Skip to content
CloudTweaks

App & Code Security (SAST/SCA)

10 providers in this category.

Application and code security tools scan your own software: source code (SAST), open-source dependencies (SCA), hardcoded secrets, containers, and IaC, inside the IDE and CI/CD pipeline, catching vulnerabilities before they ship. They suit engineering teams shifting security left without slowing delivery. Scan-type coverage, pipeline integration, and per-developer pricing are the practical separators.

Companies

Neutral ordering. Not a recommendation.

10 results

Aikido Security

www.aikido.dev

Aikido Security is an all-in-one application security platform bundling SAST, SCA, DAST, secrets detection, container image scanning, IaC scanning, API security, cloud/CSPM, malware, and license scanning behind flat seat-based pricing.

$ Budgetusage-based pricing
Strengths
Capability, Code scanning +6Compliance, 3 certificationsOpenness, Self-hostable

Checkmarx

checkmarx.com

Checkmarx One is an enterprise cloud-native application security platform unifying SAST, SCA, DAST, IaC scanning, secrets detection, container security, and supply-chain/ASPM correlation.

$$$ Premiumusage-based pricing
Strengths
Capability, Code scanning +6Maturity, operating 20 yearsCompliance, 3 certificationsOpenness, Self-hostable

Endor Labs

www.endorlabs.com

Endor Labs is an AI-native software-supply-chain security platform centered on reachability-based SCA, with integrated AI SAST, secret detection, CI/CD risk analysis, and container image scanning in a single remediation-focused platform.

$$$ Premiumusage-based pricing
Strengths
Capability, Code scanning +4Maturity, operating 5 years

GitGuardian

www.gitguardian.com

GitGuardian is a secrets-security and non-human-identity governance platform specializing in detecting hardcoded credentials across source code, CI/CD pipelines, container images, IaC files, public GitHub history, and collaboration tools.

$$ Midusage-based pricing
Strengths
Maturity, operating 9 yearsCapability, Secret scanning +3Openness, Self-hostable

GitHub Advanced Security

github.com/security/advanced-security

GitHub Advanced Security is GitHub's native application-security suite: CodeQL semantic code scanning, secret scanning with push protection, and dependency review, all surfaced directly in pull requests.

$$ Midusage-based pricing
Strengths
Maturity, operating 6 yearsCapability, Code scanning +3Openness, Self-hostable

Semgrep

semgrep.dev

Semgrep is a fast, pattern-based code analysis platform offering SAST (Semgrep Code), open-source dependency scanning (Supply Chain), and secret detection.

$$ Midusage-based pricing
Strengths
Maturity, operating 9 yearsCapability, Code scanning +3Openness, Self-hostable

Snyk

snyk.io

Snyk is a developer-first application security platform covering open-source dependency scanning (SCA), proprietary code analysis (SAST/Snyk Code), container image scanning, and infrastructure-as-code scanning.

$$ Midfrom $25/mo · Last reviewed May 2026
Strengths
Maturity, operating 11 yearsCapability, Code scanning +5Compliance, 4 certificationsOpenness, Self-hostable

SonarQube

www.sonarsource.com

SonarQube, by Sonar (SonarSource), is a code-quality and SAST platform with integrated secrets detection and infrastructure-as-code (IaC) analysis.

$$ Midusage-based pricing
Strengths
Openness, Open-source & self-hostableMaturity, operating 18 yearsCapability, Code scanning +3

Trivy

trivy.dev

Trivy is the de-facto open-source security scanner for containers and cloud-native artifacts, detecting vulnerabilities in images and dependencies, exposed secrets, and misconfigurations in IaC such as Terraform and Kubernetes manifests.

$ BudgetFree · Last reviewed July 2026
Strengths
Openness, Open-source & self-hostableCapability, Dependency scanning +4Maturity, operating 7 years

Veracode

www.veracode.com

Veracode is an enterprise application risk management platform providing SAST, DAST, SCA, container scanning, IaC scanning, and a software-supply-chain Package Firewall, integrated into IDEs and CI/CD.

$$$ Premiumusage-based pricing
Strengths
Compliance, 5 certificationsMaturity, operating 20 yearsCapability, Code scanning +5