• HOME
  • CATEGORIES

    • CATEGORIES

    • Application Development

      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • View All
    • Artificial Intelligence

      • Generative AI Knowledge Management Apps/General Productivity
      • AI Code Assistants (Transitioning to AI Coding Agents)
      • AI Application Development Platforms
      • Artificial Intelligence Applications in IT Service Management (Transitioning to AI Applications in IT Service Management)
      • Conversational AI Platforms
      • View All
    • Cloud Computing

      • Backup and Data Protection Platforms
      • Cloud Database Management Systems
      • Strategic Cloud Platform Services
      • Server Virtualization (Transitioning to Server Virtualization Platforms)
      • Hybrid Cloud Storage
      • View All
    • Customer Relationship Management

      • Contact Center as a Service
      • CRM Customer Engagement Center
      • Digital Experience Platforms
      • Web Content Management
      • Field Service Management
      • View All
    • Data and Analytics

      • Analytics and Business Intelligence Platforms
      • Data Science and Machine Learning Platforms (Transitioning to AI Platforms For Data Science and Machine Learning)
      • Data Integration Tools
      • Process Mining Platforms (Transitioning to Process Intelligence Platforms)
      • Augmented Data Quality Solutions
      • View All
    • Education

      • Manager and Leadership Training
      • Corporate Learning Technologies
      • eLearning Authoring Tools
      • Higher Education Student Information System Software as a Service (Transitioning to Higher Education SaaS Student Information Systems)
      • Digital Learning Content Providers
      • View All
    • Enterprise Networking and Communications

      • Unified Communications as a Service
      • Global WAN Services
      • Intranet Packaged Solutions
      • SD-WAN
      • Edge Distribution Platforms
      • View All
    • Finance

      • Expense Management Software
      • Financial Planning Software
      • Financial Close and Consolidation Solutions
      • Cloud Financial Management Tools
      • Accounts Payable Applications
      • View All
    • Healthcare and Life Sciences

      • Medical Device Security Solutions (Transitioning to Medical Device Risk Management Platforms)
      • Health Navigation Solutions
      • Claim Editor Software
      • Revenue Cycle Management Software (Transitioning to Revenue Cycle Management Solutions)
      • Digital Health Platforms (Transitioning to Healthcare Provider Industry Cloud Platforms)
      • View All
    • Human Resources

      • Employee Recognition and Reward Systems
      • Workforce Management Applications (Transitioning to Workforce Management (WFM) Technology)
      • Digital Employee Experience Management Tools
      • Talent Acquisition (Recruiting) Suites
      • Cloud HCM Suites for Regional and/or Sub-1,000 Employee Enterprises
      • View All
    • IT Infrastructure and IoT

      • Enterprise Wired and Wireless LAN Infrastructure (Transitioning to Enterprise Wired and Wireless LAN)
      • Endpoint Management Tools
      • IT Service Management Platforms
      • Container Management
      • Infrastructure Monitoring Tools
      • View All
    • IT Security

      • Endpoint Protection Platforms
      • Email Security
      • Managed Detection and Response
      • Security Information and Event Management
      • Security Awareness Computer-Based Training
      • View All
    • Legal

      • Contract Life Cycle Management
      • Electronic Signature
      • Governance, Risk and Compliance Tools, Assurance Leaders
      • Compliance Monitoring Solutions
      • Corporate Governance Services
      • View All
    • Manufacturing

      • Enterprise Asset Management Software
      • Manufacturing Execution Systems
      • Global Industrial IoT Platforms
      • PLM Software in Discrete Manufacturing Industries
      • Computer-Aided Design (CAD) Software
      • View All
    • Marketing

      • Video Editing Software
      • Email Marketing
      • Multichannel Marketing Hubs
      • Customer Data Platforms
      • Event Marketing and Management Platforms
      • View All
    • Productivity and Collaboration

      • Document Management
      • Collaborative Work Management
      • Visual Collaboration Applications
      • Knowledge Management (KM) Software
      • Meeting Solutions
      • View All
    • Public Sector and Government

      • Government Budgeting and Planning Solution
      • Cloud-Based ERP for U.S. Local Government
      • Citizen Service Delivery
      • Government ERP Solutions
      • Government Contracting Software
      • View All
    • Retail

      • Digital Commerce
      • Digital Commerce Payment Vendors (Transitioning to Digital Commerce Payment Platforms)
      • Retail Assortment Management Applications: Long Life Cycle Products
      • Retail Workforce Management Applications (Transitioning to Retail Workforce Management Technology)
      • Digital Shelf Analytics
      • View All
    • Sales

      • Sales Force Automation Platforms (Transitioning to CRM Sales Platforms)
      • Revenue Enablement Platforms
      • Revenue Intelligence (Transitioning to Revenue Action Orchestration)
      • Configure, Price and Quote Applications
      • Sales Performance Management
      • View All
    • Supply Chain Management

      • Supply Chain Planning Solutions
      • Transportation Management Systems
      • Real-Time Transportation Visibility Platforms
      • Warehouse Management Systems
      • Supply Chain Strategy, Planning and Operations Consulting
      • View All
    • Utilities

      • Geospatial Information Systems for Energy and Utilities
      • Mobile Workforce Management Software for Utilities (Transitioning to Mobile Workforce Management Solutions for Power and Utilities)
      • Energy Management and Optimization Systems
      • Energy Trading and Risk Management
      • Advanced Distribution Management Systems
      • View All
    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

      • Application Development
      • Artificial Intelligence
      • Cloud Computing
      • Customer Relationship Management
      • Data and Analytics
      • Education
      • Enterprise Networking and Communications
      • Finance
      • Healthcare and Life Sciences
      • Human Resources
      • IT Infrastructure and IoT
      • IT Security
      • Legal
      • Manufacturing
      • Marketing
      • Productivity and Collaboration
      • Public Sector and Government
      • Retail
      • Sales
      • Supply Chain Management
      • Utilities
      Browse All Categories

      Application Development

      68 markets
      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • API Management
      • Enterprise Low-Code Application Platforms
      • Robotic Process Automation
      • DevOps Platforms (Transitioning to DevSecOps Platforms)
      • Business Process Automation Tools
      • Enterprise Architecture Tools
      • Business Orchestration and Automation Technologies
      • Custom Software Development Services
      • Code Review Tools
      • Digital Adoption Platforms
      • Domain Registrars
      • Public Cloud IT Transformation Services (Transitioning to Public Cloud Optimization and Transformation Services)
      • Game Engine Software
      • Website Builders
      • Developer Productivity Insight Platforms
      • AI Agents for Application Developers
      • Application Platforms (Transitioning to Cloud-Native Application Protection Platforms)
      • Feature Management
      • Application Crowdtesting Services
      • Test Data Management
      • API Generation Software
      • Prototyping Software
      • Mobile App Analytics
      • Application Testing Services, Worldwide (Transitioning to Quality Engineering Services)
      • Application Integration Platforms
      • Digital Twin of an Organization Platforms
      • Event Brokers
      • Code Modernization Tools
      • Virtual Reality Development Software
      • Green Software Engineering
      • Independent Third-Party Software Support of Megavendors
      • Microsoft 365 Implementation and Support Services
      • BPM-Platform-Based Case Management Frameworks
      • Microsoft Product Support Services
      • Application Development Life Cycle Management (Transitioning to DevOps Platforms)
      • Product Roadmapping Tools for Software Engineering
      • Multiexperience Development Platforms
      • Application Portfolio Management Tools
      • Application Composition Platform
      • Internal Developer Portals
      • AI Agent Development Platforms for Software Engineering
      • Cloud Development Environments
      • Load Testing Tools
      • Blockchain Consulting and Proof-of-Concept Development Services
      • B2B Gateway Software
      • Citizen Application Development Platforms
      • Mobile Application Testing Services
      • Mobile Development Frameworks (Transitioning to Web and Mobile Development Frameworks)
      • SAP S/4HANA Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Oracle Cloud Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • SAP Application Services, Worldwide
      • SAP SuccessFactors Service Providers (Transitioning to Cloud ERP Services)
      • Service Mesh
      • Business-Outcome-Driven Enterprise Architecture Consulting (Retired)
      • Oracle Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Rapid Mobile App Development Tools
      • SAP Selective Test Data Management Tools
      • Value Stream Management Platforms
      • Augmented Reality Development Software
      • Blockchain as a Service
      • Mobile Application Management (Transitioning to Endpoint Management Tools)
      • Mobile Back-End Services
      • R&D Outsourcing Providers
      View More
  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
All Categories
/
Application Security Posture Management (ASPM) Tools

Application Security Posture Management (ASPM) Tools Reviews and Ratings

What is Application Security Posture Management (ASPM) Tools?

Application security posture management (ASPM) tools continuously manage application risk through collection, analysis and prioritization of security issues from across the software life cycle. They ingest data from multiple sources, maintain an inventory of all software within an organization, correlate and analyze findings for easier interpretation, triage and remediation. They enable the enforcement of security policies and facilitate the remediation of security issues while offering a comprehensive view of risk across applications.

How Categories and Markets Are Defined
Highest Rated By Your Peers
For Willingness to Recommend
Logo of Wiz CNAPP
Wiz CNAPP
Logo of GitLab
GitLab
Logo of Invicti
Invicti
For 50M-1B USD Companies
Logo of ArmorCode Platform
ArmorCode Platform
Logo of Phoenix Security Platform
Phoenix Security Platform
Logo of Wiz CNAPP
Wiz CNAPP
For North America
Logo of Wiz CNAPP
Wiz CNAPP
Logo of Legit Security
Legit Security
Logo of Falcon ASPM
Falcon ASPM
Integration & Deployment
Logo of Aikido Security
Aikido Security
Logo of Legit Security
Legit Security
Logo of Wiz CNAPP
Wiz CNAPP

Product Listings

Filter by

Products 1 - 20 of 43
Sort by
Logo of ArmorCode Platform

ArmorCode Platform

By ArmorCode

4.6
(84 Ratings)
customers choice 2026

ArmorCode Platform is a software that delivers centralized application security posture management by integrating multiple security tools, processes, and workflows. The software aggregates vulnerabilities and findings from different sources to provide unified visibility and prioritization of risks. It enables organizations to automate remediation, track security tasks, and coordinate communication between development and security teams. The platform facilitates policy enforcement and governance, supporting scalable management of security issues across cloud and on-premises environments. ArmorCode Platform helps organizations streamline operations, improve compliance, and reduce manual effort associated with securing software development lifecycle.

Show More Details
Logo of Falcon ASPM

Falcon ASPM

By CrowdStrike

4.6
(62 Ratings)
customers choice 2026

Falcon ASPM is a software developed by CrowdStrike for application security posture management. The software provides visibility into application vulnerabilities and misconfigurations across the software development lifecycle. Falcon ASPM integrates with development and deployment tools to identify risks in source code, dependencies, and cloud environments. The software offers automated detection and prioritized remediation guidance to help teams address security issues before they reach production. It supports risk reduction by providing context-based analysis and recommendations for improvement. Falcon ASPM is designed to help organizations manage and reduce their application security risks through continuous monitoring and integration with existing workflows.

Show More Details
Logo of Phoenix Security Platform

Phoenix Security Platform

By Phoenix Security

4.6
(53 Ratings)

Phoenix Security Platform is a software designed to facilitate security posture management by integrating vulnerability data from multiple sources and providing automated risk assessment. It enables organizations to prioritize remediation workflows based on business impact and contextual risk analysis. The software supports security operations with capabilities such as real-time reporting, continuous monitoring, and analytics to identify and manage vulnerabilities across various environments, including cloud and on-premises systems. Phoenix Security Platform also offers functionalities for compliance tracking and workflow automation, aiming to address issues related to vulnerability overload, resource allocation, and regulatory alignment within enterprise security programs.

Show More Details
Logo of Cycode Platform

Cycode Platform

By Cycode

4.5
(52 Ratings)

Cycode’s AI-Native Application Security Platform unites security and development teams with actionable context from code to runtime to identify, prioritize, and fix the software risks that matter.

Powered by proprietary scanners, third-party integrations, and the Context Intelligence Graph (CIG), Cycode delivers unified, correlated insight across the Software Factory. Its unique ability to sense, reason, and act with context in the AI-Era comes from its foundational convergence of AST, ASPM, and Software Supply Chain Security—purpose-built to secure both AI- and human-generated code.

Show More Details
Logo of Wiz CNAPP

Wiz CNAPP

By Wiz

4.6
(46 Ratings)

Wiz CNAPP is a software designed to provide cloud security by helping organizations identify and manage risks across cloud environments. This software offers visibility into cloud infrastructure, enabling detection of vulnerabilities, misconfigurations, and exposures in real time. It integrates with major cloud platforms, offering context on workloads, identities, and network configurations. Wiz CNAPP enables prioritization and remediation of security issues by presenting actionable insights into risks and compliance status. The software supports security operations by correlating various cloud resources, supporting governance and risk reduction for enterprises seeking to secure complex cloud architectures.

Show More Details
Logo of GitLab

GitLab

By GitLab

4.4
(36 Ratings)
customers choice 2026

GitLab is a comprehensive AI-powered DevSecOps platform for software innovation. The GitLab DevSecOps platform includes all capabilities required to deliver secure software faster with a unified data store, including source code management, continuous integration and delivery, agile project and portfolio planning, GitOps, software supply chain security, compliance management, and value stream management. GitLab empowers customers to improve operational efficiency, reduce security and compliance risk, build high-performing teams, and accelerate cloud transformation to maximize the overall return on software development.

Show More Details
Logo of Ivanti Neurons for ASPM

Ivanti Neurons for ASPM

By Ivanti

4.4
(34 Ratings)

Ivanti Neurons for Application Security Posture Management (ASPM) delivers full-stack visibility of application risk exposure through the entire software development lifecycle. Unify all application scan data – SAST, DAST, OSS/SCA and container – to locate misconfigurations, vulnerabilities and weaknesses and prioritize remediation. Move from detection to remediation in minutes with a contextualized, risk-based view of your organization’s cybersecurity posture and automated playbooks for remediation. Cultivate communication and cooperation from across the organization with access to dashboards designed for personnel from the DevSecOps to the C-suite.

Show More Details
Logo of Invicti

Invicti

By Invicti

4.7
(30 Ratings)

Invicti is a software designed to identify and manage security vulnerabilities in web applications. It performs automated scanning to detect potential security risks such as SQL injection, cross-site scripting, and other vulnerabilities. The software offers features including automatic scanning of web assets, vulnerability verification, and integration with issue tracking and development workflows. Invicti assists organizations in maintaining secure code by enabling continuous security assessments and streamlining remediation processes. The software addresses the business need for proactive identification and resolution of web security issues, helping organizations reduce the risk of security breaches and supporting compliance with industry standards and policies.

Show More Details
Logo of Conviso Platform

Conviso Platform

By Conviso

4.5
(27 Ratings)

The Conviso Platform is an Application Security Posture Management (ASPM) solution that centralizes the management of risks, vulnerabilities, assets, requirements, and security policies in a single environment.

It’s ideal for companies looking to structure, scale, and monitor their AppSec programs with visibility, automation, and risk-based prioritization.

The platform supports the entire development lifecycle — from secure planning and threat modeling to technical validation and remediation tracking — fostering seamless collaboration between development and security teams.

Show More Details
Logo of Legit Security

Legit Security

By Legit

4.8
(25 Ratings)

Legit Security is a software platform designed to secure software supply chains by providing automated security and compliance checks throughout the development lifecycle. The software integrates with existing DevOps environments and continuously monitors pipelines, source code repositories, and infrastructure-as-code configurations to identify vulnerabilities, misconfigurations, and policy violations. It enables organizations to detect risks related to third-party components, credentials exposure, and code changes, helping teams address threats before they reach production. Legit Security automates remediation workflows and delivers detailed insights to help organizations maintain compliance with regulatory standards and internal governance policies, aiming to reduce risk and improve the overall security posture of software development processes.

Show More Details
Logo of Aikido Security

Aikido Security

By Aikido Security

4.7
(20 Ratings)

Aikido is a developer-centric security platform that gives developers and security teams an instant overview of all code-to-cloud security issues and guides teams to fix vulnerabilities fast. Aikido supports security teams execute by aggressively reducing false-positives, automatic triage and risk bundling, and translating Common Vulnerabilities and Exposures (CVEs) into easy step-by-step explanations to resolve.

Described as an "all-in-one" application security platform, Aikido's covers the entire Software Development Lifecycle (SDLC), including: static application security testing (SAST), dynamic application security testing (DAST), infrastructure-as-code (IaC), container scanning, secrets detection, open source lisence scanning, cloud posture management (CSPM), runtime protection, and more.

Show More Details
Logo of OX Security Platform

OX Security Platform

By OX Security

4.7
(18 Ratings)

OX centralizes Application Security from AI coding to runtime, tracing every risk back to its source: your code. As AI transforms development, security teams face fragmented tooling and blind spots—OX delivers complete product security built for prevention, unifying security across your entire code journey from AI code generation through cloud runtime.

Show More Details
Logo of Apiiro

Apiiro

By Apiiro

4.6
(17 Ratings)

Deep Code Analysis: Apiiro extrapolates application components, going beyond vulnerability detection to identify changes introducing risk. Its patented technology forms the foundation for the Risk GraphTM, connecting risks to identify toxic combinations and surface invaluable context.

Code to Runtime Modeling: Connecting to runtime via API, Apiiro uses modeling technology to generate context and prioritize findings based on deployment, internet exposure, or WAF protection. This technology matches runtime APIs, containers, and security alerts to their source code and maps the entire exposure path of risks.

Risk-Based, Developer-Centric Policy Engine: Apiiro offers out-of-the-box and custom risk-based policies and workflows to define, automate, and validate security controls. With extensive developer tool integrations, the policy engine enables continuous, proactive guardrails to prevent business-critical risks from reaching the cloud.

Show More Details
Logo of Vulcan Cyber

Vulcan Cyber

By Tenable

4.4
(12 Ratings)

Vulcan Cyber is a software that focuses on vulnerability remediation orchestration for cybersecurity teams. The software integrates with existing vulnerability management, IT service management, and patching tools to prioritize vulnerabilities based on risk and business context. Vulcan Cyber automates the remediation workflow by assigning tasks, tracking progress, and assisting with patch management and configuration updates. It enables organizations to reduce security risk by streamlining vulnerability response and providing visibility into remediation processes across environments. The software helps address the business problem of managing and resolving vulnerabilities efficiently while maintaining compliance and minimizing exposure to potential threats.

Show More Details
Logo of Faraday

Faraday

By Faraday

4.5
(10 Ratings)

Faraday is an all-in-one collaborative pentest and vulnerability management platform designed to help security teams prioritize, analyze, and correlate findings for triage and remediation

It orchestrates +150 tools and vulnerability scanners, enabling you to scan your domain and have a comprehensive view of risks across all user assets. It offers a picture of your security posture. Its single dashboard allows centralized vulnerability management and custom report generation.

Show More Details
Logo of BoostSecurity

BoostSecurity

By boostsecurity.io

4.5
(9 Ratings)

BoostSecurity is a software designed to enhance software supply chain security through automated detection and remediation of risks in development workflows. The software integrates with existing CI/CD pipelines and version control systems to monitor configurations, code, dependencies, and access patterns. It provides visibility into potential vulnerabilities, misconfigurations, and policy violations throughout the development lifecycle. BoostSecurity aims to address risks associated with code changes, third-party components, and privileged actions, offering automated alerts and guidance to developers. The software supports compliance management by tracking code provenance and enforcing security policies, helping organizations mitigate threats that could disrupt software delivery or integrity.

Show More Details
Logo of Arnica

Arnica

By Arnica

4.7
(8 Ratings)

Arnica is a software designed to enhance the security and integrity of software development processes by preventing and remediating security vulnerabilities in code repositories. The software integrates with version control systems to detect and address risks such as secrets exposure, unsafe coding practices, and configuration errors. It provides automated actions and developer guidance to facilitate secure code contributions without impacting workflow efficiency. Arnica addresses the business problem of managing security risks in modern DevOps environments, helping organizations maintain compliance and reduce exposure to threats within their software supply chain.

Show More Details
Logo of Jit

Jit

By Jit

4.9
(8 Ratings)

Jit empowers developers to secure everything they code with an all-in-one platform for product security that makes eleven code and cloud scanners feel like one - including SAST, SCA, secrets detection, IaC scanning, CSPM, K8s scanning, DAST, and more.

Without ever leaving their environment, developers get automated feedback on the security of every code change. Jit reduces vulnerability noise by correlating findings with runtime and business context, so developers understand why they should resolve issues.

As a result, Jit makes security easy for developers to adopt, so they can independently and consistently resolve security issues before production.

Show More Details
Logo of PointGuard AI Platform

PointGuard AI Platform

By PointGuard AI

4.6
(8 Ratings)

PointGuard AI Platform is a software designed to enhance data security and detection capabilities within enterprise environments. The software leverages artificial intelligence and machine learning to identify potential threats, automate incident responses, and streamline threat investigation processes. PointGuard AI Platform enables organizations to monitor network activity in real time, detect unusual patterns, and manage vulnerabilities across systems. It provides analytics and reporting features that help teams prioritize security incidents and reduce the impact of potential breaches. The software aims to address the business problem of protecting sensitive information and maintaining the integrity of digital assets through automated and adaptive security measures.

Show More Details
Logo of Boman.ai

Boman.ai

By Boman.ai

4.8
(7 Ratings)

Boman.ai is a software designed to facilitate threat detection and response for organizations by leveraging artificial intelligence. The software analyzes vast volumes of cybersecurity data to identify vulnerabilities and threats across networks and endpoints. Boman.ai automates investigation and remediation processes, which helps streamline security operations and supports compliance with regulatory requirements. It integrates with existing security infrastructure to provide real-time alerts and actionable intelligence, enabling organizations to address cybersecurity risks more efficiently. The software aims to solve challenges related to manual threat analysis, prolonged incident response times, and resource-intensive security management practices.

Show More Details

Gartner Research

Gartner Peer Insights 'Voice of the Customer': Application Security Posture Management (ASPM) Tools

Top Trending Products

Falcon ASPMGitLab

Popular Product Comparisons

ArmorCode Platform vs OX Security Platform

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.