Contrast Security's Runtime Application Security solutions embed code analysis and attack prevention directly into the software development lifecycle. Patented instrumentation provides integrated and comprehensive security observability that delivers accurate assessment and continuous protection. The Contrast Runtime Security Platform enables powerful Application Security Testing and Application Detection and Response, allowing developers, AppSec teams, and SecOps teams to protect and defend their applications against an evolving threat landscape.
Do You Manage Peer Insights at Contrast Security?
Access Vendor Portal to update and manage your profile.
I used to work as a technical resource for a competing product and have very high expectations for a vendor in this space, and despite that the team has exceeded my expectations and have for over a year that I have been working with them. The product is innovative and continues to grow. I am very much looking forward to integrating an MCP server with their tool and seeing how it can advance the code analysis efforts from my company.
The dynamic scanning of the service being used is a good model.
Agents for various platforms Excellent single sign-on support with group support Configurable dashboard based upon groups
The absence of an SBOM manager/version differential; however, I just got off a call with the team and they demonstrated what they are working on and this will not be an issue. I am not (yet) a fan of the new NorthStar user interface. I have discussed my feedback with the team and my wish list is being addressed in the future of the tool. Again, this UI is in beta so not really a complaint at this time. I cannot come up with a 3rd issue, sorry.
The product, or a totally separate product, should be built more with microservices in mind. Perhaps thinking more about a different agent model, where you have a master Docker container running on a machine that can see application docker containers start up, and instrument them directly, rather than requiring each service to add the agent into its own runtime individually.
Agents cannot be configured to update automatically. Prior to Northstar, the three levels of access (view, edit, admin) were not clearly differentiated as to functions that were allowed.