All use cases
    Use case

    Network edge & segmentation

    Firewall, segment and gate the network.

    Why this fits, Next-gen firewalls, network access control and microsegmentation.

    62 vendors for this

    Aruba ClearPass logo
    Aruba ClearPass
    Network Access Control (NAC)
    1 product

    HPE Aruba Networking ClearPass Policy Manager is an on-premises Network Access Control (NAC) platform providing role- and device-based secure access across multi-vendor wired, wireless, and VPN infrastructures. It delivers device profiling via DHCP and TCP fingerprinting, posture assessment through OnGuard persistent and dissolvable agents, guest management with self-service portals, and automated enforcement using RADIUS, TACACS+, and OnConnect. ClearPass supports Zero Trust with real-time visibility, integrates with 150+ third-party systems including SIEM and MDM, and serves over 10,000 customers in healthcare, finance, education, and government for compliance and IoT security.

    Device profiling and endpoint classificationIdentity-based policy enforcement+10
    Cequence Security logo
    Cequence Security
    API Security
    4 products

    Cequence Security sells API Security as part of its Unified API Protection platform, focusing on runtime discovery, inventory, compliance checks, and attack detection for internal, external, third-party, managed, unmanaged, shadow, and zombie APIs. It integrates with API gateways and reverse proxies to inspect live traffic and evaluate API usage and risk without adding client-side instrumentation. The product is best suited for enterprises that need continuous API attack-surface visibility and runtime protection across SaaS, on-premises, or hybrid environments. Cequence also offers adjacent bot management and WAAP capabilities, but its API Security scope centers on discovery, conformance, and blocking API abuse.

    Complete API visibility and monitoring+10
    Extreme Networks ExtremeControl logo
    Extreme Networks ExtremeControl
    Network Access Control (NAC)
    3 products

    Extreme Networks ExtremeControl is a centralized Network Access Control (NAC) solution that enforces role-based access policies for wired, wireless LAN, and VPN users across multi-vendor switches and access points. It integrates authentication via 802.1X, Web-based, Kerberos, and RADIUS; vulnerability assessment for security posture checks; and location services to authorize endpoints. ExtremeControl engines detect devices by MAC/IP addresses, assign VLANs or policy roles on Extreme switches, support RFC 3580 quarantine, IPv6, Microsoft NAP, and TNC interoperability. Best for enterprises with Extreme Networks infrastructure seeking BYOD, IoT, and granular post-connect enforcement with assisted remediation.

    Pre-connect and post-connect access control+11
    Forescout logo
    Forescout
    IoT Security
    3 products

    Forescout’s IoT Security offering is an agentless device visibility and control platform for unmanaged IoT, OT, and IoMT environments. It identifies devices as they connect, classifies them by type and function, detects weak or factory-default credentials, monitors communications for anomalous behavior, and automates policy actions such as segmentation, quarantine, and least-privilege network access. The product is best suited for enterprises that need passive discovery and enforcement across mixed IT/OT networks, including healthcare, manufacturing, building automation, and critical infrastructure. Forescout also offers adjacent OT and network access control capabilities, but the IoT Security scope centers on device visibility, classification, and containment.

    Real-time device visibility+11
    Huskeys logo
    Huskeys
    Firewall / NGFW
    1 product

    Huskeys is an edge security management platform for organizations running multi-cloud and multi-WAF environments. It applies an AI-driven, agentic layer across CDN, WAF, and edge infrastructure to unify configuration, rule, and policy management across otherwise disconnected security tools. The platform gathers signals from existing WAFs, enriches them with environmental context, and analyzes traffic behavior, business logic, and risk to continuously adapt rules and policies. It is deployed as a cloud-based control plane layered on top of a customer's existing WAF and CDN providers rather than replacing them, with integration designed to take hours rather than weeks. The product targets security teams managing heterogeneous, multi-vendor edge security stacks who need centralized visibility and orchestration without migrating away from current tools.

    Multi-WAF control plane+5
    R
    Radware AppWall
    API Security
    2 products

    Radware AppWall is Radware’s web application and API protection offering, positioned around positive security policy enforcement for HTTP-based services. In the API security scope, it protects REST, GraphQL, and SOAP endpoints with auto-generated policies, request validation, and attack blocking for abuse, injection, authentication bypass, and data theft attempts. It is best suited for enterprises that already use Radware application delivery infrastructure or need API protection tied to WAF policy enforcement rather than a standalone API gateway. The product is also used in environments with PCI-driven web application security requirements.

    Applies positive security model enforcement to API traffic, allowing only known-good request patterns and blocking anomalous calls that do not match the learned schema or policy.
    Skyhigh Security CASB logo
    Skyhigh Security CASB
    CASB (Cloud Access Security Broker)
    8 products

    Skyhigh Security CASB is a cloud-based, multi-tenant Cloud Access Security Broker that deploys via forward and reverse proxy modes for real-time control over sanctioned and unsanctioned cloud services. It leverages the Cloud Registry for 50+ attribute risk assessments across 20,000+ services, enabling discovery, classification, and remediation. Key capabilities include DLP policy enforcement synced with endpoint DLP, machine learning-based UEBA for insider threat detection, malware analysis, configuration auditing against benchmarks with automated remediation, and contextual access controls. Best suited for enterprises needing comprehensive visibility and governance across hybrid cloud environments with SharePoint integration.

    Discover unsanctioned cloud services+11
    TrueFort logo
    TrueFort
    Microsegmentation
    1 product

    TrueFort is a workload protection and microsegmentation vendor focused on blocking lateral movement across hybrid environments. Its platform builds behavioral baselines from workload telemetry, then generates segmentation policies and pushes enforcement to host firewalls or supported workload agents. The product is aimed at enterprises running mixed Windows, Linux, virtualized, container, Kubernetes, on-premises, and cloud workloads that need application-level segmentation without relying only on network-based controls. TrueFort is positioned as a specialist in zero-trust segmentation and runtime workload protection, with an emphasis on application behavior visibility, policy automation, and containment of ransomware, compromised credentials, and insider threats.

    Workload behavior baselining+10