Vendor directory
Security vendors
Which companies sell which kinds of security products, filed by category. Each vendor has one page, the same company page that carries its security-leadership record, listing what it sells, where it is based, when it was founded and who owns it, with the source for every fact.
No vendor pays to be listed or to change what we write. Corrections: /corrections.
This is a record, not a buyer's guide: vendors are listed alphabetically and never ranked, scored or recommended. A vendor appears under its primary category and up to three more. Categories are defined in our own words below each name.
259 vendors · 87 categories in 17 groups
Network security
Products that inspect, filter and control traffic moving across corporate networks and between users and the internet.
- Firewalls and NGFWHardware, virtual and cloud firewalls that enforce traffic policy by port, application, user and content.9 vendors
- SASE and SSECloud-delivered bundles of secure web gateway, cloud access security broker and private access services, with or without SD-WAN networking.9 vendors
- Zero trust network accessStandalone services that grant users access to specific private applications after checking identity and device, in place of a network-level VPN.6 vendors
- Network detection and responseTools that analyse network traffic and metadata to detect threats and support investigation and response.6 vendors
- MicrosegmentationSoftware that limits which workloads, devices and users can talk to each other inside a network to contain lateral movement.3 vendors
- Network access controlSystems that identify devices as they connect to wired and wireless networks and decide what each may reach.4 vendors
- DDoS protectionServices and appliances that absorb or filter distributed denial-of-service traffic before it overwhelms a target.4 vendors
- DNS securityProtective DNS resolvers and DNS infrastructure products that block malicious domains and protect name resolution.1 vendor
- Network visibility and traffic brokeringTaps, packet brokers and observability fabrics that deliver copies of network traffic to security and monitoring tools.3 vendors
Endpoint security
Products that protect laptops, servers, phones and the firmware underneath them.
- EDR and XDRAgents and platforms that record endpoint activity to detect, investigate and respond to attacks, extended in XDR to other telemetry sources.14 vendors
- Endpoint protection platformsAntivirus and prevention-focused agents that block known and unknown malware on endpoints.4 vendors
- Mobile securityThreat defence for smartphones and tablets, covering malicious apps, phishing, network attacks and device compromise.6 vendors
- Endpoint management and application controlTools that inventory, configure and patch endpoints, or restrict which applications and privileges may run on them.6 vendors
- Firmware and device supply chain securityProducts that verify and monitor firmware, hardware components and device integrity below the operating system.2 vendors
Identity security
Products that establish who or what is requesting access and govern what each identity may do.
- Workforce IAM and SSODirectories, single sign-on, multi-factor authentication and access policy for employees and contractors.5 vendors
- Privileged access managementVaulting, brokering and recording of administrator and other high-privilege access to systems.6 vendors
- Identity governance and administrationProvisioning, access requests, role management and periodic access reviews across applications.6 vendors
- Customer identity and access managementSign-up, login, consent and profile management for an organization's own customers.1 vendor
- Identity threat detection and responseMonitoring of identity systems such as Active Directory and identity providers to detect and stop identity-based attacks.8 vendors
- Passwordless authentication and authenticatorsHardware keys, device-bound credentials and phishing-resistant authenticators that replace or strengthen passwords.1 vendor
- Password and secrets vaults for peoplePassword managers that store and share credentials for individuals and teams.2 vendors
- Non-human identity securityDiscovery, governance and protection of service accounts, API keys, tokens and workload or AI agent identities.15 vendors
- Machine identity and PKICertificate authorities and certificate lifecycle management for TLS, code signing and device identity.5 vendors
Cloud security
Products that secure infrastructure, workloads and software-as-a-service applications running in public clouds.
- Cloud-native application protection (CNAPP)Platforms that combine posture, workload, identity and code-to-cloud risk analysis for cloud environments in one product.8 vendors
- Cloud security posture managementContinuous checks of cloud account configuration against security policy and compliance frameworks.1 vendor
- Cloud workload protectionRuntime protection for virtual machines, containers, Kubernetes and serverless functions.5 vendors
- Cloud identity entitlements (CIEM)Analysis and reduction of the permissions granted to human and machine identities in cloud platforms.3 vendors
- Cloud detection and responseDetection, investigation and response built on cloud control-plane logs and runtime signals.8 vendors
- SaaS security postureMonitoring of configuration, integrations, users and data exposure inside third-party SaaS applications.4 vendors
Application security
Products that find and fix weaknesses in software an organization builds, and protect that software in production.
- Static application security testingAnalysis of source code, bytecode and infrastructure-as-code for security flaws without running the application.8 vendors
- Dynamic application security testingTesting of running web applications and APIs by sending crafted requests and observing responses.9 vendors
- Software composition analysisIdentification of open-source and third-party components in software, with their known vulnerabilities and licences.7 vendors
- Application security posture managementAggregation, correlation and prioritisation of findings from many application security tools across the software lifecycle.3 vendors
- API securityDiscovery, testing and runtime protection of application programming interfaces.13 vendors
- Software supply chain securityProtection of build pipelines, artifacts, container images and package ecosystems against tampering and malicious components.8 vendors
- Secrets detectionScanning of code, repositories and collaboration tools for exposed credentials, keys and tokens.5 vendors
- WAF and WAAPWeb application firewalls and web application and API protection services that filter malicious requests to web properties.6 vendors
- Application shielding and RASPObfuscation and anti-tampering for mobile and desktop apps, and runtime self-protection instrumented into running applications.4 vendors
Data security and privacy
Products that find, classify, protect and govern sensitive data, and manage privacy obligations about it.
- Data loss preventionControls that detect and block sensitive data leaving through endpoints, email, web and cloud channels.14 vendors
- Data security posture managementDiscovery and classification of sensitive data across cloud and on-premises stores, with analysis of who can reach it.10 vendors
- Encryption, tokenization and key managementEncryption and tokenization of data, hardware security modules and systems that manage cryptographic keys.9 vendors
- Post-quantum cryptographyProducts that inventory cryptography and migrate it to algorithms designed to resist attack by quantum computers.5 vendors
- Privacy managementSoftware for consent, data subject requests, records of processing and other privacy-law obligations.8 vendors
Email and collaboration security
Products that protect email and workplace messaging from phishing, impersonation and malicious content.
- Email securityGateways and API-based services that filter phishing, malware, spam and business email compromise.16 vendors
- Email authentication and DMARCServices that deploy and monitor SPF, DKIM, DMARC and BIMI to stop others sending mail as an organization's domains.4 vendors
- Collaboration app securityThreat and data protection for messaging and file-sharing tools such as Slack, Teams and shared drives.4 vendors
Security operations
Products and services that collect security telemetry, detect threats, and run investigation and response.
- SIEMPlatforms that collect and correlate logs and events to detect threats and support investigation and compliance reporting.14 vendors
- SOAR and security automationWorkflow and playbook engines that automate security operations tasks across tools.8 vendors
- AI SOC analystsSoftware agents that triage, investigate and document security alerts with limited human input.15 vendors
- Security data lakes and pipelinesProducts that route, reduce and store security telemetry, often separately from where detection runs.7 vendors
- Threat intelligenceFeeds, platforms and research services about threat actors, infrastructure, malware and vulnerabilities being exploited.14 vendors
- MDR and managed SOCServices in which a provider's analysts monitor a customer's environment around the clock and respond to threats.17 vendors
- Incident response and forensicsBreach investigation and containment services, digital forensics tools, and platforms that coordinate incident response.8 vendors
- Deception technologyDecoys, honeypots and canary tokens that alert when an attacker touches them.0 vendors
Exposure management
Products and services that find, test and prioritise the weaknesses an attacker could use.
- Vulnerability managementScanning and assessment of systems for known vulnerabilities and misconfigurations, with tracking of remediation.1 vendor
- External attack surface managementContinuous discovery and monitoring of an organization's internet-facing assets from an outside-in view.12 vendors
- Cyber asset inventory (CAASM)Aggregation of asset data from existing tools to build an inventory and find coverage gaps.1 vendor
- Breach simulation and automated pen-testingPlatforms that safely emulate attacker techniques against live environments to validate whether controls work.8 vendors
- Exposure prioritisation and CTEMPlatforms that unify findings across scanners and apply context to decide which exposures to fix first, as part of a continuous programme.9 vendors
- Bug bounty and crowdsourced testingPlatforms that connect organizations with outside researchers who find and report vulnerabilities.2 vendors
- Digital risk protectionMonitoring of the open, deep and dark web and social platforms for brand abuse, leaked data and impersonation, with takedown services.4 vendors
OT, ICS and IoT security
Products that secure industrial control systems, medical devices and other connected equipment that cannot run standard agents.
- OT and ICS securityAsset visibility, threat detection and secure access for industrial control systems and operational technology networks.7 vendors
- IoT and medical device securityDiscovery, risk assessment and protection of connected devices such as medical, building and enterprise IoT equipment.6 vendors
- Unidirectional gateways and secure transferHardware and software that move data or files into and out of isolated networks under strict control.1 vendor
Governance, risk and compliance
Products that document controls, measure risk and prove compliance to auditors, regulators and customers.
- GRC and integrated risk platformsSystems of record for policies, risks, controls, audits and issues across an enterprise.5 vendors
- Compliance automationTools that connect to company systems to collect evidence and track readiness for frameworks such as SOC 2, ISO 27001 and FedRAMP.7 vendors
- Third-party risk and security ratingsAssessment and monitoring of suppliers' security, including questionnaires and outside-in security ratings.20 vendors
- Cyber risk quantificationModels that express cyber risk in financial terms for boards, insurers and investment decisions.2 vendors
Security awareness and human risk
Products that train people and measure and reduce the risk that comes from human behaviour.
- Security awareness trainingTraining content and phishing simulations that teach employees to recognise and report attacks.9 vendors
- Human risk managementPlatforms that combine behaviour data from security tools to measure each person's risk and intervene in real time.10 vendors
- Insider risk managementMonitoring of user activity to detect data theft, sabotage or policy violations by trusted insiders.4 vendors
Fraud and identity verification
Products that confirm people are who they claim to be and detect fraud and automated abuse.
- Identity verificationDocument, biometric and data checks that verify a person's identity at onboarding or account recovery.7 vendors
- Fraud preventionRisk scoring of transactions, accounts and sessions to detect payment fraud, account takeover and scams.12 vendors
- Bot and abuse managementDetection and blocking of automated traffic such as scrapers, credential stuffing and fake account creation.5 vendors
Browser security
Products that secure the web browser as the place where work and data access happen.
- Enterprise browsersBrowsers built for organizations, with security and management controls inside the browser itself.1 vendor
- Browser protection extensionsExtensions and agents that add threat, data and policy controls to existing consumer browsers.3 vendors
- Remote browser isolationServices that run web content away from the user's device and send only a safe rendering.1 vendor
AI security
Products that secure AI models, applications and agents, and govern how an organization uses AI.
- AI model and agent securityScanning, red-teaming and runtime monitoring of models, AI applications and autonomous agents for attacks and unsafe behaviour.27 vendors
- AI firewalls and guardrailsInline filters that inspect prompts, responses and tool calls of AI applications an organization builds.12 vendors
- Workforce AI usage securityDiscovery and control of employees' use of third-party AI tools, including data sent to them.11 vendors
- AI governanceInventory, policy, risk assessment and regulatory compliance tracking for AI systems.12 vendors
Backup and cyber resilience
Products that preserve data and systems so an organization can recover after an attack.
Consultancies and managed services
Firms that sell security expertise and operations as a service rather than as software.
- Managed security service providersProviders that run security technology for customers, such as firewalls, identity or monitoring, under a managed contract.8 vendors
- Security consulting and advisoryAssessment, architecture, programme and compliance advisory services, excluding incident response and penetration testing.6 vendors
- Penetration testing and red team servicesHuman-led testing engagements in which consultants attack an organization's systems to find weaknesses.6 vendors
- Security resellers and integratorsFirms that select, resell, deploy and integrate other vendors' security products.0 vendors
Missing a company, or filed in the wrong place? Tell the desk through corrections or tips. How we decide what to list: the network's rules.