Vendor Directory
Explore application security and software supply chain vendors.

APIsec
Uncover API vulnerabilities with unmatched precision
APIsec is your AI-powered partner for API security, designed to find real vulnerabilities through advanced testing tools. The platform automatically maps your API endpoints and employs thousands of AI-powered attack simulations to identify logic flaws and data exposures with speed and accuracy unrivaled by traditional methods. With no false positives, APIsec provides actionable insights and expert guidance, ensuring continuous protection and monitoring of your APIs. Ideal for organizations needing robust API security solutions, APIsec enables users to create a free account and quickly perform initial scans without the need for credit card details.

Akto.io
Secure Your AI, Safeguard Your Future
Akto provides a dedicated AI security solution that focuses on securing MCPs (Managed Control Points) and AI agents. The platform offers real-time discovery, security testing, red teaming, and agentic posture management. Recognized by Gartner™ for its innovative approach, Akto allows teams to comprehensively discover, test, and protect all their APIs effectively. As a response to the evolving landscape of cybersecurity challenges, it delivers advanced security features aligned with modern AI security demands, ensuring that organizations can maximize their security posture.

AmbiSure Technologies Pvt. Ltd. || Let's Secure IT
Secure your business, protect your future
AmbiSure Technologies Pvt Ltd. presents itself as a dynamic next‑generation cyber security solution provider focused on "helping organizations run their businesses securely." The site references dynamic application security testing (DAST) and promotes "automated and orchestrated scans" and "dynamic analysis at scale," with a mention of Web‑Inspect. Contact details include [email protected] and office addresses in Mumbai and Surat. Messaging emphasizes cyber security solutions and protection of digital assets. The available content on the site is concise and service‑oriented, positioning AmbiSure as a vendor that delivers application security testing and related cyber security services to organizations.

ARMUR
Secure your code, safeguard your future
Armur AI offers advanced code vulnerability scanning, specializing in Static Application Security Testing (SAST) and smart contract auditing using LLM agents. The platform supports multiple programming languages including GO, Rust, JavaScript, and Python, enabling thorough static code analysis to identify vulnerabilities early in the development process. Additionally, Armur provides tools for auditing Solidity smart contracts and other blockchain contracts, ensuring robust security measures for decentralized applications. With features like Dynamic Application Security Testing (DAST) and Vulnerability Assessment and Penetration Testing (VAPT), Armur empowers developers and security professionals to secure their code effectively before deployment.

Akeyless Security
Secure your secrets, simplify your workflows
Akeyless offers a modern secrets management platform designed for teams using DevOps, hybrid cloud, and AI workloads. It centralizes and secures static, dynamic, and short-lived secrets, API tokens, and certificates across CI/CD pipelines, eliminating the need for vault management. The solution utilizes Distributed Fragments Cryptography (DFC) to ensure encryption keys are mathematically split across regions and providers, providing users with full control. Akeyless supports automated rotation and just-in-time access, integrating seamlessly with IDEs and cloud environments. This approach enhances security, compliance, and operational efficiency, helping teams mitigate risks associated with secrets sprawl.

Accessibility.com
Empowering digital accessibility for businesses
Accessibility.com was born out of necessity. A strong core of professionals with nearly a century of combined experience in the digital accessibility space recognized the need for tangible and practical guidance to drive digital inclusion and compliance. We're excited to work toward our vision and thank you for your support.

PortSwigger
Secure your applications, safeguard your future
PortSwigger is dedicated to web security by offering tools like Burp Suite, an enterprise-enabled dynamic web vulnerability scanner. Their software helps identify if web applications are vulnerable to attacks. By integrating security into Software Development Life Cycles (SDLCs), it assists organizations in conducting efficient penetration testing and maintaining cyber resilience. With the ability to automate recurring scans and provide intuitive reporting, PortSwigger empowers security professionals to better protect their organizations.

Infisical
Secure your secrets, simplify your systems
Infisical is an all-in-one platform designed for securely managing application secrets, certificates, SSH keys, and configurations across teams and infrastructures. It serves a wide range of users, from Fortune 500 enterprises to international governments and rapidly growing startups, enhancing both security and operational efficiency. Infisical guarantees a service level of 99.99% uptime for its cloud services, ensuring reliable access for its users. By automating the management of secrets and configurations, Infisical aims to save time while boosting security for its clients.

Scribe Security - E2E Software Supply Chain Security
Building Trust Through Secure Code Insights
Scribe Security provides an end-to-end software supply chain security platform that automates evidence collection, signing, and verification across the build process. It integrates collectors with CI/CD to generate SBOMs and provenance records, gather scanner results, pipeline posture, and process context, cryptographically sign evidence, create attestations, and build lineage trees. Collected evidence (never the code itself) is encrypted and transferred to the cloud where it is parsed, correlated, and connected into a knowledge graph to create a signed, tamper‑proof audit trail for every build. AI‑agentic workflows perform analysis, prioritization, and auto-remediation. Customers can manage risk, deploy policy gates, track performance, and operate from the ScribeHub dashboard to maintain software trust and compliance.

Spectralops.io - A Check Point Solution
Build Fast, Secure Smart with Spectral
Spectral is a software composition analysis platform aimed at enabling teams to build and ship software faster while maintaining security. It allows for the continuous scanning and monitoring of known and unknown assets to prevent data breaches, mitigating secret leaks caused by poor credential hygiene. Integrated with leading CI systems, it provides automated issue detection during static builds. SpectralOps utilizes advanced AI technology to detect risks, manage hidden sensitive assets, and provide organizations with a dashboard for monitoring security. With over 2000 detectors, it offers extensive coverage to keep organizations safe from vulnerabilities.

Data Theorem, Inc.
Secure your applications, protect your users
Data Theorem is a leading provider in modern application security, specializing in Static Application Security Testing (SAST), Software Composition Analysis (SCA), and API security. Gartner ranks them #1 in Cloud Native Apps in the 2025 Critical Capabilities for Application Security Testing. They offer continuous discovery and inventory of mobile, web, APIs, and cloud assets, as well as automated hacking that includes SAST, DAST, IAST, and SCA. Their solutions help organizations discover, test, and protect all APIs, enhancing the security of applications for over 2.8 billion users, including seven of the largest banks.

Tola Capital
Secure your code, safeguard your future
Code Intelligence empowers developers to proactively detect and address vulnerabilities at every stage of the software lifecycle. Their automated application security testing platform focuses on fuzz testing, making it easy and accessible for developers to build secure applications. By integrating seamlessly with existing tools, Code Intelligence shapes the future of automated security through AI-driven solutions, helping developers identify and resolve vulnerabilities throughout the software lifecycle. With a strong emphasis on improving security, they support users in managing compliance effectively.

Cloudsmith
Secure your software supply chain effortlessly
Cloudsmith is a fully-managed, enterprise-scale solution for controlling, securing, and distributing software packages and containers. It provides supply chain security software with observability and governance, helping organizations protect their end users by mitigating compliance issues before they reach production systems. With a single, observable home for every package and container, Cloudsmith boosts productivity with global artifact distribution and powerful analytics. Streamline operations and drive innovation with integrated analytics, logging, and audit trail tools, making it the ideal platform for enterprises looking to enhance their software supply chain security.

Entro Security
Guarding Your Digital Frontiers with Precision
Entro describes itself as an enterprise security platform focused on AI agents and non-human identities (NHIs). The product claims to unify security for AI agents, NHIs and secrets by delivering visibility, ownership attribution, and real-time detection of anomalies. Entro’s site text highlights discovery and inventory capabilities — "Discover all AI agents, non-human identities & their secrets across your organization" — and states it can manage and secure the NHI lifecycle at scale. The record also references Vendor Privileged Access Management (VPAM) and emphasizes real-time monitoring and analysis to detect and mitigate threats related to secrets and non-human identities.

FOSSA
Secure your software supply chain with confidence
FOSSA offers a platform focused on software supply chain security, combining SCA, SBOM capabilities, and container security. The product scans direct and transitive dependencies to unlimited depth and identifies deep vulnerabilities in transitive dependencies. Built-in reachability analysis is used to eliminate common false positives, and the platform surfaces prioritized vulnerability fixes using a proprietary algorithm and proprietary vulnerability database. FOSSA positions itself as a consolidated solution for SCA, BCA, and container security that scales to thousands of developers and provides comprehensive reporting across SCA, BCA, and containers to support regulatory compliance. The platform is described as used by enterprise security teams and intended to consolidate security tooling.

Toradex
Crafting Tomorrow's Embedded Solutions Today
Toradex produces embedded computing hardware and accompanying software for Single Board Computers (SBCs), Computer on Modules (CoM) and System on Modules. The site emphasizes production-ready software, strong integration between hardware and software, and software support including Long Term Supported (LTS) production releases. Product lifecycle states (In Development, Sample Production, Volume Production, Last Time Buy, End-of-Life) and software release cadence are documented. A site page titled "SBOM Reports" and mention of a Hardware Security Module (HSM) appear in the record, indicating published supply-chain or security-related artifacts alongside their hardware and software offerings.

FossID
Secure your code, innovate with confidence
FossID provides robust Software Composition Analysis (SCA) solutions designed to enhance open-source software adoption while ensuring security and compliance. Our powerful SCA capabilities facilitate deep static analysis of your source code, helping to prevent intellectual property leakage. With flexible workflows and secure deployment options, FossID aids organizations in innovating responsibly. Our services are tailored to help clients fast-track their software security success. Ensure your software integrity and compliance with FossID's expertise.

Waratek
Automate security, protect your applications seamlessly
Waratek provides an enterprise Java security platform designed for application and API security. It automates the manual process of fixing code vulnerabilities, delivering a turnkey solution that helps secure both modern and legacy applications. With a focus on compliance, Waratek allows enterprises to scale security measures effectively and efficiently, ensuring protection against exploits while improving application performance. The platform integrates compliance processes, making it easier for organizations to meet regulatory standards such as the Sarbanes-Oxley Act (SOX). Experience robust security without the common pitfalls of traditional methods.

Arnica
Build Secure Code with Confidence Today
Arnica is a leading application security platform that specializes in enhancing code security, streamlining development processes, and ensuring compliance through automated tools. Its solutions include Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC) security, and Secrets scanning. Arnica enables users to build world-class security programs by providing easy access to Software Bill of Materials (SBOM) artifacts for proving software supply chain security and compliance. With its cutting-edge technology, Arnica positions itself as an essential partner for organizations seeking to strengthen their application security posture.

PT Intersoft Integrasi Infotama (i3)
Uncover vulnerabilities, fortify your digital landscape
PT Intersoft Integrasi Infotama offers innovative information technology consultancy services, focusing on security solutions for client needs. Their Acunetix product is recognized as a high-quality DAST tool, effectively operating in both physical and virtual environments. The company aims to enhance client performance through reliable consultancy, enabling organizations to identify vulnerabilities in their web applications. Acunetix integrates seamlessly with existing systems, helping businesses achieve optimal security for their online platforms.