering is best suited to organizations that want outsourced 24x7 security operations, alarm validation, and response support without building a full internal SOC. AT&T also sells adjacent cybersecurity products, but the core Security Operations scope here is its managed SOC/MDR services.
Built by practitioners for practitioners, Optro is an AI-powered GRC system of action that unifies audit, risk, infosec, and compliance into a single, connected platform. We empower the world's leading organizations to turn intelligence into a competitive advantage.
To enable businesses to innovate fearlessly in the age of AI by transforming how they safeguard themselves with the world's most advanced AI security platform.
Aurigin.ai enables proof of ownership and authenticity for all sensitive communication devices and digital content.
Aurva provides a runtime security layer specifically designed for agentic AI architectures and LLM-driven workflows. It monitors granular data access patterns of AI agents, detects behavioral anomalies that signify prompt injection or agent hijacking, and enforces real-time compliance controls. The platform complements existing WAFs and API security tools by providing visibility into the internal logic and data orchestration of autonomous agents.
AuthLite is a specialized multi-factor authentication solution designed specifically for Microsoft Active Directory environments to secure administrative and user pivots. It replaces traditional static password vulnerabilities by dynamically assigning privileged group memberships only after successful MFA validation. This architecture natively mitigates Pass-the-Hash (PtH) and credential harvesting attacks within Windows ecosystems without requiring complex federation.
Authomize provides an AI-native Identity Governance and Administration (IGA) platform focused on continuous discovery, mapping, and governance of human and machine identities across cloud and on-premises environments. It delivers real-time visibility into permissions, entitlements, and access risks, automating remediation through policy enforcement and self-service workflows. Best suited for enterprises with complex multi-cloud infrastructures seeking to mitigate identity-based threats without disrupting operations. Authomize positions itself as a modern alternative to legacy IGA, emphasizing agentless integration and ML-driven risk prioritization for mid-to-large organizations.
We build security and governance for AI agents running on desktops.
Avanan is an email security product now sold under Check Point’s Harmony Email Security line, focused on protecting Microsoft 365 and adjacent collaboration channels from phishing, business email compromise, malware, ransomware, and data leakage. It deploys as a cloud app with no MX-record change and is positioned for organizations that want inline and post-delivery controls without replacing their existing mail stack. Its main fit is for Microsoft 365 customers that need layered protection beyond native filtering, including account-compromise and data-loss controls.
AvePoint is the unifying Trust Layer for AI. AvePoint enables more than 28,000 organizations and 6,000 channel partners to protect, secure, and govern their entire AI estate across data, infrastructure, AI and agents for Microsoft, Google, Salesforce, and other leading cloud environments, so that enterprises can deploy AI with confidence and scale innovation without scaling risk.
CyberHQ by Avertro is a cloud-native cyber resilience platform that unifies governance, risk, and compliance into a single, operationally integrated system. It replaces fragmented spreadsheets and siloed workflows with dynamic modules spanning risk registers, capabilities assessments, threat modelling, issue tracking, and board-ready reporting. Its multi-workspace architecture lets organisations manage risk locally while maintaining enterprise-wide visibility from a single pane of glass
AWS Key Management Service (AWS KMS) is AWS’s managed encryption key service for creating, storing, and controlling cryptographic keys used to protect data in AWS workloads and applications. It is positioned for organizations that want key lifecycle control without running their own HSM fleet, and it uses FIPS 140-3 Level 3 validated HSMs under the service boundary. Buyers typically use it for envelope encryption, application signing, and server-side encryption across AWS services. It is best suited to teams standardizing key governance inside AWS rather than managing separate on-premises key systems.
ConnectWise powers IT businesses by simplifying operations, enhancing experiences, and driving growth. Trusted by the most global IT solution providers, we set the standard for innovation and service delivery.
Axis Security provides HPE Aruba Networking SSE, a cloud-native security platform integrating Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), and Cloud Access Security Broker (CASB) with SD-WAN for unified SASE. Acquired by HPE Aruba, it delivers consistent Zero Trust policies across remote users, branches, and data centers via local edge virtual machines that broker traffic to private apps without cloud backhaul. Best for enterprises seeking SSE as a SASE stepping stone, with features like SSL inspection, sandboxing, and AI-driven reputation blocking for malware and risky sites.
Ensure security-relevant data is available, accessible, and affordable to SecOps.
Axonius is a Cybersecurity Asset Management Platform that aggregates device data from NAC, firewalls, vulnerability scanners, EDR, SIEM, MDM, and other security tools to provide unified visibility across IT, OT, IoT, and medical devices. The platform correlates data from siloed systems to enable automated discovery, policy enforcement, and remediation. Positioned for enterprises requiring comprehensive asset inventory and compliance across heterogeneous environments, with specialized support for healthcare organizations.
Axur focuses on External Threat Protection (ETP) and brand protection by monitoring the digital landscape for brand abuse, data leaks, and fraudulent activities. The platform automates the detection and takedown of phishing sites, unauthorized apps, and leaked credentials across the deep, dark, and open web. It complements internal security controls by mitigating risks that originate outside the traditional network perimeter.
Since 1995, BACKLINE has been providing professional musicians, bands and studios with top quality equipment rentals. More than just a rental company, we are a full-service backline company. Our technicians will deliver, set up and strike the equipment, leaving the musician with only one job: plug in and play.
Backline is an agentic security platform, built for Autonomous Exposure Remediation, Gartner's newly named category for fixing vulnerabilities, not just finding them. It ingests multi-scanner findings and delivers verified, production-ready fixes – closing the gap between detection and resolution safely, reliably, and at scale. Built by veteran enterprise security founders.
The Security Platform for The New Agentic AI Fabric.
Barndoor is one platform for AI access, safety, and control.