• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Invicti
Logo of Invicti

Invicti

byInvicti
in
4.5
Market Presence: Application Security Testing, Application Security Posture Management (ASPM) Tools

Overview

Product Information on Invicti

Updated 13th October 2025

What is Invicti?

Invicti is a software designed to identify and manage security vulnerabilities in web applications. It performs automated scanning to detect potential security risks such as SQL injection, cross-site scripting, and other vulnerabilities. The software offers features including automatic scanning of web assets, vulnerability verification, and integration with issue tracking and development workflows. Invicti assists organizations in maintaining secure code by enabling continuous security assessments and streamlining remediation processes. The software addresses the business need for proactive identification and resolution of web security issues, helping organizations reduce the risk of security breaches and supporting compliance with industry standards and policies.

Invicti Pricing

Invicti software utilizes a subscription-based pricing model, structured by the number of websites, applications, or assets scanned. Pricing varies depending on deployment as cloud or on-premises, with options for volume-based tiers and custom enterprise arrangements. Access to specific features and service levels can depend on the selected pricing plan.

Overall experience with Invicti

ASSOCIATE DIRECTOR - ARCHITECTURE
500M - 1B USD, Services (non-Government)
FAVORABLE

“Invicti: A Dependable Tool for Web Security Assessments”

5.0
Apr 23, 2025
We have been using Invicti for a few months now, mostly as part of our regular application security assessment. After using it against the real-life environment, I would say it is one of the dependable tools out there in the market. When it comes to identifying and reporting web-related vulnerabilities, I think it is doing a great job. One of the best parts is the ease of using its interface. Some security tools are hard to get into configuration and make it difficult to configure a scan whereas Invicti feels more practical and efficient. It's easy to get started with, doesn't demand a ton of configuration upfront, and the learning curve is surprisingly simple if I compare it with other tools. We had a few cases where it was able to detect legit issues that were skipped in the manual testing and that is where it fulfils its promise. I wouldn't say there are no false positives, but the number of such instances is very limited. If someone is looking for a deep insights into complex vulnerabilities that are not easy to find, the tool requires some further tuning as the vanilla scan might not capture that. Similarly, if youre doing a lot of single-page apps or dynamic content, you might want to spend a bit of time fine-tuning the scan settings. Overall, it's not a magic box but it does its job well.
IT SECURITY ASSESSMENT SPECIALIST
250M - 500M USD, Banking
CRITICAL

“Mixed User Sentiments on Cloud+'s GUI and Integration Capabilities”

3.0
Aug 30, 2024
The application has a good potential, however, the application agents were full of bugs. At least Cloud+ internal agents looked like they were in a very immature state

About Company

Company Description

Updated 17th September 2025

Formed through the combination of Netsparker, Acunetix, and Kondukto, Invicti Security provides an application security platform that unifies DAST, SAST, IAST, SCA, API security, secrets scanning, container security, and application security posture management (ASPM) to help enterprise organizations identify, prioritize, and remediate vulnerabilities across their application portfolio. The platform's proof-based scanning validates runtime vulnerabilities while ASPM capabilities correlate findings across security tools to eliminate false positives. AI-powered remediation provides contextual fix recommendations within developer workflows. Key capabilities include automated vulnerability discovery, intelligent risk prioritization, unified dashboard management, and CI/CD pipeline integration.

Company Details

Updated 17th September 2025
Company type
Private
Year Founded
2005
Head office location
Austin, United States
Number of employees
201 - 500
Annual Revenue
50M-250M USD
Website
https://www.invicti.com/

Do You Manage Peer Insights at Invicti?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Invicti
Reviewer Insights for: Invicti
Deciding Factors: Invicti Vs. Market Average
Performance of Invicti Across Market Features

Invicti Likes & Dislikes

Like

What really worked for us was the onboarding of the application and its accuracy. It is flagging vulnerabilities that matter, not just the bulk of false positives. This is saving time for my team as they don't have to investigate a wall of false positives. With the automated scans, I don't have to worry if something can get passed into production without proper review as it can capture those for us.

Like

Nice and simple GUI's Interesting integrations with WAF's and ticketing system Apparently it grabs some nice findings

Like

1. Tool Usability and features (like UI, reporting, RBAC, user management, customization etc.) 2. Integration support 3. Scans on Legacy applications, Invicti is providing really good results. 4. POC of confirm Issues.

Dislike

While Invicti does offer API scanning capabilities, it requires the manual onboarding of each individual API for testing, which is a time-consuming and cumbersome process, especially for large applications with numerous APIs. The capability to onboard already exists but it requires an API Management tool which adds an additional cost. If it could do a discovery on its own like it does for the Web, that would be a great addition to the feature list. In some cases, reporting of certain vulnerabilities may be delayed, potentially due to the time it takes for the database/reference source to be updated. More timely updates would be beneficial and help with faster reporting and response to critical vulnerabilities.

Dislike

The internal agents were not mature enough to be sold as a product Cloud solution is not currently allowing logins with MFA Poor support - only was able to get good support after threats to renounce the contract.

Dislike

As mentioned above, scanning for Single Page Applicaitons should be improved and some integration failures.

Top Invicti Alternatives

Logo of Veracode
1. Veracode
4.6
(401 Ratings)
Logo of Checkmarx SAST
2. Checkmarx SAST
4.6
(398 Ratings)
Logo of Appknox
3. Appknox
4.8
(246 Ratings)
View All Alternatives

Peer Discussions

Invicti Reviews and Ratings

Showing data for 153 ratings and reviews for Application Security Testing market. View all 183 ratings and reviews across markets for a complete picture.

4.5

(153 Ratings)

Rating Distribution

5 Star
50%
4 Star
44%
3 Star
6%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.4

Service & Support

4.4

Product Capabilities

4.4

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • ASSOCIATE DIRECTOR - ARCHITECTURE
    50M-1B USD
    Services (non-Government)
    Review Source

    Invicti: A Dependable Tool for Web Security Assessments

    5.0
    Apr 23, 2025
    We have been using Invicti for a few months now, mostly as part of our regular application security assessment. After using it against the real-life environment, I would say it is one of the dependable tools out there in the market. When it comes to identifying and reporting web-related vulnerabilities, I think it is doing a great job. One of the best parts is the ease of using its interface. Some security tools are hard to get into configuration and make it difficult to configure a scan whereas Invicti feels more practical and efficient. It's easy to get started with, doesn't demand a ton of configuration upfront, and the learning curve is surprisingly simple if I compare it with other tools. We had a few cases where it was able to detect legit issues that were skipped in the manual testing and that is where it fulfils its promise. I wouldn't say there are no false positives, but the number of such instances is very limited. If someone is looking for a deep insights into complex vulnerabilities that are not easy to find, the tool requires some further tuning as the vanilla scan might not capture that. Similarly, if youre doing a lot of single-page apps or dynamic content, you might want to spend a bit of time fine-tuning the scan settings. Overall, it's not a magic box but it does its job well.
  • Senior Security Technical Lead
    1B-10B USD
    IT Services
    Review Source

    Invicti: A Powerful Scanning Tool with Room for Improvement

    4.0
    Apr 11, 2025
    Invicti is a powerful, dynamic application security scanning tool. The tool is easy to use. It provides really good results in legacy applications; however, for single page applications (SPA), there is still a chance of improvements in terms of coverage and issue findings. It provides a wide range of integration support, which helps with DevOps by allowing security testing to be directly integrated into deployments. Jira integration custom fields are not supported, which the tool should provide. The import file size limit needs improvement; currently, 10MB is insufficient. Additionally, the overall limit of 30MB for imported files is not being handled effectively by Invicti. We have faced a few instances where scans were in queue for more than 2-3 days due to shortage of available agents on the Invicti side, Invicti should provide an isolated environment for scanning and should not be impacted by other customers scan backlog. Invicti sometimes has unexpected returns in API calls that result in CI/CD scan failures, so such instances should not occur again.
  • DIRECTOR, ENGINEERING DEVSECOPS TOOLS
    1B-10B USD
    Services (non-Government)
    Review Source

    The Impact of Invicti DAST on Web Application Security

    5.0
    Apr 23, 2025
    I have a positive experience with the Invicti DAST solution. The platform is intuitive and efficient, with robust scanning capabilities that reliably identify a wide range of vulnerabilities in web applications, including APIs.
  • SYSTEMS ENGINEER MANAGER
    10B+ USD
    Retail
    Review Source

    Seamless Vetting and Sales Process for a Feature-Rich Product

    5.0
    Apr 24, 2025
    The entire process of vetting the product features and the sales experience was smooth and easy.
  • TECHNICAL SUPPORT
    <50M USD
    Miscellaneous
    Review Source

    Invicti's Impact on Enhancing Web Application Scans for Compliance

    4.0
    Apr 22, 2025
    Invicti, Helped us scan web applications and comply against PCI DSS and other compliances.
...
Showing Result 1-5 of 153

Recommended Gartner Research

  • Critical Capabilities for Application Security Testing
  • Magic Quadrant for Application Security Testing

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.