App & Code Security (SAST/SCA)
10 providers in this category.
Application and code security tools scan your own software: source code (SAST), open-source dependencies (SCA), hardcoded secrets, containers, and IaC, inside the IDE and CI/CD pipeline, catching vulnerabilities before they ship. They suit engineering teams shifting security left without slowing delivery. Scan-type coverage, pipeline integration, and per-developer pricing are the practical separators.
Companies
Neutral ordering. Not a recommendation.
Aikido Security
www.aikido.dev
Aikido Security is an all-in-one application security platform bundling SAST, SCA, DAST, secrets detection, container image scanning, IaC scanning, API security, cloud/CSPM, malware, and license scanning behind flat seat-based pricing.
Checkmarx
checkmarx.com
Checkmarx One is an enterprise cloud-native application security platform unifying SAST, SCA, DAST, IaC scanning, secrets detection, container security, and supply-chain/ASPM correlation.
Endor Labs
www.endorlabs.com
Endor Labs is an AI-native software-supply-chain security platform centered on reachability-based SCA, with integrated AI SAST, secret detection, CI/CD risk analysis, and container image scanning in a single remediation-focused platform.
GitGuardian
www.gitguardian.com
GitGuardian is a secrets-security and non-human-identity governance platform specializing in detecting hardcoded credentials across source code, CI/CD pipelines, container images, IaC files, public GitHub history, and collaboration tools.
GitHub Advanced Security
github.com/security/advanced-security
GitHub Advanced Security is GitHub's native application-security suite: CodeQL semantic code scanning, secret scanning with push protection, and dependency review, all surfaced directly in pull requests.
Semgrep
semgrep.dev
Semgrep is a fast, pattern-based code analysis platform offering SAST (Semgrep Code), open-source dependency scanning (Supply Chain), and secret detection.
Snyk
snyk.io
Snyk is a developer-first application security platform covering open-source dependency scanning (SCA), proprietary code analysis (SAST/Snyk Code), container image scanning, and infrastructure-as-code scanning.
SonarQube
www.sonarsource.com
SonarQube, by Sonar (SonarSource), is a code-quality and SAST platform with integrated secrets detection and infrastructure-as-code (IaC) analysis.
Trivy
trivy.dev
Trivy is the de-facto open-source security scanner for containers and cloud-native artifacts, detecting vulnerabilities in images and dependencies, exposed secrets, and misconfigurations in IaC such as Terraform and Kubernetes manifests.
Veracode
www.veracode.com
Veracode is an enterprise application risk management platform providing SAST, DAST, SCA, container scanning, IaC scanning, and a software-supply-chain Package Firewall, integrated into IDEs and CI/CD.
