Skip to main content

Vendor Directory

Explore application security and software supply chain vendors.

Akeyless Security logo

Akeyless Security

Secure your secrets, simplify your workflows

Akeyless offers a modern secrets management platform designed for teams using DevOps, hybrid cloud, and AI workloads. It centralizes and secures static, dynamic, and short-lived secrets, API tokens, and certificates across CI/CD pipelines, eliminating the need for vault management. The solution utilizes Distributed Fragments Cryptography (DFC) to ensure encryption keys are mathematically split across regions and providers, providing users with full control. Akeyless supports automated rotation and just-in-time access, integrating seamlessly with IDEs and cloud environments. This approach enhances security, compliance, and operational efficiency, helping teams mitigate risks associated with secrets sprawl.

Secrets Management & Scanning
View Profile >
Accessibility.com logo

Accessibility.com

Empowering digital accessibility for businesses

Accessibility.com was born out of necessity. A strong core of professionals with nearly a century of combined experience in the digital accessibility space recognized the need for tangible and practical guidance to drive digital inclusion and compliance. We're excited to work toward our vision and thank you for your support.

API Security Testing
View Profile >
Akto.io logo

Akto.io

Secure Your AI, Safeguard Your Future

Akto provides a dedicated AI security solution that focuses on securing MCPs (Managed Control Points) and AI agents. The platform offers real-time discovery, security testing, red teaming, and agentic posture management. Recognized by Gartner™ for its innovative approach, Akto allows teams to comprehensively discover, test, and protect all their APIs effectively. As a response to the evolving landscape of cybersecurity challenges, it delivers advanced security features aligned with modern AI security demands, ensuring that organizations can maximize their security posture.

DAST
View Profile >
ARMUR logo

ARMUR

Secure your code, safeguard your future

Armur AI offers advanced code vulnerability scanning, specializing in Static Application Security Testing (SAST) and smart contract auditing using LLM agents. The platform supports multiple programming languages including GO, Rust, JavaScript, and Python, enabling thorough static code analysis to identify vulnerabilities early in the development process. Additionally, Armur provides tools for auditing Solidity smart contracts and other blockchain contracts, ensuring robust security measures for decentralized applications. With features like Dynamic Application Security Testing (DAST) and Vulnerability Assessment and Penetration Testing (VAPT), Armur empowers developers and security professionals to secure their code effectively before deployment.

API Security Testing
View Profile >
AmbiSure Technologies Pvt. Ltd. || Let's Secure IT logo

AmbiSure Technologies Pvt. Ltd. || Let's Secure IT

Secure your business, protect your future

AmbiSure Technologies Pvt Ltd. presents itself as a dynamic next‑generation cyber security solution provider focused on "helping organizations run their businesses securely." The site references dynamic application security testing (DAST) and promotes "automated and orchestrated scans" and "dynamic analysis at scale," with a mention of Web‑Inspect. Contact details include [email protected] and office addresses in Mumbai and Surat. Messaging emphasizes cyber security solutions and protection of digital assets. The available content on the site is concise and service‑oriented, positioning AmbiSure as a vendor that delivers application security testing and related cyber security services to organizations.

DAST
View Profile >
APIsec logo

APIsec

Uncover API vulnerabilities with unmatched precision

APIsec is your AI-powered partner for API security, designed to find real vulnerabilities through advanced testing tools. The platform automatically maps your API endpoints and employs thousands of AI-powered attack simulations to identify logic flaws and data exposures with speed and accuracy unrivaled by traditional methods. With no false positives, APIsec provides actionable insights and expert guidance, ensuring continuous protection and monitoring of your APIs. Ideal for organizations needing robust API security solutions, APIsec enables users to create a free account and quickly perform initial scans without the need for credit card details.

SCA
View Profile >
Corgea logo

Corgea

Code securely, ship confidently with Corgea

Corgea is an AI-native security platform designed to automatically find, triage, and fix insecure code. The solution offers capabilities to scan every line of code for vulnerabilities, including business logic flaws, broken authentication and authorization, and IDORs (Insecure Direct Object References). Corgea simplifies the development process, allowing organizations to ship code securely without vulnerabilities, and promotes productivity by automating various security operations, making it ideal for businesses of all sizes.

SAST
View Profile >
Fluid Attacks logo

Fluid Attacks

Secure your code, safeguard your future

Fluid Attacks offers a platform that integrates AI and expert pentesters to support companies in securing their software development lifecycle (SDLC). The platform enables teams to identify, prioritize, verify, and remediate security vulnerabilities throughout the entire SDLC. It provides a unified view of results from Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Cloud Security Posture Management (CSPM), Security Code Review (SCR), and Penetration Testing as a Service (PTaaS). This comprehensive approach ensures that development teams can proactively manage risk exposure while delivering secure software.

SAST
View Profile >
Code Intelligence logo

Code Intelligence

Uncovering hidden vulnerabilities with AI precision

Code Intelligence offers AI-automated fuzz testing that enables organizations to find bugs and vulnerabilities missed by other security tools. The solution is designed for embedded software to detect critical issues by thoroughly testing code with minimal developer and security team effort. By exposing software to unexpected or random inputs, fuzz testing uncovers hidden bugs and flaws that may lead to crashes or security breaches. With a single command, users can ensure software stability and security, making it an essential tool for compliance and security-focused organizations.

SAST
View Profile >
Cloud Destinations logo

Cloud Destinations

Transforming visions into cloud realities

Cloud Destinations, a Silicon Valley IT leader, provides comprehensive solutions for digital transformation and cloud computing. As an official AWS Select Tier Services Partner, they specialize in full-lifecycle AWS solutions tailored for various industries. Their services include cloud consulting, automation-first DevOps, and real-time analytics leveraging AWS-native tools. With a strong focus on security, they deliver AWS environments designed for compliance and operational efficiency. Their certified teams implement AWS best practices, ensuring businesses can unlock measurable value from the cloud and drive impactful change.

SAST
View Profile >
Terrateam logo

Terrateam

Infrastructure orchestration, redefined for GitOps

Terrateam is a GitOps-native infrastructure orchestration platform that lets teams run Terraform in pull requests and automate plans, policy checks, and applies using GitOps workflows. It works with Terraform, OpenTofu, CDKTF, Pulumi, and Terragrunt, and surfaces cloud cost estimates in pull requests before changes are deployed. Terrateam emphasizes security and compliance with fine-grained access control and policy override approvals for exceptions. The product is described as open source, privacy-focused, and runnable in CI pipelines. Terrateam advertises a generous free tier with unlimited runs and private runners and offers help designing infrastructure architecture, implementing GitOps workflows, and optimizing Terraform setups.

CI/CD Security
View Profile >
Lineaje Inc logo

Lineaje Inc

Secure your software supply chain with confidence

Lineaje offers full-lifecycle software supply chain security, ensuring safety, compliance, and risk management through AI-powered solutions. The platform allows for high-integrity sourcing of open-source packages and images while unifying scanners to provide deeper contextual analysis at every stage of the software development lifecycle. By managing the entire SBOM lifecycle, Lineaje assists organizations in achieving continuous compliance and operational efficiency, especially for those selling to federal government entities. Their agentic AI continuously identifies and mitigates risks, streamlining the process of compliance verification and vendor communication.

SBOM Management
View Profile >
PT Intersoft Integrasi Infotama (i3) logo

PT Intersoft Integrasi Infotama (i3)

Uncover vulnerabilities, fortify your digital landscape

PT Intersoft Integrasi Infotama offers innovative information technology consultancy services, focusing on security solutions for client needs. Their Acunetix product is recognized as a high-quality DAST tool, effectively operating in both physical and virtual environments. The company aims to enhance client performance through reliable consultancy, enabling organizations to identify vulnerabilities in their web applications. Acunetix integrates seamlessly with existing systems, helping businesses achieve optimal security for their online platforms.

DAST
View Profile >
Finite State logo

Finite State

Secure your devices with precision insights

Finite State positions itself as a product cybersecurity platform for connected devices and embedded systems. The platform uncovers vulnerabilities in source code, binaries, and third-party components and consolidates risks into a unified view across a product portfolio. Finite State says it can dissect source code or binaries with precision to reduce false positives and help teams prioritize and fix issues, and it offers CI/CD integrations and automatic PRs for remediation workflows. The company highlights compliance-readiness, the ability to generate reports to meet regulatory compliance requirements, and notes it is SOC 2 Type 2 certified. The site also references recorded demos and access to expertise from former U.S. government officials.

SBOM Management
View Profile >
Scribe Security - E2E Software Supply Chain Security logo

Scribe Security - E2E Software Supply Chain Security

Building Trust Through Secure Code Insights

Scribe Security provides an end-to-end software supply chain security platform that automates evidence collection, signing, and verification across the build process. It integrates collectors with CI/CD to generate SBOMs and provenance records, gather scanner results, pipeline posture, and process context, cryptographically sign evidence, create attestations, and build lineage trees. Collected evidence (never the code itself) is encrypted and transferred to the cloud where it is parsed, correlated, and connected into a knowledge graph to create a signed, tamper‑proof audit trail for every build. AI‑agentic workflows perform analysis, prioritization, and auto-remediation. Customers can manage risk, deploy policy gates, track performance, and operate from the ScribeHub dashboard to maintain software trust and compliance.

SBOM Management
View Profile >
passbolt logo

passbolt

Collaborative security for modern teams

Passbolt is an open-source password and secret management solution designed for teams. It enables organizations to manage and share passwords securely and is described as a collaborative password manager that reduces IT workload while protecting password collaboration. The site highlights that "universities worldwide rely on Passbolt" and includes a customer quote about improved credential storage, productivity and operational security after transitioning to Passbolt. The product is presented as open-source and audited, built for teams that need collaboration, compliance and control. Mentioned capabilities include secure and immediate password sharing among users and machine credentials, multi-layered protection, and streamlined secure password sharing to enhance operational efficiency.

Secrets Management & Scanning
View Profile >
hoop.dev logo

hoop.dev

Automated Security for Seamless Development Workflows

hoop.dev presents an offering described as Automated Access with Data Protection and references HoopAI in the context of AI audit readiness and AI compliance. The site highlights SBOM-related ideas — noting that SBOM updates on every build and that modern SBOM tools are embedded in the build process. Messaging targets developer security (DevExSec) with a webinar titled “DevExSec - Secure Access that Boosts DevEx,” and offers a whitepaper download. The site includes commercial calls-to-action and pricing language ("Pricing Let's Talk" / "START NOW AND EXPERIENCE THE DIFFERENCE"), indicating a productized, contact-sales offering rather than purely informational content.

SBOM Management
View Profile >
QA Camp logo

QA Camp

Test with precision, release with confidence

QA CAMP specializes in comprehensive software testing services, including SAST and DAST, to deliver high-quality applications that meet user expectations. With a focus on functional, performance, and API testing, our goal is to ensure reliability and security across different platforms. Our automated testing utilizes advanced frameworks, enhancing efficiency and effectiveness in identifying issues early. We emphasize accessibility testing based on key standards, ensuring inclusivity for diverse user needs. Our commitment to superior quality and communication aids in driving positive project outcomes, equipping teams to navigate complex QA challenges effectively.

SAST
View Profile >
Digital.ai logo

Digital.ai

Transforming software delivery with intelligent security insights

Digital.ai describes an AI-powered software delivery / DevSecOps platform that unifies, secures, and generates predictive insights across the software lifecycle. Product content lists Analytics & Intelligence, Enterprise Agile Planning, Application Protection & Security, Continuous Testing, Mobile and Desktop App Hardening, Enterprise Release Orchestration & Application Packaging, DORA metrics & predictive ML, portfolio & agile planning, and application lifecycle management. The site also references mobile & web app testing on real and virtual devices and mentions a FedRAMP solution in press materials. The record presents a product-focused platform offering multiple security and testing capabilities across development and delivery pipelines.

DAST
View Profile >
Medcrypt logo

Medcrypt

Secure your path to FDA approval

MedCrypt provides FDA-focused medical device cybersecurity products and services for manufacturers preparing regulatory submissions. Their platform offers medical device SBOM vulnerability management with AI-driven risk prioritization, automated compliance reporting, and bulk remediation. They also offer regulatory strategy, penetration testing, threat modeling, PKI and certificate management, and process optimization to prepare for 510(k) or PMA submissions and EU/Health Canada filings. Capabilities listed include integrating and analyzing the software supply chain to identify and mitigate vulnerabilities, encrypting data, device management, incident response, automated cryptographic provisioning, and benchmarking product security posture with risk quantification. The company positions its Guardian & Helm platforms to accelerate FDA readiness and claims zero FDA rejections to date.

SBOM Management
View Profile >
Showing 1-20 of 150 vendors
Page 1 of 8