Dynamic application security testing
Testing of running web applications and APIs by sending crafted requests and observing responses.
9 vendors · alphabetical, never ranked
- 42Crunch42Crunch sells an API security platform that tests APIs against their contract before they reach production, protects them at runtime, and extends the same approach to the MCP servers that AI agents call and expose.Ownership not established
- Black DuckBlack Duck sells a portfolio of application security testing tools covering software composition analysis, static analysis, dynamic testing, and checks aimed at AI-generated code.Owned by Clearlake Capital Group and Francisco Partners since 2024
- CheckmarxCheckmarx sells an application security platform combining static and dynamic testing, software composition analysis, secrets detection, and infrastructure-as-code scanning, with a posture-management layer that unifies findings across the tools.Owned by Hellman & Friedman since 2020
- Contrast SecurityContrast Security sells a runtime application security platform that instruments applications from within to observe method calls, requests, and attack paths as they run in production, aiming to report only verified, exploitable vulnerabilities with a fix attached and to block known-CVE exploitation in real time.Ownership not established
- DetectifyDetectify sells an application security platform that tests an organization's external attack surface, drawing on vulnerability data contributed by ethical hackers.Owned by Insight Partners since 2024 · primary category
- EscapeEscape sells an offensive security platform that combines business-logic-aware dynamic application security testing, AI-driven penetration testing, and external network pentesting, originally built around API security.Privately held
- InvictiInvicti sells an application security platform built around dynamic testing of running web applications and APIs, extended with static analysis, open-source dependency scanning, infrastructure-as-code checks, and secrets detection.Ownership not established · primary category
- StackHawkStackHawk sells a dynamic application and API security testing platform that runs tests against an organization's running applications, integrating into coding-agent workflows to surface exploitable vulnerabilities and verify fixes before code merges.Ownership not established · primary category
- VeracodeVeracode sells an application security platform covering static and dynamic testing, software composition analysis, and container and infrastructure-as-code scanning.Owned by Thoma Bravo since 2019
No vendor pays to be listed or to change what we write. Descriptions are ours, drawn from each company's own site and filings. Corrections: /corrections.