{"name":"Cyber Tool Stack cybersecurity tools","description":"Structured tool profiles with taxonomy, fit, source URLs, and verification dates.","lastModified":"2026-08-12","recordCount":224,"records":[{"slug":"crowdstrike-falcon-insight","name":"Falcon Insight XDR","vendorSlug":"crowdstrike","productType":"software","openSource":false,"categorySlugs":["edr-xdr"],"capabilities":["behavioral-detection","threat-hunting","response-actions","xdr-correlation","managed-option"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Security teams that want a dedicated, cloud-operated EDR platform with room to add identity, cloud, and managed response modules.","keyAdvantage":"Real Time Response, Falcon telemetry, threat intelligence, and cross-domain Falcon modules share one agent and console.","tradeoff":"Many adjacent capabilities and the fully managed service are separate subscriptions, so the final package can extend well beyond the base EDR license.","ecosystem":"Falcon modules cover endpoint, identity, cloud, mobile, data protection, and third-party security data.","licensing":"Annual sensor subscriptions; Falcon Complete MDR, OverWatch hunting, retention, and other modules are licensed separately."},"capabilityDetails":{"behavioral-detection":{"level":"native","note":"Falcon cloud analytics continuously evaluates endpoint activity with adversary intelligence and behavioral detections."},"threat-hunting":{"level":"native","note":"Falcon telemetry is searchable for proactive hunting; OverWatch adds CrowdStrike-operated 24/7 hunting."},"response-actions":{"level":"native","note":"Real Time Response provides remote system access, while Falcon Fusion automates containment and remediation workflows."},"rollback":{"level":"none","note":"Falcon emphasizes prevention, containment, and remediation rather than file-level ransomware rollback."},"xdr-correlation":{"level":"native","note":"Native XDR correlates endpoint data with Falcon identity, cloud, mobile, and data-protection telemetry."},"managed-option":{"level":"add-on","note":"Falcon Complete provides 24/7 managed detection, investigation, containment, and remediation as a separate service."}},"description":"CrowdStrike's flagship EDR/XDR: a lightweight agent streams endpoint telemetry to the Falcon cloud, where behavioral detections, threat hunting, and remote response actions run at scale.","website":"https://www.crowdstrike.com/en-us/platform/endpoint-security/falcon-insight-xdr/","sourceUrls":["https://www.crowdstrike.com/en-us/platform/endpoint-security/falcon-insight-xdr/","https://www.crowdstrike.com/en-us/legal/crowdstrike-licensing/","https://www.crowdstrike.com/en-us/services/falcon-complete-mdr/"],"verifiedAt":"2026-07-11","aiProfile":{"roles":["uses-ai-for-security"],"functions":["behavioral-ai-detection","ai-assisted-investigation"],"summary":"Uses behavioral analytics and cloud-scale AI to detect malicious endpoint activity, correlate events, and support threat hunting and investigation."}},{"slug":"sentinelone-singularity-endpoint","name":"Singularity Endpoint","vendorSlug":"sentinelone","productType":"software","openSource":false,"categorySlugs":["edr-xdr","epp-antivirus"],"capabilities":["behavioral-detection","threat-hunting","response-actions","rollback","xdr-correlation","managed-option"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Organizations that prioritize autonomous endpoint protection and ransomware remediation, including devices that may lose cloud connectivity.","keyAdvantage":"The endpoint agent builds a Storyline of related activity and can remediate or roll back supported malicious changes.","tradeoff":"Deep Visibility, broader XDR functions, and human-operated MDR depend on the selected Singularity bundle or an additional service.","ecosystem":"The Singularity platform extends endpoint telemetry into cloud, identity, network, and third-party data through its data lake and modules.","licensing":"Sold in Core, Control, and Complete endpoint bundles; Vigilance MDR and additional platform modules are separate subscriptions."},"capabilityDetails":{"behavioral-detection":{"level":"native","note":"The agent links related activity into Storylines and performs local behavioral detection and prevention."},"threat-hunting":{"level":"add-on","note":"Deep Visibility hunting is associated with higher Singularity endpoint bundles rather than the entry Core tier."},"response-actions":{"level":"native","note":"The agent supports one-click remediation and can reverse supported unauthorized changes after detection."},"rollback":{"level":"native","note":"One-click rollback can restore supported files and system changes affected by an attack."},"xdr-correlation":{"level":"add-on","note":"Cross-domain correlation expands through Singularity platform modules and the Singularity Data Lake."},"managed-option":{"level":"add-on","note":"Vigilance MDR adds a SentinelOne-operated 24/7 detection and response team."},"malware-prevention":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"device-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"application-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"exploit-prevention":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"disk-encryption-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"centralized-policy":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"SentinelOne's AI-driven endpoint protection and EDR in a single autonomous agent that can detect, block, and remediate without cloud connectivity. Its one-click ransomware rollback, which restores files encrypted during an attack, is a signature capability.","website":"https://www.sentinelone.com/platform/endpoint-security/","sourceUrls":["https://www.sentinelone.com/platform/endpoint-security/","https://www.sentinelone.com/platform/singularity-core/","https://go.sentinelone.com/rs/327-MNM-087/images/SEN0202_DataSheet_EPP_WEB.pdf"],"verifiedAt":"2026-07-11","aiProfile":{"roles":["uses-ai-for-security"],"functions":["behavioral-ai-detection","autonomous-response"],"summary":"Uses on-agent and cloud AI to detect malicious behavior, connect activity into Storylines, and autonomously block and remediate threats."}},{"slug":"microsoft-defender-for-endpoint","name":"Microsoft Defender for Endpoint","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["edr-xdr"],"capabilities":["behavioral-detection","threat-hunting","response-actions","xdr-correlation","managed-option"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Organizations already using Microsoft 365, Intune, Entra, or Defender products that want endpoint security in the same operating environment.","keyAdvantage":"Endpoint incidents can correlate with Microsoft identity, email, cloud-app, and cloud-workload signals in Defender XDR.","tradeoff":"The full EDR, automated investigation, and hunting experience requires Plan 2 or an eligible suite; teams also need KQL skills for advanced hunting.","ecosystem":"Integrates closely with Defender XDR, Microsoft Sentinel, Intune, Entra ID, Defender for Office 365, and Defender for Cloud Apps.","licensing":"Plan 1 is available standalone and in Microsoft 365 E3; Plan 2 is available standalone and in Microsoft 365 E5 and related suites."},"capabilityDetails":{"behavioral-detection":{"level":"native","note":"Defender collects endpoint behavior and combines it with cloud protection, attack-surface reduction, and incident correlation."},"threat-hunting":{"level":"native","note":"Advanced hunting uses Kusto Query Language across endpoint and other Microsoft Defender telemetry."},"response-actions":{"level":"native","note":"Live response, device isolation, automated investigation, and attack disruption support containment and remediation."},"rollback":{"level":"none","note":"Defender provides remediation and containment but does not advertise file-level ransomware rollback as an EDR feature."},"xdr-correlation":{"level":"native","note":"Defender XDR correlates endpoint incidents with identity, email, SaaS, and cloud security signals."},"managed-option":{"level":"add-on","note":"Microsoft Defender Experts services add Microsoft-operated threat hunting or managed XDR coverage."}},"description":"Microsoft's cloud-native EDR layered on the built-in Defender Antivirus, adding attack surface reduction, KQL-based advanced hunting, and automated attack disruption. Correlates with identity, email, and cloud signals through Microsoft Defender XDR, and is bundled into Microsoft 365 E5 licensing.","website":"https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint","sourceUrls":["https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint","https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-windows","https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-defender-service-description"],"verifiedAt":"2026-07-11"},{"slug":"cortex-xdr","name":"Cortex XDR","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["edr-xdr"],"capabilities":["behavioral-detection","threat-hunting","response-actions","xdr-correlation","managed-option"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Security operations teams that want endpoint detection tied closely to Palo Alto Networks firewall, cloud, identity, and broader Cortex telemetry.","keyAdvantage":"Cortex XDR joins endpoint and cross-domain events into attack stories and provides XQL for detailed investigation.","tradeoff":"Advanced hunting with XQL requires the Pro tier, and the platform is most differentiated when the organization already uses Palo Alto Networks data sources.","ecosystem":"Connects endpoint, network, cloud, identity, and email telemetry and serves as an entry point to Cortex XSIAM and XSOAR.","licensing":"Cortex XDR Prevent covers prevention; Cortex XDR Pro adds EDR and XQL capabilities. Unit 42 MDR is an additional subscription."},"capabilityDetails":{"behavioral-detection":{"level":"native","note":"The endpoint agent combines local prevention with behavioral analysis and cloud-based detection."},"threat-hunting":{"level":"add-on","note":"Cortex Query Language hunting and the primary investigation dataset require Cortex XDR Pro."},"response-actions":{"level":"native","note":"Attack stories support root-cause investigation and native automation for endpoint containment and remediation."},"rollback":{"level":"none","note":"Cortex XDR focuses on prevention and response rather than restoring files encrypted by ransomware."},"xdr-correlation":{"level":"native","note":"The platform correlates endpoint, network, cloud, identity, and email data in a common investigation layer."},"managed-option":{"level":"add-on","note":"Unit 42 MDR operates within Cortex XDR and adds continuous monitoring, hunting, containment, and remediation."}},"description":"Palo Alto Networks' detection and response platform, one of the earliest products marketed as XDR. Correlates endpoint agent telemetry with network, cloud, and identity data for AI-driven detection and automated root-cause analysis, with Unit 42 available as a managed option.","website":"https://www.paloaltonetworks.com/cortex/cortex-xdr","sourceUrls":["https://www.paloaltonetworks.com/cortex/cortex-xdr","https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/How-to-build-XQL-queries","https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/unit42-managed-detection-and-response.pdf"],"verifiedAt":"2026-07-11","aiProfile":{"roles":["uses-ai-for-security"],"functions":["behavioral-ai-detection","ai-assisted-investigation","autonomous-response"],"summary":"Uses machine learning and analytics to detect anomalous behavior, correlate cross-domain attack stories, and support automated investigation and response."}},{"slug":"huntress-managed-edr","name":"Huntress Managed EDR","vendorSlug":"huntress","productType":"service","openSource":false,"categorySlugs":["edr-xdr"],"capabilities":["behavioral-detection","response-actions","managed-option"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$","comparison":{"bestFor":"Lean IT teams and MSPs that want the EDR technology, alert triage, threat hunting, and response operated for them around the clock.","keyAdvantage":"The 24/7 Huntress SOC and managed response are included with the endpoint subscription instead of sold as a separate MDR tier.","tradeoff":"The service is intentionally hands-off, so teams seeking a deeply customizable self-operated hunting platform may have less direct control.","ecosystem":"Designed for multi-tenant MSP operations and can manage Microsoft Defender Antivirus or monitor Defender for Endpoint alerts alongside Huntress telemetry.","licensing":"Per-endpoint subscription with one feature set and included SOC coverage; standard commitments may have a 50-agent minimum."},"capabilityDetails":{"behavioral-detection":{"level":"native","note":"The Huntress agent collects endpoint activity and the managed service validates suspicious behavior before escalation."},"threat-hunting":{"level":"native","note":"Huntress threat hunters and its 24/7 SOC investigate endpoint activity as part of the included service."},"response-actions":{"level":"native","note":"Managed Response can isolate hosts, terminate malicious processes, and remove confirmed attacker footholds."},"rollback":{"level":"none","note":"The service contains and remediates threats but does not advertise file-level ransomware rollback."},"xdr-correlation":{"level":"limited","note":"The broader Huntress platform joins endpoint, identity, and log signals, but Managed EDR is not a general-purpose XDR data lake."},"managed-option":{"level":"native","note":"Human-led 24/7 SOC monitoring, investigation, hunting, and response are included in the base service."}},"description":"A fully managed EDR aimed at SMBs and the MSPs that serve them: every detection is reviewed by Huntress's 24/7 human SOC before the customer sees it. Trades the depth and configurability of enterprise EDR consoles for simplicity and a low per-endpoint price.","website":"https://www.huntress.com/platform/managed-edr","sourceUrls":["https://www.huntress.com/platform/managed-edr","https://www.huntress.com/pricing/edr","https://www.huntress.com/soc-guide/automated-threat-remediation"],"verifiedAt":"2026-07-11"},{"slug":"wazuh","name":"Wazuh","vendorSlug":"wazuh","productType":"software","openSource":true,"license":"GPL-2.0","categorySlugs":["edr-xdr","siem"],"capabilities":["behavioral-detection","threat-hunting","response-actions"],"deployment":["on-prem","agent"],"targetOrgSize":["smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Teams that want an open-source, self-hosted combination of endpoint monitoring, log analytics, compliance checks, and configurable response.","keyAdvantage":"Wazuh combines endpoint agents, a rules engine, an indexer, dashboards, and SIEM-style log collection without a software license fee.","tradeoff":"The customer must deploy, scale, tune, and maintain the manager, indexer, rules, integrations, and response scripts unless using hosted Wazuh Cloud.","ecosystem":"Integrates with threat-intelligence and automation tools including VirusTotal, MISP, osquery, and Shuffle, and also ingests non-endpoint logs.","licensing":"GPL-licensed self-hosted platform is free; Wazuh Cloud provides paid hosting but is not a fully managed detection-and-response service."},"capabilityDetails":{"behavioral-detection":{"level":"limited","note":"Rules, decoders, file-integrity monitoring, inventory, and log analysis detect activity, but this differs from a commercial behavioral EDR engine."},"threat-hunting":{"level":"native","note":"Indexed endpoint and log data, archives, MITRE mappings, dashboards, and custom queries support analyst-led hunting."},"response-actions":{"level":"native","note":"Configurable Active Response scripts can block addresses, disable accounts, delete files, or run custom commands."},"rollback":{"level":"none","note":"Wazuh can trigger containment scripts but does not provide file-level ransomware rollback."},"xdr-correlation":{"level":"limited","note":"The platform combines endpoint and third-party logs, though correlation depends heavily on customer-defined rules and integrations."},"managed-option":{"level":"none","note":"Wazuh Cloud hosts the platform; customers still operate detection and response or engage a separate service provider."},"log-ingestion":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"correlation-rules":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"search":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ueba":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dashboards":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source security platform that combines endpoint telemetry, log analysis, file integrity monitoring, and compliance checks under a self-hosted manager. Its free core makes it practical for labs and teams that can operate the infrastructure themselves.","website":"https://wazuh.com","sourceUrls":["https://wazuh.com","https://documentation.wazuh.com/current/getting-started/components/index.html","https://documentation.wazuh.com/current/getting-started/use-cases/threat-hunting.html","https://documentation.wazuh.com/current/user-manual/capabilities/active-response/index.html"],"verifiedAt":"2026-07-11"},{"slug":"osquery","name":"osquery","productType":"project","openSource":true,"license":"Apache-2.0 OR GPL-2.0","categorySlugs":["edr-xdr"],"capabilities":["threat-hunting"],"deployment":["agent","cli"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Engineering-led security teams that need a flexible endpoint telemetry layer and plan to supply their own fleet manager, storage, detections, and response tooling.","keyAdvantage":"Operating-system state is exposed as SQL tables, making endpoint inventory and investigation easy to automate and extend.","tradeoff":"osquery alone is not an EDR product: it does not provide a managed console, behavioral detection engine, incident workflow, or containment service.","ecosystem":"Commonly embedded in fleet-management, EDR, compliance, and observability products through its daemon, logging plugins, APIs, and extensions.","licensing":"Community project distributed under Apache 2.0 or GPL 2.0 terms, with no bundled commercial management service."},"capabilityDetails":{"behavioral-detection":{"level":"none","note":"osquery exposes telemetry and scheduled query results but does not ship a standalone behavioral detection engine."},"threat-hunting":{"level":"native","note":"Analysts query processes, sockets, users, files, configuration, and event tables with SQLite-compatible SQL."},"response-actions":{"level":"none","note":"Response and containment require an external fleet manager, automation layer, or security product built around osquery."},"rollback":{"level":"none","note":"The project collects endpoint state and events; it does not restore files or system changes."},"xdr-correlation":{"level":"integration","note":"Query results and event logs can feed another security platform, but osquery does not correlate cross-domain incidents itself."},"managed-option":{"level":"none","note":"The community project includes no vendor-operated monitoring or response service."}},"description":"Exposes an operating system's processes, sockets, and configuration as SQL tables you can query, on Windows, macOS, and Linux. Created at Facebook and now governed by the OSQuery Foundation under the Linux Foundation, it is a building block embedded inside many commercial EDR and fleet-visibility products.","website":"https://www.osquery.io","sourceUrls":["https://www.osquery.io","https://osquery.readthedocs.io/en/stable/introduction/using-osqueryi/"],"verifiedAt":"2026-07-11"},{"slug":"velociraptor","name":"Velociraptor","vendorSlug":"rapid7","productType":"software","openSource":true,"license":"AGPL-3.0","categorySlugs":["edr-xdr","dfir"],"capabilities":["threat-hunting","response-actions"],"deployment":["on-prem","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Incident-response and DFIR teams that need targeted forensic collection and custom hunts across large endpoint fleets.","keyAdvantage":"VQL and reusable artifacts can collect and analyze specific evidence on endpoints, including systems that reconnect after being offline.","tradeoff":"Velociraptor is an investigator-focused DFIR platform rather than a turnkey preventive EDR, so it requires expertise and complementary detection controls.","ecosystem":"Uses a community artifact exchange, supports custom VQL and external tools, and is maintained by Rapid7 as an open-source project.","licensing":"AGPL-licensed and self-hosted; organizations operate the server and endpoint clients themselves."},"capabilityDetails":{"behavioral-detection":{"level":"limited","note":"Event-monitoring artifacts can watch for defined activity, but the platform is centered on investigator-authored collections rather than autonomous prevention."},"threat-hunting":{"level":"native","note":"Hunts schedule VQL artifacts across endpoint groups, track collection status, and analyze results in notebooks."},"response-actions":{"level":"limited","note":"Artifacts can execute targeted collection or remediation logic, but turnkey containment workflows are not the primary product model."},"rollback":{"level":"none","note":"Velociraptor preserves and analyzes evidence; it does not provide ransomware file rollback."},"xdr-correlation":{"level":"none","note":"It does not provide a native cross-domain XDR incident-correlation layer."},"managed-option":{"level":"none","note":"The open-source project does not include a vendor-operated MDR service."},"forensic-acquisition":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"timeline-reconstruction":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malware-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ir-playbooks-retainer":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"chain-of-custody":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"root-cause-scope-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An AGPL-licensed DFIR and endpoint-visibility tool built around VQL, a query language for hunting and collecting forensic artifacts across many endpoints at once. Rapid7 acquired the Velocidex team in 2021 and continues to maintain the project.","website":"https://www.rapid7.com/products/velociraptor/","sourceUrls":["https://www.rapid7.com/products/velociraptor/","https://docs.velociraptor.app/docs/hunting/","https://docs.velociraptor.app/docs/vql/","https://docs.velociraptor.app/docs/file_collection/"],"verifiedAt":"2026-07-11"},{"slug":"sophos-endpoint","name":"Sophos Endpoint","vendorSlug":"sophos","productType":"software","openSource":false,"categorySlugs":["epp-antivirus","edr-xdr"],"capabilities":["malware-prevention","exploit-prevention","device-control","application-control","centralized-policy"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Endpoint Protection Platform with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Sophos's flagship endpoint protection (the successor to the long-running Intercept X line, renamed in 2025), managed from the Sophos Central cloud console.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Malware prevention, Device control, and Application control / allowlisting in a proof of concept.","ecosystem":"Primary fit is Endpoint Protection Platform; this guide also maps the product to Endpoint & Extended Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"malware-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"application-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exploit-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"disk-encryption-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"centralized-policy":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-hunting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rollback":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"xdr-correlation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"managed-option":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Sophos's flagship endpoint protection (the successor to the long-running Intercept X line, renamed in 2025), managed from the Sophos Central cloud console. Combines deep-learning malware prevention with anti-ransomware and exploit protection, with EDR and Sophos MDR available as add-on tiers.","website":"https://www.sophos.com/en-us/products/endpoint-security","sourceUrls":["https://www.sophos.com/en-us/products/endpoint-security"],"verifiedAt":"2026-07-11"},{"slug":"bitdefender-gravityzone","name":"GravityZone","vendorSlug":"bitdefender","productType":"software","openSource":false,"categorySlugs":["epp-antivirus","edr-xdr"],"capabilities":["malware-prevention","exploit-prevention","device-control","application-control","disk-encryption-management","centralized-policy"],"deployment":["saas","hybrid","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Endpoint Protection Platform with a preference for a SaaS, hybrid, and endpoint-agent operating model.","keyAdvantage":"Bitdefender's business endpoint platform, tiered from baseline protection up to Business Security Premium with EDR and Enterprise plans with XDR correlation and threat hunting.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Malware prevention, Device control, and Application control / allowlisting in a proof of concept.","ecosystem":"Primary fit is Endpoint Protection Platform; this guide also maps the product to Endpoint & Extended Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"malware-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"application-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exploit-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"disk-encryption-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-policy":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-hunting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rollback":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"xdr-correlation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"managed-option":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Bitdefender's business endpoint platform, tiered from baseline protection up to Business Security Premium with EDR and Enterprise plans with XDR correlation and threat hunting. Management is available through cloud-hosted or on-premises consoles.","website":"https://www.bitdefender.com/en-us/business/products/gravityzone-enterprise-security","sourceUrls":["https://www.bitdefender.com/en-us/business/products/gravityzone-enterprise-security"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-defender-antivirus","name":"Microsoft Defender Antivirus","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["epp-antivirus"],"capabilities":["malware-prevention","exploit-prevention"],"deployment":["agent"],"targetOrgSize":["individual","smb"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners and small businesses evaluating Endpoint Protection Platform with a preference for a endpoint-agent operating model.","keyAdvantage":"The antivirus built into every copy of Windows: cloud-assisted malware prevention and exploit protection with no installation or extra cost.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Malware prevention, Device control, and Application control / allowlisting in a proof of concept.","ecosystem":"Primary fit is Endpoint Protection Platform. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"malware-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"application-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"exploit-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"disk-encryption-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"centralized-policy":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The antivirus built into every copy of Windows: cloud-assisted malware prevention and exploit protection with no installation or extra cost. Consistently scores at or near the top of independent AV testing, and serves as the prevention layer under Microsoft Defender for Endpoint in business deployments.","website":"https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-windows","sourceUrls":["https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-windows"],"verifiedAt":"2026-07-11"},{"slug":"threatdown","name":"ThreatDown","vendorSlug":"malwarebytes","productType":"software","openSource":false,"categorySlugs":["epp-antivirus","edr-xdr"],"capabilities":["malware-prevention","exploit-prevention","application-control","centralized-policy"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Endpoint Protection Platform with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Malwarebytes' business endpoint line (rebranded from Malwarebytes for Business in 2023), sold in bundles that stack EDR, application blocking, and managed detection on the core anti-malware engine.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Malware prevention, Device control, and Application control / allowlisting in a proof of concept.","ecosystem":"Primary fit is Endpoint Protection Platform; this guide also maps the product to Endpoint & Extended Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the lower relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"malware-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"application-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exploit-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"disk-encryption-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"centralized-policy":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-hunting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rollback":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"xdr-correlation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"managed-option":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Malwarebytes' business endpoint line (rebranded from Malwarebytes for Business in 2023), sold in bundles that stack EDR, application blocking, and managed detection on the core anti-malware engine. Cloud-managed and positioned as a simpler, cheaper alternative to enterprise EDR suites for resource-constrained IT teams.","website":"https://www.threatdown.com","sourceUrls":["https://www.threatdown.com"],"verifiedAt":"2026-07-11"},{"slug":"eset-protect","name":"ESET PROTECT","vendorSlug":"eset","productType":"software","openSource":false,"categorySlugs":["epp-antivirus","edr-xdr"],"capabilities":["malware-prevention","exploit-prevention","device-control","disk-encryption-management","centralized-policy"],"deployment":["saas","on-prem","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Endpoint Protection Platform with a preference for a SaaS, self-hosted, and endpoint-agent operating model.","keyAdvantage":"ESET's business endpoint platform, tiered from core multi-layered antimalware (Entry) up to full-disk encryption, cloud sandboxing, and EDR/XDR (Complete and Elite tiers).","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Malware prevention, Device control, and Application control / allowlisting in a proof of concept.","ecosystem":"Primary fit is Endpoint Protection Platform; this guide also maps the product to Endpoint & Extended Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"malware-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"application-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"exploit-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"disk-encryption-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-policy":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-hunting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rollback":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"xdr-correlation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"managed-option":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"ESET's business endpoint platform, tiered from core multi-layered antimalware (Entry) up to full-disk encryption, cloud sandboxing, and EDR/XDR (Complete and Elite tiers). Notable for offering both a cloud console and a fully on-prem management server, and for a long record in independent AV testing.","website":"https://www.eset.com/us/business/protect-platform/","sourceUrls":["https://www.eset.com/us/business/protect-platform/"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-intune","name":"Microsoft Intune","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["mdm-uem"],"capabilities":["device-enrollment","policy-configuration","app-management","patch-os-updates","remote-wipe-lock","conditional-access-integration","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Mobile & Unified Endpoint Management with a preference for a SaaS operating model.","keyAdvantage":"Microsoft's cloud-native unified endpoint management for Windows, macOS, iOS, and Android, bundled into most Microsoft 365 business plans.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Device enrollment & provisioning, Policy & configuration management, and Application management in a proof of concept.","ecosystem":"Primary fit is Mobile & Unified Endpoint Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"device-enrollment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-configuration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"patch-os-updates":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remote-wipe-lock":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"conditional-access-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Microsoft's cloud-native unified endpoint management for Windows, macOS, iOS, and Android, bundled into most Microsoft 365 business plans. Its tightest differentiator is native integration with Entra ID conditional access, letting device compliance directly gate access to corporate apps.","website":"https://www.microsoft.com/en-us/security/business/microsoft-intune","sourceUrls":["https://www.microsoft.com/en-us/security/business/microsoft-intune"],"verifiedAt":"2026-07-11"},{"slug":"jamf-pro","name":"Jamf Pro","vendorSlug":"jamf","productType":"software","openSource":false,"categorySlugs":["mdm-uem"],"capabilities":["device-enrollment","policy-configuration","app-management","patch-os-updates","remote-wipe-lock","conditional-access-integration","compliance-reporting"],"deployment":["saas","on-prem"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Mobile & Unified Endpoint Management with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"Apple-focused device management with zero-touch enrollment, configuration profiles, application management, and support for new macOS and iOS releases.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Device enrollment & provisioning, Policy & configuration management, and Application management in a proof of concept.","ecosystem":"Primary fit is Mobile & Unified Endpoint Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"device-enrollment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-configuration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"patch-os-updates":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remote-wipe-lock":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"conditional-access-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Apple-focused device management with zero-touch enrollment, configuration profiles, application management, and support for new macOS and iOS releases. Windows management requires another product, and Jamf Protect is sold separately for endpoint security.","website":"https://www.jamf.com/products/jamf-pro/","sourceUrls":["https://www.jamf.com/products/jamf-pro/"],"verifiedAt":"2026-07-11"},{"slug":"iru","name":"Iru","vendorSlug":"iru","productType":"software","openSource":false,"categorySlugs":["mdm-uem"],"capabilities":["device-enrollment","policy-configuration","app-management","patch-os-updates","remote-wipe-lock","compliance-reporting"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Mobile & Unified Endpoint Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"The device management platform formerly known as Kandji, rebranded Iru in October 2025 as it expanded beyond Apple to Windows and Android.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Device enrollment & provisioning, Policy & configuration management, and Application management in a proof of concept.","ecosystem":"Primary fit is Mobile & Unified Endpoint Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"device-enrollment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-configuration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"patch-os-updates":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remote-wipe-lock":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"conditional-access-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The device management platform formerly known as Kandji, rebranded Iru in October 2025 as it expanded beyond Apple to Windows and Android. It combines device policy, patching, vulnerability management, and compliance automation in the same product family.","website":"https://www.iru.com","sourceUrls":["https://www.iru.com","https://www.iru.com/newsroom/kandji-now-iru"],"verifiedAt":"2026-07-11"},{"slug":"okta-workforce-identity","name":"Okta Workforce Identity Cloud","vendorSlug":"okta","productType":"software","openSource":false,"categorySlugs":["iam-sso"],"capabilities":["single-sign-on","directory-integration","adaptive-access","lifecycle-provisioning","mfa-support","audit-logging","app-catalog"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Identity & Access Management / Single Sign-On with a preference for a SaaS operating model.","keyAdvantage":"A workforce identity platform with thousands of pre-built app integrations in the Okta Integration Network.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Single sign-on, Directory integration, and Adaptive / conditional access in a proof of concept.","ecosystem":"Primary fit is Identity & Access Management / Single Sign-On. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"single-sign-on":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"directory-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"lifecycle-provisioning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"mfa-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-catalog":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A workforce identity platform with thousands of pre-built app integrations in the Okta Integration Network. It covers SSO, adaptive MFA, lifecycle provisioning, and directory synchronization without requiring the rest of a productivity suite.","website":"https://www.okta.com/products/workforce-identity/","sourceUrls":["https://www.okta.com/products/workforce-identity/"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-entra-id","name":"Microsoft Entra ID","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["iam-sso"],"capabilities":["single-sign-on","directory-integration","adaptive-access","lifecycle-provisioning","mfa-support","audit-logging","app-catalog"],"deployment":["saas","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Identity & Access Management / Single Sign-On with a preference for a SaaS and hybrid operating model.","keyAdvantage":"Microsoft's cloud identity platform (renamed from Azure Active Directory in 2023) and the default identity provider for any Microsoft 365 shop.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Single sign-on, Directory integration, and Adaptive / conditional access in a proof of concept.","ecosystem":"Primary fit is Identity & Access Management / Single Sign-On. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"single-sign-on":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"directory-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"lifecycle-provisioning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"mfa-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-catalog":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Microsoft's cloud identity platform (renamed from Azure Active Directory in 2023) and the default identity provider for any Microsoft 365 shop. Conditional access policies, hybrid sync with on-prem Active Directory, and a free baseline tier make it the identity backbone for a huge share of organizations.","website":"https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id","sourceUrls":["https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-id"],"verifiedAt":"2026-07-11"},{"slug":"pingone-for-workforce","name":"PingOne for Workforce","vendorSlug":"ping-identity","productType":"software","openSource":false,"categorySlugs":["iam-sso"],"capabilities":["single-sign-on","directory-integration","adaptive-access","mfa-support","audit-logging","app-catalog"],"deployment":["saas","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Identity & Access Management / Single Sign-On with a preference for a SaaS and hybrid operating model.","keyAdvantage":"Ping Identity's workforce SSO and MFA platform, known for handling complex, hybrid enterprise environments and for the DaVinci no-code orchestration engine for building custom authentication flows.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Single sign-on, Directory integration, and Adaptive / conditional access in a proof of concept.","ecosystem":"Primary fit is Identity & Access Management / Single Sign-On. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"single-sign-on":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"directory-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"lifecycle-provisioning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"mfa-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-catalog":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Ping Identity's workforce SSO and MFA platform, known for handling complex, hybrid enterprise environments and for the DaVinci no-code orchestration engine for building custom authentication flows. Absorbed ForgeRock's technology after Thoma Bravo merged the two companies in 2023.","website":"https://www.pingidentity.com/en/platform/pingone-for-workforce.html","sourceUrls":["https://www.pingidentity.com/en/platform/pingone-for-workforce.html"],"verifiedAt":"2026-07-11"},{"slug":"keycloak","name":"Keycloak","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["iam-sso"],"capabilities":["single-sign-on","directory-integration","mfa-support","audit-logging"],"deployment":["on-prem"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Identity & Access Management / Single Sign-On with a preference for a self-hosted operating model.","keyAdvantage":"A self-hosted, Apache-licensed identity server supporting OIDC, SAML, LDAP and Active Directory federation, and built-in MFA.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Single sign-on, Directory integration, and Adaptive / conditional access before standardizing.","ecosystem":"Primary fit is Identity & Access Management / Single Sign-On. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"single-sign-on":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"directory-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"lifecycle-provisioning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"mfa-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"app-catalog":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A self-hosted, Apache-licensed identity server supporting OIDC, SAML, LDAP and Active Directory federation, and built-in MFA. Keycloak moved from Red Hat stewardship to the CNCF in 2023; Red Hat also sells a supported downstream build.","website":"https://www.keycloak.org","sourceUrls":["https://www.keycloak.org"],"verifiedAt":"2026-07-11"},{"slug":"cisco-duo","name":"Cisco Duo","vendorSlug":"cisco","productType":"software","openSource":false,"categorySlugs":["mfa-passwordless"],"capabilities":["phishing-resistant-factors","push-otp-factors","adaptive-step-up","biometric-authentication","device-trust","enforcement-policies"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating MFA & Passwordless Authentication with a preference for a SaaS operating model.","keyAdvantage":"The MFA product that made push-to-approve mainstream, now a Cisco product line sold in Essentials, Advantage, and Premier tiers.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing-resistant factors, Push & one-time-passcode factors, and Adaptive step-up authentication in a proof of concept.","ecosystem":"Primary fit is MFA & Passwordless Authentication. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the lower relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-resistant-factors":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"push-otp-factors":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-step-up":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"biometric-authentication":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-trust":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"enforcement-policies":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The MFA product that made push-to-approve mainstream, now a Cisco product line sold in Essentials, Advantage, and Premier tiers. Pairs phishing-resistant and passwordless factors with device health checks, and remains one of the fastest MFA rollouts for protecting VPNs and legacy apps.","website":"https://duo.com","sourceUrls":["https://duo.com"],"verifiedAt":"2026-07-11"},{"slug":"yubico-yubikey","name":"YubiKey","vendorSlug":"yubico","productType":"hardware","openSource":false,"categorySlugs":["mfa-passwordless"],"capabilities":["phishing-resistant-factors","push-otp-factors","biometric-authentication"],"deployment":["on-prem","saas"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"$","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating MFA & Passwordless Authentication with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"A physical authenticator supporting FIDO2/WebAuthn, PIV, and OTP.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Phishing-resistant factors, Push & one-time-passcode factors, and Adaptive step-up authentication in a proof of concept.","ecosystem":"Primary fit is MFA & Passwordless Authentication. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the lower relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-resistant-factors":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"push-otp-factors":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-step-up":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"biometric-authentication":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"device-trust":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"enforcement-policies":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A physical authenticator supporting FIDO2/WebAuthn, PIV, and OTP. FIDO credentials remain on the device, which makes that authentication flow resistant to credential phishing. Yubico sells fleet purchasing and lifecycle management through YubiEnterprise, while the Bio series adds on-key fingerprint matching.","website":"https://www.yubico.com/products/","sourceUrls":["https://www.yubico.com/products/"],"verifiedAt":"2026-07-11"},{"slug":"idira-privileged-access-manager","name":"Idira Privileged Access Manager","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["pam"],"capabilities":["credential-vaulting","session-recording","just-in-time-access","least-privilege-elevation","service-account-management"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Privileged Access Management with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"The PAM product formerly sold under the CyberArk name, now part of Palo Alto Networks' Idira identity platform following the February 2026 acquisition.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Privileged credential vaulting, Session recording & monitoring, and Just-in-time access in a proof of concept.","ecosystem":"Primary fit is Privileged Access Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"credential-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"session-recording":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"just-in-time-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"least-privilege-elevation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secrets-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"service-account-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The PAM product formerly sold under the CyberArk name, now part of Palo Alto Networks' Idira identity platform following the February 2026 acquisition. It vaults and rotates privileged credentials, records sessions, and supports just-in-time access in SaaS and self-hosted deployments.","website":"https://www.paloaltonetworks.com/idira","sourceUrls":["https://www.paloaltonetworks.com/idira","https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-completes-acquisition-cyberark-secure--ai-era"],"verifiedAt":"2026-07-11"},{"slug":"delinea-secret-server","name":"Delinea Secret Server","vendorSlug":"delinea","productType":"software","openSource":false,"categorySlugs":["pam"],"capabilities":["credential-vaulting","session-recording","just-in-time-access","service-account-management"],"deployment":["saas","on-prem"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Privileged Access Management with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"Delinea's flagship privileged credential vault (originally Thycotic Secret Server), available as SaaS or on-prem.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Privileged credential vaulting, Session recording & monitoring, and Just-in-time access in a proof of concept.","ecosystem":"Primary fit is Privileged Access Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"credential-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"session-recording":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"just-in-time-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"least-privilege-elevation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"service-account-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Delinea's flagship privileged credential vault (originally Thycotic Secret Server), available as SaaS or on-prem. Long regarded as one of the faster PAM products to deploy, with checkout-based time-limited access, session recording, and automated discovery and rotation of service account credentials.","website":"https://delinea.com/products/secret-server","sourceUrls":["https://delinea.com/products/secret-server"],"verifiedAt":"2026-07-11"},{"slug":"beyondtrust-password-safe","name":"BeyondTrust Password Safe","vendorSlug":"beyondtrust","productType":"software","openSource":false,"categorySlugs":["pam"],"capabilities":["credential-vaulting","session-recording","just-in-time-access","service-account-management"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Privileged Access Management with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"BeyondTrust's credential and session management product, combining privileged password vaulting, rotation, and full session recording in one deployment.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Privileged credential vaulting, Session recording & monitoring, and Just-in-time access in a proof of concept.","ecosystem":"Primary fit is Privileged Access Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"credential-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"session-recording":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"just-in-time-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"least-privilege-elevation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"service-account-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"BeyondTrust's credential and session management product, combining privileged password vaulting, rotation, and full session recording in one deployment. Frequently bundled with the company's Privileged Remote Access product to cover vendor and remote-worker privileged sessions.","website":"https://www.beyondtrust.com/products/password-safe","sourceUrls":["https://www.beyondtrust.com/products/password-safe"],"verifiedAt":"2026-07-11"},{"slug":"teleport","name":"Teleport","vendorSlug":"teleport","productType":"software","openSource":true,"license":"AGPL-3.0","categorySlugs":["pam"],"capabilities":["just-in-time-access","session-recording"],"deployment":["saas","on-prem","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Privileged Access Management with a preference for a SaaS, self-hosted, and endpoint-agent operating model.","keyAdvantage":"Infrastructure access for engineers: replaces standing SSH keys and passwords with short-lived certificates for servers, Kubernetes, databases, and internal apps, with every session recorded.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Privileged credential vaulting, Session recording & monitoring, and Just-in-time access before standardizing.","ecosystem":"Primary fit is Privileged Access Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the AGPL-3.0 license and a freemium entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"credential-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"session-recording":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"just-in-time-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"least-privilege-elevation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"service-account-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Infrastructure access for engineers: replaces standing SSH keys and passwords with short-lived certificates for servers, Kubernetes, databases, and internal apps, with every session recorded. Open-core — the source is AGPL-licensed, but official prebuilt Community Edition binaries carry usage restrictions for larger companies, which are steered to the Enterprise edition.","website":"https://goteleport.com","sourceUrls":["https://goteleport.com"],"verifiedAt":"2026-07-11"},{"slug":"hashicorp-vault","name":"HashiCorp Vault","vendorSlug":"hashicorp","productType":"software","openSource":false,"categorySlugs":["pam"],"capabilities":["secrets-management","credential-vaulting","service-account-management"],"deployment":["saas","on-prem","cli"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Privileged Access Management with a preference for a SaaS, self-hosted, and command-line operating model.","keyAdvantage":"A secrets-management server that stores API keys and certificates and can issue short-lived database and cloud credentials on demand.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Privileged credential vaulting, Session recording & monitoring, and Just-in-time access in a proof of concept.","ecosystem":"Primary fit is Privileged Access Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"credential-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"session-recording":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"just-in-time-access":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"least-privilege-elevation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"service-account-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A secrets-management server that stores API keys and certificates and can issue short-lived database and cloud credentials on demand. Vault moved to BUSL-1.1 for new releases in 2023 and became part of IBM through its 2025 acquisition of HashiCorp.","website":"https://www.hashicorp.com/en/products/vault","sourceUrls":["https://www.hashicorp.com/en/products/vault"],"verifiedAt":"2026-07-11"},{"slug":"sailpoint-identity-security-cloud","name":"SailPoint Identity Security Cloud","vendorSlug":"sailpoint","productType":"software","openSource":false,"categorySlugs":["iga"],"capabilities":["access-certification","role-based-modeling","automated-provisioning","segregation-of-duties","access-request-workflows","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Identity Governance & Administration with a preference for a SaaS operating model.","keyAdvantage":"SailPoint's cloud-native IGA platform (successor to the IdentityNow branding), widely treated as the reference product in identity governance.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Access certification campaigns, Role-based access modeling, and Automated provisioning & deprovisioning in a proof of concept.","ecosystem":"Primary fit is Identity Governance & Administration. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"access-certification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"role-based-modeling":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-provisioning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"segregation-of-duties":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-request-workflows":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"SailPoint's cloud-native IGA platform (successor to the IdentityNow branding), widely treated as the reference product in identity governance. Automates joiner-mover-leaver provisioning, runs certification campaigns, and applies AI-driven recommendations to who-should-have-what decisions.","website":"https://www.sailpoint.com/products/identity-security-cloud","sourceUrls":["https://www.sailpoint.com/products/identity-security-cloud"],"verifiedAt":"2026-07-11"},{"slug":"saviynt-identity-cloud","name":"Saviynt Identity Cloud","vendorSlug":"saviynt","productType":"software","openSource":false,"categorySlugs":["iga"],"capabilities":["access-certification","role-based-modeling","automated-provisioning","segregation-of-duties","access-request-workflows","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Identity Governance & Administration with a preference for a SaaS operating model.","keyAdvantage":"Saviynt's SaaS identity platform combines IGA, application GRC, and privileged access.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Access certification campaigns, Role-based access modeling, and Automated provisioning & deprovisioning in a proof of concept.","ecosystem":"Primary fit is Identity Governance & Administration. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"access-certification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"role-based-modeling":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-provisioning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"segregation-of-duties":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-request-workflows":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Saviynt's SaaS identity platform combines IGA, application GRC, and privileged access. Its controls include segregation-of-duties analysis for ERP systems such as SAP and Oracle.","website":"https://saviynt.com/platform","sourceUrls":["https://saviynt.com/platform"],"verifiedAt":"2026-07-11"},{"slug":"one-identity-manager","name":"One Identity Manager","vendorSlug":"one-identity","productType":"software","openSource":false,"categorySlugs":["iga"],"capabilities":["access-certification","role-based-modeling","automated-provisioning","segregation-of-duties","access-request-workflows","compliance-reporting"],"deployment":["on-prem","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Identity Governance & Administration with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"One Identity's long-established IGA suite, connecting HR systems to downstream applications for automated provisioning, certification campaigns, and segregation-of-duties enforcement.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Access certification campaigns, Role-based access modeling, and Automated provisioning & deprovisioning in a proof of concept.","ecosystem":"Primary fit is Identity Governance & Administration. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"access-certification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"role-based-modeling":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-provisioning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"segregation-of-duties":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-request-workflows":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"One Identity's long-established IGA suite, connecting HR systems to downstream applications for automated provisioning, certification campaigns, and segregation-of-duties enforcement. Traditionally deployed on-prem with a cloud-hosted option, and a common choice in Microsoft- and SAP-heavy enterprises.","website":"https://www.oneidentity.com/products/identity-manager/","sourceUrls":["https://www.oneidentity.com/products/identity-manager/"],"verifiedAt":"2026-07-11"},{"slug":"palo-alto-pa-series-ngfw","name":"PA-Series Next-Generation Firewalls","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking"],"deployment":["on-prem","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"Palo Alto Networks' physical and virtual NGFW line, spanning branch-office to data-center models and managed centrally through Strata Cloud Manager.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Palo Alto Networks' physical and virtual NGFW line, spanning branch-office to data-center models and managed centrally through Strata Cloud Manager. App-ID and Content-ID inspect traffic by application rather than port, with cloud sandboxing, inline TLS decryption, and Advanced Threat Prevention — a full inline IPS native to PAN-OS — built into the same appliance.","website":"https://www.paloaltonetworks.com/network-security/next-generation-firewall","sourceUrls":["https://www.paloaltonetworks.com/network-security/next-generation-firewall"],"verifiedAt":"2026-07-11"},{"slug":"fortinet-fortigate","name":"FortiGate","vendorSlug":"fortinet","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking"],"deployment":["on-prem","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"Fortinet's NGFW appliance line, running FortiOS on purpose-built security processing units that offload TLS decryption and threat inspection — including FortiGuard's native inline IPS — for higher throughput per dollar than software-only…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Fortinet's NGFW appliance line, running FortiOS on purpose-built security processing units that offload TLS decryption and threat inspection — including FortiGuard's native inline IPS — for higher throughput per dollar than software-only competitors. Models scale from desktop branch devices to chassis-based data-center firewalls under one management fabric, FortiManager.","website":"https://www.fortinet.com/products/next-generation-firewall","sourceUrls":["https://www.fortinet.com/products/next-generation-firewall"],"verifiedAt":"2026-07-11"},{"slug":"cisco-secure-firewall","name":"Cisco Secure Firewall","vendorSlug":"cisco","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking"],"deployment":["on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"Cisco's NGFW hardware line (renamed from Firepower), running Secure Firewall Threat Defense software with Snort 3 as its built-in intrusion prevention engine.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Cisco's NGFW hardware line (renamed from Firepower), running Secure Firewall Threat Defense software with Snort 3 as its built-in intrusion prevention engine. Managed through Secure Firewall Management Center, it integrates natively with Cisco's broader networking gear in Cisco-heavy environments.","website":"https://www.cisco.com/site/us/en/products/security/firewalls/index.html","sourceUrls":["https://www.cisco.com/site/us/en/products/security/firewalls/index.html"],"verifiedAt":"2026-07-11"},{"slug":"check-point-quantum-force","name":"Check Point Quantum Force","vendorSlug":"check-point","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking","behavioral-anomaly-detection"],"deployment":["on-prem","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"Check Point's current NGFW appliance line, running Quantum Firewall Software and managed through the Infinity Portal.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Check Point's current NGFW appliance line, running Quantum Firewall Software and managed through the Infinity Portal. SandBlast Zero-Day Protection sandboxes unknown files before they reach the network, its IPS software blade blocks known exploits inline, and threat prevention policy is shared with Check Point's cloud and SASE products.","website":"https://www.checkpoint.com/quantum/next-generation-firewall/","sourceUrls":["https://www.checkpoint.com/quantum/next-generation-firewall/"],"verifiedAt":"2026-07-11"},{"slug":"hpe-juniper-networking-srx","name":"HPE Juniper Networking SRX Series","vendorSlug":"juniper-networks","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking","behavioral-anomaly-detection"],"deployment":["on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"Juniper's NGFW line, running Junos OS with a native IDP (intrusion detection and prevention) engine, and long favored in service-provider and large-enterprise networks for routing performance alongside firewalling.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Juniper's NGFW line, running Junos OS with a native IDP (intrusion detection and prevention) engine, and long favored in service-provider and large-enterprise networks for routing performance alongside firewalling. Now sold as HPE Juniper Networking SRX following HPE's July 2025 acquisition close, with AI-driven Mist management increasingly folded into the operating model.","website":"https://www.hpe.com/us/en/juniper-srx-firewall.html","sourceUrls":["https://www.hpe.com/us/en/juniper-srx-firewall.html"],"verifiedAt":"2026-07-11"},{"slug":"sonicwall-gen8-firewalls","name":"SonicWall Gen 8 Firewalls","vendorSlug":"sonicwall","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking"],"deployment":["on-prem","hybrid"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"$","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"SonicWall's TZ and NSa appliance lines, positioned as lower-cost NGFWs for small and mid-sized organizations and the MSPs that manage them at scale.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the lower relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"SonicWall's TZ and NSa appliance lines, positioned as lower-cost NGFWs for small and mid-sized organizations and the MSPs that manage them at scale. Built-in intrusion prevention with over 10,000 signatures, Capture ATP sandboxing, and DPI-SSL inspection are managed centrally through Capture Security Center across a customer's whole fleet of boxes.","website":"https://www.sonicwall.com/products/firewalls","sourceUrls":["https://www.sonicwall.com/products/firewalls"],"verifiedAt":"2026-07-11"},{"slug":"watchguard-firebox","name":"WatchGuard Firebox","vendorSlug":"watchguard","productType":"software","openSource":false,"categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["app-awareness","intrusion-prevention","ssl-inspection","url-content-filtering","sandboxing","centralized-management","vpn-remote-access","signature-detection","inline-blocking"],"deployment":["on-prem","hybrid"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"$","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"WatchGuard's UTM appliance line, running Fireware with an inline IPS among its security services and aimed at small and mid-sized businesses through a channel-partner and MSP model rather than direct enterprise sales.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection in a proof of concept.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the lower relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"app-awareness":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"WatchGuard's UTM appliance line, running Fireware with an inline IPS among its security services and aimed at small and mid-sized businesses through a channel-partner and MSP model rather than direct enterprise sales. WatchGuard Cloud centralizes configuration and reporting across a partner's whole customer base from one console.","website":"https://www.watchguard.com/wgrd-products/firewalls","sourceUrls":["https://www.watchguard.com/wgrd-products/firewalls"],"verifiedAt":"2026-07-11"},{"slug":"pfsense","name":"pfSense CE","vendorSlug":"netgate","productType":"distribution","openSource":true,"license":"Apache-2.0","categorySlugs":["ngfw"],"capabilities":["intrusion-prevention","url-content-filtering","vpn-remote-access","centralized-management"],"deployment":["on-prem","hybrid"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"A free, open-source firewall and router distribution built on FreeBSD, self-hosted on commodity hardware or a virtual machine.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection before standardizing.","ecosystem":"Primary fit is Next-Generation Firewall. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"app-awareness":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A free, open-source firewall and router distribution built on FreeBSD, self-hosted on commodity hardware or a virtual machine. Intrusion prevention and content filtering come from add-on packages (Suricata/Snort, pfBlockerNG) rather than a single built-in engine; Netgate also sells a proprietary pfSense Plus edition and preconfigured appliances.","website":"https://www.pfsense.org","sourceUrls":["https://www.pfsense.org"],"verifiedAt":"2026-07-11"},{"slug":"opnsense","name":"OPNsense","vendorSlug":"deciso","productType":"distribution","openSource":true,"license":"BSD-2-Clause","categorySlugs":["ngfw","ids-ips-ndr"],"capabilities":["intrusion-prevention","url-content-filtering","vpn-remote-access","centralized-management","signature-detection","inline-blocking"],"deployment":["on-prem","hybrid"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Next-Generation Firewall with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"An open-source firewall and router platform forked from pfSense/m0n0wall in 2015, built on HardenedBSD with Suricata-based intrusion prevention in its base system, plus a plugin ecosystem for WireGuard/IPsec VPN and content filtering.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Application awareness, Built-in intrusion prevention, and Encrypted traffic inspection before standardizing.","ecosystem":"Primary fit is Next-Generation Firewall; this guide also maps the product to Intrusion Detection & Network Detection and Response. Confirm the integrations required by the existing stack.","licensing":"The dataset records the BSD-2-Clause license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"app-awareness":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"intrusion-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ssl-inspection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"url-content-filtering":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"centralized-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vpn-remote-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source firewall and router platform forked from pfSense/m0n0wall in 2015, built on HardenedBSD with Suricata-based intrusion prevention in its base system, plus a plugin ecosystem for WireGuard/IPsec VPN and content filtering. Fully open with no crippled free tier — Deciso monetizes through support contracts and its own hardware rather than a paid software edition.","website":"https://opnsense.org","sourceUrls":["https://opnsense.org"],"verifiedAt":"2026-07-11"},{"slug":"darktrace-network","name":"Darktrace / NETWORK","vendorSlug":"darktrace","productType":"software","openSource":false,"categorySlugs":["ids-ips-ndr"],"capabilities":["behavioral-anomaly-detection","east-west-visibility","inline-blocking","encrypted-traffic-analysis","threat-intel-integration"],"deployment":["on-prem","hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted, hybrid, and SaaS operating model.","keyAdvantage":"The network module of Darktrace's ActiveAI Security Platform, which builds a continuously updated behavioral model of an organization's traffic rather than matching known attack signatures.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility in a proof of concept.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"signature-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"behavioral-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The network module of Darktrace's ActiveAI Security Platform, which builds a continuously updated behavioral model of an organization's traffic rather than matching known attack signatures. Its Autonomous Response capability can take real-time, proportionate blocking action on traffic that deviates from that learned baseline.","website":"https://www.darktrace.com/products/network","sourceUrls":["https://www.darktrace.com/products/network"],"verifiedAt":"2026-07-11"},{"slug":"corelight-open-ndr","name":"Corelight Open NDR Platform","vendorSlug":"corelight","productType":"software","openSource":false,"categorySlugs":["ids-ips-ndr"],"capabilities":["packet-capture-forensics","signature-detection","east-west-visibility","threat-intel-integration","encrypted-traffic-analysis"],"deployment":["on-prem","hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted, hybrid, and SaaS operating model.","keyAdvantage":"A commercial network detection platform built around the open-source Zeek framework its founders created, generating rich structured connection and protocol logs rather than raw packet dumps.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility in a proof of concept.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A commercial network detection platform built around the open-source Zeek framework its founders created, generating rich structured connection and protocol logs rather than raw packet dumps. Bundles a Suricata signature engine and JA3/JA3S encrypted-traffic fingerprinting alongside Zeek's native logging.","website":"https://corelight.com/products/open-ndr/","sourceUrls":["https://corelight.com/products/open-ndr/"],"verifiedAt":"2026-07-11"},{"slug":"extrahop-revealx-360","name":"ExtraHop RevealX","vendorSlug":"extrahop","productType":"software","openSource":false,"categorySlugs":["ids-ips-ndr"],"capabilities":["behavioral-anomaly-detection","east-west-visibility","encrypted-traffic-analysis","threat-intel-integration","packet-capture-forensics"],"deployment":["hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a hybrid and SaaS operating model.","keyAdvantage":"ExtraHop's NDR platform, decrypting and analyzing east-west traffic at the packet level to build behavioral baselines without deploying agents on every host.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility in a proof of concept.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"signature-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"behavioral-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"ExtraHop's NDR platform, decrypting and analyzing east-west traffic at the packet level to build behavioral baselines without deploying agents on every host. Sensors capture and forward traffic to a SaaS analytics tier, with full-packet retrieval available for post-incident investigation.","website":"https://www.extrahop.com/platform/revealx","sourceUrls":["https://www.extrahop.com/platform/revealx"],"verifiedAt":"2026-07-11"},{"slug":"vectra-ai-platform","name":"Vectra AI Platform","vendorSlug":"vectra-ai","productType":"software","openSource":false,"categorySlugs":["ids-ips-ndr"],"capabilities":["behavioral-anomaly-detection","east-west-visibility","threat-intel-integration","encrypted-traffic-analysis"],"deployment":["hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a hybrid and SaaS operating model.","keyAdvantage":"A cloud-delivered NDR platform marketed under the Attack Signal Intelligence brand, correlating behavioral detections across network, identity, and cloud telemetry rather than network traffic alone.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility in a proof of concept.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"signature-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"behavioral-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A cloud-delivered NDR platform marketed under the Attack Signal Intelligence brand, correlating behavioral detections across network, identity, and cloud telemetry rather than network traffic alone. Prioritization scoring is aimed at cutting the number of alerts an analyst has to triage down to the ones that represent a real attack progression.","website":"https://www.vectra.ai/platform","sourceUrls":["https://www.vectra.ai/platform"],"verifiedAt":"2026-07-11"},{"slug":"snort","name":"Snort","vendorSlug":"cisco","productType":"software","openSource":true,"license":"GPL-2.0","categorySlugs":["ids-ips-ndr"],"capabilities":["signature-detection","inline-blocking","threat-intel-integration","packet-capture-forensics"],"deployment":["on-prem","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted and command-line operating model.","keyAdvantage":"An open-source intrusion detection and prevention engine that matches network traffic against an actively maintained ruleset.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility before standardizing.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the GPL-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source intrusion detection and prevention engine that matches network traffic against an actively maintained ruleset. Cisco maintains Snort 3 following its 2013 acquisition of Sourcefire and uses the engine inside Cisco Secure Firewall.","website":"https://www.snort.org","sourceUrls":["https://www.snort.org"],"verifiedAt":"2026-07-11"},{"slug":"suricata","name":"Suricata","productType":"project","openSource":true,"license":"GPL-2.0","categorySlugs":["ids-ips-ndr"],"capabilities":["signature-detection","inline-blocking","packet-capture-forensics","encrypted-traffic-analysis","threat-intel-integration"],"deployment":["on-prem","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted and command-line operating model.","keyAdvantage":"An open-source IDS/IPS engine maintained by the nonprofit Open Information Security Foundation, compatible with Snort-style rulesets while adding multi-threaded performance and richer built-in protocol and TLS/JA3 logging.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility before standardizing.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the GPL-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An open-source IDS/IPS engine maintained by the nonprofit Open Information Security Foundation, compatible with Snort-style rulesets while adding multi-threaded performance and richer built-in protocol and TLS/JA3 logging. Frequently deployed as the detection engine inside larger platforms such as Security Onion.","website":"https://suricata.io","sourceUrls":["https://suricata.io"],"verifiedAt":"2026-07-11"},{"slug":"zeek","name":"Zeek","productType":"project","openSource":true,"license":"BSD-3-Clause","categorySlugs":["ids-ips-ndr"],"capabilities":["packet-capture-forensics","east-west-visibility","encrypted-traffic-analysis","threat-intel-integration"],"deployment":["on-prem","cli"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted and command-line operating model.","keyAdvantage":"An open-source network security monitor (formerly named Bro) that transforms raw traffic into detailed, structured logs of every connection and protocol transaction rather than matching signatures directly.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility before standardizing.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the BSD-3-Clause license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"signature-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An open-source network security monitor (formerly named Bro) that transforms raw traffic into detailed, structured logs of every connection and protocol transaction rather than matching signatures directly. Its scripting language lets analysts build custom detection logic on top of that log stream, and it underlies several commercial NDR products, including Corelight.","website":"https://zeek.org","sourceUrls":["https://zeek.org"],"verifiedAt":"2026-07-11"},{"slug":"security-onion","name":"Security Onion","vendorSlug":"security-onion-solutions","productType":"distribution","openSource":false,"categorySlugs":["ids-ips-ndr"],"capabilities":["signature-detection","packet-capture-forensics","east-west-visibility","threat-intel-integration","encrypted-traffic-analysis"],"deployment":["on-prem","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"A free Linux distribution that bundles Suricata, Zeek, and the Elastic Stack into a ready-to-deploy network security monitoring platform, saving a team from integrating those tools by hand.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility in a proof of concept.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"signature-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A free Linux distribution that bundles Suricata, Zeek, and the Elastic Stack into a ready-to-deploy network security monitoring platform, saving a team from integrating those tools by hand. Distributed under the Elastic License 2.0 rather than an OSI-approved open-source license, so it is free to use but source-available rather than fully open source.","website":"https://securityonionsolutions.com","sourceUrls":["https://securityonionsolutions.com"],"verifiedAt":"2026-07-11"},{"slug":"nmap","name":"Nmap","productType":"project","openSource":false,"categorySlugs":["ids-ips-ndr"],"capabilities":["east-west-visibility"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a command-line operating model.","keyAdvantage":"The standard command-line network scanner for discovering live hosts, open ports, and running services, used by defenders for asset inventory and by attackers for reconnaissance alike.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility in a proof of concept.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"signature-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"packet-capture-forensics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The standard command-line network scanner for discovering live hosts, open ports, and running services, used by defenders for asset inventory and by attackers for reconnaissance alike. Distributed under the Nmap Public Source License, which restricts commercial redistribution and is not an OSI-approved open-source license, so it is free to use but source-available rather than open source.","website":"https://nmap.org","sourceUrls":["https://nmap.org"],"verifiedAt":"2026-07-11"},{"slug":"wireshark","name":"Wireshark","productType":"project","openSource":true,"license":"GPL-2.0","categorySlugs":["ids-ips-ndr"],"capabilities":["packet-capture-forensics"],"deployment":["on-prem","cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Intrusion Detection & Network Detection and Response with a preference for a self-hosted and command-line operating model.","keyAdvantage":"The standard graphical packet analyzer for capturing and manually inspecting network traffic down to the individual field, widely used for troubleshooting and forensic investigation rather than automated detection.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Signature-based detection, Behavioral anomaly detection, and East-west traffic visibility before standardizing.","ecosystem":"Primary fit is Intrusion Detection & Network Detection and Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the GPL-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"signature-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"behavioral-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"east-west-visibility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"packet-capture-forensics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"threat-intel-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encrypted-traffic-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The standard graphical packet analyzer for capturing and manually inspecting network traffic down to the individual field, widely used for troubleshooting and forensic investigation rather than automated detection. Maintained by the nonprofit Wireshark Foundation, with the tshark command-line variant used for scripted or headless capture.","website":"https://www.wireshark.org","sourceUrls":["https://www.wireshark.org"],"verifiedAt":"2026-07-11"},{"slug":"zscaler-zero-trust-exchange","name":"Zscaler Zero Trust Exchange","vendorSlug":"zscaler","productType":"software","openSource":false,"categorySlugs":["sase-ztna"],"capabilities":["ztna-private-access","secure-web-gateway","cloud-delivered-pops","casb-controls","inline-dlp","unified-policy-engine"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating SASE, SSE & Zero Trust Network Access with a preference for a SaaS operating model.","keyAdvantage":"Zscaler's combined secure web gateway (Zscaler Internet Access) and zero trust private access (Zscaler Private Access) products, delivered entirely from Zscaler's global network of cloud points of presence rather than customer-managed…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Zero trust private app access, Secure web gateway (SWG), and SD-WAN connectivity in a proof of concept.","ecosystem":"Primary fit is SASE, SSE & Zero Trust Network Access. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ztna-private-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secure-web-gateway":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sd-wan":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"cloud-delivered-pops":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"casb-controls":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"unified-policy-engine":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Zscaler's combined secure web gateway (Zscaler Internet Access) and zero trust private access (Zscaler Private Access) products, delivered entirely from Zscaler's global network of cloud points of presence rather than customer-managed appliances. Users connect out to the nearest node instead of backhauling traffic to a data center, with policy enforced consistently regardless of location.","website":"https://www.zscaler.com/products-and-solutions/zero-trust-exchange-zte","sourceUrls":["https://www.zscaler.com/products-and-solutions/zero-trust-exchange-zte"],"verifiedAt":"2026-07-11"},{"slug":"netskope-one","name":"Netskope One","vendorSlug":"netskope","productType":"software","openSource":false,"categorySlugs":["sase-ztna"],"capabilities":["ztna-private-access","secure-web-gateway","casb-controls","inline-dlp","cloud-delivered-pops","unified-policy-engine"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating SASE, SSE & Zero Trust Network Access with a preference for a SaaS operating model.","keyAdvantage":"Netskope's converged SASE platform, built out from the company's original CASB product and carrying particularly deep SaaS visibility and data-loss-prevention controls into its zero trust access and web gateway components.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Zero trust private app access, Secure web gateway (SWG), and SD-WAN connectivity in a proof of concept.","ecosystem":"Primary fit is SASE, SSE & Zero Trust Network Access. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ztna-private-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secure-web-gateway":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sd-wan":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"cloud-delivered-pops":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"casb-controls":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"unified-policy-engine":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Netskope's converged SASE platform, built out from the company's original CASB product and carrying particularly deep SaaS visibility and data-loss-prevention controls into its zero trust access and web gateway components. Netskope completed its IPO on Nasdaq in September 2025.","website":"https://www.netskope.com/netskope-one","sourceUrls":["https://www.netskope.com/netskope-one"],"verifiedAt":"2026-07-11"},{"slug":"cloudflare-one","name":"Cloudflare One","vendorSlug":"cloudflare","productType":"software","openSource":false,"categorySlugs":["sase-ztna"],"capabilities":["ztna-private-access","secure-web-gateway","sd-wan","cloud-delivered-pops","inline-dlp","unified-policy-engine"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating SASE, SSE & Zero Trust Network Access with a preference for a SaaS operating model.","keyAdvantage":"Cloudflare's SASE platform, built on the same global anycast network that carries its CDN and DNS traffic rather than a separate purpose-built edge.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Zero trust private app access, Secure web gateway (SWG), and SD-WAN connectivity in a proof of concept.","ecosystem":"Primary fit is SASE, SSE & Zero Trust Network Access. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ztna-private-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secure-web-gateway":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sd-wan":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"cloud-delivered-pops":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"casb-controls":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"unified-policy-engine":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Cloudflare's SASE platform, built on the same global anycast network that carries its CDN and DNS traffic rather than a separate purpose-built edge. Cloudflare Access provides zero trust private-app connections and Magic WAN ties branch-site SD-WAN connectivity into the same fabric as web gateway and DLP policy.","website":"https://www.cloudflare.com/sase/","sourceUrls":["https://www.cloudflare.com/sase/"],"verifiedAt":"2026-07-11"},{"slug":"prisma-sase","name":"Prisma SASE","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["sase-ztna"],"capabilities":["ztna-private-access","secure-web-gateway","sd-wan","casb-controls","inline-dlp","cloud-delivered-pops","unified-policy-engine"],"deployment":["saas","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating SASE, SSE & Zero Trust Network Access with a preference for a SaaS and hybrid operating model.","keyAdvantage":"Palo Alto Networks' SASE platform, combining Prisma Access (cloud-delivered zero trust access and secure web gateway) with Prisma SD-WAN branch connectivity — the latter inherited from its 2020 acquisition of CloudGenix.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Zero trust private app access, Secure web gateway (SWG), and SD-WAN connectivity in a proof of concept.","ecosystem":"Primary fit is SASE, SSE & Zero Trust Network Access. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ztna-private-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secure-web-gateway":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sd-wan":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"cloud-delivered-pops":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"casb-controls":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"inline-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"unified-policy-engine":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Palo Alto Networks' SASE platform, combining Prisma Access (cloud-delivered zero trust access and secure web gateway) with Prisma SD-WAN branch connectivity — the latter inherited from its 2020 acquisition of CloudGenix. Both are managed through Strata Cloud Manager, the same console used for the company's on-prem NGFWs.","website":"https://www.paloaltonetworks.com/sase","sourceUrls":["https://www.paloaltonetworks.com/sase"],"verifiedAt":"2026-07-11"},{"slug":"tailscale","name":"Tailscale","vendorSlug":"tailscale","productType":"software","openSource":false,"categorySlugs":["sase-ztna"],"capabilities":["ztna-private-access","unified-policy-engine"],"deployment":["agent","saas"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating SASE, SSE & Zero Trust Network Access with a preference for a endpoint-agent and SaaS operating model.","keyAdvantage":"A mesh VPN built on the WireGuard protocol that connects devices directly to one another peer-to-peer instead of routing traffic through a central gateway.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Zero trust private app access, Secure web gateway (SWG), and SD-WAN connectivity in a proof of concept.","ecosystem":"Primary fit is SASE, SSE & Zero Trust Network Access. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ztna-private-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secure-web-gateway":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sd-wan":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"cloud-delivered-pops":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"casb-controls":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"unified-policy-engine":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A mesh VPN built on the WireGuard protocol that connects devices directly to one another peer-to-peer instead of routing traffic through a central gateway. A lightweight agent runs on each device, with a hosted coordination server (or self-hosted Headscale alternative) handling key exchange and an ACL-based access policy.","website":"https://tailscale.com","sourceUrls":["https://tailscale.com"],"verifiedAt":"2026-07-11"},{"slug":"twingate","name":"Twingate","vendorSlug":"twingate","productType":"software","openSource":false,"categorySlugs":["sase-ztna"],"capabilities":["ztna-private-access","unified-policy-engine","cloud-delivered-pops"],"deployment":["agent","saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating SASE, SSE & Zero Trust Network Access with a preference for a endpoint-agent and SaaS operating model.","keyAdvantage":"A zero trust network access product built specifically to replace corporate VPNs, using lightweight connectors deployed inside the private network rather than requiring inbound firewall rules or a public IP for internal resources.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Zero trust private app access, Secure web gateway (SWG), and SD-WAN connectivity in a proof of concept.","ecosystem":"Primary fit is SASE, SSE & Zero Trust Network Access. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ztna-private-access":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secure-web-gateway":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sd-wan":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"cloud-delivered-pops":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"casb-controls":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"inline-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"unified-policy-engine":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A zero trust network access product built specifically to replace corporate VPNs, using lightweight connectors deployed inside the private network rather than requiring inbound firewall rules or a public IP for internal resources. Access policy is managed centrally and enforced per application rather than granting broad network reachability.","website":"https://www.twingate.com","sourceUrls":["https://www.twingate.com"],"verifiedAt":"2026-07-11"},{"slug":"cloudflare-magic-transit","name":"Cloudflare Magic Transit","vendorSlug":"cloudflare","productType":"software","openSource":false,"categorySlugs":["ddos-protection"],"capabilities":["volumetric-mitigation","traffic-redirection","scrubbing-capacity","always-on-vs-on-demand"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating DDoS Protection with a preference for a SaaS operating model.","keyAdvantage":"Network-layer DDoS protection that routes a customer's whole IP range through Cloudflare's global network via BGP announcement, scrubbing volumetric attacks before clean traffic is forwarded on.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Volumetric attack mitigation, Application-layer (L7) protection, and Always-on or on-demand mitigation in a proof of concept.","ecosystem":"Primary fit is DDoS Protection. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"volumetric-mitigation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"layer7-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"always-on-vs-on-demand":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"scrubbing-capacity":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"traffic-redirection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"mitigation-response-time":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Network-layer DDoS protection that routes a customer's whole IP range through Cloudflare's global network via BGP announcement, scrubbing volumetric attacks before clean traffic is forwarded on. Application-layer (L7) DDoS and WAF protection are handled by a separate part of Cloudflare's platform layered on top of the same edge.","website":"https://www.cloudflare.com/network-services/products/magic-transit/","sourceUrls":["https://www.cloudflare.com/network-services/products/magic-transit/"],"verifiedAt":"2026-07-11"},{"slug":"akamai-prolexic","name":"Akamai Prolexic","vendorSlug":"akamai","productType":"software","openSource":false,"categorySlugs":["ddos-protection"],"capabilities":["volumetric-mitigation","layer7-protection","always-on-vs-on-demand","scrubbing-capacity","traffic-redirection","mitigation-response-time"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating DDoS Protection with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"Akamai's DDoS mitigation service, built on the Prolexic technology it acquired in 2014 and sold in cloud-routed, on-premises, and hybrid configurations depending on how much latency and control a customer needs.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Volumetric attack mitigation, Application-layer (L7) protection, and Always-on or on-demand mitigation in a proof of concept.","ecosystem":"Primary fit is DDoS Protection. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"volumetric-mitigation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"layer7-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"always-on-vs-on-demand":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"scrubbing-capacity":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"traffic-redirection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"mitigation-response-time":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Akamai's DDoS mitigation service, built on the Prolexic technology it acquired in 2014 and sold in cloud-routed, on-premises, and hybrid configurations depending on how much latency and control a customer needs. Always-on cloud routing and on-demand activation are both available, backed by a distributed scrubbing network sized well beyond any single customer's normal traffic.","website":"https://www.akamai.com/products/prolexic-solutions","sourceUrls":["https://www.akamai.com/products/prolexic-solutions"],"verifiedAt":"2026-07-11"},{"slug":"radware-defensepro","name":"Radware DefensePro","vendorSlug":"radware","productType":"software","openSource":false,"categorySlugs":["ddos-protection"],"capabilities":["volumetric-mitigation","layer7-protection","always-on-vs-on-demand","scrubbing-capacity","traffic-redirection","mitigation-response-time"],"deployment":["on-prem","hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating DDoS Protection with a preference for a self-hosted, hybrid, and SaaS operating model.","keyAdvantage":"Radware's DDoS mitigation appliance, deployable on-premises for the fastest local response and paired with the vendor's Cloud DDoS Protection Service for volumetric attacks that exceed local link capacity.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Volumetric attack mitigation, Application-layer (L7) protection, and Always-on or on-demand mitigation in a proof of concept.","ecosystem":"Primary fit is DDoS Protection. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"volumetric-mitigation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"layer7-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"always-on-vs-on-demand":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"scrubbing-capacity":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"traffic-redirection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"mitigation-response-time":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Radware's DDoS mitigation appliance, deployable on-premises for the fastest local response and paired with the vendor's Cloud DDoS Protection Service for volumetric attacks that exceed local link capacity. Behavioral algorithms are built to auto-tune detection thresholds rather than relying only on static rate limits.","website":"https://www.radware.com/products/defensepro/","sourceUrls":["https://www.radware.com/products/defensepro/"],"verifiedAt":"2026-07-11"},{"slug":"netscout-arbor-edge-defense","name":"NETSCOUT Arbor Edge Defense","vendorSlug":"netscout","productType":"software","openSource":false,"categorySlugs":["ddos-protection"],"capabilities":["volumetric-mitigation","traffic-redirection","always-on-vs-on-demand","mitigation-response-time","scrubbing-capacity"],"deployment":["on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating DDoS Protection with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"An inline, stateless on-premises appliance placed at the network edge for the first line of DDoS defense, descended from Arbor Networks' Peakflow/Sightline product line following NETSCOUT's 2015 acquisition of Arbor.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Volumetric attack mitigation, Application-layer (L7) protection, and Always-on or on-demand mitigation in a proof of concept.","ecosystem":"Primary fit is DDoS Protection. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"volumetric-mitigation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"layer7-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"always-on-vs-on-demand":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"scrubbing-capacity":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"traffic-redirection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"mitigation-response-time":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An inline, stateless on-premises appliance placed at the network edge for the first line of DDoS defense, descended from Arbor Networks' Peakflow/Sightline product line following NETSCOUT's 2015 acquisition of Arbor. Cloud signaling automatically escalates to NETSCOUT's Arbor Cloud scrubbing service when an attack exceeds what the local appliance can absorb.","website":"https://www.netscout.com/product/arbor-edge-defense","sourceUrls":["https://www.netscout.com/product/arbor-edge-defense"],"verifiedAt":"2026-07-11"},{"slug":"wiz","name":"Wiz","vendorSlug":"wiz","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","iac-scanning","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS operating model.","keyAdvantage":"The agentless CNAPP that connects to cloud accounts through provider APIs and builds a security graph of resources, identities, network exposure, and data, correlating findings into attack paths rather than flat lists.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The agentless CNAPP that connects to cloud accounts through provider APIs and builds a security graph of resources, identities, network exposure, and data, correlating findings into attack paths rather than flat lists. Google's ~$32B acquisition of Wiz closed in March 2026; the platform continues under the Wiz brand inside Google Cloud and remains multi-cloud.","website":"https://www.wiz.io","sourceUrls":["https://www.wiz.io","https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/"],"verifiedAt":"2026-07-11"},{"slug":"orca-cloud-security","name":"Orca Cloud Security Platform","vendorSlug":"orca-security","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","iac-scanning","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS operating model.","keyAdvantage":"Orca's agentless CNAPP, built on its patented SideScanning technique: workload block storage is read out-of-band through cloud provider APIs, so vulnerabilities, malware, and misconfigurations are inventoried without installing anything…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Orca's agentless CNAPP, built on its patented SideScanning technique: workload block storage is read out-of-band through cloud provider APIs, so vulnerabilities, malware, and misconfigurations are inventoried without installing anything on the workload. Findings across posture, workloads, identities, and data feed one unified risk model.","website":"https://orca.security","sourceUrls":["https://orca.security"],"verifiedAt":"2026-07-11"},{"slug":"cortex-cloud","name":"Cortex Cloud","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","iac-scanning","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Palo Alto Networks' cloud security platform, introduced in 2025 as the successor to Prisma Cloud and merging its CNAPP capabilities with Cortex detection and response on one data foundation.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Palo Alto Networks' cloud security platform, introduced in 2025 as the successor to Prisma Cloud and merging its CNAPP capabilities with Cortex detection and response on one data foundation. Both names remain in use during the multi-year customer migration, with Cortex Cloud as the go-forward brand.","website":"https://www.paloaltonetworks.com/cortex/cloud","sourceUrls":["https://www.paloaltonetworks.com/cortex/cloud"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-defender-for-cloud","name":"Microsoft Defender for Cloud","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","attack-path-analysis","iac-scanning","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Microsoft's CNAPP, native to Azure and extended to AWS and Google Cloud through connectors.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Microsoft's CNAPP, native to Azure and extended to AWS and Google Cloud through connectors. Foundational posture recommendations are free for Azure customers; paid Defender plans add agentless workload scanning, attack path analysis, DevOps/IaC scanning, and runtime protection for servers, containers, and databases, priced per resource.","website":"https://www.microsoft.com/en-us/security/business/cloud-security/microsoft-defender-cloud/","sourceUrls":["https://www.microsoft.com/en-us/security/business/cloud-security/microsoft-defender-cloud/"],"verifiedAt":"2026-07-11"},{"slug":"lacework-forticnapp","name":"Lacework FortiCNAPP","vendorSlug":"fortinet","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Fortinet's CNAPP, built from its August 2024 acquisition of Lacework and centered on the Polygraph engine, which baselines normal cloud activity and flags behavioral anomalies rather than relying only on static rules.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Fortinet's CNAPP, built from its August 2024 acquisition of Lacework and centered on the Polygraph engine, which baselines normal cloud activity and flags behavioral anomalies rather than relying only on static rules. Increasingly branded simply FortiCNAPP and integrated with the broader Fortinet Security Fabric.","website":"https://www.fortinet.com/products/forticnapp","sourceUrls":["https://www.fortinet.com/products/forticnapp"],"verifiedAt":"2026-07-11"},{"slug":"upwind","name":"Upwind","vendorSlug":"upwind","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","attack-path-analysis","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"A runtime-focused CNAPP from the founders of Spot.io.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A runtime-focused CNAPP from the founders of Spot.io. Its eBPF sensors add live workload, exposure, and usage context to posture findings so teams can distinguish active attack paths from dormant configuration issues.","website":"https://www.upwind.io","sourceUrls":["https://www.upwind.io"],"verifiedAt":"2026-07-11"},{"slug":"tenable-cloud-security","name":"Tenable Cloud Security","vendorSlug":"tenable","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","iac-scanning","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS operating model.","keyAdvantage":"Tenable's CNAPP, built on the identity-centric Ermetic platform acquired in October 2023, with cloud entitlement analysis (CIEM) as a particular strength alongside agentless posture and workload scanning.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Tenable's CNAPP, built on the identity-centric Ermetic platform acquired in October 2023, with cloud entitlement analysis (CIEM) as a particular strength alongside agentless posture and workload scanning. Increasingly folded into the Tenable One exposure management platform, where cloud findings sit beside the company's vulnerability data.","website":"https://www.tenable.com/solutions/cloud-security","sourceUrls":["https://www.tenable.com/solutions/cloud-security"],"verifiedAt":"2026-07-11"},{"slug":"check-point-cloudguard-cnapp","name":"CloudGuard CNAPP","vendorSlug":"check-point","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","iac-scanning","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS operating model.","keyAdvantage":"Check Point's cloud posture and workload protection line, now delivered through its strategic partnership with Wiz rather than as a native product: the partnership (GA September 2025) pairs Wiz's CNAPP with Check Point Cloud Firewall for…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Check Point's cloud posture and workload protection line, now delivered through its strategic partnership with Wiz rather than as a native product: the partnership (GA September 2025) pairs Wiz's CNAPP with Check Point Cloud Firewall for enforcement, and existing CloudGuard CNAPP customers were offered assisted migration to Wiz.","website":"https://www.checkpoint.com/cloudguard/wiz/","sourceUrls":["https://www.checkpoint.com/cloudguard/wiz/"],"verifiedAt":"2026-07-11"},{"slug":"crowdstrike-falcon-cloud-security","name":"Falcon Cloud Security","vendorSlug":"crowdstrike","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","entitlement-management","attack-path-analysis","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"CrowdStrike's CNAPP, pairing agentless posture assessment with the same Falcon sensor used for endpoint protection to add runtime cloud workload defense — one agent and console spanning endpoints and cloud infrastructure.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"CrowdStrike's CNAPP, pairing agentless posture assessment with the same Falcon sensor used for endpoint protection to add runtime cloud workload defense — one agent and console spanning endpoints and cloud infrastructure. Detections feed the same threat intelligence and managed hunting services as the rest of the Falcon platform.","website":"https://www.crowdstrike.com/en-us/platform/cloud-security/","sourceUrls":["https://www.crowdstrike.com/en-us/platform/cloud-security/"],"verifiedAt":"2026-07-11"},{"slug":"sentinelone-singularity-cloud-security","name":"Singularity Cloud Security","vendorSlug":"sentinelone","productType":"software","openSource":false,"categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","agentless-scanning","attack-path-analysis","vulnerability-prioritization","compliance-benchmarks"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"SentinelOne's CNAPP, assembled around the agentless PingSafe platform acquired in 2024 plus the Singularity agent for runtime cloud workload protection.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) in a proof of concept.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"SentinelOne's CNAPP, assembled around the agentless PingSafe platform acquired in 2024 plus the Singularity agent for runtime cloud workload protection. Its offensive security engine safely attempts to exploit discovered issues to verify which findings are actually attackable before they reach an analyst's queue.","website":"https://www.sentinelone.com/platform/cloud-security/","sourceUrls":["https://www.sentinelone.com/platform/cloud-security/"],"verifiedAt":"2026-07-11"},{"slug":"prowler","name":"Prowler","vendorSlug":"prowler","productType":"software","openSource":true,"license":"Apache-2.0","categorySlugs":["cnapp-cspm"],"capabilities":["misconfiguration-detection","compliance-benchmarks"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a command-line operating model.","keyAdvantage":"An open-source cloud security assessment tool that began in 2016 as an AWS auditing script and now runs hundreds of posture checks across AWS, Azure, Google Cloud, and Kubernetes, mapped to frameworks like CIS, PCI DSS, and SOC 2.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) before standardizing.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"compliance-benchmarks":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An open-source cloud security assessment tool that began in 2016 as an AWS auditing script and now runs hundreds of posture checks across AWS, Azure, Google Cloud, and Kubernetes, mapped to frameworks like CIS, PCI DSS, and SOC 2. The company of the same name, incorporated in 2023 by the project's creator, sells a hosted Prowler Cloud edition.","website":"https://prowler.com","sourceUrls":["https://prowler.com"],"verifiedAt":"2026-07-11"},{"slug":"checkov","name":"Checkov","vendorSlug":"palo-alto-networks","productType":"software","openSource":true,"license":"Apache-2.0","categorySlugs":["cnapp-cspm"],"capabilities":["iac-scanning","misconfiguration-detection"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Cloud-Native Application Protection / Posture Management with a preference for a command-line operating model.","keyAdvantage":"An open-source static analysis tool for infrastructure-as-code, scanning Terraform, CloudFormation, Kubernetes manifests, Helm charts, and Dockerfiles for misconfigurations before anything is deployed.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Misconfiguration detection (CSPM), Agentless workload scanning, and Cloud entitlement management (CIEM) before standardizing.","ecosystem":"Primary fit is Cloud-Native Application Protection / Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"misconfiguration-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agentless-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"compliance-benchmarks":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source static analysis tool for infrastructure-as-code, scanning Terraform, CloudFormation, Kubernetes manifests, Helm charts, and Dockerfiles for misconfigurations before anything is deployed. Created by Bridgecrew, acquired by Palo Alto Networks in 2021, and still actively maintained under the Bridgecrew GitHub organization.","website":"https://www.checkov.io","sourceUrls":["https://www.checkov.io"],"verifiedAt":"2026-07-11"},{"slug":"aqua-platform","name":"Aqua Platform","vendorSlug":"aqua-security","productType":"software","openSource":false,"categorySlugs":["container-kubernetes-security","cnapp-cspm"],"capabilities":["image-scanning","runtime-threat-detection","kubernetes-posture","admission-control","response-actions","registry-scanning"],"deployment":["saas","on-prem","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Container & Kubernetes Security with a preference for a SaaS, self-hosted, and endpoint-agent operating model.","keyAdvantage":"Aqua Security's CNAPP, from one of the earliest dedicated container security vendors, covering the workload lifecycle from image and registry scanning through admission control to runtime protection with drift prevention that blocks…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) in a proof of concept.","ecosystem":"Primary fit is Container & Kubernetes Security; this guide also maps the product to Cloud-Native Application Protection / Posture Management. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"image-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-threat-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"kubernetes-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"admission-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"response-actions":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"registry-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"misconfiguration-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"agentless-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"compliance-benchmarks":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Aqua Security's CNAPP, from one of the earliest dedicated container security vendors, covering the workload lifecycle from image and registry scanning through admission control to runtime protection with drift prevention that blocks anything not present in the original image. The open-source Trivy scanner Aqua maintains also powers parts of the commercial platform.","website":"https://www.aquasec.com","sourceUrls":["https://www.aquasec.com"],"verifiedAt":"2026-07-11"},{"slug":"sysdig-platform","name":"Sysdig Platform","vendorSlug":"sysdig","productType":"software","openSource":false,"categorySlugs":["container-kubernetes-security","cnapp-cspm"],"capabilities":["image-scanning","runtime-threat-detection","kubernetes-posture","admission-control","response-actions","registry-scanning"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Container & Kubernetes Security with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Sysdig's cloud and container security platform, built around runtime detection from the open-source Falco engine the company created and donated to the CNCF.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) in a proof of concept.","ecosystem":"Primary fit is Container & Kubernetes Security; this guide also maps the product to Cloud-Native Application Protection / Posture Management. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"image-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-threat-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"kubernetes-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"admission-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"response-actions":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"registry-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"misconfiguration-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"agentless-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"entitlement-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"compliance-benchmarks":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Sysdig's cloud and container security platform, built around runtime detection from the open-source Falco engine the company created and donated to the CNCF. Runtime context feeds back into vulnerability triage — packages never actually loaded in a running container are deprioritized, cutting the backlog to what is genuinely in use.","website":"https://www.sysdig.com/products/platform","sourceUrls":["https://www.sysdig.com/products/platform"],"verifiedAt":"2026-07-11"},{"slug":"red-hat-advanced-cluster-security","name":"Red Hat Advanced Cluster Security for Kubernetes","vendorSlug":"red-hat","productType":"software","openSource":false,"categorySlugs":["container-kubernetes-security"],"capabilities":["image-scanning","runtime-threat-detection","kubernetes-posture","admission-control"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Container & Kubernetes Security with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"Red Hat's Kubernetes-native security platform, built from its 2021 acquisition of StackRox, whose engine was subsequently open-sourced as the StackRox community project.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) in a proof of concept.","ecosystem":"Primary fit is Container & Kubernetes Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"image-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-threat-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"kubernetes-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"admission-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"registry-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Red Hat's Kubernetes-native security platform, built from its 2021 acquisition of StackRox, whose engine was subsequently open-sourced as the StackRox community project. Policy enforcement spans build, deploy, and runtime phases, with especially deep integration into OpenShift; sold self-managed or as a Red Hat-hosted cloud service.","website":"https://www.redhat.com/en/technologies/cloud-computing/openshift/advanced-cluster-security-kubernetes","sourceUrls":["https://www.redhat.com/en/technologies/cloud-computing/openshift/advanced-cluster-security-kubernetes"],"verifiedAt":"2026-07-11"},{"slug":"trivy","name":"Trivy","vendorSlug":"aqua-security","productType":"software","openSource":true,"license":"Apache-2.0","categorySlugs":["container-kubernetes-security"],"capabilities":["image-scanning","kubernetes-posture"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Container & Kubernetes Security with a preference for a command-line operating model.","keyAdvantage":"A widely used open-source scanner covering container images (OS packages and language dependencies), IaC misconfigurations, exposed secrets, SBOM generation, and live Kubernetes clusters via the Trivy Operator.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) before standardizing.","ecosystem":"Primary fit is Container & Kubernetes Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"image-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-threat-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"kubernetes-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"admission-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"registry-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A widely used open-source scanner covering container images (OS packages and language dependencies), IaC misconfigurations, exposed secrets, SBOM generation, and live Kubernetes clusters via the Trivy Operator. Created and maintained by Aqua Security — despite its ubiquity in cloud-native pipelines it is not a CNCF project.","website":"https://trivy.dev","sourceUrls":["https://trivy.dev"],"verifiedAt":"2026-07-11"},{"slug":"falco","name":"Falco","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["container-kubernetes-security"],"capabilities":["runtime-threat-detection"],"deployment":["on-prem","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Container & Kubernetes Security with a preference for a self-hosted and endpoint-agent operating model.","keyAdvantage":"An open-source runtime security engine that watches Linux kernel system calls to detect anomalous behavior in containers and Kubernetes — a shell spawning in a production pod, an unexpected outbound connection, a sensitive file read.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) before standardizing.","ecosystem":"Primary fit is Container & Kubernetes Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"image-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"runtime-threat-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"kubernetes-posture":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"admission-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"registry-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source runtime security engine that watches Linux kernel system calls to detect anomalous behavior in containers and Kubernetes — a shell spawning in a production pod, an unexpected outbound connection, a sensitive file read. Created by Sysdig, donated to the CNCF in 2018, and a graduated CNCF project since February 2024.","website":"https://falco.org","sourceUrls":["https://falco.org"],"verifiedAt":"2026-07-11"},{"slug":"kyverno","name":"Kyverno","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["container-kubernetes-security"],"capabilities":["admission-control","kubernetes-posture"],"deployment":["on-prem","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Container & Kubernetes Security with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"A policy engine designed specifically for Kubernetes: admission policies are written as plain YAML rather than a separate policy language, validating, mutating, or blocking workloads as they are submitted to the cluster and auditing…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) before standardizing.","ecosystem":"Primary fit is Container & Kubernetes Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"image-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"runtime-threat-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"kubernetes-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"admission-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"registry-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A policy engine designed specifically for Kubernetes: admission policies are written as plain YAML rather than a separate policy language, validating, mutating, or blocking workloads as they are submitted to the cluster and auditing existing resources in the background. Created by Nirmata; a graduated CNCF project since March 2026.","website":"https://kyverno.io","sourceUrls":["https://kyverno.io"],"verifiedAt":"2026-07-11"},{"slug":"open-policy-agent","name":"Open Policy Agent","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["container-kubernetes-security"],"capabilities":["admission-control"],"deployment":["on-prem","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Container & Kubernetes Security with a preference for a self-hosted and command-line operating model.","keyAdvantage":"A general-purpose policy engine that evaluates decisions against policies written in its Rego language, applied to Kubernetes admission control through the Gatekeeper project and well beyond it — API authorization, CI/CD gates, and…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) before standardizing.","ecosystem":"Primary fit is Container & Kubernetes Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"image-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"runtime-threat-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"kubernetes-posture":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"admission-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"registry-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A general-purpose policy engine that evaluates decisions against policies written in its Rego language, applied to Kubernetes admission control through the Gatekeeper project and well beyond it — API authorization, CI/CD gates, and infrastructure policy. A graduated CNCF project since 2021; created at Styra, whose founders moved to Apple in 2025 while OPA continues under CNCF governance.","website":"https://www.openpolicyagent.org","sourceUrls":["https://www.openpolicyagent.org"],"verifiedAt":"2026-07-11"},{"slug":"kubescape","name":"Kubescape","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["container-kubernetes-security"],"capabilities":["kubernetes-posture","image-scanning","runtime-threat-detection"],"deployment":["cli","on-prem"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Container & Kubernetes Security with a preference for a command-line and self-hosted operating model.","keyAdvantage":"An open-source Kubernetes security platform that scans clusters, manifests, and images against hardening frameworks including the NSA-CISA guidance, MITRE ATT&CK, and CIS benchmarks.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Container image scanning, Runtime threat detection, and Kubernetes posture management (KSPM) before standardizing.","ecosystem":"Primary fit is Container & Kubernetes Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"image-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-threat-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"kubernetes-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"admission-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"response-actions":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"registry-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source Kubernetes security platform that scans clusters, manifests, and images against hardening frameworks including the NSA-CISA guidance, MITRE ATT&CK, and CIS benchmarks. Created by ARMO and the first security scanner accepted into the CNCF sandbox; promoted to incubating in 2025, with version 4.0 adding runtime threat detection in 2026.","website":"https://kubescape.io","sourceUrls":["https://kubescape.io"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-defender-for-cloud-apps","name":"Microsoft Defender for Cloud Apps","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["casb"],"capabilities":["shadow-it-discovery","saas-dlp","saas-threat-protection","adaptive-access-control","deployment-modes","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Cloud Access Security Broker with a preference for a SaaS operating model.","keyAdvantage":"Microsoft's CASB (renamed from Microsoft Cloud App Security), bundled in Microsoft 365 E5.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Shadow IT discovery, Sanctioned app data controls, and SaaS threat protection in a proof of concept.","ecosystem":"Primary fit is Cloud Access Security Broker. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"shadow-it-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-threat-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-modes":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Microsoft's CASB (renamed from Microsoft Cloud App Security), bundled in Microsoft 365 E5. Cloud Discovery mines firewall and Defender for Endpoint logs for shadow IT, API connectors govern sanctioned apps, and Conditional Access App Control provides inline session controls wired directly into Entra ID sign-in policy.","website":"https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-cloud-apps","sourceUrls":["https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-cloud-apps"],"verifiedAt":"2026-07-11"},{"slug":"netskope-one-casb","name":"Netskope One CASB","vendorSlug":"netskope","productType":"software","openSource":false,"categorySlugs":["casb"],"capabilities":["shadow-it-discovery","saas-dlp","saas-threat-protection","adaptive-access-control","deployment-modes","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud Access Security Broker with a preference for a SaaS operating model.","keyAdvantage":"The CASB component of the Netskope One platform — the product line Netskope was founded on in 2012 — with instance awareness that distinguishes corporate from personal instances of the same app and applies different policy to each.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Shadow IT discovery, Sanctioned app data controls, and SaaS threat protection in a proof of concept.","ecosystem":"Primary fit is Cloud Access Security Broker. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"shadow-it-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-threat-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-modes":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The CASB component of the Netskope One platform — the product line Netskope was founded on in 2012 — with instance awareness that distinguishes corporate from personal instances of the same app and applies different policy to each. Sold as a module and as part of the broader SASE platform, in both API and inline enforcement modes.","website":"https://www.netskope.com/products/casb","sourceUrls":["https://www.netskope.com/products/casb"],"verifiedAt":"2026-07-11"},{"slug":"skyhigh-casb","name":"Skyhigh Cloud Access Security Broker","vendorSlug":"skyhigh-security","productType":"software","openSource":false,"categorySlugs":["casb"],"capabilities":["shadow-it-discovery","saas-dlp","saas-threat-protection","adaptive-access-control","deployment-modes","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud Access Security Broker with a preference for a SaaS operating model.","keyAdvantage":"The CASB at the core of Skyhigh Security Service Edge, carrying the lineage of Skyhigh Networks — one of the original CASB vendors, founded in 2011, acquired by McAfee in 2018, and spun back out under Symphony Technology Group in 2022.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Shadow IT discovery, Sanctioned app data controls, and SaaS threat protection in a proof of concept.","ecosystem":"Primary fit is Cloud Access Security Broker. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"shadow-it-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-threat-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-modes":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The CASB at the core of Skyhigh Security Service Edge, carrying the lineage of Skyhigh Networks — one of the original CASB vendors, founded in 2011, acquired by McAfee in 2018, and spun back out under Symphony Technology Group in 2022. A large registry of risk-rated cloud services drives shadow IT discovery, with forward and reverse proxy plus API enforcement modes.","website":"https://www.skyhighsecurity.com/products/cloud-access-security-broker.html","sourceUrls":["https://www.skyhighsecurity.com/products/cloud-access-security-broker.html"],"verifiedAt":"2026-07-11"},{"slug":"symantec-cloudsoc","name":"Symantec CloudSOC CASB","vendorSlug":"broadcom","productType":"software","openSource":false,"categorySlugs":["casb"],"capabilities":["shadow-it-discovery","saas-dlp","saas-threat-protection","deployment-modes","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Enterprises evaluating Cloud Access Security Broker with a preference for a SaaS operating model.","keyAdvantage":"Broadcom's CASB, part of the Symantec enterprise security portfolio acquired in 2019 and still actively sold and updated as of 2026.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Shadow IT discovery, Sanctioned app data controls, and SaaS threat protection in a proof of concept.","ecosystem":"Primary fit is Cloud Access Security Broker. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"shadow-it-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-threat-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adaptive-access-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"deployment-modes":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Broadcom's CASB, part of the Symantec enterprise security portfolio acquired in 2019 and still actively sold and updated as of 2026. Its tightest integration is with Symantec DLP, letting one policy set span endpoint, network, and cloud channels — a common reason existing Symantec DLP shops choose it.","website":"https://www.broadcom.com/products/cybersecurity/information-protection/data-loss-prevention-cloud/cloud-application-security-cloudsoc","sourceUrls":["https://www.broadcom.com/products/cybersecurity/information-protection/data-loss-prevention-cloud/cloud-application-security-cloudsoc"],"verifiedAt":"2026-07-11"},{"slug":"forcepoint-cloud-app-security","name":"Forcepoint Cloud App Security","vendorSlug":"forcepoint","productType":"software","openSource":false,"categorySlugs":["casb"],"capabilities":["shadow-it-discovery","saas-dlp","adaptive-access-control","deployment-modes","compliance-reporting"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Cloud Access Security Broker with a preference for a SaaS operating model.","keyAdvantage":"Forcepoint's CASB, sold within its data-first security platform and sharing classifiers and policy with the company's DLP engine, so rules written once apply across cloud apps, endpoint, and email channels.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Shadow IT discovery, Sanctioned app data controls, and SaaS threat protection in a proof of concept.","ecosystem":"Primary fit is Cloud Access Security Broker. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"shadow-it-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"saas-threat-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"adaptive-access-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-modes":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Forcepoint's CASB, sold within its data-first security platform and sharing classifiers and policy with the company's DLP engine, so rules written once apply across cloud apps, endpoint, and email channels. Offers both inline and API-based enforcement with risk-adaptive controls that tighten what a session can do as user risk rises.","website":"https://www.forcepoint.com/product/casb-cloud-access-security-broker","sourceUrls":["https://www.forcepoint.com/product/casb-cloud-access-security-broker"],"verifiedAt":"2026-07-11"},{"slug":"snyk-code","name":"Snyk Code","vendorSlug":"snyk","productType":"software","openSource":false,"categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration","finding-prioritization","custom-rules","pr-gating"],"deployment":["saas","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Static Application Security Testing with a preference for a SaaS and command-line operating model.","keyAdvantage":"Snyk's AI-assisted SAST engine, sold alongside Snyk Open Source (SCA) as part of the same developer-first platform and CLI.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Snyk's AI-assisted SAST engine, sold alongside Snyk Open Source (SCA) as part of the same developer-first platform and CLI. Findings surface directly in the IDE and pull request, with AI-generated fix suggestions rather than just flagging the line.","website":"https://snyk.io/product/snyk-code","sourceUrls":["https://snyk.io/product/snyk-code","https://snyk.io/platform/deepcode-ai/","https://docs.snyk.io/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["uses-ai-for-security"],"functions":["behavioral-ai-detection","ai-assisted-remediation"],"summary":"Uses Snyk's DeepCode AI analysis and Agent Fix to find, prioritize, and propose targeted fixes for source-code vulnerabilities."}},{"slug":"veracode-static-analysis","name":"Veracode Static Analysis","vendorSlug":"veracode","productType":"software","openSource":false,"categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration","language-coverage","finding-prioritization","pr-gating"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Static Application Security Testing with a preference for a SaaS operating model.","keyAdvantage":"Veracode's cloud-based SAST engine, scanning compiled binaries and bytecode rather than raw source for many languages — a design choice from the product's early SaaS-only era that still shapes how it's deployed today.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Veracode's cloud-based SAST engine, scanning compiled binaries and bytecode rather than raw source for many languages — a design choice from the product's early SaaS-only era that still shapes how it's deployed today. Shares a single policy engine and dashboard with Veracode's SCA and DAST products.","website":"https://www.veracode.com/products/binary-static-analysis-sast/","sourceUrls":["https://www.veracode.com/products/binary-static-analysis-sast/"],"verifiedAt":"2026-07-11"},{"slug":"checkmarx-one-sast","name":"Checkmarx One (SAST)","vendorSlug":"checkmarx","productType":"software","openSource":false,"categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration","language-coverage","finding-prioritization","custom-rules","pr-gating","iac-container-scanning"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Static Application Security Testing with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"Checkmarx's SAST engine, sold within the unified Checkmarx One platform alongside SCA and API security modules under one risk-scoring model.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Checkmarx's SAST engine, sold within the unified Checkmarx One platform alongside SCA and API security modules under one risk-scoring model. A long-running enterprise incumbent, with deep IDE plugin support and a custom query language for organization-specific rules.","website":"https://checkmarx.com/product/application-security-platform/","sourceUrls":["https://checkmarx.com/product/application-security-platform/"],"verifiedAt":"2026-07-11"},{"slug":"github-code-security","name":"GitHub Code Security","vendorSlug":"github","productType":"software","openSource":false,"categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration","pr-gating","custom-rules"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Static Application Security Testing with a preference for a SaaS operating model.","keyAdvantage":"CodeQL-based SAST built directly into GitHub, surfacing findings and Copilot-generated autofixes as pull request checks.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"CodeQL-based SAST built directly into GitHub, surfacing findings and Copilot-generated autofixes as pull request checks. Free for public repositories; for private repos it became a standalone paid SKU in April 2025 when GitHub unbundled Advanced Security into separately priced Code Security and Secret Protection products.","website":"https://github.com/security/advanced-security","sourceUrls":["https://github.com/security/advanced-security","https://docs.github.com/en/code-security/concepts/code-scanning/autofix-for-code-scanning","https://docs.github.com/en/enterprise-cloud@latest/code-security/responsible-use/security-and-quality-ai-features"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["uses-ai-for-security"],"functions":["behavioral-ai-detection","ai-assisted-remediation"],"summary":"Uses AI-powered detections and large-language-model-generated autofixes to help identify and remediate code-security findings."}},{"slug":"gitlab-ultimate-appsec","name":"GitLab Ultimate (Application Security)","vendorSlug":"gitlab","productType":"software","openSource":false,"categorySlugs":["sast","sca-supply-chain"],"capabilities":["source-code-scanning","ide-ci-integration","secrets-detection","custom-rules","pr-gating","iac-container-scanning"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Static Application Security Testing with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"The security scanning bundle in GitLab's top Ultimate tier, combining SAST, dependency (SCA), container, IaC, and secret detection with results shown directly in the merge request rather than a separate tool.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing; this guide also maps the product to Software Composition Analysis & Supply Chain Security. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"custom-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dependency-vulnerability-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"license-compliance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sbom-generation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malicious-package-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-gating":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"reachability-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The security scanning bundle in GitLab's top Ultimate tier, combining SAST, dependency (SCA), container, IaC, and secret detection with results shown directly in the merge request rather than a separate tool. The advantage is a single pipeline and policy model instead of stitching several point products together.","website":"https://about.gitlab.com/solutions/application-security-testing/","sourceUrls":["https://about.gitlab.com/solutions/application-security-testing/"],"verifiedAt":"2026-07-11"},{"slug":"semgrep","name":"Semgrep","vendorSlug":"semgrep","productType":"software","openSource":false,"categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration","language-coverage","custom-rules","pr-gating"],"deployment":["cli","saas"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Static Application Security Testing with a preference for a command-line and SaaS operating model.","keyAdvantage":"A fast, pattern-matching SAST engine popular for how easy its rule syntax is to write custom checks in.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A fast, pattern-matching SAST engine popular for how easy its rule syntax is to write custom checks in. The CLI/engine itself is LGPL-2.1, but the default rule registry bundled with the free Community Edition moved to a separate, non-OSI Semgrep Rules License in December 2024 — a shift that prompted the community to fork a fully open alternative, Opengrep, in early 2025.","website":"https://semgrep.dev","sourceUrls":["https://semgrep.dev"],"verifiedAt":"2026-07-11"},{"slug":"sonarqube","name":"SonarQube","vendorSlug":"sonarsource","productType":"software","openSource":false,"categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration","language-coverage","pr-gating","iac-container-scanning"],"deployment":["saas","on-prem","cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Static Application Security Testing with a preference for a SaaS, self-hosted, and command-line operating model.","keyAdvantage":"A long-established code quality and security scanner sold in three editions since a late-2024 rebrand: self-hosted SonarQube Server, SaaS-delivered SonarQube Cloud, and the free SonarQube Community Build.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A long-established code quality and security scanner sold in three editions since a late-2024 rebrand: self-hosted SonarQube Server, SaaS-delivered SonarQube Cloud, and the free SonarQube Community Build. The Community Build's core is LGPL-3.0, but Sonar moved its bundled language analyzers to a separate, non-OSI source-available license in November 2024, so the free edition as typically run is not fully OSI open source.","website":"https://www.sonarsource.com/products/sonarqube/","sourceUrls":["https://www.sonarsource.com/products/sonarqube/"],"verifiedAt":"2026-07-11"},{"slug":"hcl-appscan","name":"HCL AppScan","vendorSlug":"hcl-software","productType":"software","openSource":false,"categorySlugs":["sast","dast"],"capabilities":["source-code-scanning","ide-ci-integration","language-coverage","pr-gating"],"deployment":["on-prem","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Static Application Security Testing with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"A long-running application security suite covering AppScan Source (SAST), AppScan Standard (DAST), and the unified AppScan on Cloud service.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage in a proof of concept.","ecosystem":"Primary fit is Static Application Security Testing; this guide also maps the product to Dynamic Application Security Testing. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"pr-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"black-box-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"authenticated-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"api-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-verification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"owasp-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A long-running application security suite covering AppScan Source (SAST), AppScan Standard (DAST), and the unified AppScan on Cloud service. Acquired from IBM in 2019 and developed since under the HCLSoftware brand, it remains common in enterprises with an existing IBM security tooling footprint.","website":"https://www.hcl-software.com/appscan","sourceUrls":["https://www.hcl-software.com/appscan"],"verifiedAt":"2026-07-11"},{"slug":"bandit","name":"Bandit","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["sast"],"capabilities":["source-code-scanning","ide-ci-integration"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Static Application Security Testing with a preference for a command-line operating model.","keyAdvantage":"A free, Python-specific static analysis linter that walks a codebase's abstract syntax tree looking for common security mistakes — hardcoded passwords, use of insecure functions, SQL string construction.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Source code vulnerability scanning, IDE & CI/CD integration, and Language & framework coverage before standardizing.","ecosystem":"Primary fit is Static Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"source-code-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ide-ci-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"language-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"pr-gating":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A free, Python-specific static analysis linter that walks a codebase's abstract syntax tree looking for common security mistakes — hardcoded passwords, use of insecure functions, SQL string construction. Governed by PyCQA (the Python Code Quality Authority) rather than any single company, and a frequent building block inside larger CI security pipelines.","website":"https://bandit.readthedocs.io","sourceUrls":["https://bandit.readthedocs.io"],"verifiedAt":"2026-07-11"},{"slug":"invicti","name":"Invicti","vendorSlug":"invicti-security","productType":"software","openSource":false,"categorySlugs":["dast"],"capabilities":["black-box-scanning","authenticated-scanning","api-scanning","ci-cd-automation","finding-verification"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Dynamic Application Security Testing with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"An enterprise DAST platform, renamed from Netsparker in 2021, built around proof-based scanning that safely re-exploits a finding to confirm it's real before it reaches a report.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Black-box scanning, Authenticated scanning, and API scanning in a proof of concept.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"black-box-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-verification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"owasp-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An enterprise DAST platform, renamed from Netsparker in 2021, built around proof-based scanning that safely re-exploits a finding to confirm it's real before it reaches a report. Increasingly bundled with SCA and ASPM correlation following Invicti Security's 2025 acquisition of Kondukto.","website":"https://www.invicti.com/product","sourceUrls":["https://www.invicti.com/product"],"verifiedAt":"2026-07-11"},{"slug":"acunetix","name":"Acunetix","vendorSlug":"invicti-security","productType":"software","openSource":false,"categorySlugs":["dast"],"capabilities":["black-box-scanning","authenticated-scanning","api-scanning","owasp-coverage"],"deployment":["on-prem","saas"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Dynamic Application Security Testing with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"A web vulnerability scanner sold as a lighter-weight, per-site-priced sibling to Invicti under the same Invicti Security parent company — the two brands trace back to a 2017-2018 merger of the previously independent Acunetix and…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Black-box scanning, Authenticated scanning, and API scanning in a proof of concept.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"black-box-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-verification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"owasp-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A web vulnerability scanner sold as a lighter-weight, per-site-priced sibling to Invicti under the same Invicti Security parent company — the two brands trace back to a 2017-2018 merger of the previously independent Acunetix and Netsparker, and both are still sold as separate, actively developed products.","website":"https://www.acunetix.com","sourceUrls":["https://www.acunetix.com"],"verifiedAt":"2026-07-11"},{"slug":"burp-suite","name":"Burp Suite","vendorSlug":"portswigger","productType":"software","openSource":false,"categorySlugs":["dast"],"capabilities":["black-box-scanning","authenticated-scanning","api-scanning","finding-verification"],"deployment":["on-prem","cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Dynamic Application Security Testing with a preference for a self-hosted and command-line operating model.","keyAdvantage":"The standard toolkit for manual and automated web application penetration testing, sold in a free Community Edition, a single-user Professional edition built for hands-on testers, and a scaled-out Burp Suite DAST edition for continuous,…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Black-box scanning, Authenticated scanning, and API scanning in a proof of concept.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"black-box-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-verification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"owasp-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The standard toolkit for manual and automated web application penetration testing, sold in a free Community Edition, a single-user Professional edition built for hands-on testers, and a scaled-out Burp Suite DAST edition for continuous, less hands-on scanning across many applications.","website":"https://portswigger.net/burp","sourceUrls":["https://portswigger.net/burp"],"verifiedAt":"2026-07-11"},{"slug":"stackhawk","name":"StackHawk","vendorSlug":"stackhawk","productType":"software","openSource":false,"categorySlugs":["dast"],"capabilities":["api-scanning","authenticated-scanning","ci-cd-automation"],"deployment":["cli","saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Dynamic Application Security Testing with a preference for a command-line and SaaS operating model.","keyAdvantage":"A developer-first DAST built specifically for APIs, configured with a file checked into the repository and run automatically as a build step rather than kicked off manually from a separate security console.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Black-box scanning, Authenticated scanning, and API scanning in a proof of concept.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"black-box-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-verification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"owasp-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A developer-first DAST built specifically for APIs, configured with a file checked into the repository and run automatically as a build step rather than kicked off manually from a separate security console. Positioned for teams that want dynamic testing to feel like any other CI check.","website":"https://www.stackhawk.com","sourceUrls":["https://www.stackhawk.com"],"verifiedAt":"2026-07-11"},{"slug":"zap-by-checkmarx","name":"ZAP by Checkmarx","vendorSlug":"checkmarx","productType":"software","openSource":true,"license":"Apache-2.0","categorySlugs":["dast"],"capabilities":["black-box-scanning","authenticated-scanning","api-scanning","owasp-coverage"],"deployment":["cli","on-prem"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Dynamic Application Security Testing with a preference for a command-line and self-hosted operating model.","keyAdvantage":"A free, widely used web application scanner that spent years as an OWASP flagship project before its core team left OWASP in 2023 and, after a brief Linux Foundation funding effort fell through, joined Checkmarx in September 2024 — the…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Black-box scanning, Authenticated scanning, and API scanning before standardizing.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"black-box-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-verification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"owasp-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A free, widely used web application scanner that spent years as an OWASP flagship project before its core team left OWASP in 2023 and, after a brief Linux Foundation funding effort fell through, joined Checkmarx in September 2024 — the project is now branded ZAP by Checkmarx, though governance stays with the independent ZAP Core Team rather than Checkmarx itself.","website":"https://www.zaproxy.org","sourceUrls":["https://www.zaproxy.org"],"verifiedAt":"2026-07-11"},{"slug":"nuclei","name":"Nuclei","vendorSlug":"projectdiscovery","productType":"software","openSource":true,"license":"MIT","categorySlugs":["dast"],"capabilities":["black-box-scanning","ci-cd-automation"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Dynamic Application Security Testing with a preference for a command-line operating model.","keyAdvantage":"A free, template-based scanner that checks a target against a huge, community-contributed library of YAML templates covering known CVEs, exposed panels, and common misconfigurations, rather than crawling and fuzzing from scratch.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Black-box scanning, Authenticated scanning, and API scanning before standardizing.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the MIT license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"black-box-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"api-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"finding-verification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"owasp-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A free, template-based scanner that checks a target against a huge, community-contributed library of YAML templates covering known CVEs, exposed panels, and common misconfigurations, rather than crawling and fuzzing from scratch. ProjectDiscovery also sells a commercial cloud platform for running Nuclei at fleet scale.","website":"https://projectdiscovery.io/nuclei","sourceUrls":["https://projectdiscovery.io/nuclei"],"verifiedAt":"2026-07-11"},{"slug":"nikto","name":"Nikto","productType":"project","openSource":true,"license":"GPL-3.0","categorySlugs":["dast"],"capabilities":["black-box-scanning"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Dynamic Application Security Testing with a preference for a command-line operating model.","keyAdvantage":"A long-running, free command-line scanner that checks a web server for outdated software versions, dangerous default files, and known misconfigurations.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Black-box scanning, Authenticated scanning, and API scanning before standardizing.","ecosystem":"Primary fit is Dynamic Application Security Testing. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the GPL-3.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"black-box-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"api-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-verification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"owasp-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A long-running, free command-line scanner that checks a web server for outdated software versions, dangerous default files, and known misconfigurations. Simpler and older than modern DAST platforms, but still commonly used as a quick first pass before a deeper authenticated scan.","website":"https://github.com/sullo/nikto","sourceUrls":["https://github.com/sullo/nikto"],"verifiedAt":"2026-07-11"},{"slug":"snyk-open-source","name":"Snyk Open Source","vendorSlug":"snyk","productType":"software","openSource":false,"categorySlugs":["sca-supply-chain"],"capabilities":["dependency-vulnerability-scanning","license-compliance","ci-cd-gating","reachability-analysis"],"deployment":["saas","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Software Composition Analysis & Supply Chain Security with a preference for a SaaS and command-line operating model.","keyAdvantage":"Snyk's SCA product, sharing a CLI, dashboard, and free-tier limits with Snyk Code so dependency and first-party findings sit side by side.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Dependency vulnerability scanning, License compliance, and SBOM generation in a proof of concept.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sbom-generation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malicious-package-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"reachability-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Snyk's SCA product, sharing a CLI, dashboard, and free-tier limits with Snyk Code so dependency and first-party findings sit side by side. Its vulnerability database is maintained by an in-house research team rather than sourced purely from public feeds.","website":"https://snyk.io/product/open-source-security-management/","sourceUrls":["https://snyk.io/product/open-source-security-management/"],"verifiedAt":"2026-07-11"},{"slug":"veracode-sca","name":"Veracode Software Composition Analysis","vendorSlug":"veracode","productType":"software","openSource":false,"categorySlugs":["sca-supply-chain"],"capabilities":["dependency-vulnerability-scanning","license-compliance","sbom-generation","ci-cd-gating"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Software Composition Analysis & Supply Chain Security with a preference for a SaaS operating model.","keyAdvantage":"Veracode's dependency scanner, sharing a single policy engine and risk dashboard with Veracode Static Analysis so open-source and first-party findings roll up into one score instead of two separate tools with two separate backlogs.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Dependency vulnerability scanning, License compliance, and SBOM generation in a proof of concept.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sbom-generation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"malicious-package-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"reachability-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Veracode's dependency scanner, sharing a single policy engine and risk dashboard with Veracode Static Analysis so open-source and first-party findings roll up into one score instead of two separate tools with two separate backlogs.","website":"https://www.veracode.com/products/software-composition-analysis/","sourceUrls":["https://www.veracode.com/products/software-composition-analysis/"],"verifiedAt":"2026-07-11"},{"slug":"github-dependabot","name":"GitHub Dependabot","vendorSlug":"github","productType":"software","openSource":false,"categorySlugs":["sca-supply-chain"],"capabilities":["dependency-vulnerability-scanning","ci-cd-gating"],"deployment":["saas"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Software Composition Analysis & Supply Chain Security with a preference for a SaaS operating model.","keyAdvantage":"GitHub's automatic dependency-update bot, opening pull requests to bump vulnerable or outdated packages and free on every repository, public or private.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Dependency vulnerability scanning, License compliance, and SBOM generation in a proof of concept.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sbom-generation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malicious-package-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"reachability-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"GitHub's automatic dependency-update bot, opening pull requests to bump vulnerable or outdated packages and free on every repository, public or private. It stayed free through GitHub's April 2025 unbundling of Advanced Security, which moved code and secret scanning onto separate paid SKUs but left Dependabot untouched.","website":"https://github.com/dependabot","sourceUrls":["https://github.com/dependabot"],"verifiedAt":"2026-07-11"},{"slug":"endor-labs","name":"Endor Labs","vendorSlug":"endor-labs","productType":"software","openSource":false,"categorySlugs":["sca-supply-chain"],"capabilities":["dependency-vulnerability-scanning","reachability-analysis","malicious-package-detection","ci-cd-gating"],"deployment":["saas","cli"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Software Composition Analysis & Supply Chain Security with a preference for a SaaS and command-line operating model.","keyAdvantage":"An SCA platform built reachability-first: rather than listing every known vulnerability in every dependency, it determines which vulnerable functions are actually called by the application and prioritizes almost entirely around that…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Dependency vulnerability scanning, License compliance, and SBOM generation in a proof of concept.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sbom-generation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malicious-package-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"reachability-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An SCA platform built reachability-first: rather than listing every known vulnerability in every dependency, it determines which vulnerable functions are actually called by the application and prioritizes almost entirely around that smaller, real set.","website":"https://www.endorlabs.com","sourceUrls":["https://www.endorlabs.com"],"verifiedAt":"2026-07-11"},{"slug":"socket","name":"Socket","vendorSlug":"socket-security","productType":"software","openSource":false,"categorySlugs":["sca-supply-chain"],"capabilities":["malicious-package-detection","dependency-vulnerability-scanning","ci-cd-gating"],"deployment":["saas","cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Software Composition Analysis & Supply Chain Security with a preference for a SaaS and command-line operating model.","keyAdvantage":"Socket Firewall inspects what an open-source package actually does at install and runtime — obfuscated code, unexpected network calls, new maintainer accounts — to catch malicious and typosquatted packages that pure CVE-matching tools…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Dependency vulnerability scanning, License compliance, and SBOM generation in a proof of concept.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sbom-generation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malicious-package-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"reachability-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Socket Firewall inspects what an open-source package actually does at install and runtime — obfuscated code, unexpected network calls, new maintainer accounts — to catch malicious and typosquatted packages that pure CVE-matching tools miss, since a brand-new malicious package by definition has no known vulnerability yet.","website":"https://socket.dev","sourceUrls":["https://socket.dev"],"verifiedAt":"2026-07-11"},{"slug":"owasp-dependency-check","name":"OWASP Dependency-Check","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["sca-supply-chain"],"capabilities":["dependency-vulnerability-scanning","sbom-generation"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Software Composition Analysis & Supply Chain Security with a preference for a command-line operating model.","keyAdvantage":"A free command-line and build-plugin SCA tool that matches project dependencies against the National Vulnerability Database and other feeds.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Dependency vulnerability scanning, License compliance, and SBOM generation before standardizing.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"sbom-generation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"malicious-package-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ci-cd-gating":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"reachability-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-container-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A free command-line and build-plugin SCA tool that matches project dependencies against the National Vulnerability Database and other feeds. Led by its original creator, it remains actively released, though its canonical repository moved to a new GitHub organization in 2025 after years under the maintainer's personal account.","website":"https://owasp.org/www-project-dependency-check/","sourceUrls":["https://owasp.org/www-project-dependency-check/"],"verifiedAt":"2026-07-11"},{"slug":"aikido-security","name":"Aikido Security","vendorSlug":"aikido-security","productType":"software","openSource":false,"categorySlugs":["sca-supply-chain","sast"],"capabilities":["dependency-vulnerability-scanning","license-compliance","sbom-generation","malicious-package-detection","ci-cd-gating","iac-container-scanning"],"deployment":["saas"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Software Composition Analysis & Supply Chain Security with a preference for a SaaS operating model.","keyAdvantage":"A consolidated application security platform that aggregates SCA, SAST, secrets, container-image, and IaC scanning together with its own cloud posture (CSPM) behind a single dashboard — correlating a code finding through to the cloud…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Dependency vulnerability scanning, License compliance, and SBOM generation in a proof of concept.","ecosystem":"Primary fit is Software Composition Analysis & Supply Chain Security; this guide also maps the product to Static Application Security Testing. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"dependency-vulnerability-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"license-compliance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sbom-generation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"malicious-package-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ci-cd-gating":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"reachability-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"iac-container-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"source-code-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ide-ci-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"language-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"finding-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"secrets-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"custom-rules":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"pr-gating":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A consolidated application security platform that aggregates SCA, SAST, secrets, container-image, and IaC scanning together with its own cloud posture (CSPM) behind a single dashboard — correlating a code finding through to the cloud infrastructure it ships to, and aimed at small engineering teams that don't want to run and tune a dozen separate scanners. Reached unicorn status in January 2026.","website":"https://www.aikido.dev","sourceUrls":["https://www.aikido.dev"],"verifiedAt":"2026-07-11"},{"slug":"akamai-app-and-api-protector","name":"Akamai App & API Protector","vendorSlug":"akamai","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["attack-signature-blocking","api-discovery","schema-validation","bot-management","rate-limiting"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating WAF & API Security with a preference for a SaaS operating model.","keyAdvantage":"Akamai's edge-delivered WAF and bot management bundle, running on its global CDN network.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"schema-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bot-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"rate-limiting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-api-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Akamai's edge-delivered WAF and bot management bundle, running on its global CDN network. Deeper, standalone API discovery and runtime protection — carrying the technology lineage of Akamai's 2024 acquisition of Noname Security — is sold as a separately branded Akamai API Security product alongside it.","website":"https://www.akamai.com/products/app-and-api-protector","sourceUrls":["https://www.akamai.com/products/app-and-api-protector"],"verifiedAt":"2026-07-11"},{"slug":"f5-distributed-cloud-waf","name":"F5 Distributed Cloud WAF","vendorSlug":"f5","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["attack-signature-blocking","api-discovery","schema-validation","bot-management","rate-limiting","runtime-api-protection"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating WAF & API Security with a preference for a SaaS operating model.","keyAdvantage":"F5's SaaS/CDN-delivered WAF and API security service, managed as one policy set across multiple clouds rather than per-appliance.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"schema-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bot-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"rate-limiting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-api-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"F5's SaaS/CDN-delivered WAF and API security service, managed as one policy set across multiple clouds rather than per-appliance. API discovery and lifecycle protection draw on technology from F5's 2024 acquisition of the API security startup Wib.","website":"https://www.f5.com/products/distributed-cloud-services/api-security","sourceUrls":["https://www.f5.com/products/distributed-cloud-services/api-security"],"verifiedAt":"2026-07-11"},{"slug":"f5-waf-for-nginx","name":"F5 WAF for NGINX","vendorSlug":"f5","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["attack-signature-blocking","schema-validation","rate-limiting"],"deployment":["on-prem","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating WAF & API Security with a preference for a self-hosted and endpoint-agent operating model.","keyAdvantage":"A lightweight, software-only WAF module that runs as a sidecar alongside NGINX, built for containerized and Kubernetes-native environments rather than a dedicated appliance.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"schema-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bot-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rate-limiting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-api-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A lightweight, software-only WAF module that runs as a sidecar alongside NGINX, built for containerized and Kubernetes-native environments rather than a dedicated appliance. Renamed from NGINX App Protect, though the older name still appears throughout F5's own documentation and community references.","website":"https://www.f5.com/products/nginx/f5-waf-for-nginx","sourceUrls":["https://www.f5.com/products/nginx/f5-waf-for-nginx"],"verifiedAt":"2026-07-11"},{"slug":"imperva-waf","name":"Imperva Web Application Firewall","vendorSlug":"imperva","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["attack-signature-blocking","bot-management","rate-limiting","api-discovery"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating WAF & API Security with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"A long-established WAF with particularly deep bot management and DDoS mitigation built in, sold standalone or as part of Imperva's broader application and data security portfolio.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"schema-validation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"bot-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"rate-limiting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-api-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A long-established WAF with particularly deep bot management and DDoS mitigation built in, sold standalone or as part of Imperva's broader application and data security portfolio. Part of the French Thales Group since Thales completed its ~$3.6B acquisition from Thoma Bravo in December 2023.","website":"https://www.imperva.com/products/web-application-firewall-waf/","sourceUrls":["https://www.imperva.com/products/web-application-firewall-waf/"],"verifiedAt":"2026-07-11"},{"slug":"salt-security-platform","name":"Salt Security Agentic Security Platform","vendorSlug":"salt-security","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["api-discovery","runtime-api-protection","schema-validation"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating WAF & API Security with a preference for a SaaS operating model.","keyAdvantage":"An API security platform that learns from a copy of live traffic rather than sitting inline as a proxy, building a picture of normal API behavior over time to catch slow reconnaissance and abuse that a single-request signature match would…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"api-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"schema-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bot-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rate-limiting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"runtime-api-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An API security platform that learns from a copy of live traffic rather than sitting inline as a proxy, building a picture of normal API behavior over time to catch slow reconnaissance and abuse that a single-request signature match would miss. Rebranded from the Salt Security API Protection Platform in 2026.","website":"https://salt.security/platform","sourceUrls":["https://salt.security/platform"],"verifiedAt":"2026-07-11"},{"slug":"traceable-by-harness","name":"Traceable by Harness","vendorSlug":"harness","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["api-discovery","runtime-api-protection","schema-validation"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating WAF & API Security with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"An API discovery, runtime protection, and data-exposure monitoring product built independently by Traceable AI before its March 2025 merger into Harness; it now ships as an integrated module of Harness's software delivery platform rather…","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"api-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"schema-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bot-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"rate-limiting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"runtime-api-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An API discovery, runtime protection, and data-exposure monitoring product built independently by Traceable AI before its March 2025 merger into Harness; it now ships as an integrated module of Harness's software delivery platform rather than as a standalone company's product.","website":"https://www.traceable.ai","sourceUrls":["https://www.traceable.ai"],"verifiedAt":"2026-07-11"},{"slug":"cloudflare-waf","name":"Cloudflare WAF","vendorSlug":"cloudflare","productType":"software","openSource":false,"categorySlugs":["waf-api-security"],"capabilities":["attack-signature-blocking","schema-validation","bot-management","rate-limiting","api-discovery"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating WAF & API Security with a preference for a SaaS operating model.","keyAdvantage":"An edge WAF running on Cloudflare's global network, paired with the separately named API Shield for schema validation and API-specific abuse detection.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Attack signature blocking, API discovery, and Schema validation in a proof of concept.","ecosystem":"Primary fit is WAF & API Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"attack-signature-blocking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"api-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"schema-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bot-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"rate-limiting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-api-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An edge WAF running on Cloudflare's global network, paired with the separately named API Shield for schema validation and API-specific abuse detection. A distinct product line from the same company's Cloudflare One SASE platform and Magic Transit DDoS service.","website":"https://www.cloudflare.com/products/waf/","sourceUrls":["https://www.cloudflare.com/products/waf/"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-purview-dlp","name":"Microsoft Purview Data Loss Prevention","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["dlp"],"capabilities":["content-inspection","endpoint-dlp","network-email-dlp","cloud-saas-dlp","regulatory-policy-templates","incident-workflow"],"deployment":["saas","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Data Loss Prevention with a preference for a SaaS and hybrid operating model.","keyAdvantage":"Microsoft's native DLP engine built into Microsoft 365, extending one set of policies across Exchange Online, SharePoint, Teams, and endpoint devices without a separate agent to deploy.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Content inspection & classification, Endpoint DLP, and Network & email DLP in a proof of concept.","ecosystem":"Primary fit is Data Loss Prevention. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"content-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"endpoint-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"network-email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"cloud-saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"regulatory-policy-templates":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"incident-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Microsoft's native DLP engine built into Microsoft 365, extending one set of policies across Exchange Online, SharePoint, Teams, and endpoint devices without a separate agent to deploy. Sold as part of Microsoft 365 E5 compliance licensing or as a standalone add-on, and increasingly extended to cover Copilot and other AI interactions with sensitive data.","website":"https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp","sourceUrls":["https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp"],"verifiedAt":"2026-07-11"},{"slug":"forcepoint-dlp","name":"Forcepoint DLP","vendorSlug":"forcepoint","productType":"software","openSource":false,"categorySlugs":["dlp"],"capabilities":["content-inspection","endpoint-dlp","network-email-dlp","cloud-saas-dlp","incident-workflow"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Loss Prevention with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"Forcepoint's core DLP product, built around risk-adaptive protection that adjusts enforcement strictness to a user's ongoing behavioral risk score rather than applying one static rule to everyone.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Content inspection & classification, Endpoint DLP, and Network & email DLP in a proof of concept.","ecosystem":"Primary fit is Data Loss Prevention. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"content-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"endpoint-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"network-email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"cloud-saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"regulatory-policy-templates":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"incident-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Forcepoint's core DLP product, built around risk-adaptive protection that adjusts enforcement strictness to a user's ongoing behavioral risk score rather than applying one static rule to everyone. Shares classifiers and policy with the company's CASB product, so rules written once apply consistently across endpoint, network, and cloud app channels.","website":"https://www.forcepoint.com/product/dlp-data-loss-prevention","sourceUrls":["https://www.forcepoint.com/product/dlp-data-loss-prevention"],"verifiedAt":"2026-07-11"},{"slug":"proofpoint-enterprise-dlp","name":"Proofpoint Enterprise DLP","vendorSlug":"proofpoint","productType":"software","openSource":false,"categorySlugs":["dlp"],"capabilities":["content-inspection","network-email-dlp","cloud-saas-dlp","incident-workflow"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Loss Prevention with a preference for a SaaS operating model.","keyAdvantage":"A people-centric DLP product that ties content violations to Proofpoint's broader picture of user risk — who's already flagged for phishing susceptibility, who's departing the company — rather than treating every policy match with equal…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Content inspection & classification, Endpoint DLP, and Network & email DLP in a proof of concept.","ecosystem":"Primary fit is Data Loss Prevention. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"content-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"endpoint-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"network-email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"cloud-saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"regulatory-policy-templates":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"incident-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A people-centric DLP product that ties content violations to Proofpoint's broader picture of user risk — who's already flagged for phishing susceptibility, who's departing the company — rather than treating every policy match with equal urgency. Covers email, cloud apps, and endpoint channels from Proofpoint's unified console.","website":"https://www.proofpoint.com/us/products/data-loss-prevention","sourceUrls":["https://www.proofpoint.com/us/products/data-loss-prevention"],"verifiedAt":"2026-07-11"},{"slug":"nightfall-ai","name":"Nightfall AI","vendorSlug":"nightfall-ai","productType":"software","openSource":false,"categorySlugs":["dlp"],"capabilities":["content-inspection","cloud-saas-dlp","incident-workflow"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Data Loss Prevention with a preference for a SaaS operating model.","keyAdvantage":"A SaaS- and AI-native DLP platform that connects directly to apps like Slack, GitHub, and Jira and to generative AI tools via API rather than a network or endpoint agent, using machine-learned classifiers tuned for the unstructured…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Content inspection & classification, Endpoint DLP, and Network & email DLP in a proof of concept.","ecosystem":"Primary fit is Data Loss Prevention. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"content-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"endpoint-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"network-email-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"cloud-saas-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"regulatory-policy-templates":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"incident-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A SaaS- and AI-native DLP platform that connects directly to apps like Slack, GitHub, and Jira and to generative AI tools via API rather than a network or endpoint agent, using machine-learned classifiers tuned for the unstructured content typical of chat and code. Its Nyx capability automates a chunk of the incident-triage work a human analyst would otherwise do by hand.","website":"https://www.nightfall.ai","sourceUrls":["https://www.nightfall.ai"],"verifiedAt":"2026-07-11"},{"slug":"symantec-dlp","name":"Symantec Data Loss Prevention","vendorSlug":"broadcom","productType":"software","openSource":false,"categorySlugs":["dlp"],"capabilities":["content-inspection","endpoint-dlp","network-email-dlp","regulatory-policy-templates","incident-workflow"],"deployment":["on-prem","hybrid"],"targetOrgSize":["enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Enterprises evaluating Data Loss Prevention with a preference for a self-hosted and hybrid operating model.","keyAdvantage":"Broadcom's long-established DLP suite, covering endpoint, network, email, and storage discovery under one policy engine and console.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Content inspection & classification, Endpoint DLP, and Network & email DLP in a proof of concept.","ecosystem":"Primary fit is Data Loss Prevention. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"content-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"endpoint-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"network-email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"cloud-saas-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"regulatory-policy-templates":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"incident-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Broadcom's long-established DLP suite, covering endpoint, network, email, and storage discovery under one policy engine and console. A separately sold cloud edition, Symantec DLP Cloud, extends the same detection logic to SaaS and web traffic; both remain actively maintained as of mid-2026.","website":"https://www.broadcom.com/products/cybersecurity/information-protection/data-loss-prevention","sourceUrls":["https://www.broadcom.com/products/cybersecurity/information-protection/data-loss-prevention"],"verifiedAt":"2026-07-11"},{"slug":"cyera","name":"Cyera","vendorSlug":"cyera","productType":"software","openSource":false,"categorySlugs":["dspm"],"capabilities":["automated-data-discovery","ai-classification","access-mapping","risk-prioritization","shadow-data-detection"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Security Posture Management with a preference for a SaaS operating model.","keyAdvantage":"An agentless DSPM platform that connects to cloud, SaaS, and on-premises data stores through APIs.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Automated data discovery, AI-driven classification, and Data access mapping in a proof of concept.","ecosystem":"Primary fit is Data Security Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"automated-data-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-classification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-workflows":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"shadow-data-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An agentless DSPM platform that connects to cloud, SaaS, and on-premises data stores through APIs. It classifies sensitive data and combines those findings with identity and permission data to show which stores are exposed and who can reach them.","website":"https://www.cyera.com","sourceUrls":["https://www.cyera.com"],"verifiedAt":"2026-07-11"},{"slug":"bigid","name":"BigID","vendorSlug":"bigid","productType":"software","openSource":false,"categorySlugs":["dspm"],"capabilities":["automated-data-discovery","ai-classification","access-mapping","remediation-workflows","shadow-data-detection"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Security Posture Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"One of the earlier dedicated data discovery and classification platforms, now sold as a broader data intelligence suite spanning DSPM, privacy automation, and AI data governance under one catalog of discovered data.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Automated data discovery, AI-driven classification, and Data access mapping in a proof of concept.","ecosystem":"Primary fit is Data Security Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"automated-data-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-classification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"remediation-workflows":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"shadow-data-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"One of the earlier dedicated data discovery and classification platforms, now sold as a broader data intelligence suite spanning DSPM, privacy automation, and AI data governance under one catalog of discovered data. Deployable inside a customer's own cloud or on-prem environment for organizations unwilling to send data samples to a vendor-hosted service.","website":"https://bigid.com","sourceUrls":["https://bigid.com"],"verifiedAt":"2026-07-11"},{"slug":"varonis-data-security-platform","name":"Varonis Data Security Platform","vendorSlug":"varonis","productType":"software","openSource":false,"categorySlugs":["dspm"],"capabilities":["automated-data-discovery","access-mapping","risk-prioritization","remediation-workflows","shadow-data-detection"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Security Posture Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"A data security platform with roots in data access governance and DLP that has expanded into full DSPM: automated discovery and classification across cloud and on-prem stores, continuous access-risk scoring, and automated remediation of…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Automated data discovery, AI-driven classification, and Data access mapping in a proof of concept.","ecosystem":"Primary fit is Data Security Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"automated-data-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-classification":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"access-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-workflows":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"shadow-data-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A data security platform with roots in data access governance and DLP that has expanded into full DSPM: automated discovery and classification across cloud and on-prem stores, continuous access-risk scoring, and automated remediation of excess permissions. Varonis is publicly traded on Nasdaq (VRNS).","website":"https://www.varonis.com","sourceUrls":["https://www.varonis.com"],"verifiedAt":"2026-07-11"},{"slug":"sentra","name":"Sentra","vendorSlug":"sentra","productType":"software","openSource":false,"categorySlugs":["dspm"],"capabilities":["automated-data-discovery","ai-classification","risk-prioritization","shadow-data-detection"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Security Posture Management with a preference for a SaaS operating model.","keyAdvantage":"A cloud-native DSPM platform built for petabyte-scale data estates, prioritizing discovered data by a combination of sensitivity, access exposure, and whether it actually feeds AI models and pipelines rather than sitting unused.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Automated data discovery, AI-driven classification, and Data access mapping in a proof of concept.","ecosystem":"Primary fit is Data Security Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"automated-data-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-classification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-workflows":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"shadow-data-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A cloud-native DSPM platform built for petabyte-scale data estates, prioritizing discovered data by a combination of sensitivity, access exposure, and whether it actually feeds AI models and pipelines rather than sitting unused. Independent and VC-backed, having raised a $50M Series B in 2025.","website":"https://sentra.io","sourceUrls":["https://sentra.io"],"verifiedAt":"2026-07-11"},{"slug":"securiti","name":"Securiti","vendorSlug":"securiti","productType":"software","openSource":false,"categorySlugs":["dspm"],"capabilities":["automated-data-discovery","ai-classification","access-mapping","risk-prioritization"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Data Security Posture Management with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"A broader data command platform that bundles DSPM discovery and classification with privacy compliance automation and AI governance controls under one catalog, aimed at organizations that want a single system of record for data,…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Automated data discovery, AI-driven classification, and Data access mapping in a proof of concept.","ecosystem":"Primary fit is Data Security Posture Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"automated-data-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-classification":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-workflows":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"shadow-data-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A broader data command platform that bundles DSPM discovery and classification with privacy compliance automation and AI governance controls under one catalog, aimed at organizations that want a single system of record for data, regulatory, and AI risk rather than separate tools for each. Became a Veeam subsidiary when that acquisition closed in December 2025.","website":"https://securiti.ai","sourceUrls":["https://securiti.ai"],"verifiedAt":"2026-07-11"},{"slug":"thales-ciphertrust","name":"Thales CipherTrust Data Security Platform","vendorSlug":"thales","productType":"software","openSource":false,"categorySlugs":["encryption-key-management"],"capabilities":["key-lifecycle-management","hsm-backed-storage","encryption-enforcement","byok-hyok-support","access-audit-logging"],"deployment":["on-prem","hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Encryption & Key Management with a preference for a self-hosted, hybrid, and SaaS operating model.","keyAdvantage":"A unified encryption and key management platform combining transparent data encryption, tokenization, and centralized key lifecycle management across on-prem, cloud, and big-data environments, formed by consolidating the previously…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement in a proof of concept.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"key-lifecycle-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"hsm-backed-storage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encryption-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-key-rotation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"byok-hyok-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A unified encryption and key management platform combining transparent data encryption, tokenization, and centralized key lifecycle management across on-prem, cloud, and big-data environments, formed by consolidating the previously separate Vormetric and SafeNet/KeySecure product lines Thales acquired in 2016 and 2019. Luna hardware security modules provide the FIPS-validated storage underneath.","website":"https://cpl.thalesgroup.com/encryption/data-security-platform","sourceUrls":["https://cpl.thalesgroup.com/encryption/data-security-platform"],"verifiedAt":"2026-07-11"},{"slug":"fortanix-data-security-manager","name":"Fortanix Data Security Manager","vendorSlug":"fortanix","productType":"software","openSource":false,"categorySlugs":["encryption-key-management"],"capabilities":["key-lifecycle-management","hsm-backed-storage","automated-key-rotation","byok-hyok-support","access-audit-logging"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Encryption & Key Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"A key management and tokenization platform built on confidential computing, processing keys inside hardware-isolated secure enclaves so they're never exposed in plaintext to the underlying host — including Fortanix's own service, when run…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement in a proof of concept.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"key-lifecycle-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"hsm-backed-storage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encryption-enforcement":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-key-rotation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"byok-hyok-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A key management and tokenization platform built on confidential computing, processing keys inside hardware-isolated secure enclaves so they're never exposed in plaintext to the underlying host — including Fortanix's own service, when run as SaaS. Sold standalone or as part of the broader Fortanix Armor platform, which adds unified access management and audit across an organization's whole key and secrets estate.","website":"https://www.fortanix.com/platform/data-security-manager","sourceUrls":["https://www.fortanix.com/platform/data-security-manager"],"verifiedAt":"2026-07-11"},{"slug":"aws-kms","name":"AWS Key Management Service","vendorSlug":"amazon","productType":"software","openSource":false,"categorySlugs":["encryption-key-management"],"capabilities":["key-lifecycle-management","hsm-backed-storage","automated-key-rotation","byok-hyok-support","access-audit-logging"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Encryption & Key Management with a preference for a SaaS operating model.","keyAdvantage":"Amazon's managed key management service, wired deeply enough into the rest of AWS that most other services — S3, EBS, RDS — can encrypt data using keys it creates, rotates, and audits automatically.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement in a proof of concept.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"key-lifecycle-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"hsm-backed-storage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encryption-enforcement":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-key-rotation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"byok-hyok-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Amazon's managed key management service, wired deeply enough into the rest of AWS that most other services — S3, EBS, RDS — can encrypt data using keys it creates, rotates, and audits automatically. Customer keys can be moved to dedicated single-tenant hardware through the paired AWS CloudHSM service for the strictest isolation requirements.","website":"https://aws.amazon.com/kms/","sourceUrls":["https://aws.amazon.com/kms/"],"verifiedAt":"2026-07-11"},{"slug":"azure-key-vault","name":"Azure Key Vault","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["encryption-key-management"],"capabilities":["key-lifecycle-management","hsm-backed-storage","encryption-enforcement","automated-key-rotation","access-audit-logging"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Encryption & Key Management with a preference for a SaaS operating model.","keyAdvantage":"Microsoft's cloud key, secret, and certificate management service, available in a shared-hardware Standard tier and an HSM-backed Premium or Managed HSM tier for keys that need dedicated, single-tenant hardware.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement in a proof of concept.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"key-lifecycle-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"hsm-backed-storage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encryption-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-key-rotation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"byok-hyok-support":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"access-audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Microsoft's cloud key, secret, and certificate management service, available in a shared-hardware Standard tier and an HSM-backed Premium or Managed HSM tier for keys that need dedicated, single-tenant hardware. Integrates tightly with Entra ID for access policy and with most other Azure services for at-rest encryption key management.","website":"https://azure.microsoft.com/en-us/products/key-vault","sourceUrls":["https://azure.microsoft.com/en-us/products/key-vault"],"verifiedAt":"2026-07-11"},{"slug":"google-cloud-kms","name":"Cloud Key Management Service","vendorSlug":"google","productType":"software","openSource":false,"categorySlugs":["encryption-key-management"],"capabilities":["key-lifecycle-management","hsm-backed-storage","automated-key-rotation","byok-hyok-support","access-audit-logging"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Encryption & Key Management with a preference for a SaaS operating model.","keyAdvantage":"Google Cloud's key management service, spanning software-backed keys, a dedicated single-tenant Cloud HSM tier, and a Cloud External Key Manager option for organizations that want to hold keys entirely outside Google's infrastructure…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement in a proof of concept.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"key-lifecycle-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"hsm-backed-storage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"encryption-enforcement":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-key-rotation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"byok-hyok-support":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"access-audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Google Cloud's key management service, spanning software-backed keys, a dedicated single-tenant Cloud HSM tier, and a Cloud External Key Manager option for organizations that want to hold keys entirely outside Google's infrastructure while still using them to encrypt Google Cloud data. Integrates natively with Cloud IAM for granular key-use permissions.","website":"https://cloud.google.com/security/products/security-key-management","sourceUrls":["https://cloud.google.com/security/products/security-key-management"],"verifiedAt":"2026-07-11"},{"slug":"age","name":"age","productType":"project","openSource":true,"license":"BSD-3-Clause","categorySlugs":["encryption-key-management"],"capabilities":["encryption-enforcement"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Encryption & Key Management with a preference for a command-line operating model.","keyAdvantage":"A modern, deliberately simple file encryption tool and format, built as a smaller and harder-to-misuse alternative to PGP for encrypting individual files with a passphrase, an SSH key, or a small dedicated recipient key.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement before standardizing.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the BSD-3-Clause license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"key-lifecycle-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"hsm-backed-storage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encryption-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-key-rotation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"byok-hyok-support":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"access-audit-logging":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A modern, deliberately simple file encryption tool and format, built as a smaller and harder-to-misuse alternative to PGP for encrypting individual files with a passphrase, an SSH key, or a small dedicated recipient key. Created by security engineer Filippo Valsorda; a project rather than a company, with no centralized key management — it encrypts and decrypts files, not an organization's whole key estate.","website":"https://github.com/FiloSottile/age","sourceUrls":["https://github.com/FiloSottile/age"],"verifiedAt":"2026-07-11"},{"slug":"gnupg","name":"GnuPG","productType":"project","openSource":true,"license":"GPL-3.0-or-later","categorySlugs":["encryption-key-management"],"capabilities":["encryption-enforcement"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Encryption & Key Management with a preference for a command-line operating model.","keyAdvantage":"The free, complete implementation of the OpenPGP standard: encrypts files and email and creates and verifies digital signatures, built around a distributed web of individually managed keypairs rather than a centralized key server.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement before standardizing.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the GPL-3.0-or-later license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"key-lifecycle-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"hsm-backed-storage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encryption-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-key-rotation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"byok-hyok-support":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"access-audit-logging":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The free, complete implementation of the OpenPGP standard: encrypts files and email and creates and verifies digital signatures, built around a distributed web of individually managed keypairs rather than a centralized key server. A GNU Project maintained by volunteers rather than a company, and the engine underneath many higher-level email encryption tools.","website":"https://gnupg.org","sourceUrls":["https://gnupg.org"],"verifiedAt":"2026-07-11"},{"slug":"openbao","name":"OpenBao","productType":"project","openSource":true,"license":"MPL-2.0","categorySlugs":["encryption-key-management"],"capabilities":["key-lifecycle-management","automated-key-rotation","access-audit-logging","encryption-enforcement"],"deployment":["on-prem","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Encryption & Key Management with a preference for a self-hosted and command-line operating model.","keyAdvantage":"A community-governed fork of HashiCorp Vault, created in 2023 after Vault's license changed away from an OSI-approved open-source license, rebuilding the same secrets-management and encryption-as-a-service features under a fully open…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Centralized key lifecycle management, HSM-backed key storage, and Encryption enforcement before standardizing.","ecosystem":"Primary fit is Encryption & Key Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the MPL-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"key-lifecycle-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"hsm-backed-storage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"encryption-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-key-rotation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"byok-hyok-support":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"access-audit-logging":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A community-governed fork of HashiCorp Vault, created in 2023 after Vault's license changed away from an OSI-approved open-source license, rebuilding the same secrets-management and encryption-as-a-service features under a fully open MPL-2.0 license. Joined the Linux Foundation's Open Source Security Foundation (OpenSSF) in 2025, and remains in the foundation's early Sandbox stage as of mid-2026.","website":"https://openbao.org","sourceUrls":["https://openbao.org"],"verifiedAt":"2026-07-11"},{"slug":"venafi-control-plane","name":"Venafi Control Plane for Machine Identities","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["certificate-management"],"capabilities":["certificate-discovery","automated-renewal","expiry-monitoring","private-ca","crypto-agility"],"deployment":["saas","hybrid","agent"],"targetOrgSize":["enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Enterprises evaluating Certificate Lifecycle Management with a preference for a SaaS, hybrid, and endpoint-agent operating model.","keyAdvantage":"The platform that defined enterprise machine identity management, discovering TLS and machine certificates across enterprise, cloud, and Kubernetes environments and automating their issuance and renewal through ACME, EST, and direct CA…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting in a proof of concept.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"certificate-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"private-ca":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-integrations":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"crypto-agility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The platform that defined enterprise machine identity management, discovering TLS and machine certificates across enterprise, cloud, and Kubernetes environments and automating their issuance and renewal through ACME, EST, and direct CA integrations, backed by cloud-hosted private PKI and expiry monitoring that flags an outage risk before a certificate lapses. Venafi was acquired by CyberArk from Thoma Bravo in October 2024, and now sits inside Palo Alto Networks' Idira identity portfolio following its acquisition of CyberArk.","website":"https://www.paloaltonetworks.com/idira","sourceUrls":["https://www.paloaltonetworks.com/idira"],"verifiedAt":"2026-07-11"},{"slug":"keyfactor-command","name":"Keyfactor Command","vendorSlug":"keyfactor","productType":"software","openSource":false,"categorySlugs":["certificate-management"],"capabilities":["certificate-discovery","automated-renewal","deployment-integrations","private-ca","crypto-agility"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Certificate Lifecycle Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"A certificate lifecycle automation and PKI-as-a-service platform that discovers certificates and keys across public and private CAs, cloud, network endpoints, and Kubernetes, then automates renewal and provisioning under central governance.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting in a proof of concept.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"certificate-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"private-ca":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-integrations":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"crypto-agility":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A certificate lifecycle automation and PKI-as-a-service platform that discovers certificates and keys across public and private CAs, cloud, network endpoints, and Kubernetes, then automates renewal and provisioning under central governance. Integrates tightly with the open-source EJBCA certificate authority — also a Keyfactor product — and third-party CAs, and adds post-quantum crypto-agility workflows for inventorying and rotating algorithms at scale.","website":"https://www.keyfactor.com/products/command/","sourceUrls":["https://www.keyfactor.com/products/command/"],"verifiedAt":"2026-07-11"},{"slug":"digicert-trust-lifecycle-manager","name":"DigiCert Trust Lifecycle Manager","vendorSlug":"digicert","productType":"software","openSource":false,"categorySlugs":["certificate-management"],"capabilities":["certificate-discovery","automated-renewal","expiry-monitoring","private-ca"],"deployment":["saas","hybrid","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Certificate Lifecycle Management with a preference for a SaaS, hybrid, and self-hosted operating model.","keyAdvantage":"A CA-agnostic certificate lifecycle manager handling organization-wide certificate discovery, automated issuance and renewal via ACME, EST, and SCEP, and private PKI delivered as a managed service.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting in a proof of concept.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"certificate-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"private-ca":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-integrations":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"crypto-agility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A CA-agnostic certificate lifecycle manager handling organization-wide certificate discovery, automated issuance and renewal via ACME, EST, and SCEP, and private PKI delivered as a managed service. Backed by DigiCert, one of the world's largest public certificate authorities, so a single platform can govern both its own publicly-trusted certificates and those issued by other CAs.","website":"https://www.digicert.com/trust-lifecycle-manager","sourceUrls":["https://www.digicert.com/trust-lifecycle-manager"],"verifiedAt":"2026-07-11"},{"slug":"sectigo-certificate-manager","name":"Sectigo Certificate Manager","vendorSlug":"sectigo","productType":"software","openSource":false,"categorySlugs":["certificate-management"],"capabilities":["certificate-discovery","automated-renewal","deployment-integrations","private-ca"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Certificate Lifecycle Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"A CA-agnostic certificate lifecycle platform that discovers public and private certificates and automates their issuance, renewal, and revocation through ACME, SCEP, and EST across both public and private CAs, including Microsoft CA.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting in a proof of concept.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"certificate-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"private-ca":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-integrations":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"crypto-agility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A CA-agnostic certificate lifecycle platform that discovers public and private certificates and automates their issuance, renewal, and revocation through ACME, SCEP, and EST across both public and private CAs, including Microsoft CA. Ships with more than fifty integrations to push certificates where they're needed, and covers TLS, S/MIME, code-signing, and device certificates from one console.","website":"https://www.sectigo.com/certificate-manager","sourceUrls":["https://www.sectigo.com/certificate-manager"],"verifiedAt":"2026-07-11"},{"slug":"appviewx-avx-one-clm","name":"AppViewX AVX ONE CLM","vendorSlug":"appviewx","productType":"software","openSource":false,"categorySlugs":["certificate-management"],"capabilities":["certificate-discovery","automated-renewal","expiry-monitoring","deployment-integrations"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Certificate Lifecycle Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"A certificate lifecycle management platform that discovers, issues, renews, deploys, revokes, and monitors certificates across cloud, hybrid, Kubernetes, and on-prem environments, with ACME automation and deep CI/CD and DevOps integrations.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting in a proof of concept.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"certificate-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"private-ca":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"deployment-integrations":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"crypto-agility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A certificate lifecycle management platform that discovers, issues, renews, deploys, revokes, and monitors certificates across cloud, hybrid, Kubernetes, and on-prem environments, with ACME automation and deep CI/CD and DevOps integrations. Positioned around machine identity, it pushes certificates directly into the infrastructure that consumes them rather than stopping at issuance.","website":"https://www.appviewx.com/products/avx-one-clm/","sourceUrls":["https://www.appviewx.com/products/avx-one-clm/"],"verifiedAt":"2026-07-11"},{"slug":"step-ca","name":"step-ca","vendorSlug":"smallstep","productType":"software","openSource":true,"license":"Apache-2.0","categorySlugs":["certificate-management"],"capabilities":["private-ca","automated-renewal"],"deployment":["cli","on-prem","hybrid"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Certificate Lifecycle Management with a preference for a command-line, self-hosted, and hybrid operating model.","keyAdvantage":"An open-source, self-hosted private certificate authority for issuing X.509 and SSH certificates, with a built-in ACME server so internal services can request and renew their own certificates automatically.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting before standardizing.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"certificate-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"private-ca":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-integrations":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"crypto-agility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An open-source, self-hosted private certificate authority for issuing X.509 and SSH certificates, with a built-in ACME server so internal services can request and renew their own certificates automatically. Driven by the companion step command-line tool; Smallstep sells a hosted Certificate Manager built on the same engine for teams that don't want to run the CA themselves.","website":"https://smallstep.com/docs/step-ca/","sourceUrls":["https://smallstep.com/docs/step-ca/"],"verifiedAt":"2026-07-11"},{"slug":"certbot","name":"Certbot","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["certificate-management"],"capabilities":["automated-renewal","deployment-integrations"],"deployment":["cli","agent"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Certificate Lifecycle Management with a preference for a command-line and endpoint-agent operating model.","keyAdvantage":"The EFF's open-source ACME client — the most widely used way to automatically request, install, and renew free, publicly-trusted TLS certificates from Let's Encrypt, the certificate authority run by the nonprofit ISRG, or any other…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting before standardizing.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"certificate-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"private-ca":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"deployment-integrations":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"crypto-agility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The EFF's open-source ACME client — the most widely used way to automatically request, install, and renew free, publicly-trusted TLS certificates from Let's Encrypt, the certificate authority run by the nonprofit ISRG, or any other ACME-compliant CA. It runs on the server it protects, installing certificates straight into Apache or nginx, and recently added support for short-lived six-day certificates and IP-address certificates.","website":"https://certbot.eff.org/","sourceUrls":["https://certbot.eff.org/"],"verifiedAt":"2026-07-11"},{"slug":"ejbca","name":"EJBCA Community","vendorSlug":"keyfactor","productType":"software","openSource":true,"license":"LGPL-2.1-or-later","categorySlugs":["certificate-management"],"capabilities":["private-ca","automated-renewal"],"deployment":["on-prem","hybrid","cli"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Certificate Lifecycle Management with a preference for a self-hosted, hybrid, and command-line operating model.","keyAdvantage":"Open-source PKI and certificate authority software for issuing and managing X.509 certificates at scale, with CRL and OCSP revocation and support for the SCEP, EST, CMP, and ACME enrollment protocols.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Certificate discovery & inventory, Automated issuance & renewal, and Expiry monitoring & alerting before standardizing.","ecosystem":"Primary fit is Certificate Lifecycle Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the LGPL-2.1-or-later license and a freemium entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"certificate-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-renewal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"expiry-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"private-ca":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"deployment-integrations":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"crypto-agility":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Open-source PKI and certificate authority software for issuing and managing X.509 certificates at scale, with CRL and OCSP revocation and support for the SCEP, EST, CMP, and ACME enrollment protocols. The commercial Enterprise edition adds high availability, HSM integration, and support; EJBCA originated at Sweden's PrimeKey, which merged into Keyfactor in 2021.","website":"https://www.ejbca.org/","sourceUrls":["https://www.ejbca.org/"],"verifiedAt":"2026-07-11"},{"slug":"splunk-enterprise-security","name":"Splunk Enterprise Security","vendorSlug":"splunk","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"An enterprise SIEM built on the Splunk platform and its SPL search language, with broad support for correlation, investigation, dashboards, and user behavior analytics.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An enterprise SIEM built on the Splunk platform and its SPL search language, with broad support for correlation, investigation, dashboards, and user behavior analytics. Cisco completed its acquisition of Splunk in March 2024, and the product continues under the Splunk brand.","website":"https://www.splunk.com/en_us/products/enterprise-security.html","sourceUrls":["https://www.splunk.com/en_us/products/enterprise-security.html"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-sentinel","name":"Microsoft Sentinel","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["siem","soar"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"Microsoft's cloud SIEM with automation playbooks and consumption-based data ingestion.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management; this guide also maps the product to Security Orchestration, Automation & Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"playbook-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"case-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"connector-library":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"alert-triage-enrichment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"low-code-playbook-builder":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Microsoft's cloud SIEM with automation playbooks and consumption-based data ingestion. Many Microsoft 365 log sources ingest without charge. New customers have been directed to the Microsoft Defender portal since July 2025, and support for the Azure portal experience ends March 31, 2027.","website":"https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel","sourceUrls":["https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel","https://learn.microsoft.com/en-us/azure/sentinel/microsoft-sentinel-defender-portal"],"verifiedAt":"2026-07-11"},{"slug":"google-secops","name":"Google Security Operations","vendorSlug":"google","productType":"software","openSource":false,"categorySlugs":["siem","soar"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards","detection-as-code"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"Google's SIEM and SOAR platform, renamed from Chronicle in 2024, built on the same infrastructure that powers Google Search to make searching a year of security telemetry feel instant.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management; this guide also maps the product to Security Orchestration, Automation & Response. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"playbook-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"case-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"connector-library":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"alert-triage-enrichment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"low-code-playbook-builder":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Google's SIEM and SOAR platform, renamed from Chronicle in 2024, built on the same infrastructure that powers Google Search to make searching a year of security telemetry feel instant. Threat intelligence from Mandiant and VirusTotal is applied to customer data automatically, and pricing is designed around retaining everything rather than sampling.","website":"https://cloud.google.com/security/products/security-operations","sourceUrls":["https://cloud.google.com/security/products/security-operations"],"verifiedAt":"2026-07-11"},{"slug":"elastic-security","name":"Elastic Security","vendorSlug":"elastic","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards","detection-as-code"],"deployment":["saas","on-prem","hybrid"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Information & Event Management with a preference for a SaaS, self-hosted, and hybrid operating model.","keyAdvantage":"SIEM and endpoint security built on the Elasticsearch stack, with a genuinely usable free self-managed tier and an openly published detection rule repository.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"SIEM and endpoint security built on the Elasticsearch stack, with a genuinely usable free self-managed tier and an openly published detection rule repository. Elastic re-added the OSI-approved AGPL as a source-license option in 2024, but its official distributions still ship under the non-OSI Elastic License 2.0, so the product as normally run is free-tier source-available rather than fully open source.","website":"https://www.elastic.co/security","sourceUrls":["https://www.elastic.co/security"],"verifiedAt":"2026-07-11"},{"slug":"sumo-logic-cloud-siem","name":"Sumo Logic Cloud SIEM","vendorSlug":"sumo-logic","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"A SaaS SIEM running on Sumo Logic's log analytics platform.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A SaaS SIEM running on Sumo Logic's log analytics platform. It groups related alerts into prioritized insights and lets customers use the same ingestion and search layer for observability and security data. Francisco Partners took the company private in 2023.","website":"https://www.sumologic.com/solutions/cloud-siem","sourceUrls":["https://www.sumologic.com/solutions/cloud-siem"],"verifiedAt":"2026-07-11"},{"slug":"datadog-cloud-siem","name":"Datadog Cloud SIEM","vendorSlug":"datadog","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","dashboards"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"Security detection built into the Datadog observability platform, using logs that engineering teams already send for monitoring.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Security detection built into the Datadog observability platform, using logs that engineering teams already send for monitoring. Detection rules and investigations sit alongside Datadog's other monitors, which suits organizations where DevOps and security share the platform.","website":"https://www.datadoghq.com/product/cloud-siem/","sourceUrls":["https://www.datadoghq.com/product/cloud-siem/"],"verifiedAt":"2026-07-11"},{"slug":"exabeam-new-scale","name":"Exabeam New-Scale Security Operations Platform","vendorSlug":"exabeam","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"Exabeam's flagship SIEM, distinguished by the user and entity behavior analytics the company was founded on — building a per-user baseline and assembling anomalous events into scored timelines instead of leaving analysts to correlate…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Exabeam's flagship SIEM, distinguished by the user and entity behavior analytics the company was founded on — building a per-user baseline and assembling anomalous events into scored timelines instead of leaving analysts to correlate manually. Following the 2024 merger, the LogRhythm SIEM continues to be sold and developed as a separate self-hosted line.","website":"https://www.exabeam.com/platform/exabeam-new-scale-fusion-security-operations-platform/","sourceUrls":["https://www.exabeam.com/platform/exabeam-new-scale-fusion-security-operations-platform/"],"verifiedAt":"2026-07-11"},{"slug":"securonix-unified-defense-siem","name":"Securonix Unified Defense SIEM","vendorSlug":"securonix","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","ueba","dashboards"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"A cloud SIEM built around behavior analytics, running on a Snowflake-based data backend and threat content curated by Securonix's research labs.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A cloud SIEM built around behavior analytics, running on a Snowflake-based data backend and threat content curated by Securonix's research labs. The 2025 acquisition of ThreatQuotient folded a dedicated threat intelligence platform into the same portfolio; backed by a $1B+ Vista Equity Partners investment.","website":"https://www.securonix.com/products/siem-solutions/","sourceUrls":["https://www.securonix.com/products/siem-solutions/"],"verifiedAt":"2026-07-11"},{"slug":"panther","name":"Panther","vendorSlug":"panther-labs","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","dashboards","detection-as-code"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"A detection-as-code SIEM where detections are written in Python, versioned in git, and tested in CI like any other software, running on a security data lake architecture that separates storage from compute to keep high-volume retention…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A detection-as-code SIEM where detections are written in Python, versioned in git, and tested in CI like any other software, running on a security data lake architecture that separates storage from compute to keep high-volume retention affordable. Databricks announced an agreement to acquire Panther Labs in June 2026.","website":"https://panther.com","sourceUrls":["https://panther.com"],"verifiedAt":"2026-07-11"},{"slug":"crowdstrike-falcon-next-gen-siem","name":"Falcon Next-Gen SIEM","vendorSlug":"crowdstrike","productType":"software","openSource":false,"categorySlugs":["siem"],"capabilities":["log-ingestion","correlation-rules","search","dashboards"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Information & Event Management with a preference for a SaaS operating model.","keyAdvantage":"CrowdStrike's SIEM uses the log management engine acquired with Humio in 2021 and is sold through the Falcon platform.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ueba":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dashboards":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"detection-as-code":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"CrowdStrike's SIEM uses the log management engine acquired with Humio in 2021 and is sold through the Falcon platform. Falcon endpoint and identity telemetry is already available there and does not count against third-party ingest volume.","website":"https://www.crowdstrike.com/en-us/platform/next-gen-siem/","sourceUrls":["https://www.crowdstrike.com/en-us/platform/next-gen-siem/"],"verifiedAt":"2026-07-11"},{"slug":"sigma","name":"Sigma","productType":"project","openSource":false,"categorySlugs":["siem"],"capabilities":["detection-as-code","correlation-rules"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Security Information & Event Management with a preference for a command-line operating model.","keyAdvantage":"The generic, YAML-based signature format for SIEM detections — write a detection once, convert it to the query language of whichever SIEM you run.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Broad log ingestion, Correlation & detection rules, and Fast historical search in a proof of concept.","ecosystem":"Primary fit is Security Information & Event Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"log-ingestion":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"correlation-rules":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"search":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ueba":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dashboards":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"detection-as-code":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"The generic, YAML-based signature format for SIEM detections — write a detection once, convert it to the query language of whichever SIEM you run. The conversion tooling (pySigma, sigma-cli) is LGPL-licensed open source, but the community rule repository ships under the non-OSI Detection Rule License, so the project as a whole is mixed-license rather than fully open source.","website":"https://sigmahq.io","sourceUrls":["https://sigmahq.io"],"verifiedAt":"2026-07-11"},{"slug":"cortex-xsoar","name":"Cortex XSOAR","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["soar"],"capabilities":["playbook-automation","case-management","connector-library","alert-triage-enrichment","low-code-playbook-builder","metrics-sla-reporting"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Orchestration, Automation & Response with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"Palo Alto Networks' dedicated SOAR product, built from its 2019 acquisition of Demisto.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Playbook / workflow automation, Case management, and Integration & connector library in a proof of concept.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"low-code-playbook-builder":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"metrics-sla-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Palo Alto Networks' dedicated SOAR product, built from its 2019 acquisition of Demisto. It ships with a large catalog of integrations and playbooks and remains available separately from Cortex XSIAM.","website":"https://www.paloaltonetworks.com/cortex/cortex-xsoar","sourceUrls":["https://www.paloaltonetworks.com/cortex/cortex-xsoar"],"verifiedAt":"2026-07-11"},{"slug":"splunk-soar","name":"Splunk SOAR","vendorSlug":"splunk","productType":"software","openSource":false,"categorySlugs":["soar"],"capabilities":["playbook-automation","case-management","connector-library","alert-triage-enrichment","low-code-playbook-builder"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Orchestration, Automation & Response with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"Splunk's orchestration and automation product, acquired as Phantom in 2018 and most commonly deployed as the response arm alongside Splunk Enterprise Security.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Playbook / workflow automation, Case management, and Integration & connector library in a proof of concept.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"low-code-playbook-builder":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Splunk's orchestration and automation product, acquired as Phantom in 2018 and most commonly deployed as the response arm alongside Splunk Enterprise Security. Playbooks can be built in a visual editor or written directly in Python for teams that prefer code.","website":"https://www.splunk.com/en_us/products/splunk-security-orchestration-and-automation.html","sourceUrls":["https://www.splunk.com/en_us/products/splunk-security-orchestration-and-automation.html"],"verifiedAt":"2026-07-11"},{"slug":"tines","name":"Tines","vendorSlug":"tines","productType":"software","openSource":false,"categorySlugs":["soar"],"capabilities":["playbook-automation","connector-library","alert-triage-enrichment","low-code-playbook-builder"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Orchestration, Automation & Response with a preference for a SaaS operating model.","keyAdvantage":"A no-code workflow automation platform that grew out of security orchestration, built from seven simple composable actions rather than tool-specific integrations — any service with an API can be automated without waiting for a vendor…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Playbook / workflow automation, Case management, and Integration & connector library in a proof of concept.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"low-code-playbook-builder":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A no-code workflow automation platform that grew out of security orchestration, built from seven simple composable actions rather than tool-specific integrations — any service with an API can be automated without waiting for a vendor connector. A free Community Edition makes it one of the easiest ways to start automating; increasingly sold beyond security into general IT workflows.","website":"https://www.tines.com","sourceUrls":["https://www.tines.com"],"verifiedAt":"2026-07-11"},{"slug":"torq","name":"Torq","vendorSlug":"torq","productType":"software","openSource":false,"categorySlugs":["soar"],"capabilities":["playbook-automation","case-management","connector-library","alert-triage-enrichment","low-code-playbook-builder"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Orchestration, Automation & Response with a preference for a SaaS operating model.","keyAdvantage":"A security 'hyperautomation' platform positioned explicitly against first-generation SOAR, pairing no-code workflow building with AI agents that autonomously triage and investigate a share of routine alerts before a human sees them.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Playbook / workflow automation, Case management, and Integration & connector library in a proof of concept.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"low-code-playbook-builder":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A security 'hyperautomation' platform positioned explicitly against first-generation SOAR, pairing no-code workflow building with AI agents that autonomously triage and investigate a share of routine alerts before a human sees them. Independent and VC-backed, valued at $1.2B after a January 2026 Series D.","website":"https://torq.io","sourceUrls":["https://torq.io"],"verifiedAt":"2026-07-11"},{"slug":"swimlane-turbine","name":"Swimlane Turbine","vendorSlug":"swimlane","productType":"software","openSource":false,"categorySlugs":["soar"],"capabilities":["playbook-automation","case-management","connector-library","low-code-playbook-builder","metrics-sla-reporting"],"deployment":["saas","on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Orchestration, Automation & Response with a preference for a SaaS and self-hosted operating model.","keyAdvantage":"Swimlane's low-code automation platform, pairing workflow automation with unusually deep case management and dashboarding — closer to a build-your-own security operations workbench than a pure playbook runner.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Playbook / workflow automation, Case management, and Integration & connector library in a proof of concept.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"low-code-playbook-builder":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"metrics-sla-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Swimlane's low-code automation platform, pairing workflow automation with unusually deep case management and dashboarding — closer to a build-your-own security operations workbench than a pure playbook runner. Self-hosted deployment options keep it viable for government and other restricted environments.","website":"https://swimlane.com/swimlane-turbine/","sourceUrls":["https://swimlane.com/swimlane-turbine/"],"verifiedAt":"2026-07-11"},{"slug":"shuffle","name":"Shuffle","vendorSlug":"shuffle","productType":"software","openSource":true,"license":"AGPL-3.0","categorySlugs":["soar"],"capabilities":["playbook-automation","connector-library","low-code-playbook-builder"],"deployment":["on-prem","saas"],"targetOrgSize":["smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Security Orchestration, Automation & Response with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"A self-hosted, AGPL-licensed SOAR workflow engine with a visual editor and an app library built from OpenAPI specifications.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Playbook / workflow automation, Case management, and Integration & connector library before standardizing.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the AGPL-3.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"low-code-playbook-builder":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A self-hosted, AGPL-licensed SOAR workflow engine with a visual editor and an app library built from OpenAPI specifications. The company also sells hosted cloud and enterprise support tiers.","website":"https://shuffler.io","sourceUrls":["https://shuffler.io"],"verifiedAt":"2026-07-11"},{"slug":"thehive","name":"TheHive","vendorSlug":"strangebee","productType":"software","openSource":false,"categorySlugs":["soar"],"capabilities":["case-management","alert-triage-enrichment","connector-library","metrics-sla-reporting"],"deployment":["on-prem","saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Orchestration, Automation & Response with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"A security incident response and case management platform with a huge community following from its open-source era.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Playbook / workflow automation, Case management, and Integration & connector library in a proof of concept.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"playbook-automation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"case-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"low-code-playbook-builder":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"metrics-sla-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A security incident response and case management platform with a huge community following from its open-source era. Versions 3 and 4 were AGPL open source but are end-of-life and no longer publicly distributed; the current TheHive 5, developed by StrangeBee, is a proprietary product with a free-but-limited Community license and paid tiers above it.","website":"https://strangebee.com/thehive/","sourceUrls":["https://strangebee.com/thehive/"],"verifiedAt":"2026-07-11"},{"slug":"cortex-thehive","name":"Cortex (TheHive)","vendorSlug":"strangebee","productType":"software","openSource":true,"license":"AGPL-3.0","categorySlugs":["soar"],"capabilities":["alert-triage-enrichment","connector-library","playbook-automation"],"deployment":["on-prem"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Orchestration, Automation & Response with a preference for a self-hosted operating model.","keyAdvantage":"TheHive project's open-source analysis engine — no relation to Palo Alto Networks' similarly named Cortex products.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Playbook / workflow automation, Case management, and Integration & connector library before standardizing.","ecosystem":"Primary fit is Security Orchestration, Automation & Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the AGPL-3.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"playbook-automation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"case-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"connector-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"alert-triage-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"low-code-playbook-builder":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"metrics-sla-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"TheHive project's open-source analysis engine — no relation to Palo Alto Networks' similarly named Cortex products. It runs a library of analyzers to enrich observables like IPs, domains, and file hashes against dozens of intelligence services, plus responders that take automated action; unlike TheHive itself, it remains fully AGPL open source under StrangeBee's maintenance.","website":"https://github.com/TheHive-Project/Cortex","sourceUrls":["https://github.com/TheHive-Project/Cortex"],"verifiedAt":"2026-07-11"},{"slug":"recorded-future","name":"Recorded Future","vendorSlug":"recorded-future","productType":"software","openSource":false,"categorySlugs":["threat-intelligence"],"capabilities":["curated-ioc-feeds","adversary-ttp-profiles","dark-web-brand-monitoring","siem-soar-enrichment","vulnerability-exploit-intel","analyst-research-portal"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Threat Intelligence with a preference for a SaaS operating model.","keyAdvantage":"A threat intelligence platform combining automated collection across the open, deep, and dark web with research from the Insikt Group.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Curated IOC feeds, Adversary & TTP profiles, and Dark web & brand monitoring in a proof of concept.","ecosystem":"Primary fit is Threat Intelligence. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"curated-ioc-feeds":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adversary-ttp-profiles":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dark-web-brand-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"siem-soar-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-exploit-intel":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"analyst-research-portal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A threat intelligence platform combining automated collection across the open, deep, and dark web with research from the Insikt Group. Its modules range from indicator feeds to brand, third-party, and geopolitical intelligence. Recorded Future has operated as a Mastercard subsidiary since December 2024.","website":"https://www.recordedfuture.com","sourceUrls":["https://www.recordedfuture.com"],"verifiedAt":"2026-07-11"},{"slug":"google-threat-intelligence","name":"Google Threat Intelligence","vendorSlug":"google","productType":"software","openSource":false,"categorySlugs":["threat-intelligence"],"capabilities":["curated-ioc-feeds","adversary-ttp-profiles","siem-soar-enrichment","vulnerability-exploit-intel","analyst-research-portal"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Threat Intelligence with a preference for a SaaS operating model.","keyAdvantage":"Google's consolidated threat intelligence product, combining Mandiant's frontline incident-response research, VirusTotal's malware corpus, and Google's own visibility from protecting billions of users.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Curated IOC feeds, Adversary & TTP profiles, and Dark web & brand monitoring in a proof of concept.","ecosystem":"Primary fit is Threat Intelligence. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"curated-ioc-feeds":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adversary-ttp-profiles":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dark-web-brand-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"siem-soar-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-exploit-intel":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"analyst-research-portal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Google's consolidated threat intelligence product, combining Mandiant's frontline incident-response research, VirusTotal's malware corpus, and Google's own visibility from protecting billions of users. Replaced the separately branded Mandiant Threat Intelligence product, though the Mandiant name lives on for consulting and IR services.","website":"https://cloud.google.com/security/products/threat-intelligence","sourceUrls":["https://cloud.google.com/security/products/threat-intelligence"],"verifiedAt":"2026-07-11"},{"slug":"anomali-threatstream","name":"Anomali ThreatStream","vendorSlug":"anomali","productType":"software","openSource":false,"categorySlugs":["threat-intelligence"],"capabilities":["curated-ioc-feeds","adversary-ttp-profiles","siem-soar-enrichment","analyst-research-portal"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Threat Intelligence with a preference for a SaaS operating model.","keyAdvantage":"A threat intelligence platform (TIP) rather than primarily an intel producer: it aggregates commercial, open-source, and ISAC feeds, deduplicates and scores the indicators, and pushes the curated result into SIEM and security controls.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Curated IOC feeds, Adversary & TTP profiles, and Dark web & brand monitoring in a proof of concept.","ecosystem":"Primary fit is Threat Intelligence. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"curated-ioc-feeds":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adversary-ttp-profiles":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dark-web-brand-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"siem-soar-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-exploit-intel":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"analyst-research-portal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A threat intelligence platform (TIP) rather than primarily an intel producer: it aggregates commercial, open-source, and ISAC feeds, deduplicates and scores the indicators, and pushes the curated result into SIEM and security controls. Relaunched as ThreatStream Next-Gen in 2026 with AI-assisted analysis on top of the aggregation core.","website":"https://www.anomali.com/products/threatstream","sourceUrls":["https://www.anomali.com/products/threatstream"],"verifiedAt":"2026-07-11"},{"slug":"flashpoint-ignite","name":"Flashpoint Ignite","vendorSlug":"flashpoint","productType":"software","openSource":false,"categorySlugs":["threat-intelligence"],"capabilities":["dark-web-brand-monitoring","curated-ioc-feeds","vulnerability-exploit-intel","analyst-research-portal"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Threat Intelligence with a preference for a SaaS operating model.","keyAdvantage":"Flashpoint's intelligence platform, differentiated by deep, long-cultivated visibility into closed criminal communities — ransomware gangs, fraud shops, extremist forums — that automated crawlers can't reach.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Curated IOC feeds, Adversary & TTP profiles, and Dark web & brand monitoring in a proof of concept.","ecosystem":"Primary fit is Threat Intelligence. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"curated-ioc-feeds":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adversary-ttp-profiles":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dark-web-brand-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"siem-soar-enrichment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vulnerability-exploit-intel":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"analyst-research-portal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Flashpoint's intelligence platform, differentiated by deep, long-cultivated visibility into closed criminal communities — ransomware gangs, fraud shops, extremist forums — that automated crawlers can't reach. Serves fraud and physical security teams alongside cyber threat intelligence, reflecting where that community visibility pays off.","website":"https://flashpoint.io/ignite/","sourceUrls":["https://flashpoint.io/ignite/"],"verifiedAt":"2026-07-11"},{"slug":"misp","name":"MISP","productType":"project","openSource":true,"license":"AGPL-3.0","categorySlugs":["threat-intelligence"],"capabilities":["curated-ioc-feeds","siem-soar-enrichment"],"deployment":["on-prem"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Threat Intelligence with a preference for a self-hosted operating model.","keyAdvantage":"An AGPL-licensed platform for storing and sharing structured threat intelligence, developed and stewarded by CIRCL, Luxembourg's national CERT.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Curated IOC feeds, Adversary & TTP profiles, and Dark web & brand monitoring before standardizing.","ecosystem":"Primary fit is Threat Intelligence. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the AGPL-3.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"curated-ioc-feeds":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adversary-ttp-profiles":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dark-web-brand-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"siem-soar-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-exploit-intel":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"analyst-research-portal":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An AGPL-licensed platform for storing and sharing structured threat intelligence, developed and stewarded by CIRCL, Luxembourg's national CERT. Organizations can run their own instance and synchronize selected data with ISACs, national CERTs, and other sharing communities.","website":"https://www.misp-project.org","sourceUrls":["https://www.misp-project.org"],"verifiedAt":"2026-07-11"},{"slug":"opencti","name":"OpenCTI","vendorSlug":"filigran","productType":"software","openSource":true,"license":"Apache-2.0","categorySlugs":["threat-intelligence"],"capabilities":["adversary-ttp-profiles","curated-ioc-feeds","siem-soar-enrichment","analyst-research-portal"],"deployment":["on-prem","saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Threat Intelligence with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"An open-source threat intelligence platform that structures knowledge as a connected STIX graph — linking adversaries, campaigns, techniques, and indicators rather than storing flat feeds — with a large connector ecosystem for imports and…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Curated IOC feeds, Adversary & TTP profiles, and Dark web & brand monitoring before standardizing.","ecosystem":"Primary fit is Threat Intelligence. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a freemium entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"curated-ioc-feeds":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"adversary-ttp-profiles":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dark-web-brand-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"siem-soar-enrichment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vulnerability-exploit-intel":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"analyst-research-portal":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An open-source threat intelligence platform that structures knowledge as a connected STIX graph — linking adversaries, campaigns, techniques, and indicators rather than storing flat feeds — with a large connector ecosystem for imports and enrichment. The Apache-2.0 Community Edition is fully open source; Filigran sells a proprietary Enterprise Edition and hosted service on top.","website":"https://filigran.io/platform/opencti/","sourceUrls":["https://filigran.io/platform/opencti/"],"verifiedAt":"2026-07-11"},{"slug":"tenable-nessus","name":"Tenable Nessus","vendorSlug":"tenable","productType":"software","openSource":false,"categorySlugs":["vulnerability-management"],"capabilities":["asset-discovery-scanning","authenticated-scanning","compliance-benchmark-reporting"],"deployment":["on-prem","cli"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Vulnerability Management with a preference for a self-hosted and command-line operating model.","keyAdvantage":"Tenable's standalone vulnerability scanner and the scanning engine used by its larger platform products.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Asset discovery & scanning, Risk-based prioritization, and Remediation & patch tracking in a proof of concept.","ecosystem":"Primary fit is Vulnerability Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"asset-discovery-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-based-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"remediation-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmark-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ticketing-cmdb-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Tenable's standalone vulnerability scanner and the scanning engine used by its larger platform products. Nessus Essentials scans up to 16 IP addresses at no charge; Professional and Expert add commercial features and higher limits.","website":"https://www.tenable.com/products/nessus","sourceUrls":["https://www.tenable.com/products/nessus"],"verifiedAt":"2026-07-11"},{"slug":"tenable-vulnerability-management","name":"Tenable Vulnerability Management","vendorSlug":"tenable","productType":"software","openSource":false,"categorySlugs":["vulnerability-management"],"capabilities":["asset-discovery-scanning","risk-based-prioritization","remediation-tracking","authenticated-scanning","compliance-benchmark-reporting","ticketing-cmdb-integration"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Vulnerability Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Tenable's cloud-based VM platform (formerly Tenable.io), running Nessus-powered scans and agents at fleet scale with Vulnerability Priority Rating to rank findings by predicted exploitation rather than raw severity.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Asset discovery & scanning, Risk-based prioritization, and Remediation & patch tracking in a proof of concept.","ecosystem":"Primary fit is Vulnerability Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"asset-discovery-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-based-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmark-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ticketing-cmdb-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Tenable's cloud-based VM platform (formerly Tenable.io), running Nessus-powered scans and agents at fleet scale with Vulnerability Priority Rating to rank findings by predicted exploitation rather than raw severity. Feeds the broader Tenable One exposure management platform, which extends the same risk model across cloud, identity, and OT.","website":"https://www.tenable.com/products/vulnerability-management","sourceUrls":["https://www.tenable.com/products/vulnerability-management"],"verifiedAt":"2026-07-11"},{"slug":"qualys-vmdr","name":"Qualys VMDR","vendorSlug":"qualys","productType":"software","openSource":false,"categorySlugs":["vulnerability-management"],"capabilities":["asset-discovery-scanning","risk-based-prioritization","remediation-tracking","authenticated-scanning","compliance-benchmark-reporting","ticketing-cmdb-integration"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Vulnerability Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Qualys's flagship — Vulnerability Management, Detection and Response — covering the full loop from asset discovery through TruRisk-scored prioritization to one-click patch deployment, all through the single lightweight cloud agent that…","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Asset discovery & scanning, Risk-based prioritization, and Remediation & patch tracking in a proof of concept.","ecosystem":"Primary fit is Vulnerability Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"asset-discovery-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-based-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmark-reporting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ticketing-cmdb-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Qualys's flagship — Vulnerability Management, Detection and Response — covering the full loop from asset discovery through TruRisk-scored prioritization to one-click patch deployment, all through the single lightweight cloud agent that underpins the whole Qualys platform. One of the longest-running SaaS products in security.","website":"https://www.qualys.com/apps/vulnerability-management-detection-response/","sourceUrls":["https://www.qualys.com/apps/vulnerability-management-detection-response/"],"verifiedAt":"2026-07-11"},{"slug":"rapid7-insightvm","name":"Rapid7 InsightVM","vendorSlug":"rapid7","productType":"software","openSource":false,"categorySlugs":["vulnerability-management"],"capabilities":["asset-discovery-scanning","risk-based-prioritization","remediation-tracking","authenticated-scanning","ticketing-cmdb-integration"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Vulnerability Management with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"Rapid7's vulnerability management product, known for its Active Risk scoring and live dashboards that track remediation progress by team.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Asset discovery & scanning, Risk-based prioritization, and Remediation & patch tracking in a proof of concept.","ecosystem":"Primary fit is Vulnerability Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"asset-discovery-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-based-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"remediation-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmark-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ticketing-cmdb-integration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Rapid7's vulnerability management product, known for its Active Risk scoring and live dashboards that track remediation progress by team. Now sold within the tiered Rapid7 Exposure Command platform, though InsightVM remains the working product name; Rapid7 itself stayed an independent public company through 2025-2026 activist-investor pressure.","website":"https://www.rapid7.com/products/insightvm/","sourceUrls":["https://www.rapid7.com/products/insightvm/"],"verifiedAt":"2026-07-11"},{"slug":"openvas","name":"OpenVAS (Greenbone Community Edition)","vendorSlug":"greenbone","productType":"software","openSource":true,"license":"GPL-2.0","categorySlugs":["vulnerability-management"],"capabilities":["asset-discovery-scanning","authenticated-scanning"],"deployment":["on-prem"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Vulnerability Management with a preference for a self-hosted operating model.","keyAdvantage":"The standard open-source vulnerability scanner, forked from the last free Nessus release in 2005 and developed since by Germany's Greenbone.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Asset discovery & scanning, Risk-based prioritization, and Remediation & patch tracking before standardizing.","ecosystem":"Primary fit is Vulnerability Management. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the GPL-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"asset-discovery-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-based-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"remediation-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"authenticated-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"compliance-benchmark-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ticketing-cmdb-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The standard open-source vulnerability scanner, forked from the last free Nessus release in 2005 and developed since by Germany's Greenbone. The GPL-licensed scanner ships in the free Greenbone Community Edition with a community vulnerability-test feed; Greenbone's paid appliances and Enterprise Feed add coverage, support, and management at scale.","website":"https://www.greenbone.net/en/testnow/","sourceUrls":["https://www.greenbone.net/en/testnow/"],"verifiedAt":"2026-07-11"},{"slug":"runzero","name":"runZero","vendorSlug":"runzero","productType":"software","openSource":false,"categorySlugs":["asm-bas","vulnerability-management"],"capabilities":["external-attack-surface-discovery","exposure-prioritization"],"deployment":["saas","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"An asset discovery and exposure management platform co-created by Metasploit author HD Moore, using unusually careful unauthenticated scanning plus passive discovery to find the unmanaged, OT, and IoT devices agent-based tools can't see —…","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation in a proof of concept.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation; this guide also maps the product to Vulnerability Management. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exposure-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"breach-attack-simulation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"control-validation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"asset-discovery-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-based-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"remediation-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"authenticated-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"compliance-benchmark-reporting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ticketing-cmdb-integration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An asset discovery and exposure management platform co-created by Metasploit author HD Moore, using unusually careful unauthenticated scanning plus passive discovery to find the unmanaged, OT, and IoT devices agent-based tools can't see — inside the network as well as on its internet edge. Accenture announced an agreement to acquire the company in 2026.","website":"https://www.runzero.com","sourceUrls":["https://www.runzero.com"],"verifiedAt":"2026-07-11"},{"slug":"censys-attack-surface-management","name":"Censys Attack Surface Management","vendorSlug":"censys","productType":"software","openSource":false,"categorySlugs":["asm-bas"],"capabilities":["external-attack-surface-discovery","exposure-prioritization"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a SaaS operating model.","keyAdvantage":"External attack surface management built on Censys's continuous scans of the entire public internet — the same data researchers query through the free Censys Search community tier.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation in a proof of concept.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exposure-prioritization":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"breach-attack-simulation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"control-validation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"External attack surface management built on Censys's continuous scans of the entire public internet — the same data researchers query through the free Censys Search community tier. Attributes internet-facing assets to an organization automatically and flags new exposures as its scan data refreshes.","website":"https://censys.com/product/attack-surface-management/","sourceUrls":["https://censys.com/product/attack-surface-management/"],"verifiedAt":"2026-07-11"},{"slug":"shodan","name":"Shodan","productType":"software","openSource":false,"categorySlugs":["asm-bas"],"capabilities":["external-attack-surface-discovery"],"deployment":["saas"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"freemium","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a SaaS operating model.","keyAdvantage":"The original search engine for internet-connected devices, launched in 2009 by John Matherly and still famously accessible — a one-time membership fee unlocks most researcher features, with API subscriptions and the Shodan Monitor…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation in a proof of concept.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exposure-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"breach-attack-simulation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"control-validation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"attack-path-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The original search engine for internet-connected devices, launched in 2009 by John Matherly and still famously accessible — a one-time membership fee unlocks most researcher features, with API subscriptions and the Shodan Monitor alerting service on top. The quickest way to see what an attacker sees about any organization's exposed services.","website":"https://www.shodan.io","sourceUrls":["https://www.shodan.io"],"verifiedAt":"2026-07-11"},{"slug":"pentera","name":"Pentera","vendorSlug":"pentera","productType":"software","openSource":false,"categorySlugs":["asm-bas"],"capabilities":["breach-attack-simulation","control-validation","attack-path-mapping","continuous-testing"],"deployment":["on-prem","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a self-hosted and SaaS operating model.","keyAdvantage":"Automated security validation that goes a step beyond simulation: it safely executes real exploits and attack chains against production systems — agentlessly — to prove which exposures are actually exploitable end to end, not just…","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation in a proof of concept.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"exposure-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"breach-attack-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"control-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Automated security validation that goes a step beyond simulation: it safely executes real exploits and attack chains against production systems — agentlessly — to prove which exposures are actually exploitable end to end, not just theoretically present. Output is a prioritized list of proven attack paths with the choke points that break them.","website":"https://pentera.io","sourceUrls":["https://pentera.io"],"verifiedAt":"2026-07-11"},{"slug":"safebreach","name":"SafeBreach","vendorSlug":"safebreach","productType":"software","openSource":false,"categorySlugs":["asm-bas"],"capabilities":["breach-attack-simulation","control-validation","continuous-testing"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"A breach and attack simulation pioneer whose platform continuously replays thousands of attack methods from its Hacker's Playbook — mapped to MITRE ATT&CK and updated within 24 hours of major new threats — through simulators deployed…","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation in a proof of concept.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"exposure-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"breach-attack-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"control-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A breach and attack simulation pioneer whose platform continuously replays thousands of attack methods from its Hacker's Playbook — mapped to MITRE ATT&CK and updated within 24 hours of major new threats — through simulators deployed across the environment, scoring which security controls blocked, detected, or missed each one.","website":"https://www.safebreach.com","sourceUrls":["https://www.safebreach.com"],"verifiedAt":"2026-07-11"},{"slug":"metasploit-framework","name":"Metasploit Framework","vendorSlug":"rapid7","productType":"software","openSource":true,"license":"BSD-3-Clause","categorySlugs":["asm-bas"],"capabilities":["breach-attack-simulation","control-validation"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a command-line operating model.","keyAdvantage":"The standard open-source penetration testing framework: a huge, continuously updated library of exploits and payloads that security teams use to validate whether vulnerabilities are actually exploitable and whether defenses catch the…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation before standardizing.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the BSD-3-Clause license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"exposure-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"breach-attack-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"control-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The standard open-source penetration testing framework: a huge, continuously updated library of exploits and payloads that security teams use to validate whether vulnerabilities are actually exploitable and whether defenses catch the attempt. Stewarded by Rapid7 since 2009, which sells the separate Metasploit Pro on top of the free BSD-licensed framework.","website":"https://www.metasploit.com","sourceUrls":["https://www.metasploit.com"],"verifiedAt":"2026-07-11"},{"slug":"kali-linux","name":"Kali Linux","vendorSlug":"offsec","productType":"distribution","openSource":false,"categorySlugs":["asm-bas"],"capabilities":["external-attack-surface-discovery","control-validation"],"deployment":["on-prem"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Attack Surface Management & Breach/Attack Simulation with a preference for a self-hosted operating model.","keyAdvantage":"A free Debian-based distribution maintained by OffSec and preloaded with reconnaissance, exploitation, and forensics tools.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and External attack surface discovery, Exposure prioritization, and Breach and attack simulation in a proof of concept.","ecosystem":"Primary fit is Attack Surface Management & Breach/Attack Simulation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"external-attack-surface-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"exposure-prioritization":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"breach-attack-simulation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"control-validation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"attack-path-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A free Debian-based distribution maintained by OffSec and preloaded with reconnaissance, exploitation, and forensics tools. Kali's own infrastructure is GPL-licensed and many bundled tools are open source, but the distribution also includes software under other terms, so it does not have one project-wide open-source license.","website":"https://www.kali.org","sourceUrls":["https://www.kali.org"],"verifiedAt":"2026-07-11"},{"slug":"magnet-axiom","name":"Magnet Axiom","vendorSlug":"magnet-forensics","productType":"software","openSource":false,"categorySlugs":["dfir"],"capabilities":["forensic-acquisition","timeline-reconstruction","chain-of-custody","root-cause-scope-analysis"],"deployment":["on-prem"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Digital Forensics & Incident Response with a preference for a self-hosted operating model.","keyAdvantage":"A digital forensics suite for recovering and analyzing evidence from computers, smartphones, and cloud accounts in one case file.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Endpoint & memory forensic acquisition, Timeline reconstruction, and Malware analysis in a proof of concept.","ecosystem":"Primary fit is Digital Forensics & Incident Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"forensic-acquisition":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"timeline-reconstruction":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"malware-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ir-playbooks-retainer":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"chain-of-custody":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"root-cause-scope-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A digital forensics suite for recovering and analyzing evidence from computers, smartphones, and cloud accounts in one case file. Magnet sells it to law-enforcement and corporate investigation teams alongside the GrayKey mobile-access products added through the Grayshift merger.","website":"https://www.magnetforensics.com/products/magnet-axiom/","sourceUrls":["https://www.magnetforensics.com/products/magnet-axiom/"],"verifiedAt":"2026-07-11"},{"slug":"binalyze-air","name":"Binalyze AIR","vendorSlug":"binalyze","productType":"software","openSource":false,"categorySlugs":["dfir"],"capabilities":["forensic-acquisition","timeline-reconstruction","root-cause-scope-analysis"],"deployment":["saas","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Digital Forensics & Incident Response with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"A DFIR automation platform built for speed at enterprise scale: agents collect full forensic evidence — hundreds of artifact types — from remote endpoints in minutes rather than the hours of a traditional disk image, then run automated…","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Endpoint & memory forensic acquisition, Timeline reconstruction, and Malware analysis in a proof of concept.","ecosystem":"Primary fit is Digital Forensics & Incident Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"forensic-acquisition":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"timeline-reconstruction":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"malware-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ir-playbooks-retainer":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"chain-of-custody":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"root-cause-scope-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A DFIR automation platform built for speed at enterprise scale: agents collect full forensic evidence — hundreds of artifact types — from remote endpoints in minutes rather than the hours of a traditional disk image, then run automated compromise assessment across the collected data. Positioned to make forensic-depth investigation part of routine incident response.","website":"https://binalyze.com","sourceUrls":["https://binalyze.com"],"verifiedAt":"2026-07-11"},{"slug":"mandiant-incident-response","name":"Mandiant Incident Response","vendorSlug":"google","productType":"service","openSource":false,"categorySlugs":["dfir"],"capabilities":["ir-playbooks-retainer","forensic-acquisition","malware-analysis","root-cause-scope-analysis"],"deployment":["hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Digital Forensics & Incident Response with a preference for a hybrid operating model.","keyAdvantage":"Google Cloud's incident response and investigation service, acquired with Mandiant in 2022 and still sold under the Mandiant brand.","tradeoff":"The result depends on the provider's operating scope. Validate coverage hours, response authority, escalation paths, evidence access, and what remains customer-owned.","ecosystem":"Primary fit is Digital Forensics & Incident Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"forensic-acquisition":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"timeline-reconstruction":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malware-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ir-playbooks-retainer":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"chain-of-custody":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"root-cause-scope-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Google Cloud's incident response and investigation service, acquired with Mandiant in 2022 and still sold under the Mandiant brand. Organizations can retain the team before an incident, and findings from investigations also inform Google's threat intelligence products.","website":"https://cloud.google.com/security/consulting/mandiant-incident-response-services","sourceUrls":["https://cloud.google.com/security/consulting/mandiant-incident-response-services"],"verifiedAt":"2026-07-11"},{"slug":"autopsy","name":"Autopsy","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["dfir"],"capabilities":["forensic-acquisition","timeline-reconstruction"],"deployment":["on-prem"],"targetOrgSize":["individual","smb","mid-market"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, and mid-market organizations evaluating Digital Forensics & Incident Response with a preference for a self-hosted operating model.","keyAdvantage":"A free graphical forensics tool built on The Sleuth Kit for analyzing disk images, recovering deleted files, and building activity timelines.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Endpoint & memory forensic acquisition, Timeline reconstruction, and Malware analysis before standardizing.","ecosystem":"Primary fit is Digital Forensics & Incident Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"forensic-acquisition":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"timeline-reconstruction":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"malware-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ir-playbooks-retainer":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"chain-of-custody":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"root-cause-scope-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A free graphical forensics tool built on The Sleuth Kit for analyzing disk images, recovering deleted files, and building activity timelines. Brian Carrier created it, and Sleuth Kit Labs has maintained it since 2023.","website":"https://www.autopsy.com","sourceUrls":["https://www.autopsy.com"],"verifiedAt":"2026-07-11"},{"slug":"volatility","name":"Volatility 3","productType":"project","openSource":false,"categorySlugs":["dfir"],"capabilities":["malware-analysis"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Digital Forensics & Incident Response with a preference for a command-line operating model.","keyAdvantage":"The standard framework for memory forensics — extracting processes, network connections, and injected code from RAM captures, where much modern malware lives without ever touching disk.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Endpoint & memory forensic acquisition, Timeline reconstruction, and Malware analysis in a proof of concept.","ecosystem":"Primary fit is Digital Forensics & Incident Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the free relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"forensic-acquisition":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"timeline-reconstruction":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malware-analysis":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ir-playbooks-retainer":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"chain-of-custody":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"root-cause-scope-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"The standard framework for memory forensics — extracting processes, network connections, and injected code from RAM captures, where much modern malware lives without ever touching disk. Maintained by the nonprofit Volatility Foundation; version 3 is distributed under the custom Volatility Software License, which is free to use but not OSI-approved, so it is source-available rather than open source.","website":"https://volatilityfoundation.org","sourceUrls":["https://volatilityfoundation.org"],"verifiedAt":"2026-07-11"},{"slug":"grr","name":"GRR Rapid Response","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["dfir"],"capabilities":["forensic-acquisition"],"deployment":["on-prem","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Digital Forensics & Incident Response with a preference for a self-hosted and endpoint-agent operating model.","keyAdvantage":"Google's open-source framework for remote live forensics: a lightweight agent plus server that lets responders collect forensic artifacts and hunt for indicators across an entire fleet without touching machines individually.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Endpoint & memory forensic acquisition, Timeline reconstruction, and Malware analysis before standardizing.","ecosystem":"Primary fit is Digital Forensics & Incident Response. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"forensic-acquisition":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"timeline-reconstruction":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"malware-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ir-playbooks-retainer":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"chain-of-custody":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"root-cause-scope-analysis":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Google's open-source framework for remote live forensics: a lightweight agent plus server that lets responders collect forensic artifacts and hunt for indicators across an entire fleet without touching machines individually. Apache-licensed and still actively maintained under Google's GitHub organization, with a major 4.0 release in late 2025.","website":"https://github.com/google/grr","sourceUrls":["https://github.com/google/grr"],"verifiedAt":"2026-07-11"},{"slug":"veeam-data-platform","name":"Veeam Data Platform","vendorSlug":"veeam","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["immutable-backups","ransomware-anomaly-detection","dr-orchestration","workload-coverage","granular-restore"],"deployment":["on-prem","hybrid","agent"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Backup & Cyber Recovery with a preference for a self-hosted, hybrid, and endpoint-agent operating model.","keyAdvantage":"Veeam's flagship backup and recovery suite, spanning virtual, physical, cloud, and SaaS workloads under one platform.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"air-gapped-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ransomware-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dr-orchestration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"workload-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Veeam's flagship backup and recovery suite, spanning virtual, physical, cloud, and SaaS workloads under one platform. Backups can be written to immutable, hardened repositories, an inline engine scans data for malware and ransomware anomalies as it is ingested, and instant recovery spins protected workloads — VMs, physical servers, Kubernetes (via Kasten), SaaS, and cloud — back up in place.","website":"https://www.veeam.com/products/veeam-data-platform.html","sourceUrls":["https://www.veeam.com/products/veeam-data-platform.html"],"verifiedAt":"2026-07-11"},{"slug":"rubrik-security-cloud","name":"Rubrik Security Cloud","vendorSlug":"rubrik","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["immutable-backups","ransomware-anomaly-detection","dr-orchestration","workload-coverage","granular-restore"],"deployment":["saas","hybrid","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Backup & Cyber Recovery with a preference for a SaaS, hybrid, and endpoint-agent operating model.","keyAdvantage":"Rubrik's data security platform, built around zero-trust, append-only immutable backups that can't be modified once written.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"air-gapped-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ransomware-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dr-orchestration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"workload-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Rubrik's data security platform, built around zero-trust, append-only immutable backups that can't be modified once written. Its Radar capability watches backups for ransomware and anomalous change and orchestrates recovery testing, protecting VMs, physical servers, Kubernetes, SaaS (including Microsoft 365 and Salesforce), and cloud workloads.","website":"https://www.rubrik.com/products","sourceUrls":["https://www.rubrik.com/products"],"verifiedAt":"2026-07-11"},{"slug":"cohesity-dataprotect","name":"Cohesity DataProtect","vendorSlug":"cohesity","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["immutable-backups","ransomware-anomaly-detection","air-gapped-vaulting","workload-coverage","granular-restore"],"deployment":["on-prem","hybrid","saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Backup & Cyber Recovery with a preference for a self-hosted, hybrid, and SaaS operating model.","keyAdvantage":"Cohesity's backup and recovery product, storing data as DataLock immutable snapshots and scanning inside those backups for threats and anomalies.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"air-gapped-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ransomware-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dr-orchestration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"workload-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Cohesity's backup and recovery product, storing data as DataLock immutable snapshots and scanning inside those backups for threats and anomalies. Its FortKnox service adds an air-gapped, vendor-managed cyber vault holding an isolated recovery copy, and it protects a broad range of workloads — including large legacy estates migrated off Veritas NetBackup.","website":"https://www.cohesity.com/platform/dataprotect/","sourceUrls":["https://www.cohesity.com/platform/dataprotect/"],"verifiedAt":"2026-07-11"},{"slug":"commvault-cloud","name":"Commvault Cloud","vendorSlug":"commvault","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["air-gapped-vaulting","dr-orchestration","workload-coverage","granular-restore"],"deployment":["saas","hybrid","agent"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Backup & Cyber Recovery with a preference for a SaaS, hybrid, and endpoint-agent operating model.","keyAdvantage":"Commvault's cyber resilience platform, centered on recovering cleanly after an attack.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"air-gapped-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ransomware-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dr-orchestration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"workload-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Commvault's cyber resilience platform, centered on recovering cleanly after an attack. Cleanroom Recovery restores workloads into an isolated, ransomware-free environment for testing or production failover, Cloud Rewind rebuilds entire cloud environments after an incident, and it protects VMs, SaaS, Kubernetes, cloud, and database workloads from one control plane.","website":"https://www.commvault.com/","sourceUrls":["https://www.commvault.com/"],"verifiedAt":"2026-07-11"},{"slug":"druva-data-security-cloud","name":"Druva Data Security Cloud","vendorSlug":"druva","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["immutable-backups","air-gapped-vaulting","ransomware-anomaly-detection","workload-coverage","granular-restore"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Backup & Cyber Recovery with a preference for a SaaS operating model.","keyAdvantage":"Druva's fully SaaS, agentless data protection service: backups live in Druva's own isolated cloud, air-gapped by design and immutable, with built-in ransomware anomaly detection.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"air-gapped-vaulting":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ransomware-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dr-orchestration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"workload-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Druva's fully SaaS, agentless data protection service: backups live in Druva's own isolated cloud, air-gapped by design and immutable, with built-in ransomware anomaly detection. One platform covers endpoints, VMs, SaaS apps (Microsoft 365, Salesforce, Google Workspace), Kubernetes, and AWS and Azure workloads, with nothing to install or maintain on-site.","website":"https://www.druva.com/products/data-security-cloud/platform-overview","sourceUrls":["https://www.druva.com/products/data-security-cloud/platform-overview"],"verifiedAt":"2026-07-11"},{"slug":"acronis-cyber-protect","name":"Acronis Cyber Protect","vendorSlug":"acronis","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["ransomware-anomaly-detection","dr-orchestration","workload-coverage","granular-restore"],"deployment":["saas","on-prem","hybrid","agent"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Backup & Cyber Recovery with a preference for a SaaS, self-hosted, hybrid, and endpoint-agent operating model.","keyAdvantage":"Acronis's integrated backup and cyber protection product, combining backup with anti-malware and behavioral ransomware defense in a single agent so that recovery and prevention share one console.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"air-gapped-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ransomware-anomaly-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"dr-orchestration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"workload-coverage":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Acronis's integrated backup and cyber protection product, combining backup with anti-malware and behavioral ransomware defense in a single agent so that recovery and prevention share one console. It adds disaster-recovery orchestration and is heavily oriented toward MSPs, covering servers, endpoints, and Microsoft 365 and Google Workspace data.","website":"https://www.acronis.com/en/products/cyber-protect/","sourceUrls":["https://www.acronis.com/en/products/cyber-protect/"],"verifiedAt":"2026-07-11"},{"slug":"restic","name":"restic","productType":"project","openSource":true,"license":"BSD-2-Clause","categorySlugs":["backup-recovery"],"capabilities":["granular-restore"],"deployment":["cli"],"targetOrgSize":["individual","smb"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners and small businesses evaluating Backup & Cyber Recovery with a preference for a command-line operating model.","keyAdvantage":"A free, open-source command-line backup tool that makes encrypted, deduplicated, content-addressable backups to almost any backend — local disk, SFTP, S3-compatible object storage, Backblaze B2, Azure, or Google Cloud Storage.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection before standardizing.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the BSD-2-Clause license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"immutable-backups":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"air-gapped-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ransomware-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dr-orchestration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"workload-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A free, open-source command-line backup tool that makes encrypted, deduplicated, content-addressable backups to almost any backend — local disk, SFTP, S3-compatible object storage, Backblaze B2, Azure, or Google Cloud Storage. Immutability depends on configuring append-only or retention locks on the chosen backend, and there is no built-in anomaly detection or recovery orchestration; restore is file-level, from any snapshot.","website":"https://restic.net/","sourceUrls":["https://restic.net/"],"verifiedAt":"2026-07-11"},{"slug":"velero","name":"Velero","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["backup-recovery"],"capabilities":["granular-restore","dr-orchestration"],"deployment":["cli","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Backup & Cyber Recovery with a preference for a command-line and hybrid operating model.","keyAdvantage":"An open-source, Kubernetes-native backup and restore tool that captures cluster and namespace state — and, paired with restic or Kopia, the volume data behind it — on a schedule, and can restore or migrate selected resources into another…","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection before standardizing.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"immutable-backups":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"air-gapped-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ransomware-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dr-orchestration":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"workload-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An open-source, Kubernetes-native backup and restore tool that captures cluster and namespace state — and, paired with restic or Kopia, the volume data behind it — on a schedule, and can restore or migrate selected resources into another cluster for disaster recovery. Immutability depends on the object-storage backend (for example S3 Object Lock). Donated by Broadcom to the CNCF Sandbox in 2026.","website":"https://velero.io/","sourceUrls":["https://velero.io/"],"verifiedAt":"2026-07-11"},{"slug":"backblaze-computer-backup","name":"Backblaze Computer Backup","vendorSlug":"backblaze","productType":"software","openSource":false,"categorySlugs":["backup-recovery"],"capabilities":["granular-restore"],"deployment":["saas","agent"],"targetOrgSize":["individual","smb"],"pricingTier":"$","comparison":{"bestFor":"Individual practitioners and small businesses evaluating Backup & Cyber Recovery with a preference for a SaaS and endpoint-agent operating model.","keyAdvantage":"A low-cost, flat-rate cloud backup service that continuously backs up an entire Mac or Windows computer for one price per machine, with almost no setup.","tradeoff":"Agent-based coverage depends on rollout quality. Validate platform support, performance impact, update control, and Immutable backups, Air-gapped vaulting, and Ransomware anomaly detection in a proof of concept.","ecosystem":"Primary fit is Backup & Cyber Recovery. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the lower relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"immutable-backups":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"air-gapped-vaulting":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ransomware-anomaly-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"dr-orchestration":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"workload-coverage":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"granular-restore":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A low-cost, flat-rate cloud backup service that continuously backs up an entire Mac or Windows computer for one price per machine, with almost no setup. Versioned file history lets a user roll individual files back to a point before a ransomware infection, and restore is file- and folder-level. Separately, Backblaze's B2 object storage offers Object Lock immutability that other backup tools can use as a target.","website":"https://www.backblaze.com/cloud-backup/personal","sourceUrls":["https://www.backblaze.com/cloud-backup/personal"],"verifiedAt":"2026-07-11"},{"slug":"vanta","name":"Vanta","vendorSlug":"vanta","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","continuous-control-monitoring","risk-register","audit-evidence-collection","policy-management","vendor-risk-tracking"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"A compliance automation platform that connects to cloud, HR, and identity systems through APIs and collects control evidence throughout the audit period.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-register":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-evidence-collection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A compliance automation platform that connects to cloud, HR, and identity systems through APIs and collects control evidence throughout the audit period. It supports frameworks including SOC 2, ISO 27001, and HIPAA and includes public trust-center pages for sharing compliance material.","website":"https://www.vanta.com","sourceUrls":["https://www.vanta.com"],"verifiedAt":"2026-07-11"},{"slug":"drata","name":"Drata","vendorSlug":"drata","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","continuous-control-monitoring","audit-evidence-collection","policy-management","vendor-risk-tracking"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"A close competitor to Vanta in continuous compliance automation, differentiated by deeper native risk management and an in-house auditor marketplace connecting customers directly with firms already familiar with the platform.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-register":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"audit-evidence-collection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A close competitor to Vanta in continuous compliance automation, differentiated by deeper native risk management and an in-house auditor marketplace connecting customers directly with firms already familiar with the platform. Automated evidence collection runs continuously against connected cloud, identity, and device-management systems rather than through periodic manual checks.","website":"https://drata.com","sourceUrls":["https://drata.com"],"verifiedAt":"2026-07-11"},{"slug":"secureframe","name":"Secureframe","vendorSlug":"secureframe","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","continuous-control-monitoring","audit-evidence-collection","policy-management"],"deployment":["saas"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"A compliance automation platform aimed squarely at startups and growing companies chasing their first SOC 2 or ISO 27001 report, pairing continuous control monitoring with bundled security training and vendor risk assessments in one…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-register":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"audit-evidence-collection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A compliance automation platform aimed squarely at startups and growing companies chasing their first SOC 2 or ISO 27001 report, pairing continuous control monitoring with bundled security training and vendor risk assessments in one subscription. Positions its pricing and onboarding speed against the two larger, better-funded players in the category.","website":"https://secureframe.com","sourceUrls":["https://secureframe.com"],"verifiedAt":"2026-07-11"},{"slug":"onetrust","name":"OneTrust","vendorSlug":"onetrust","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","risk-register","policy-management","vendor-risk-tracking"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"A broad privacy, security, and GRC suite that grew out of consent-management and data-mapping tools, now selling dedicated compliance automation and third-party risk modules alongside its original privacy products under one platform.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-register":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-evidence-collection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A broad privacy, security, and GRC suite that grew out of consent-management and data-mapping tools, now selling dedicated compliance automation and third-party risk modules alongside its original privacy products under one platform. Divested its separately branded Convercent ethics and whistleblowing business to EQS Group in December 2024 but continues to actively develop the rest of the suite.","website":"https://www.onetrust.com","sourceUrls":["https://www.onetrust.com"],"verifiedAt":"2026-07-11"},{"slug":"servicenow-integrated-risk-management","name":"ServiceNow Integrated Risk Management","vendorSlug":"servicenow","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","risk-register","policy-management","vendor-risk-tracking"],"deployment":["saas"],"targetOrgSize":["enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"GRC built on the same Now Platform workflow engine that runs ServiceNow's much larger IT service management business, letting risk and compliance findings link directly to the tickets, assets, and approval flows IT teams already use.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-register":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-evidence-collection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"GRC built on the same Now Platform workflow engine that runs ServiceNow's much larger IT service management business, letting risk and compliance findings link directly to the tickets, assets, and approval flows IT teams already use. Best suited to enterprises already deep in the ServiceNow ecosystem that want one system of record rather than a dedicated point tool.","website":"https://www.servicenow.com/products/integrated-risk-management.html","sourceUrls":["https://www.servicenow.com/products/integrated-risk-management.html"],"verifiedAt":"2026-07-11"},{"slug":"optro","name":"Optro","vendorSlug":"optro","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","risk-register","audit-evidence-collection","policy-management"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"A connected risk platform that began with internal audit and SOX compliance and expanded into enterprise risk, controls, and ESG management on a shared data model.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-register":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-evidence-collection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A connected risk platform that began with internal audit and SOX compliance and expanded into enterprise risk, controls, and ESG management on a shared data model. Hg acquired the company in 2024, and AuditBoard rebranded as Optro in March 2026.","website":"https://optro.ai","sourceUrls":["https://optro.ai"],"verifiedAt":"2026-07-11"},{"slug":"logicgate-risk-cloud","name":"LogicGate Risk Cloud","vendorSlug":"logicgate","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","risk-register","vendor-risk-tracking","policy-management"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"A no-code GRC platform where risk and compliance teams build their own applications and workflows on a shared object model rather than adapting their process to a vendor's fixed data structure.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-register":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-evidence-collection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A no-code GRC platform where risk and compliance teams build their own applications and workflows on a shared object model rather than adapting their process to a vendor's fixed data structure. Popular for stitching together adjacent programs — vendor risk, policy management, incident tracking — that would otherwise live in separate tools.","website":"https://www.logicgate.com","sourceUrls":["https://www.logicgate.com"],"verifiedAt":"2026-07-11"},{"slug":"hyperproof","name":"Hyperproof","vendorSlug":"hyperproof","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","continuous-control-monitoring","audit-evidence-collection","vendor-risk-tracking"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating GRC & Compliance Automation with a preference for a SaaS operating model.","keyAdvantage":"Compliance operations software focused on the mechanics of staying audit-ready year-round — mapping one piece of evidence to every framework it satisfies, so a single control test doesn't have to be repeated separately for SOC 2, ISO…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-register":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"audit-evidence-collection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"policy-management":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"vendor-risk-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Compliance operations software focused on the mechanics of staying audit-ready year-round — mapping one piece of evidence to every framework it satisfies, so a single control test doesn't have to be repeated separately for SOC 2, ISO 27001, and HIPAA. Extended into AI-assisted third-party risk assessment through its October 2025 acquisition of Expent.ai.","website":"https://hyperproof.io","sourceUrls":["https://hyperproof.io"],"verifiedAt":"2026-07-11"},{"slug":"eramba","name":"eramba","vendorSlug":"eramba","productType":"software","openSource":false,"categorySlugs":["grc-compliance"],"capabilities":["control-framework-mapping","risk-register","policy-management"],"deployment":["on-prem"],"targetOrgSize":["smb","mid-market"],"pricingTier":"freemium","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating GRC & Compliance Automation with a preference for a self-hosted operating model.","keyAdvantage":"A self-hosted GRC platform covering risk registers, control frameworks, policy management, and audit workflows, aimed at organizations that want GRC tooling without a SaaS subscription.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Control & framework mapping, Continuous control monitoring, and Risk register & assessments in a proof of concept.","ecosystem":"Primary fit is GRC & Compliance Automation. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the freemium relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"control-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-control-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-register":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"audit-evidence-collection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"policy-management":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"vendor-risk-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A self-hosted GRC platform covering risk registers, control frameworks, policy management, and audit workflows, aimed at organizations that want GRC tooling without a SaaS subscription. Its free Community Edition is real and fully functional, but eramba's own maintainers describe the project as free rather than open source, since the license permits use only for an organization's own purposes and prohibits redistribution or modification; a paid Enterprise Edition adds support and additional modules.","website":"https://www.eramba.org/eramba-software","sourceUrls":["https://www.eramba.org/eramba-software"],"verifiedAt":"2026-07-11"},{"slug":"knowbe4-security-awareness-training","name":"KnowBe4 Security Awareness Training","vendorSlug":"knowbe4","productType":"software","openSource":false,"categorySlugs":["security-awareness-training"],"capabilities":["phishing-simulation","training-content-library","risk-scoring","completion-tracking","culture-behavior-analytics","automated-remediation-assignment"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Awareness Training with a preference for a SaaS operating model.","keyAdvantage":"A security awareness platform combining phishing simulations, training content, and per-user risk scoring.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing simulation campaigns, Training content library, and Risk scoring by user & department in a proof of concept.","ecosystem":"Primary fit is Security Awareness Training. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"training-content-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-scoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"completion-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"culture-behavior-analytics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-remediation-assignment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A security awareness platform combining phishing simulations, training content, and per-user risk scoring. KnowBe4 added Egress email security through a July 2024 acquisition and now links training signals with inbox-level threat detection.","website":"https://www.knowbe4.com/products/security-awareness-training","sourceUrls":["https://www.knowbe4.com/products/security-awareness-training"],"verifiedAt":"2026-07-11"},{"slug":"proofpoint-zenguide","name":"Proofpoint ZenGuide","vendorSlug":"proofpoint","productType":"software","openSource":false,"categorySlugs":["security-awareness-training"],"capabilities":["phishing-simulation","training-content-library","risk-scoring","completion-tracking","automated-remediation-assignment"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Awareness Training with a preference for a SaaS operating model.","keyAdvantage":"Proofpoint's security awareness product, rebranded from its long-running Security Awareness Training line to ZenGuide, ties training assignments to the same people-risk data Proofpoint already collects from its email security products —…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing simulation campaigns, Training content library, and Risk scoring by user & department in a proof of concept.","ecosystem":"Primary fit is Security Awareness Training. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"training-content-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-scoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"completion-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"culture-behavior-analytics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-remediation-assignment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Proofpoint's security awareness product, rebranded from its long-running Security Awareness Training line to ZenGuide, ties training assignments to the same people-risk data Proofpoint already collects from its email security products — who's already been targeted, who's clicked before. Proofpoint remains Thoma Bravo-owned and continues to actively develop and sell this product line as of mid-2026 rather than having divested it.","website":"https://www.proofpoint.com/us/products/mitigate-human-risk","sourceUrls":["https://www.proofpoint.com/us/products/mitigate-human-risk"],"verifiedAt":"2026-07-11"},{"slug":"hoxhunt","name":"Hoxhunt","vendorSlug":"hoxhunt","productType":"software","openSource":false,"categorySlugs":["security-awareness-training"],"capabilities":["phishing-simulation","training-content-library","risk-scoring","culture-behavior-analytics","automated-remediation-assignment"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Security Awareness Training with a preference for a SaaS operating model.","keyAdvantage":"An adaptive phishing simulation and training platform that personalizes difficulty to each employee's demonstrated skill level, gamifying reporting with streaks and rewards rather than punishing failure.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing simulation campaigns, Training content library, and Risk scoring by user & department in a proof of concept.","ecosystem":"Primary fit is Security Awareness Training. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"training-content-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-scoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"completion-tracking":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"culture-behavior-analytics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-remediation-assignment":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An adaptive phishing simulation and training platform that personalizes difficulty to each employee's demonstrated skill level, gamifying reporting with streaks and rewards rather than punishing failure. Markets its behavior-change results through simulated-phishing click and report rates rather than training completion alone.","website":"https://hoxhunt.com","sourceUrls":["https://hoxhunt.com"],"verifiedAt":"2026-07-11"},{"slug":"sosafe","name":"SoSafe","vendorSlug":"sosafe","productType":"software","openSource":false,"categorySlugs":["security-awareness-training"],"capabilities":["phishing-simulation","training-content-library","risk-scoring","completion-tracking","culture-behavior-analytics"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Awareness Training with a preference for a SaaS operating model.","keyAdvantage":"A security awareness platform that describes itself as Europe's largest provider in the category by revenue, built around behavioral science research into what actually changes employee habits rather than compliance-driven click-through…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing simulation campaigns, Training content library, and Risk scoring by user & department in a proof of concept.","ecosystem":"Primary fit is Security Awareness Training. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"training-content-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-scoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"completion-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"culture-behavior-analytics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-remediation-assignment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A security awareness platform that describes itself as Europe's largest provider in the category by revenue, built around behavioral science research into what actually changes employee habits rather than compliance-driven click-through modules. Strong in GDPR-sensitive European markets, with multilingual content and phishing simulations tuned to regional threat patterns.","website":"https://sosafe-awareness.com","sourceUrls":["https://sosafe-awareness.com"],"verifiedAt":"2026-07-11"},{"slug":"ninjio","name":"NINJIO","vendorSlug":"ninjio","productType":"software","openSource":false,"categorySlugs":["security-awareness-training"],"capabilities":["training-content-library","completion-tracking","culture-behavior-analytics"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Security Awareness Training with a preference for a SaaS operating model.","keyAdvantage":"Security awareness training built around short, Hollywood-style animated episodes dramatizing real breaches, betting that narrative and production value drive higher completion and retention than generic slide-based modules.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing simulation campaigns, Training content library, and Risk scoring by user & department in a proof of concept.","ecosystem":"Primary fit is Security Awareness Training. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-simulation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"training-content-library":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"risk-scoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"completion-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"culture-behavior-analytics":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"automated-remediation-assignment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Security awareness training built around short, Hollywood-style animated episodes dramatizing real breaches, betting that narrative and production value drive higher completion and retention than generic slide-based modules. Lighter on phishing simulation and risk-scoring depth than platform-first competitors, and positioned more as premium training content than a full human-risk management suite.","website":"https://ninjio.com","sourceUrls":["https://ninjio.com"],"verifiedAt":"2026-07-11"},{"slug":"gophish","name":"Gophish","productType":"project","openSource":true,"license":"MIT","categorySlugs":["security-awareness-training"],"capabilities":["phishing-simulation","completion-tracking"],"deployment":["on-prem","cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating Security Awareness Training with a preference for a self-hosted and command-line operating model.","keyAdvantage":"A free, self-hosted phishing simulation framework for building campaigns, landing pages, and tracking results through a REST API.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Phishing simulation campaigns, Training content library, and Risk scoring by user & department before standardizing.","ecosystem":"Primary fit is Security Awareness Training. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the MIT license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"phishing-simulation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"training-content-library":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"risk-scoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"completion-tracking":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"culture-behavior-analytics":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"automated-remediation-assignment":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A free, self-hosted phishing simulation framework for building campaigns, landing pages, and tracking results through a REST API. Jordan Wright created the MIT-licensed project; tagged release activity has slowed, so prospective users should review the repository before deploying it.","website":"https://getgophish.com","sourceUrls":["https://getgophish.com"],"verifiedAt":"2026-07-11"},{"slug":"proofpoint-email-protection","name":"Proofpoint Email Protection","vendorSlug":"proofpoint","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","sandboxing","domain-authentication-enforcement","user-reported-phishing-workflow","email-dlp"],"deployment":["saas","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Email Security with a preference for a SaaS and hybrid operating model.","keyAdvantage":"One of the longest-established secure email gateways, filtering inbound mail for malware, phishing, and impersonation while also enforcing outbound DMARC/SPF/DKIM policy for an organization's own domains.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"One of the longest-established secure email gateways, filtering inbound mail for malware, phishing, and impersonation while also enforcing outbound DMARC/SPF/DKIM policy for an organization's own domains. Sold standalone or bundled into Proofpoint's broader Prime suite, launched in 2025, which layers in collaboration-tool protection alongside email.","website":"https://www.proofpoint.com/us/emailprotection","sourceUrls":["https://www.proofpoint.com/us/emailprotection"],"verifiedAt":"2026-07-11"},{"slug":"mimecast-advanced-email-security","name":"Mimecast Advanced Email Security","vendorSlug":"mimecast","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","sandboxing","domain-authentication-enforcement","user-reported-phishing-workflow"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"A cloud email security gateway historically known for continuity features that keep mail flowing during an outage, now sold as part of a broader human risk management platform following Mimecast's 2024 acquisitions of Elevate Security,…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"A cloud email security gateway historically known for continuity features that keep mail flowing during an outage, now sold as part of a broader human risk management platform following Mimecast's 2024 acquisitions of Elevate Security, Code42, and Aware. Increasingly extends the same risk signal from email into Slack and Teams monitoring.","website":"https://www.mimecast.com/products/email-security/","sourceUrls":["https://www.mimecast.com/products/email-security/"],"verifiedAt":"2026-07-11"},{"slug":"abnormal-ai","name":"Abnormal AI","vendorSlug":"abnormal-ai","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","domain-authentication-enforcement","email-dlp"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"An API-based email security platform that connects directly to Microsoft 365 or Google Workspace rather than sitting inline as a gateway, using behavioral AI to baseline normal vendor and executive communication patterns and flag the…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An API-based email security platform that connects directly to Microsoft 365 or Google Workspace rather than sitting inline as a gateway, using behavioral AI to baseline normal vendor and executive communication patterns and flag the subtle impersonation and payload-free social engineering that signature-based filters typically miss. Renamed from Abnormal Security to Abnormal AI in April 2025.","website":"https://abnormal.ai","sourceUrls":["https://abnormal.ai"],"verifiedAt":"2026-07-11"},{"slug":"microsoft-defender-for-office-365","name":"Microsoft Defender for Office 365","vendorSlug":"microsoft","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","sandboxing","domain-authentication-enforcement","user-reported-phishing-workflow"],"deployment":["saas"],"targetOrgSize":["smb","mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses, mid-market organizations, and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"Microsoft's native email security layer for Exchange Online, bundled into Microsoft 365 E5 licensing or sold as an add-on for lower tiers, correlating detections with the rest of Microsoft Defender XDR across endpoint and identity signal.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Microsoft's native email security layer for Exchange Online, bundled into Microsoft 365 E5 licensing or sold as an add-on for lower tiers, correlating detections with the rest of Microsoft Defender XDR across endpoint and identity signal. The default choice for organizations already fully committed to Microsoft 365, though often paired with a third-party layer for defense in depth.","website":"https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365","sourceUrls":["https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365"],"verifiedAt":"2026-07-11"},{"slug":"sublime-security","name":"Sublime Security","vendorSlug":"sublime-security","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","user-reported-phishing-workflow","domain-authentication-enforcement"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"An email security platform with an editable detection engine.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"An email security platform with an editable detection engine. Defenders can read, write, and version rules directly, making it possible to audit why a message was blocked or allowed and tune the logic in-house.","website":"https://sublime.security","sourceUrls":["https://sublime.security"],"verifiedAt":"2026-07-11"},{"slug":"material-security","name":"Material Security","vendorSlug":"material-security","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["email-dlp","bec-detection","user-reported-phishing-workflow"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"A cloud email and workspace security product that continues monitoring after delivery.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"domain-authentication-enforcement":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"A cloud email and workspace security product that continues monitoring after delivery. It can quarantine sensitive content already in mailboxes and limit what an attacker could reach after an account takeover. It supports Google Workspace and Microsoft 365.","website":"https://material.security","sourceUrls":["https://material.security"],"verifiedAt":"2026-07-11"},{"slug":"barracuda-email-protection","name":"Barracuda Email Protection","vendorSlug":"barracuda","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","sandboxing","domain-authentication-enforcement","user-reported-phishing-workflow","email-dlp"],"deployment":["saas"],"targetOrgSize":["smb","mid-market"],"pricingTier":"$$","comparison":{"bestFor":"Small businesses and mid-market organizations evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"Barracuda's email security suite for small and mid-sized organizations, bundling gateway filtering, impersonation protection, and automated incident response into one product connected via API without an MX record change.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Barracuda's email security suite for small and mid-sized organizations, bundling gateway filtering, impersonation protection, and automated incident response into one product connected via API without an MX record change. Its agentic clawback feature can remove a malicious message from every mailbox it reached in a single action once a threat is confirmed. A KKR portfolio company since a 2022 take-private from Thoma Bravo.","website":"https://www.barracuda.com/products/email-protection","sourceUrls":["https://www.barracuda.com/products/email-protection"],"verifiedAt":"2026-07-11"},{"slug":"check-point-email-security","name":"Check Point Email Security","vendorSlug":"check-point","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","sandboxing","domain-authentication-enforcement","user-reported-phishing-workflow"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"Check Point's API-based email and collaboration security product, rebranded from Harmony Email & Collaboration, scanning Microsoft 365 and Google Workspace inboxes plus Slack and Teams for phishing, malware, and account takeover without…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"domain-authentication-enforcement":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"Check Point's API-based email and collaboration security product, rebranded from Harmony Email & Collaboration, scanning Microsoft 365 and Google Workspace inboxes plus Slack and Teams for phishing, malware, and account takeover without rerouting mail through an inline gateway. Shares threat intelligence with the rest of Check Point's Infinity platform.","website":"https://www.checkpoint.com/harmony/email-security/","sourceUrls":["https://www.checkpoint.com/harmony/email-security/"],"verifiedAt":"2026-07-11"},{"slug":"knowbe4-cloud-email-security","name":"KnowBe4 Cloud Email Security","vendorSlug":"knowbe4","productType":"software","openSource":false,"categorySlugs":["email-security"],"capabilities":["phishing-malware-detection","bec-detection","user-reported-phishing-workflow","email-dlp"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating Email Security with a preference for a SaaS operating model.","keyAdvantage":"An API-based cloud email security product built from Egress, the UK data-loss-prevention and email security vendor KnowBe4 acquired in 2024, now sold alongside KnowBe4's training platform so simulated-phishing failures and real inbound…","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and Phishing & malware detection, Business email compromise detection, and Link & attachment sandboxing in a proof of concept.","ecosystem":"Primary fit is Email Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset places this product in the mid-range relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"phishing-malware-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"bec-detection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"sandboxing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"domain-authentication-enforcement":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"user-reported-phishing-workflow":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"email-dlp":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"An API-based cloud email security product built from Egress, the UK data-loss-prevention and email security vendor KnowBe4 acquired in 2024, now sold alongside KnowBe4's training platform so simulated-phishing failures and real inbound threats feed the same per-user human risk score. Positioned as a complement to an organization's existing secure email gateway rather than a full replacement.","website":"https://www.knowbe4.com/products/cloud-email-security","sourceUrls":["https://www.knowbe4.com/products/cloud-email-security"],"verifiedAt":"2026-07-11"},{"slug":"prisma-airs","name":"Prisma AIRS","vendorSlug":"palo-alto-networks","productType":"software","openSource":false,"categorySlugs":["ai-security-posture-governance","ai-security-testing-model-assurance","ai-application-agent-security"],"capabilities":["ai-asset-discovery","ai-risk-posture","ai-policy-governance","ai-red-teaming","prompt-injection-testing","model-artifact-scanning","ai-supply-chain-assurance","prompt-response-inspection","runtime-ai-firewall","agent-tool-control","retrieval-content-protection","ai-data-loss-prevention","ai-runtime-monitoring"],"deployment":["saas","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating AI Security Posture & Governance with a preference for a SaaS and hybrid operating model.","keyAdvantage":"Palo Alto Networks' AI-security platform combines AI asset discovery and posture management with model scanning, automated red teaming, runtime traffic inspection, and controls for AI agents.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and AI asset discovery, Inventory & ownership, and AI risk posture in a proof of concept.","ecosystem":"Primary fit is AI Security Posture & Governance; this guide also maps the product to AI Security Testing & Model Assurance and AI Application & Agent Security. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ai-asset-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-inventory-ownership":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-risk-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-policy-governance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-framework-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"shadow-ai-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-red-teaming":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-injection-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"jailbreak-safety-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"model-artifact-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-supply-chain-assurance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-ai-evaluation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"prompt-response-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-ai-firewall":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agent-tool-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"retrieval-content-protection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-data-loss-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-runtime-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Palo Alto Networks' AI-security platform combines AI asset discovery and posture management with model scanning, automated red teaming, runtime traffic inspection, and controls for AI agents. Its runtime layer can evaluate prompts, responses, retrieved content, and agent activity across public, private, and hybrid AI deployments.","website":"https://www.paloaltonetworks.com/prisma/airs","sourceUrls":["https://www.paloaltonetworks.com/prisma/airs","https://docs.paloaltonetworks.com/ai-runtime-security/administration/prisma-airs-overview","https://www.paloaltonetworks.com/prisma/ai-model-security","https://www.paloaltonetworks.com/resources/datasheets/prisma-airs-ai-agent-security"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems","uses-ai-for-security"],"functions":["ai-discovery-and-governance","ai-security-testing","model-supply-chain-security","runtime-prompt-and-response-protection","agent-and-tool-governance","ai-data-protection"],"summary":"Protects AI models, applications, and agents across discovery, posture, model scanning, red teaming, and runtime prompt, response, and tool-call enforcement."}},{"slug":"cisco-ai-defense","name":"Cisco AI Defense","vendorSlug":"cisco","productType":"software","openSource":false,"categorySlugs":["ai-security-posture-governance","ai-security-testing-model-assurance","ai-application-agent-security"],"capabilities":["ai-asset-discovery","ai-inventory-ownership","ai-risk-posture","ai-policy-governance","shadow-ai-monitoring","ai-red-teaming","prompt-injection-testing","jailbreak-safety-testing","ai-supply-chain-assurance","continuous-ai-evaluation","prompt-response-inspection","runtime-ai-firewall","ai-data-loss-prevention","ai-runtime-monitoring"],"deployment":["saas","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating AI Security Posture & Governance with a preference for a SaaS and hybrid operating model.","keyAdvantage":"Cisco AI Defense addresses both employee use of third-party AI services and security of internally developed AI applications.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and AI asset discovery, Inventory & ownership, and AI risk posture in a proof of concept.","ecosystem":"Primary fit is AI Security Posture & Governance; this guide also maps the product to AI Security Testing & Model Assurance and AI Application & Agent Security. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ai-asset-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-inventory-ownership":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-risk-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-policy-governance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-framework-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"shadow-ai-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-red-teaming":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-injection-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"jailbreak-safety-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"model-artifact-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-supply-chain-assurance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-ai-evaluation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-response-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-ai-firewall":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agent-tool-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"retrieval-content-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-data-loss-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-runtime-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Cisco AI Defense addresses both employee use of third-party AI services and security of internally developed AI applications. It discovers AI assets and applications, assesses models and supply-chain risk, applies access and data policies, and enforces runtime guardrails against threats such as prompt injection and sensitive-data exposure.","website":"https://www.cisco.com/site/us/en/products/security/ai-defense/index.html","sourceUrls":["https://www.cisco.com/site/us/en/products/security/ai-defense/index.html","https://www.cisco.com/c/en/us/products/collateral/security/ai-defense/ai-defense-ds.html"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems","uses-ai-for-security"],"functions":["ai-discovery-and-governance","ai-security-testing","runtime-prompt-and-response-protection","ai-data-protection"],"summary":"Protects workforce AI use and internally developed AI through discovery, model and application assessment, policy controls, and runtime guardrails."}},{"slug":"hiddenlayer-ai-security-platform","name":"HiddenLayer AI Security Platform","vendorSlug":"hiddenlayer","productType":"software","openSource":false,"categorySlugs":["ai-security-posture-governance","ai-security-testing-model-assurance","ai-application-agent-security"],"capabilities":["ai-asset-discovery","ai-inventory-ownership","ai-risk-posture","ai-policy-governance","ai-framework-mapping","ai-red-teaming","prompt-injection-testing","jailbreak-safety-testing","model-artifact-scanning","ai-supply-chain-assurance","continuous-ai-evaluation","prompt-response-inspection","runtime-ai-firewall","ai-data-loss-prevention","ai-runtime-monitoring"],"deployment":["saas","hybrid"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating AI Security Posture & Governance with a preference for a SaaS and hybrid operating model.","keyAdvantage":"HiddenLayer's platform spans AI discovery, AI supply-chain security, attack simulation, and runtime security.","tradeoff":"Deployment flexibility adds infrastructure and lifecycle choices. Validate hosting responsibility, upgrades, availability, and AI asset discovery, Inventory & ownership, and AI risk posture in a proof of concept.","ecosystem":"Primary fit is AI Security Posture & Governance; this guide also maps the product to AI Security Testing & Model Assurance and AI Application & Agent Security. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ai-asset-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-inventory-ownership":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-risk-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-policy-governance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-framework-mapping":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"shadow-ai-monitoring":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-red-teaming":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-injection-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"jailbreak-safety-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"model-artifact-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-supply-chain-assurance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-ai-evaluation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-response-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-ai-firewall":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agent-tool-control":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"retrieval-content-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-data-loss-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-runtime-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"HiddenLayer's platform spans AI discovery, AI supply-chain security, attack simulation, and runtime security. It inventories AI assets, scans model artifacts, tracks model lineage and integrity, runs adversarial assessments, and monitors model inputs and outputs so policy can redact or block risky interactions.","website":"https://www.hiddenlayer.com/","sourceUrls":["https://www.hiddenlayer.com/","https://docs.hiddenlayer.ai/","https://docs.hiddenlayer.ai/docs/products/runtime/overview"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems","uses-ai-for-security"],"functions":["ai-discovery-and-governance","ai-security-testing","model-supply-chain-security","runtime-prompt-and-response-protection","ai-data-protection"],"summary":"Protects predictive, generative, and agentic AI with asset discovery, model supply-chain controls, adversarial testing, and runtime monitoring and enforcement."}},{"slug":"sentinelone-prompt-security","name":"Prompt Security","vendorSlug":"sentinelone","productType":"software","openSource":false,"categorySlugs":["ai-security-posture-governance","ai-security-testing-model-assurance","ai-application-agent-security"],"capabilities":["ai-asset-discovery","ai-inventory-ownership","ai-risk-posture","ai-policy-governance","shadow-ai-monitoring","ai-red-teaming","prompt-injection-testing","jailbreak-safety-testing","continuous-ai-evaluation","prompt-response-inspection","runtime-ai-firewall","agent-tool-control","ai-data-loss-prevention","ai-runtime-monitoring"],"deployment":["saas"],"targetOrgSize":["mid-market","enterprise"],"pricingTier":"$$$","comparison":{"bestFor":"Mid-market organizations and enterprises evaluating AI Security Posture & Governance with a preference for a SaaS operating model.","keyAdvantage":"Prompt Security, now part of SentinelOne's Singularity platform, covers workforce AI use, homegrown AI applications, and AI agents.","tradeoff":"A SaaS feature checklist does not show operational depth. Validate data location, retention, export, administration, and AI asset discovery, Inventory & ownership, and AI risk posture in a proof of concept.","ecosystem":"Primary fit is AI Security Posture & Governance; this guide also maps the product to AI Security Testing & Model Assurance and AI Application & Agent Security. Confirm the integrations required by the existing stack.","licensing":"The dataset places this product in the higher relative pricing tier. Confirm editions, minimums, retention, support, and add-ons in the vendor quote."},"capabilityDetails":{"ai-asset-discovery":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-inventory-ownership":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-risk-posture":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-policy-governance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-framework-mapping":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"shadow-ai-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-red-teaming":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-injection-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"jailbreak-safety-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"model-artifact-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-supply-chain-assurance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-ai-evaluation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-response-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-ai-firewall":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agent-tool-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"retrieval-content-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-data-loss-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-runtime-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"Prompt Security, now part of SentinelOne's Singularity platform, covers workforce AI use, homegrown AI applications, and AI agents. It discovers AI and MCP usage, applies access and data policies, supports AI red teaming, and places runtime guardrails around prompts, responses, and agent activity.","website":"https://www.sentinelone.com/platform/securing-ai/","sourceUrls":["https://www.sentinelone.com/platform/securing-ai/","https://www.sentinelone.com/press/sentinelone-delivers-end-to-end-ai-security-from-data-to-runtime/","https://www.sentinelone.com/press/sentinelone-to-acquire-prompt-security-to-advance-genai-security/"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems","uses-ai-for-security"],"functions":["ai-discovery-and-governance","ai-security-testing","runtime-prompt-and-response-protection","agent-and-tool-governance","ai-data-protection"],"summary":"Protects employee AI use, internally built applications, and agents through discovery, policy, red teaming, data controls, and runtime guardrails."}},{"slug":"garak","name":"garak","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["ai-security-testing-model-assurance"],"capabilities":["ai-red-teaming","prompt-injection-testing","jailbreak-safety-testing","continuous-ai-evaluation"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating AI Security Testing & Model Assurance with a preference for a command-line operating model.","keyAdvantage":"garak is an Apache-2.0 open-source command-line vulnerability scanner for generative AI systems.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and AI red teaming, Prompt-injection testing, and Jailbreak & safety testing before standardizing.","ecosystem":"Primary fit is AI Security Testing & Model Assurance. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"ai-red-teaming":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-injection-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"jailbreak-safety-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"model-artifact-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-supply-chain-assurance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-ai-evaluation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"garak is an Apache-2.0 open-source command-line vulnerability scanner for generative AI systems. It runs probes and detectors against supported model interfaces to test failure modes including prompt injection, data leakage, hallucination, misinformation, toxicity, and jailbreaks.","website":"https://garak.ai/","sourceUrls":["https://garak.ai/","https://github.com/NVIDIA/garak"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems"],"functions":["ai-security-testing"],"summary":"Open-source command-line vulnerability scanner that probes language models for prompt injection, data leakage, jailbreaks, toxicity, and other failure modes."}},{"slug":"pyrit","name":"PyRIT","vendorSlug":"microsoft","productType":"project","openSource":true,"license":"MIT","categorySlugs":["ai-security-testing-model-assurance"],"capabilities":["ai-red-teaming","prompt-injection-testing","jailbreak-safety-testing","continuous-ai-evaluation"],"deployment":["cli"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating AI Security Testing & Model Assurance with a preference for a command-line operating model.","keyAdvantage":"PyRIT, the Python Risk Identification Tool for generative AI, is an MIT-licensed Microsoft project for proactive AI risk testing.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and AI red teaming, Prompt-injection testing, and Jailbreak & safety testing before standardizing.","ecosystem":"Primary fit is AI Security Testing & Model Assurance. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the MIT license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"ai-red-teaming":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"prompt-injection-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"jailbreak-safety-testing":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"model-artifact-scanning":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-supply-chain-assurance":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"continuous-ai-evaluation":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"PyRIT, the Python Risk Identification Tool for generative AI, is an MIT-licensed Microsoft project for proactive AI risk testing. Its framework composes targets, prompt datasets, converters, attack strategies, memory, and scoring so security teams can run and reproduce adversarial assessments.","website":"https://github.com/microsoft/PyRIT","sourceUrls":["https://github.com/microsoft/PyRIT","https://microsoft.github.io/PyRIT/"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems"],"functions":["ai-security-testing"],"summary":"Microsoft's open-source Python Risk Identification Tool orchestrates adversarial prompts, targets, converters, and scoring for repeatable generative-AI risk testing."}},{"slug":"nemo-guardrails","name":"NeMo Guardrails","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["ai-application-agent-security"],"capabilities":["prompt-response-inspection","runtime-ai-firewall","agent-tool-control","ai-data-loss-prevention","ai-runtime-monitoring"],"deployment":["on-prem"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating AI Application & Agent Security with a preference for a self-hosted operating model.","keyAdvantage":"NeMo Guardrails is an Apache-2.0 open-source toolkit for adding programmable controls to LLM applications.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and Prompt & response inspection, Runtime AI firewall, and Agent & tool control before standardizing.","ecosystem":"Primary fit is AI Application & Agent Security. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"prompt-response-inspection":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"runtime-ai-firewall":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"agent-tool-control":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"retrieval-content-protection":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"ai-data-loss-prevention":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-runtime-monitoring":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."}},"description":"NeMo Guardrails is an Apache-2.0 open-source toolkit for adding programmable controls to LLM applications. Teams can define input, retrieval, execution, dialog, and output rails to check content, constrain tool use, protect data, and apply policy around model interactions.","website":"https://github.com/NVIDIA-NeMo/Guardrails","sourceUrls":["https://github.com/NVIDIA-NeMo/Guardrails","https://docs.nvidia.com/nemo/guardrails/latest/index.html"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems","uses-ai-for-security"],"functions":["runtime-prompt-and-response-protection","agent-and-tool-governance","ai-data-protection"],"summary":"Open-source toolkit for adding programmable input, retrieval, execution, and output rails to LLM applications and agents."}},{"slug":"modelscan","name":"ModelScan","productType":"project","openSource":true,"license":"Apache-2.0","categorySlugs":["ai-security-testing-model-assurance"],"capabilities":["model-artifact-scanning","ai-supply-chain-assurance"],"deployment":["cli","on-prem"],"targetOrgSize":["individual","smb","mid-market","enterprise"],"pricingTier":"free","comparison":{"bestFor":"Individual practitioners, small businesses, mid-market organizations, and enterprises evaluating AI Security Testing & Model Assurance with a preference for a command-line and self-hosted operating model.","keyAdvantage":"ModelScan is an Apache-2.0 open-source scanner from Protect AI for identifying unsafe code in serialized machine-learning model files.","tradeoff":"Open-source availability shifts more of the buying decision toward operations. Validate deployment, upgrades, support, and AI red teaming, Prompt-injection testing, and Jailbreak & safety testing before standardizing.","ecosystem":"Primary fit is AI Security Testing & Model Assurance. Confirm compatibility with the organization's identity, logging, ticketing, cloud, and workflow systems.","licensing":"The dataset records the Apache-2.0 license and a free entry point. Hosted, enterprise, support, or managed offerings may carry separate terms."},"capabilityDetails":{"ai-red-teaming":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"prompt-injection-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"jailbreak-safety-testing":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."},"model-artifact-scanning":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"ai-supply-chain-assurance":{"level":"documented","note":"Mapped in the verified product profile; native, add-on, and integration depth has not yet been assessed separately."},"continuous-ai-evaluation":{"level":"not-verified","note":"No support claim is recorded in the verified product profile. Confirm current edition or integration coverage with the vendor."}},"description":"ModelScan is an Apache-2.0 open-source scanner from Protect AI for identifying unsafe code in serialized machine-learning model files. It reads supported artifacts without loading them and can run from the command line or in ML and CI/CD pipelines before models are trained, modified, or deployed.","website":"https://github.com/protectai/modelscan","sourceUrls":["https://github.com/protectai/modelscan"],"verifiedAt":"2026-08-12","aiProfile":{"roles":["protects-ai-systems"],"functions":["model-supply-chain-security"],"summary":"Open-source scanner that inspects serialized machine-learning model files for unsafe code without loading or executing the model."}}]}