Browse top cybersecurity platforms. Compare threat protection, monitoring, and security software by features and reviews.
145 tools
Tools in Security
openarchiver — OpenArchiver is a self-hosted, open-source platform for legally compliant email archiving, giving organizations tamper-evident storage and full-text search across Google Workspace, Microsoft 365, and IMAP inboxes.
mailpiler — Piler (mailpiler) is an open-source email archiving application that indexes and stores incoming and outgoing mail for compliance, e-discovery, and long-term storage, with a paid Enterprise edition offering AI-powered search and support.
1Password — 1Password is a password manager and secrets-management platform that stores, generates, and autofills passwords, passkeys, and credentials for individuals, families, and businesses.
LastPass — LastPass is a cloud-based password manager that stores, generates and autofills passwords across devices, with tiers for individuals, families and businesses.
Okta — Okta is a publicly traded identity and access management platform providing single sign-on, multi-factor authentication, and lifecycle management for workforce and customer identity.
Auth0 — Auth0, owned by Okta, is an authentication and identity platform offering SSO, MFA, and passwordless login for web and mobile applications.
Microsoft Entra ID — Microsoft's cloud-based identity and access management platform, formerly Azure Active Directory, providing single sign-on, multi-factor authentication, and conditional access.
CrowdStrike Falcon — CrowdStrike Falcon is a cloud-native cybersecurity platform combining endpoint protection, XDR, identity security, and threat intelligence in a single lightweight agent.
SentinelOne — AI-powered autonomous cybersecurity platform delivering endpoint, cloud, and identity threat protection through a single lightweight agent and the unified Singularity console.
Malwarebytes — Malwarebytes is a cybersecurity company offering anti-malware, antivirus, VPN, and identity protection software for consumers and, through its ThreatDown brand, endpoint security for businesses.
NinjaOne — NinjaOne is a unified IT and endpoint management platform offering remote monitoring and management (RMM), patch management, backup, and endpoint security for MSPs and internal IT teams.
Kandji — Apple-first device management (MDM) and security platform, now rebranding to Iru as it expands to Windows and Android.
Jamf — Publicly traded Apple device management platform providing MDM, identity, and endpoint security for Mac, iPhone, and iPad fleets.
Cloudflare Zero Trust — Cloudflare Zero Trust is a SASE security suite from Cloudflare offering Zero Trust Network Access, a secure web gateway, CASB, and DLP to replace VPN-based access.
Tailscale — Tailscale is a zero-configuration mesh VPN built on WireGuard that lets teams securely connect devices, servers, and services across any network without managing firewall rules or VPN concentrators.
Proton VPN — Proton VPN is a Swiss-based, privacy-focused VPN service from Proton AG that offers a genuinely free tier alongside paid plans with high-speed servers, streaming access, and integration with Proton's broader privacy suite.
Surfshark — Surfshark is a consumer VPN service offering unlimited simultaneous device connections, ad blocking, and optional antivirus and identity protection add-ons under a no-logs privacy policy.
ExpressVPN — ExpressVPN is a consumer and small-business virtual private network service that encrypts internet traffic and masks IP addresses across 105+ countries, built on its proprietary open-source Lightway protocol and RAM-only TrustedServer infrastructure.
NordVPN — NordVPN is a virtual private network service from Nord Security that encrypts internet traffic, masks IP addresses, and bundles threat protection and cloud storage into tiered subscription plans.
Avast — Avast is a cybersecurity company offering antivirus, VPN, and online privacy software for consumers and businesses, now part of Gen Digital.
Bitdefender — Bitdefender is a cybersecurity company offering antivirus, internet security, and endpoint protection software for consumers, small businesses, and enterprises.
McAfee — McAfee is a long-established consumer and business cybersecurity company offering antivirus, VPN, identity protection, and password management software under brands like McAfee+ and Total Protection.
Norton 360 — Norton 360 is Gen Digital's consumer security suite bundling antivirus, a VPN, a password manager, cloud backup, and dark web monitoring into tiered annual subscription plans.
JumpCloud — Cloud directory platform unifying identity, device management, SSO and MFA for modern IT teams.
Duo Security — Duo Security, now marketed as Cisco Duo, is a cloud-based multi-factor authentication and unified access security platform that verifies user and device trust before granting access to applications and networks.
Twingate — Twingate is a zero trust network access platform that replaces traditional VPNs with secure, identity-based remote access to private applications and infrastructure.
Teleport — Teleport (goteleport.com) is an infrastructure identity and access security platform that replaces passwords, SSH keys, and static credentials with short-lived, cryptographically verified access to servers, Kubernetes, databases, and cloud consoles.
StrongDM — StrongDM is a zero-trust privileged access management platform that gives IT and security teams a single control plane to grant, monitor, and revoke just-in-time access to databases, servers, clouds, and web apps; it was acquired by Delinea in March 2026.
Drata — Drata is an automated compliance and trust management platform that continuously monitors controls and evidence for frameworks like SOC 2, ISO 27001, HIPAA, and GDPR to streamline security audits.
Hyperproof — Cloud-based GRC platform that automates compliance evidence collection, risk management and audit workflows across frameworks.
Thoropass — Thoropass is a compliance automation platform that pairs software with an in-house CPA audit team to help companies achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS, and other security certifications.
Sprinto — Sprinto is a compliance automation platform that helps SaaS and technology companies achieve and maintain certifications like SOC 2, ISO 27001, GDPR, and HIPAA through continuous monitoring.
Scrut Automation — Cloud-based governance, risk, and compliance (GRC) automation platform that helps growth-stage and cloud-native companies manage security compliance, risk assessments, and audits.
Astra Security — Astra Security is a continuous penetration testing platform combining AI-powered vulnerability scanning with expert-led pentests for web apps, APIs, and cloud.
Snyk — Snyk is a developer-first security platform that finds and fixes vulnerabilities in open source dependencies, container images, infrastructure as code, and application code, including AI-generated code.
Semgrep — Semgrep is a fast, open-source static application security testing (SAST) tool that scans source code for bugs, vulnerabilities, and secrets using lightweight, pattern-based rules across 30-plus programming languages.
SonarQube Cloud — SonarQube Cloud, formerly SonarCloud, is SonarSource's hosted SaaS code quality and security platform, integrating directly with GitHub, GitLab, Bitbucket, and Azure DevOps.
GitGuardian — GitGuardian is a code security platform that detects hardcoded secrets, manages non-human identities, and monitors public and private repositories, CI/CD pipelines, and developer endpoints for exposed credentials.
Socket — Socket is a developer-first software supply chain security platform that detects malicious, vulnerable, and risky open source packages across ecosystems like npm, PyPI, and Go before they reach production.
Aikido Security — Aikido Security is a unified application security platform combining SAST, SCA, cloud security, secrets detection, and AI-powered pentesting in one dashboard.
Wiz — Wiz is a cloud-native application protection platform (CNAPP) that scans AWS, Azure, Google Cloud, Oracle Cloud and Kubernetes environments to find and prioritize security risks across the full cloud stack.
Orca Security — Orca Security is an agentless cloud-native application protection platform (CNAPP) that scans AWS, Azure, GCP, and Kubernetes environments for vulnerabilities, misconfigurations, and compliance risks without deploying agents.
Tenable — Tenable is a publicly traded cybersecurity company best known for Nessus, one of the most widely deployed vulnerability scanners, plus a broader exposure management platform called Tenable One.
Rapid7 — Publicly traded cybersecurity company providing vulnerability management, cloud security, SIEM/XDR, and managed detection and response
Huntress — Managed cybersecurity platform delivering EDR, MDR, identity threat detection, and security awareness training via a 24/7 SOC.
Vanta — Vanta is a security and compliance automation platform that continuously monitors a company's systems to help it achieve and maintain certifications such as SOC 2, ISO 27001, HIPAA, and GDPR.
CrowdSec — CrowdSec is an open-source, crowdsourced intrusion detection and threat intelligence platform that shares real-time malicious IP data across its global community.
Wazuh — Open source security platform unifying SIEM and XDR for threat detection, log analysis, compliance, and incident response.
Security Onion — Free, open-source Linux distribution for threat hunting, enterprise security monitoring, and log management, bundling tools like Suricata, Zeek, and the Elastic Stack.
Falco — Falco is an open-source, CNCF-graduated runtime security tool that uses kernel-level syscall monitoring (via eBPF or a kernel module) to detect anomalous and malicious behavior in containers, Kubernetes clusters, hosts, and cloud accounts in real time.
Trivy — Trivy is Aqua Security's free, open-source all-in-one scanner that finds vulnerabilities, misconfigurations, secrets, and license issues across containers, code repositories, and cloud infrastructure.
Grype — Grype is Anchore's open-source vulnerability scanner for container images, filesystems, and SBOMs across major OS and language package ecosystems.
Syft — Syft is Anchore's open-source CLI and Go library for generating Software Bills of Materials from container images and filesystems.
Clair — Clair is a free, open-source vulnerability scanner that statically analyzes container images against CVE databases to secure registries and CI/CD pipelines.
OpenVAS — OpenVAS (Open Vulnerability Assessment Scanner) is a free, open-source network vulnerability scanner that also forms the core scan engine behind Greenbone's commercial vulnerability management products.
Greenbone — Greenbone is a German vulnerability management company behind OpenVAS, offering GDPR-compliant scanning appliances and software to find and prioritize IT security weaknesses.
Nuclei — Nuclei is a fast, open-source, template-based vulnerability scanner from ProjectDiscovery that uses a YAML DSL to detect security issues across web applications, APIs, networks, DNS and cloud configurations.
Burp Suite — Burp Suite is PortSwigger's web application security testing toolkit, combining an intercepting proxy, scanner, and manual testing tools for penetration testers.
OWASP ZAP — OWASP ZAP (Zed Attack Proxy) is a free, open-source dynamic application security testing tool that acts as an intercepting proxy to actively and passively scan running web applications for vulnerabilities.
Mend.io — Mend.io is an enterprise application security platform that combines software composition analysis, static analysis and automated remediation to secure open-source and custom code.
Checkmarx — Checkmarx is an enterprise application security testing platform combining SAST, SCA, DAST, and API security scanning in the unified Checkmarx One cloud platform.
Veracode — Veracode is an application security testing platform offering static, dynamic, and software-composition analysis to help enterprises find and fix vulnerabilities across the software development lifecycle.
Gitleaks — Gitleaks is a free, open-source command-line tool that scans git repositories, files, and directories to detect hardcoded secrets such as API keys, passwords, and tokens using regex and entropy analysis.
TruffleHog — TruffleHog is Truffle Security's open-source and enterprise secret-scanning tool that finds, verifies, and helps remediate leaked API keys, tokens, and credentials across code, cloud, and collaboration platforms.
Akeyless — Akeyless is a SaaS identity security platform for managing secrets, certificates, encryption keys, and machine/AI agent identities with zero-trust access controls.
HashiCorp Vault — Identity-based secrets management platform for securely storing, generating and tightly controlling access to tokens, passwords, certificates and encryption keys.
1Password Secrets Automation — 1Password's toolkit for automating secure secrets access in apps, CI/CD pipelines, and infrastructure, via Service Accounts, self-hosted Connect servers, a CLI, and SDKs — included with a 1Password Business subscription.
Passbolt — Passbolt is an open-source password manager built for teams, offering encrypted credential sharing, self-hosted or cloud deployment, and AGPL-licensed source code developed by a Luxembourg-based company.
Psono — Psono is an open source, self-hosted password manager that lets businesses store, encrypt, and share credentials on their own infrastructure instead of relying on a third-party cloud vault.
Padloc — Padloc is an open-source, end-to-end encrypted password manager for individuals and teams, offering vaults, an authenticator, and secure file storage across web, desktop, and mobile.
KeeWeb — KeeWeb is a free, open-source, cross-platform password manager fully compatible with KeePass .kdbx database files.
Vaultwarden — Free, open-source Rust server that implements the Bitwarden Client API for self-hosted password management.
Authentik — Authentik is a self-hosted, open-source identity provider supporting OAuth2/OIDC, SAML, LDAP, and SCIM, with an optional paid Enterprise tier.
Zitadel — Open-source, API-first identity and access management platform offering hosted login, multi-factor and passwordless authentication, and B2B multi-tenancy for developers.
FusionAuth — FusionAuth is a customer identity and access management platform that can be self-hosted or run in the cloud, offering authentication, authorization, SSO, MFA, and user management with a free Community edition and flat-rate paid pricing.
Keycloak — Open-source identity and access management platform providing single sign-on, OAuth 2.0, OpenID Connect and SAML support for modern applications.
SuperTokens — SuperTokens is an open-source user authentication platform that offers prebuilt login flows, session management, and either self-hosted or managed cloud deployment.
Ory — Ory is an open-source identity and access management platform providing authentication, authorization, and fine-grained permissions infrastructure, available self-hosted or as the managed Ory Network cloud service.
Cerbos — Cerbos is an open-source, language-agnostic authorization engine that lets developers define and enforce access-control policies outside application code.
Permit.io — Permit.io is a full-stack authorization-as-a-service platform that gives developers a hosted policy engine, embeddable UI components and SDKs to implement RBAC, ABAC and ReBAC access control without building permissions from scratch.
Aserto — Aserto was a developer-focused authorization platform for building fine-grained permissions such as RBAC, ABAC, and ReBAC into applications using policy-as-code and Open Policy Agent, before the company wound down its commercial SaaS in 2025.
OpenFGA — OpenFGA is a free, open-source fine-grained authorization engine inspired by Google's Zanzibar paper, originally built by Auth0/Okta and now a CNCF Incubating project used to add scalable permissions to applications.
SpiceDB — SpiceDB is an open-source, Google Zanzibar-inspired database for storing and querying fine-grained authorization and permissions data, built and maintained by AuthZed.
BoxyHQ — BoxyHQ is an open-source enterprise identity and security infrastructure company founded in August 2021 by Deepak Prabhakara and Carlos Samame, originally headquartered in London, United Kingdom. It built a suite of self-hostable, developer-first building blocks - most notably SAML Jackson for SAML and OIDC single sign-on, a SCIM 2.0 Directory Sync service for automated user provisioning and deprovisioning, and Retraced for audit logging - that let SaaS companies add enterprise-ready authentication and compliance features without building SSO plumbing from scratch. The tools are offered under open-source licenses for self-hosting, with a hosted or enterprise tier for teams that want a managed service, SLAs, and support. In May 2025, identity infrastructure company Ory acquired BoxyHQ, and BoxyHQ's product line has since been rebranded and continued as Ory Polis (SSO and Directory Sync) alongside Ory's broader identity platform, though the original open-source repositories remain available and are still maintained under the Ory organization.
WorkOS — WorkOS is a developer platform that adds enterprise-ready features such as single sign-on, SCIM directory sync, audit logs, and user management to B2B SaaS applications through a small set of APIs.
Stytch — Stytch is a developer-first authentication and identity platform offering passwordless login, SSO, and fraud prevention for consumer and B2B apps; it was acquired by Twilio in November 2025.
Descope — Descope is a no-code/low-code customer identity and access management (CIAM) platform for building authentication, MFA, SSO, and user journeys.
Kinde — Kinde is a developer platform combining authentication, user management, access control, and billing for building and monetizing SaaS products.
Clerk — Clerk is a developer-focused authentication and user management platform offering prebuilt sign-in flows, UI components, and enterprise SSO for modern web apps.
Logto — Open-source identity and access management platform offering authentication, authorization, and user management as an Auth0 alternative.
Hanko — Hanko is an open source, developer-first authentication platform focused on passkeys, offering passwordless and social login with a generous free tier.
Corbado — Corbado is a passkey intelligence and managed-authentication platform that helps enterprises deploy, monitor, and optimize passwordless WebAuthn login at scale.
Frontegg — Frontegg is a customer identity and access management (CIAM) platform that gives B2B SaaS companies drop-in authentication, authorization, multi-tenancy, and user management so engineering teams do not have to build identity infrastructure from scratch.
SlashID — SlashID is an identity security platform that gives developers unified detection, response, and governance across human and non-human identities in cloud, SaaS, and on-premises environments.
Scalekit — Scalekit is a B2B authentication infrastructure platform providing enterprise SSO, SCIM provisioning, and passwordless login for SaaS applications, along with an authentication and actions layer built for AI agent applications.
PropelAuth — Authentication and user management platform built specifically for B2B SaaS products, with organizations, roles, and enterprise SSO as first-class concepts.
Casdoor — Casdoor is a free, open-source identity and access management (IAM) and SSO server supporting OAuth 2.0, OIDC, SAML, LDAP, WebAuthn, and MFA, self-hosted.
Boundary — Boundary is HashiCorp's open-source, identity-based secure remote access tool that grants least-privilege access to hosts and services without exposing the network.
Authelia — Authelia is a free, open-source single sign-on and multi-factor authentication portal designed to sit in front of self-hosted apps via a reverse proxy.
Permify — Permify is an open-source, Google Zanzibar-inspired authorization engine that lets engineering teams centralize fine-grained permission logic (RBAC, ABAC and ReBAC) outside application code. The project was acquired by FusionAuth in November 2025 and now ships as part of FusionAuth's identity stack.
Casbin — Casbin is a free, open-source authorization library that supports ACL, RBAC, and ABAC access control models across Go, Python, Java, Node.js, and more.
Open Policy Agent — Open Policy Agent (OPA) is a CNCF-graduated, open-source, general-purpose policy engine that lets developers write policy-as-code rules in the Rego language to enforce authorization and compliance across Kubernetes, microservices, and CI/CD pipelines.
Conjur — Conjur is CyberArk's open-source secrets management and machine-identity platform, providing policy-based access control and a REST API for DevOps.
TheHive — TheHive is a Security Incident Response Platform built by StrangeBee for SOC, CERT and CSIRT teams to triage alerts, manage cases and collaborate on investigations; not to be confused with Apache Hive or unrelated project-management apps also named Hive.
MISP — MISP is a free, open-source threat intelligence platform for collecting, storing, correlating, and sharing cybersecurity indicators of compromise and threat information between organizations.
OpenCTI — OpenCTI is an open-source cyber threat intelligence platform that helps security teams ingest, correlate, and visualize threat data from multiple sources using the STIX2 standard, developed by French company Filigran.
Velociraptor — Velociraptor is a free, open-source digital forensics and incident response tool for endpoint monitoring, evidence collection, and threat hunting across large fleets of machines.
FleetDM — Fleet is an open-source device management platform built on osquery that gives IT and security teams cross-platform MDM, endpoint visibility, and vulnerability management for macOS, Windows, Linux, iOS, iPadOS, Android, and ChromeOS.
osquery — osquery is an open-source, SQL-powered operating system instrumentation and monitoring framework, originally created by Facebook in 2014 and now governed by the vendor-neutral OSquery Foundation under the Linux Foundation.
Suricata — Suricata is a free, open-source network intrusion detection (IDS), intrusion prevention (IPS), and network security monitoring (NSM) engine maintained by the Open Information Security Foundation (OISF).
Zeek — Open-source network security monitoring framework, formerly named Bro, that turns raw network traffic into detailed logs for security analysis and threat hunting.
Snort — Free, open-source network intrusion detection and prevention system (IDS/IPS) created in 1998 by Martin Roesch and now maintained by Cisco Talos.
DefectDojo — DefectDojo is an open-source DevSecOps and ASPM platform that aggregates, deduplicates, and manages vulnerabilities from 200+ security scanning tools.
Faraday — Faraday is a vulnerability management and penetration-test collaboration platform that aggregates findings from more than 80 security tools into unified workspaces, letting offensive security teams centralize, deduplicate, and prioritize risk.
Dependency-Track — Dependency-Track is a free, open-source OWASP platform that uses SBOMs to continuously identify and manage risk across the software supply chain.
OWASP Dependency-Check — OWASP Dependency-Check is a free, open-source software composition analysis tool that scans project dependencies and flags known publicly disclosed vulnerabilities (CVEs) using CPE matching.
AdwCleaner — AdwCleaner is a free, portable Windows utility from Malwarebytes that scans and removes adware, browser hijackers, toolbars, and other potentially unwanted programs.
AlienVault — AlienVault was a cybersecurity and threat intelligence company known for its Unified Security Management (USM) platform and the open-source OSSIM SIEM; it was acquired by AT&T in 2018, rebranded as AT&T Cybersecurity, and its products are now operated by LevelBlue, a standalone managed cybersecurity company launched in 2024.
asgardeo.io — Asgardeo is a Customer Identity and Access Management (CIAM) SaaS from WSO2, a two-decade-old enterprise identity and API management vendor, offering login, single sign-on, MFA, and user management APIs for developers.
Authgear — Authgear is an open-source customer identity and access management (CIAM) platform that gives developers passkeys, passwordless login, single sign-on, and multi-factor authentication as a ready-to-use service, deployable as managed cloud or self-hosted software.
Authress — Authress is a developer-focused login and access control API that combines authentication with fine-grained, resource-based authorization, billed on a pay-per-call basis.
Authy — Authy is a two-factor authentication (2FA) mobile app owned by Twilio; its desktop apps were discontinued in 2024, and Twilio has scaled back investment in the consumer product while steering developers toward its Twilio Verify API.
Avatier — Avatier is an enterprise identity governance and administration (IGA) platform that automates user provisioning, single sign-on, password management, and IT self-service through a containerized, workflow-driven architecture.
Bugcrowd — Bugcrowd is a crowdsourced cybersecurity platform that connects organizations with a global network of vetted security researchers to run bug bounty, vulnerability disclosure, penetration-testing-as-a-service, and attack surface management programs.
Castle — Castle is an account security and fraud prevention platform that helps online businesses stop bots, account takeovers, fake account creation, and other forms of account abuse in real time. Founded in 2015 in Malmo, Sweden by Sebastian Wallin and Johan Brissmyr, the company later moved to the San Francisco Bay Area to join Y Combinator's Winter 2016 batch and has since raised roughly $13.7 million from investors including Index Ventures, First Round Capital, and Y Combinator. Castle analyzes signals like device fingerprinting, behavioral biometrics, IP and proxy data, and email intelligence to produce real-time risk scores, typically responding within around 100 milliseconds, and it can be deployed both at the network edge and inside application code for layered protection. Customers use Castle to detect and block account takeover attempts, fake sign-ups, multi-accounting abuse, SMS pumping fraud, and API abuse, with notable customers including Atlassian, Rockstar Games, Rakuten, Canva, and Framer. Pricing is usage-based, starting with a free evaluation tier and scaling through a self-serve Pro plan into custom Enterprise agreements.
CertKit — CertKit is SSL and TLS certificate lifecycle management software built by TrackJS LLC that discovers, issues, renews, deploys, and monitors certificates across servers, load balancers, and network appliances to prevent unexpected expirations.
CertObserver CT Search — CertObserver CT Search is a free, no-signup tool for searching public Certificate Transparency logs by domain, and serves as the entry point to CertObserver, a paid TLS certificate monitoring and inventory platform built by Swedish company Kodhaj AB.
CipherCloud — CipherCloud was a cloud security company that built a cloud access security broker, or CASB, platform providing encryption, tokenization, data loss prevention, and adaptive access controls for enterprise cloud applications such as Salesforce, Office 365, and Google Drive. Founded in 2010 and headquartered in San Jose, California, CipherCloud was acquired by Lookout in March 2021, and its CASB technology line was later sold by Lookout to Fortra in May 2025.
Cloud-IAM — Cloud-IAM is a managed hosting service for Keycloak, the open-source identity and access management server, providing dedicated instances, automated operations, and expert support so teams do not have to self-host and maintain Keycloak. The service has operated since 2018 and is delivered by a joint venture of ELLIXO SAS and FGRibreau SARL, headquartered in Rennes, France. It offers deployment across more than 70 regions on providers including AWS, Google Cloud, Azure, Scaleway, and Outscale.
ColorTokens — ColorTokens is a cybersecurity company that provides a cloud-delivered Zero Trust microsegmentation platform designed to stop the lateral spread of ransomware and malware inside enterprise networks. Its flagship Xshield product isolates applications, workloads and devices into micro-perimeters without requiring a network re-architecture. Founded in 2015 and headquartered in Santa Clara, California, it serves mid-market and enterprise customers across healthcare, manufacturing, finance and other regulated industries.
Corgea — Corgea is an AI-powered application security platform that scans source code, dependencies, containers, and infrastructure-as-code to find vulnerabilities and automatically generates fixable code patches. Founded in 2023 and based in San Francisco, it is backed by Y Combinator and positions itself as an AI-native alternative to traditional static application security testing (SAST) tools.
crypteron.com — Crypteron was a developer-focused data encryption and key management platform that added application-layer security, including automated encryption, tamper protection, and audit trails, to backend applications built in .NET or Java. Founded in San Diego, California, it targeted enterprises and regulated industries needing HIPAA, PCI, and GDPR-style compliance. As of 2026, the company has officially concluded operations and its website displays a shutdown notice rather than an active signup flow.
CyberCube — CyberCube is a cyber risk analytics platform that provides insurers, reinsurers, and brokers with data-driven tools to quantify, price, and manage cyber insurance risk and accumulation exposure. Founded in 2015 and originally incubated within Symantec before spinning out as a standalone company, CyberCube is headquartered in San Francisco, California, and its clients include a large majority of the global cyber (re)insurance market by premium.
CyberGhost — CyberGhost is a consumer VPN service that encrypts internet traffic, masks IP addresses, and unblocks geo-restricted streaming content across thousands of servers worldwide. Founded in Romania in 2011, it was acquired in 2017 by Crossrider, which later rebranded as Kape Technologies, the same parent company that also owns ExpressVPN and Private Internet Access.
dAppling Network — dAppling Network is a decentralized web hosting platform that lets developers deploy static sites and Web3 frontends directly to IPFS by connecting a GitHub repository. It provides CI/CD-style automatic deployments, preview builds, and support for both ENS and traditional DNS domains, aiming to make hosting censorship-resistant decentralized applications as easy as using a mainstream hosting provider.
Datree — Datree was a policy-enforcement and configuration-validation tool that scanned Kubernetes manifests and Infrastructure-as-Code files for misconfigurations before they reached production. It shipped as a CLI plus a hosted policy dashboard used in CI/CD pipelines and pre-commit hooks. The commercial company behind Datree closed in July 2023, and its GitHub repository was archived as read-only in June 2024, so the product is no longer actively developed, supported, or sold.
DeepSource — DeepSource is an AI-powered code review platform combining static analysis and AI agents to catch bugs, security issues, and quality problems in pull requests.
Forcepoint — Forcepoint is an enterprise data security platform providing DLP, DSPM, insider threat, web, email, and cloud security tools for regulated industries and large organizations.
GlassWire — GlassWire is a network monitoring and personal firewall app that visualizes network activity and alerts users to threats on Windows and Android.
HimitsuShell — HimitsuShell is a shell script compiler that converts POSIX/LSB shell scripts into obfuscated, encrypted binaries with anti-debugging protection, aimed at IoT devices, Linux servers, and containers.
holistic.dev — holistic.dev is a SaaS static analysis tool that scans SQL source code to flag performance, security, and architecture issues in databases, without ever connecting to the live database or its data.
hostedscan.com — HostedScan is a unified vulnerability scanning platform that combines Nmap, OpenVAS, Nessus, OWASP ZAP, and Nuclei into one dashboard for continuous scanning of websites, servers, networks, and APIs.
Imperva — Imperva is an enterprise cybersecurity company providing application security (WAF, bot protection, DDoS, API security) and data security solutions for large organizations.
CookieYes — CookieYes is a Google-certified consent management platform that automates cookie scanning, consent banners, and compliance logging for GDPR, CCPA, and other privacy laws, powering more than 1.5 million websites. It began in 2018 as the WordPress plugin Cookie Law Info and grew into a standalone CMP operated by CookieYes Limited, headquartered in Milton Keynes, England.
CrowdStrike — CrowdStrike is a publicly traded cybersecurity company, listed on NASDAQ as CRWD, best known for its Falcon platform, a cloud-native, AI-powered endpoint detection and response system delivered through a single lightweight agent. Founded in 2011 and headquartered in Austin, Texas, CrowdStrike is also known for causing the largest IT outage in history on July 19, 2024, when a faulty Falcon sensor content update crashed roughly 8.5 million Windows systems worldwide.