Vertical

Security

AI-assisted tools for finding vulnerabilities, auditing dependencies, and enforcing compliance.

45 tools
AI-Audit
open-source

AI-native security auditing CLI for compliance reporting

Aikido Security
freemium

All-in-one AppSec platform with AI AutoFix for SAST, IaC, and secrets

Apiiro
paid

Agentic ASPM with deep code analysis and an AI guardian for generated code

Arnica
freemium

Real-time AppSec platform with hybrid deterministic and AI SAST

Backslash Security
paid

Reachability-based AppSec with AI-powered attack path remediation

Checkmarx
paid

Enterprise AppSec platform with agentic Assist agents for code, triage, and remediation

Checkmarx SCA
paid

Software composition analysis with agentic AI remediation

CodeAnt AI
freemium

AI code review, SAST, and pentesting with outcome-based pricing

CodeThreat
paid

Agentic SAST that builds a full architecture map of the application

Corgea
freemium

AI SAST that auto-fixes vulnerabilities via pull request

Cycode
paid

Agentic AppSec platform combining ASPM, SAST, and supply chain security

Debricked
freemium

Machine-learning software composition analysis for dependency security and license compliance

DeepSource
freemium

AI code review platform combining static analysis with LLM-powered Autofix for developers

DepsHub
freemium

AI-powered dependency management and automated updates

DryRun Security
freemium

AI-native SAST with contextual analysis of code, data flow, and architecture

Endor Labs
freemium

AI-native AppSec with full-stack reachability from code to container

GitHub Advanced Security
paid

Native GitHub code scanning, secret scanning, and Copilot Autofix

GitLab Application Security
paid

GitLab-native SAST, DAST, and AI vulnerability summaries via Duo

Lineaje
paid

Agentic AI for continuous software supply chain security and SBOM management

Mend
paid

Unified application and AI security platform with SCA, SAST, and AI-powered remediation

Mend.io
paid

AI-assisted application security platform combining SCA, SAST, and AI security

Mobb
freemium

AI-driven auto-remediation that fixes findings from existing SAST tools

NPMScan
freemium

Malicious npm package detection with AI-powered threat intelligence

OX Security
paid

Active ASPM platform with AI-driven prioritization from code to cloud

Panto AI
freemium

AI code review agent that analyzes pull requests for quality, security, and business context

Phylum
paid

Software supply chain risk analysis with ML-based malicious package detection

Pixee
freemium

Automated security remediation priced per vulnerability fixed

Plexicus
freemium

AI-powered ASPM and CNAPP with the Codex Remedium remediation agent

Qwiet AI
paid

AI SAST and SCA using a Code Property Graph and reachability analysis to find and fix flaws

Rafter
freemium

SaaS security platform that scans SAST, SCA, and secrets on every commit

Semgrep
open-source

Fast, open-source static analysis with semantic pattern matching and AI-assisted rules

Snyk
freemium

Developer-first security platform for finding and fixing open-source vulnerabilities

Socket
freemium

Supply chain security that blocks malicious dependencies at install time

Sonar
freemium

Code quality and SAST platform with AI CodeFix for bugs, vulnerabilities, and AI-written code

Sonar SCA
paid

SCA built into SonarQube with AI CodeFix for vulnerable dependencies

SonarQube
freemium

Code quality and SAST platform with AI Code Assurance and AI CodeFix

Sonatype Lifecycle
paid

Enterprise SCA with AI-generated upgrade pull requests

StepSecurity
freemium

Supply chain attack detection for GitHub Actions and OSS packages

TheAuditor
open-source

Offline security scanner built for AI-generated code

Trace-AI
freemium

Predictive supply-chain security using metadata analysis of dependencies and maintainers

Veracode
paid

Enterprise AppSec with Veracode Fix for AI-generated remediation

Vigolium
open-source

Open-source vulnerability scanner combining deterministic scanning with LLM-driven code auditing

Vulert
freemium

AI-driven SCA that monitors manifests without code access

Xygeni
paid

AI-powered AppSec covering SAST, supply chain, IaC, and secrets

ZeroPath
paid

AI-native SAST that converts findings into executable code fixes