Static application security testing
Analysis of source code, bytecode and infrastructure-as-code for security flaws without running the application.
8 vendors · alphabetical, never ranked
- Black DuckBlack Duck sells a portfolio of application security testing tools covering software composition analysis, static analysis, dynamic testing, and checks aimed at AI-generated code.Owned by Clearlake Capital Group and Francisco Partners since 2024
- CheckmarxCheckmarx sells an application security platform combining static and dynamic testing, software composition analysis, secrets detection, and infrastructure-as-code scanning, with a posture-management layer that unifies findings across the tools.Owned by Hellman & Friedman since 2020 · primary category
- CycodeCycode sells an application security platform that combines testing, software supply chain security, and posture management, using deterministic and AI scanning engines to correlate findings from code to runtime.Ownership not established
- Data TheoremData Theorem sells a set of application security products covering API discovery and runtime protection, code testing (SAST, SCA and SBOM management), cloud-native application testing, and mobile app testing and runtime protection.Ownership not established
- InvictiInvicti sells an application security platform built around dynamic testing of running web applications and APIs, extended with static analysis, open-source dependency scanning, infrastructure-as-code checks, and secrets detection.Ownership not established
- SemgrepSemgrep sells static analysis software that scans source code for security issues, along with tools for open-source dependency and secrets scanning and an AI-assisted layer for detection and remediation.Privately held · primary category
- SnykSnyk sells a platform for application security that combines static code analysis, open-source dependency scanning, container and infrastructure-as-code checks, and secrets detection engines, alongside newer tools aimed at code generated by AI assistants and autonomous coding agents.Ownership not established
- VeracodeVeracode sells an application security platform covering static and dynamic testing, software composition analysis, and container and infrastructure-as-code scanning.Owned by Thoma Bravo since 2019 · primary category
No vendor pays to be listed or to change what we write. Descriptions are ours, drawn from each company's own site and filings. Corrections: /corrections.