Contrast Security's Runtime Application Security solutions embed code analysis and attack prevention directly into the software development lifecycle. Patented instrumentation provides integrated and comprehensive security observability that delivers accurate assessment and continuous protection. The Contrast Runtime Security Platform enables powerful Application Security Testing and Application Detection and Response, allowing developers, AppSec teams, and SecOps teams to protect and defend their applications against an evolving threat landscape.
Do You Manage Peer Insights at Contrast Security?
Access Vendor Portal to update and manage your profile.
High quality, low false positive findings at runtime was the best i would say and Contrast also gave us a unified platform combining IAST, SCA, ADR, RASP which really helped us in breaking the silos in dev, appsec and devops.
The dynamic scanning of the service being used is a good model.
I used to work as a technical resource for a competing product and have very high expectations for a vendor in this space, and despite that the team has exceeded my expectations and have for over a year that I have been working with them. The product is innovative and continues to grow. I am very much looking forward to integrating an MCP server with their tool and seeing how it can advance the code analysis efforts from my company.
Agent centric deployment can be tricky in highly regulated environments and alert fatigue is something which I haven't liked so far, but maybe once we get used to it it gets better. I also felt the UI and navigation is a bit complex and could be better.
The product, or a totally separate product, should be built more with microservices in mind. Perhaps thinking more about a different agent model, where you have a master Docker container running on a machine that can see application docker containers start up, and instrument them directly, rather than requiring each service to add the agent into its own runtime individually.
The absence of an SBOM manager/version differential; however, I just got off a call with the team and they demonstrated what they are working on and this will not be an issue. I am not (yet) a fan of the new NorthStar user interface. I have discussed my feedback with the team and my wish list is being addressed in the future of the tool. Again, this UI is in beta so not really a complaint at this time. I cannot come up with a 3rd issue, sorry.