All use cases
    Use case

    AppSec (SAST/DAST/SCA)

    Find vulnerabilities in code before it ships.

    Why this fits, Static, dynamic and software composition analysis: the AppSec core.

    74 vendors for this

    Burgus Security logo
    Burgus Security
    Application Security (DAST/SAST)
    2 products

    I could not verify that a distinct vendor named Burgus Security has a documented Application Security product from the provided results. The only application-security-related result tied to the name is a directory-style entry that appears to refer to general application security services rather than a clearly described vendor platform. Based on the evidence available, Burgus Security cannot be reliably profiled as an AppSec product vendor, so the safest characterization is that its AppSec positioning is unconfirmed. If the intent was a different vendor name, the profile should be rebuilt from source documentation for that vendor.

    Inspects LLM API traffic in production to enforce security checkpoints on prompts, responses, and agent-to-model exchanges for agentic applications.
    Heeler logo
    Heeler
    Static Application Security Testing (SAST)
    1 product

    Heeler is an application security vendor focused on SAST-centric code analysis and remediation workflows, with product messaging that also spans adjacent AppSec functions such as secrets and open-source risk. In its SAST offering, Heeler emphasizes context-aware findings, runtime-aware prioritization, and validated fixes for developer teams that need to reduce alert noise and connect code issues to production behavior. It appears best suited for CISOs, AppSec, Product Security, and DevSecOps groups in cloud-native environments that want security findings tied to actual application context rather than static code-only results. The company also offers related AppSec posture and remediation capabilities beyond pure SAST/DAST.

    Context-aware SAST scanning+10
    Mobb logo
    Mobb
    Application Security Posture Management (ASPM)
    3 products

    Mobb is a code remediation product positioned around static application security testing workflows rather than a standalone scanner. It takes vulnerabilities detected by SAST tools such as OpenText Fortify and generates secure code fixes that can be pushed back into the codebase, helping teams reduce manual triage and remediation time. The product is best suited for development and AppSec teams already using SAST in CI/CD who want automated fix suggestions and pull-request-based workflows. Its documented role is complementary to SAST rather than replacing DAST or other testing layers.

    Transforms vulnerabilities detected by Fortify into concrete secure code fixes, reducing manual rewrite work after static analysis findings.Pushes suggested remediation changes back into the codebase with a one-click workflow, fitting pull-request and developer-review processes.
    Phoenix Security logo
    Phoenix Security
    Application Security Posture Management (ASPM)
    5 products

    Phoenix Security is an application security platform focused on finding and triaging code-level and runtime vulnerabilities across the software delivery lifecycle. In the DAST/SAST scope, it normalizes findings from source-code analysis, dynamic testing, and related appsec scanners into a single model, then uses runtime context to help prioritize remediation. Public materials also indicate support for air-gapped deployments and broader AppSec workflows, but the core value for buyers in this category is combining static and dynamic findings with remediation guidance. It is best suited for security teams and developers that need one place to correlate application vulnerability signals from multiple testing methods.

    Static application security testing for source code and compiled artifacts to identify issues such as injection flaws, unsafe input handling, and other OWASP Top 10-style defects before deployment.
    Qualys logo
    Qualys
    Vulnerability Management
    6 products

    Qualys provides Vulnerability Management, Detection and Response (VMDR), a cloud-based platform that automatically discovers assets across on-premises, cloud, and mobile environments, including unmanaged devices. It scans for vulnerabilities using over 20,000 checks from its Vulnerability KnowledgeBase, correlates findings with threat intelligence and machine learning to prioritize risks on critical assets, and detects indicators of compromise. VMDR supports hybrid IT scanning from a single console, generates role-based reports for compliance, and integrates with ticketing systems for automated remediation workflows. Best for enterprises needing continuous visibility and prioritization in complex, distributed networks.

    Continuous vulnerability scanning+10
    Raven logo
    Raven
    Application Security Posture Management (ASPM)
    6 products

    Raven.io provides a runtime application security platform that runs inside cloud-deployed applications to detect and block malicious code execution as it happens, independent of whether a CVE exists. The platform includes application detection and response for forensic visibility down to libraries, functions and call paths, a runtime software composition analysis capability that uses reachability data to de-prioritize vulnerabilities, and a module for discovering and controlling AI agents operating inside application environments. It is aimed at enterprises running internet-facing applications on Kubernetes, containers and compute instances across AWS, GCP and Azure, supporting languages including Java, Python, JavaScript, Go, Ruby, PHP, C++ and .NET. Customers include organizations in regulated industries such as insurance and financial services.

    Runtime exploit prevention+5