Contrast Security, founded by OWASP co-creator Jeff Williams, instruments applications with in-app sensors: Contrast Assess (IAST) and Scan (SAST) find vulnerabilities, Contrast SCA flags risky dependencies, and its ADR/RASP layer detects and blocks attacks in production.
Application Security
Explore SAST and DAST tools for identifying vulnerabilities in application code and runtime environments.
Refine results
How to choose application security tools
Application Security tools support a defined technical workload. Start with the systems, users and operating constraints the tool must cover before comparing individual features.
What belongs in this category: A listing belongs in Application Security when this workload is a primary product function rather than a secondary integration or marketing label.
Who uses these tools
- Technical owners responsible for the workload
- Operators who deploy, secure and support the system
- Teams evaluating integrations, cost and migration risk
Capabilities to compare
- Core workflow and platform coverage
- Deployment, identity and integration controls
- Administration, observability and recovery
Operating considerations
- Compatibility with the current environment
- Security, data location and access boundaries
- Migration effort, support and total operating cost
Selection checklist
- Write down the production workload, scale and failure scenarios.
- Test the most important integration and an export or recovery path.
- Verify current limits, licensing and support in official documentation.
Continue the technical evaluation
Use the resources that match your decision stage. Profile data and linked sources were refreshed through September 27, 2026.
7 results in Application Security
Detectify combines automated DAST scanning with crowdsourced vulnerability research to monitor internet-facing assets and web apps for exploitable issues.
ImmuniWeb offers AI-assisted penetration testing, continuous application testing, attack surface discovery and dark web monitoring, plus free Community Edition tools.
Mend.io (formerly WhiteSource) pioneered software composition analysis and now covers SCA, SAST, container scanning, dependency updates (Mend Renovate), and AI security — red-teaming and runtime guardrails for LLM-based applications.
Rapid7 helps security teams find vulnerabilities, assess exposure and investigate threats across its distinct products.
Snyk scans open-source dependencies, code, containers and infrastructure-as-code for vulnerabilities, built into IDEs, CLI and CI/CD pipelines.
Veracode supplies application security testing for proprietary code and open-source components.