AppSecNews

ASPM

Application Security Posture Management

Aggregate, deduplicate and prioritize findings across every other tool in the program.

16 tools profiled

How it differs Collects findings from your other scanners, deduplicates them and ranks them by application context. It aggregates rather than scans, though some platforms bundle scanners of their own.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

16 tools match

  • AccuKnox

    AccuKnox

    ASPM

    A cloud workload and application posture platform built on KubeArmor, using eBPF for observability and kernel LSMs to enforce least-privilege policy on workloads.

    Commercial
    Growing
  • Aikido Security

    Aikido Security

    ASPM

    A developer-facing platform that runs code, dependency, secret, container, IaC and surface scanning from one place and filters results down to what is reachable.

    Commercial, free tier
    Growing
  • Apiiro

    Apiiro

    ASPM

    An application security posture platform that builds an inventory from source code and correlates scanner findings against code context, ownership and material change.

    Commercial
    Established
  • ArmorCode

    ArmorCode

    ASPM

    A posture management platform that ingests findings from many security tools, deduplicates and correlates them, and drives remediation through ticketing workflows.

    Commercial
    Established
  • ASPM

    An application posture module in the Falcon platform that builds a live map of services, dependencies and data flows from instrumented cloud workloads.

    Commercial
    Growing
  • Cycode

    Cycode

    ASPM

    A posture platform that started with source control and CI/CD hardening and grew into first-party scanning plus correlation of findings across the delivery chain.

    Commercial
    Established
  • DefectDojo

    DefectDojo (originally an OWASP project)

    ASPM

    An open source vulnerability management system that imports scanner output through a large parser library, deduplicates findings and tracks them to closure.

    Open source
    Established Verified
  • Faraday

    Faraday Security

    ASPM

    A vulnerability management and collaboration platform built for offensive teams, importing output from security tools into a shared workspace with reporting.

    Freemium
    Established
  • AccuKnox

    AccuKnox

    A cloud workload and application posture platform built on KubeArmor, using eBPF for observability and kernel LSMs to enforce least-privilege policy on workloads.

    Commercial Growing
    ASPM
  • Aikido Security

    Aikido Security

    A developer-facing platform that runs code, dependency, secret, container, IaC and surface scanning from one place and filters results down to what is reachable.

    Commercial, free tier Growing
    ASPM
  • Apiiro

    Apiiro

    An application security posture platform that builds an inventory from source code and correlates scanner findings against code context, ownership and material change.

    Commercial Established
    ASPM
  • ArmorCode

    ArmorCode

    A posture management platform that ingests findings from many security tools, deduplicates and correlates them, and drives remediation through ticketing workflows.

    Commercial Established
    ASPM
  • An application posture module in the Falcon platform that builds a live map of services, dependencies and data flows from instrumented cloud workloads.

    Commercial Growing
    ASPM
  • Cycode

    Cycode

    A posture platform that started with source control and CI/CD hardening and grew into first-party scanning plus correlation of findings across the delivery chain.

    Commercial Established
    ASPM
  • DefectDojo

    DefectDojo (originally an OWASP project)

    An open source vulnerability management system that imports scanner output through a large parser library, deduplicates findings and tracks them to closure.

    Open source Established
    ASPM
  • Faraday

    Faraday Security

    A vulnerability management and collaboration platform built for offensive teams, importing output from security tools into a shared workspace with reporting.

    Freemium Established
    ASPM
  • Jit

    Jit

    ASPM

    An orchestration layer that runs a curated set of open source security scanners in CI, delivers results in pull requests, and manages the plans as code.

    Commercial
    Growing
  • Legit Security

    Legit Security

    ASPM

    A posture platform that discovers and evaluates the whole build and release environment, then correlates code findings back to the pipelines that produced them.

    Commercial
    Growing
  • OX Security

    OX Security

    ASPM

    A posture platform that maps the path from code to running workload and uses that path to decide which findings are actually reachable and worth fixing.

    Commercial
    Growing
  • Phoenix Security

    Phoenix Security

    ASPM

    A platform that aggregates application and cloud findings and ranks them by exploitability, asset context and business risk rather than by raw severity score.

    Commercial
    Growing
  • Seemplicity

    Seemplicity

    ASPM

    A remediation operations platform that aggregates findings from security tools and automates routing, ownership assignment and progress tracking to closure.

    Commercial
    Growing
  • Software Risk Manager

    Black Duck (originally Code Dx)

    ASPM

    A correlation and triage platform, descended from Code Dx, that normalizes output from many analysis tools and merges overlapping findings into a single review queue.

    Commercial
    Established
  • ThreadFix

    Coalfire (originally Denim Group)

    ASPM

    A vulnerability resolution platform that normalizes scanner output, correlates static and dynamic findings, and can emit WAF rules as temporary mitigation.

    Commercial
    Established
  • Xygeni

    Xygeni

    ASPM

    A software supply chain security platform covering malicious package detection, pipeline and source control hardening, secrets, dependencies and code analysis.

    Commercial, free tier
    Growing
  • Jit

    Jit

    An orchestration layer that runs a curated set of open source security scanners in CI, delivers results in pull requests, and manages the plans as code.

    Commercial Growing
    ASPM
  • Legit Security

    Legit Security

    A posture platform that discovers and evaluates the whole build and release environment, then correlates code findings back to the pipelines that produced them.

    Commercial Growing
    ASPM
  • OX Security

    OX Security

    A posture platform that maps the path from code to running workload and uses that path to decide which findings are actually reachable and worth fixing.

    Commercial Growing
    ASPM
  • Phoenix Security

    Phoenix Security

    A platform that aggregates application and cloud findings and ranks them by exploitability, asset context and business risk rather than by raw severity score.

    Commercial Growing
    ASPM
  • Seemplicity

    Seemplicity

    A remediation operations platform that aggregates findings from security tools and automates routing, ownership assignment and progress tracking to closure.

    Commercial Growing
    ASPM
  • Software Risk Manager

    Black Duck (originally Code Dx)

    A correlation and triage platform, descended from Code Dx, that normalizes output from many analysis tools and merges overlapping findings into a single review queue.

    Commercial Established
    ASPM
  • ThreadFix

    Coalfire (originally Denim Group)

    A vulnerability resolution platform that normalizes scanner output, correlates static and dynamic findings, and can emit WAF rules as temporary mitigation.

    Commercial Established
    ASPM
  • Xygeni

    Xygeni

    A software supply chain security platform covering malicious package detection, pipeline and source control hardening, secrets, dependencies and code analysis.

    Commercial, free tier Growing
    ASPM
Tick up to 4 tools above.