The 2026 Cybersecurity
Tool Landscape Report
163 tools across 26 categories. Pricing, deployment, standards, and reported pros and considerations, side by side. As a downloadable spreadsheet (CSV).
No spam. Unsubscribe any time. Or scroll down and browse the listings free.
Inside the report
- ✓ Downloadable spreadsheet (CSV) you can sort and filter
- ✓ 163 tools listed alphabetically per category
- ✓ Public pricing per tool (free tiers, per-seat, enterprise)
- ✓ Reported pros and considerations from practitioner discussions
- ✓ Deployment model, standards, and certifications
163
Tools listed
26
Categories covered
0
Scoring weights
0
Hidden placements
What's inside
Alphabetical category listings
Every tool in every category, in alphabetical order. No editorial scoring, no “Top 5”. Just the listings, side by side.
Aggregated public pricing
Free tiers, per-seat costs, and enterprise ranges pulled from official vendor pages and what practitioners report paying. Verify with the vendor before any purchase.
Reported pros and considerations
What real practitioners say on Reddit, Hacker News, Stack Overflow, and verified review sites. Not vendor marketing. We report; we don't verdict.
AI Agent Security
See all 10 tools →Tools that secure AI agents and LLM applications: the guardrails, gateways and controls that sit between a model and the actions it can take. They intercept tool and MCP calls, file access and shell c…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Harden | Developers and teams running coding agents such as Claude Code, Codex or Cursor who want tool calls checked on the machine before they execute | Free for individuals; enterprise on request |
| HiddenLayer | Large enterprises and government buyers that want agent runtime enforcement, red teaming and model scanning from one platform with self-hosted and air-gapped options. | Subscription (annual contract via AWS Marketplace; private offers) |
| HOL GuardOSS | Developers and teams using AI coding agents who want local pre-execution controls on risky actions without sending data to a cloud service. | Open source (Apache-2.0) with optional paid cloud subscription |
| Lakera | Enterprises that want runtime guardrails, agent tool governance and red teaming from a vendor now inside a large security platform (Check Point). | Contact sales (free account sign-up offered, tiers not published) |
| Lasso Security | Enterprises deploying agents across platforms such as Bedrock, Vertex AI, Microsoft Copilot and Salesforce Agentforce that want one gateway-level policy and detection layer. | Subscription (annual contract via AWS Marketplace; private offers) |
| Noma Security | Enterprises that want one independent platform spanning agent posture, MCP and tool permissions, runtime detection and red teaming across SaaS, homegrown and endpoint agents. | Contact sales |
Application Security
See all 5 tools →Application security testing tools for finding and fixing vulnerabilities in code, dependencies, and containers. Compare SCA, SAST, and open-source application security solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| AISafe Labs | Development teams wanting on-demand AI-driven code audits and web application pentests without a traditional engagement. | Freemium |
| Snyk | Developer-first application security platform for finding and fixing vulnerabilities in code, dependencies, containers, and IaC | Per-developer (monthly) |
| VibeCoden't | Solo builders and small teams shipping sites made with AI coding tools who want a quick external check and fixes they can hand to their agent. | Freemium, scan packs or monthly subscription |
| Vulert | Small and mid-sized teams that want continuous open-source dependency and licence monitoring without granting a scanner access to their repositories. | Per-tier subscription capped by number of applications and users, billed monthly or annually, with extra applications charged monthly. Add-on modules are priced per application per month, including licence compliance, SBOM, container and Docker SBOM export. |
| WebSlurpOSS | Web and API testers who want quick capture, edit and replay of a page's own requests without standing up an intercepting proxy. | Free and open source |
Automotive Cybersecurity
See all 5 tools →Automotive cybersecurity companies protect connected and software-defined vehicles across their lifecycle, from ECUs, in-vehicle networks and telematics to cloud backends, fleets and EV charging. This…
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434 | Project-based engagements |
| Upstream Security | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets | Subscription (custom) |
| Vector Informatik | Automotive OEMs and Tier 1 suppliers needing production-grade ECU security software and ISO 21434 verification tooling inside an existing AUTOSAR toolchain. | Quote-based licensing for embedded software and tools, with separate fees for consulting and training |
| VicOne | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent | Subscription (custom) |
| VxLabs | OEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering. | Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services |
Cloud Security & CNAPP
See all 0 tools →Cloud-native application protection platforms for securing cloud workloads, containers, and infrastructure. Compare CNAPP, agentless cloud security, and cloud workload protection solutions.…
| Tool | Best fit for | Pricing model |
|---|
Cyber Resilience Act Compliance
See all 9 tools →Companies that help manufacturers comply with the EU Cyber Resilience Act (Regulation 2024/2847), the mandatory cybersecurity rules for products with digital elements sold in the EU. From hands-on emb…
| Tool | Best fit for | Pricing model |
|---|---|---|
| pi3g | SME manufacturers of embedded-Linux and IoT products that need hands-on engineering help to reach CRA compliance, not just an audit | Consulting + engineering engagements |
| Article 14 Ready | Product security and compliance teams at manufacturers preparing CRA Article 14 reports for exploited vulnerabilities or severe incidents. | Freemium |
| CVD Portal | EU manufacturers, importers and distributors that need an Article 13 disclosure contact and Article 14 reporting workflow in place before the 11 September 2026 deadline. | Freemium subscription with a permanent free tier and three paid tiers |
| ONEKEY | Device manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle | Platform subscription + advisory |
| Bureau Veritas | Manufacturers wanting one TIC partner spanning hands-on pen testing, RED/IEC 62443 testing, and CRA conformity advisory | Consulting + testing + certification |
| ConformOps | Small software teams that want a first, evidence-led CRA readiness pass on a repository at a fixed published price. | One-off assessment plus subscription, with free preview tier |
Data Security & Governance
See all 3 tools →Data security and governance platforms for discovering, classifying, and protecting sensitive data across your organization. Compare enterprise DLP, cloud data security, and data discovery solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Lepide Data Security Platform | Organisations wanting unstructured-data security, access governance and auditing across AD, Microsoft 365 and file servers, as a per-user alternative to Varonis or Netwrix | Quote-based (per user, per year, by platform) |
| Varonis | Data security and governance platform for access visibility, insider threat detection, and sensitive data protection | SaaS subscription (per-user platform licence) |
| VaultDB | Development teams embedding encrypted storage with fine grained access control and verifiable audit into Rust applications. | Licence |
Email Security
See all 6 tools →Email security platforms for protecting against phishing, BEC, malware, and other email-borne threats. Compare cloud email security, AI-powered, enterprise gateway, and email encryption solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Mailinblack | French and European organisations wanting email filtering, awareness training and password management from a single locally registered vendor. | Subscription, quote on request |
| DMARCSwiss | Organisations that want their DMARC reports processed in Switzerland while they move their domains to an enforced policy | Monthly or annual subscription, with a 14-day free trial |
| makeBIMI | Teams setting up BIMI who need a compliant SVG logo file and DNS record before they apply for a certificate | Free |
| Proofpoint | Enterprise email security platform for advanced threat protection, compliance, and data loss prevention | Per-user subscription |
| SecLens.ONEOSS | Anyone who wants an outside view of how hard a domain is to spoof, and the DNS changes that would fix it | Free |
| veriBIMI | Brands that want a managed DMARC audit and VMC or CMC application handled for a fixed fee rather than dealing with the certificate authority directly. | One-off professional service fees plus certificate authority fee |
Endpoint & EDR
See all 2 tools →Endpoint detection and response platforms for protecting devices against malware, ransomware, and advanced threats. Compare enterprise EDR, XDR, and SMB endpoint solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Acronis Cyber Protect | Teams and MSPs that want backup, disaster recovery, and endpoint security (anti-ransomware, EDR) in one platform | Subscription (per workload or per GB; MSP consumption-based) |
| CrowdStrike | Cloud-native endpoint protection platform with AI-powered threat detection | Per-device subscription, billed monthly or annually |
Firewall & NGFW
See all 1 tools →Next-generation firewall platforms for network security, intrusion prevention, and application-layer protection. Compare enterprise NGFW, cloud firewalls, and SMB solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Palo Alto Networks | Enterprise next-generation firewall platform with advanced threat prevention, application visibility, and centralized management | Appliance purchase + annual subscription licenses per feature |
Identity & Access Management
See all 9 tools →Managing who can access what across cloud apps, internal tools, and infrastructure. Whether you need enterprise SSO with thousands of integrations, developer-friendly CIAM for your SaaS app, or open-s…
| Tool | Best fit for | Pricing model |
|---|---|---|
| OneLogin | Mid-market teams wanting full IAM features at a lower per-seat price | Per-user tiers |
| Okta Workforce Identity | Enterprises with large SaaS portfolios needing a proven, broadly-integrated IAM backbone | Per-user tiers (billed annually) |
| Auth0 | SaaS teams that need customer login with a great developer experience | Per monthly active user (MAU) |
| Cloudflare Access | Teams replacing a VPN with zero trust access to internal apps | Per-user (free tier + paid tiers) |
| JumpCloud | SMBs and mid-market teams wanting IAM plus MDM without buying both | Per-user (billed annually) |
| KeycloakOSS | Teams that need full control, auditability, and zero license cost | Open Source + Enterprise Subscription |
Managed Security Service Providers
See all 7 tools →Managed Security Service Providers and MDR firms compared on services, EDR-stack neutrality, transparency posture, and delivery model. From vendor-neutral cloud-native MDR to traditional 24/7 SOC outs…
| Tool | Best fit for | Pricing model |
|---|---|---|
| UnderDefense | Mid-market organisations that want a 24/7 outsourced SOC layered onto security tools they already own, often alongside SOC 2 or ISO 27001 readiness work. | Per device or asset per month on an annual contract, plus project fees for penetration testing and compliance work |
| Arctic Wolf | Organizations without in-house security expertise wanting fully managed vulnerability scanning and prioritized remediation guidance | Per-asset managed service (annual contract) |
| Critical Start | Mid-market and enterprise teams that already own EDR/XDR and want managed response with strong noise reduction | Subscription per integrated surface |
| eSentire | Financial services, legal, and insurance firms that want a mature MDR partner with deep vertical playbooks | Subscription tiers (Atlas Essentials / Advanced / Complete) |
| Expel | Teams that already own a quality EDR/SIEM/cloud stack and want a transparent, vendor-neutral SOC layered on top | Subscription per integrated surface |
| Red Canary (a Zscaler company) | Microsoft-centric organisations wanting Defender / Sentinel telemetry analysed by a high-fidelity detection-engineering team | Subscription per managed surface |
Network Detection & Response (NDR)
See all 7 tools →Network detection and response (NDR) tools monitor network traffic to detect, investigate, and respond to threats that bypass endpoint and perimeter controls. This directory lists NDR tools and vendor…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Arista NDR | Organizations wanting agentless, AI-assisted network detection | Subscription |
| CorelightOSS | Teams wanting open, Zeek-based network evidence and forensics | Open source + Enterprise subscription |
| Darktrace | Organizations wanting AI-driven detection of unknown threats across hybrid environments | Enterprise |
| ExtraHop | Organizations needing deep network visibility and forensics across hybrid environments | SaaS / Appliance |
| Fidelis Network | Government and enterprise buyers wanting deep session inspection NDR | Appliance + Subscription |
| Stamus NetworksOSS | Teams wanting Suricata-based NDR with an open-source edition | Open source + Enterprise |
Observability Pipelines
See all 7 tools →General-purpose telemetry pipelines that route, filter and transform logs, metrics and traces before they reach a backend. These tools carry security data but are not sold specifically for security op…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Azure Data Explorer | Microsoft-centric organizations wanting a scalable security data lake with powerful KQL analytics at lower cost than SIEM | Consumption-based (compute + storage) |
| Datadog Observability Pipelines | Organizations already using Datadog that want managed pipeline capabilities with enterprise support and monitoring | Volume-based (per GB processed) |
| FluentdOSS | Cloud-native teams wanting a lightweight, proven open-source data collector with a massive plugin ecosystem | Open source |
| Mezmo | Teams wanting combined log management and pipeline capabilities with a developer-friendly experience | Ingest-based (per GB) |
| Sawmills | Teams on Datadog, Splunk or similar that want to cut observability cost by filtering and optimising telemetry before ingestion | Usage-based (ingest volume; annual commitment) |
| Splunk Data Stream Processor | Existing Splunk customers wanting to optimize data flows and reduce ingest costs within the Splunk ecosystem | Bundled with Splunk licensing |
OSINT Tools
See all 10 tools →Open-source intelligence (OSINT) tools gather what is already public about a person, an organisation or a piece of infrastructure: the accounts registered to a username or email address, records in le…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Opsis OSINT | Investigators, journalists and small security teams who want username and email pivoting in a hosted interface or API, without installing and maintaining open-source tools such as Maigret or WhatsMyName. | Subscription |
| Intelligence X | Threat intelligence and security teams checking exposure in leaked data and darknet sources. | Free tier and annual subscription |
| MaigretOSS | Investigators who want a free tool that turns a username into a report of linked accounts. | Open source |
| Maltego | Investigation and threat intelligence teams that need to connect many sources on one graph. | Free tier and annual subscription with data credits |
| OSINT Industries | Investigators who need to pivot from an email address, phone number or username to linked accounts quickly. | Monthly subscription with search credits |
| OSINTLeak | Security, threat intelligence and investigative teams that need to search and monitor breach and stealer-log data with API access. | Freemium |
PCI PTS Compliance Testing Companies
See all 6 tools →Companies involved in PCI PTS compliance for payment devices fall into two distinct roles. PCI Recognized evaluation laboratories perform the formal PCI PTS POI and HSM evaluations (and related EMVCo …
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434 | Project-based engagements |
| Keysight (Riscure Device Security) | Payment device, terminal and mobile payment vendors needing accredited EMVCo or PCI security evaluation of hardware and secure elements | Project-based engagements |
| SERMA Safety & Security | Manufacturers needing PCI PTS and payment-acceptance device evaluation from an accredited European lab | Project-based engagements |
| SGS Brightsight | Payment terminal and HSM manufacturers needing formal PCI PTS, EMVCo or Common Criteria evaluation | Project-based engagements |
| SRC Security Research & Consulting | Manufacturers needing PCI PTS plus German DK/OSeC/JTEMS terminal evaluation | Project-based engagements |
| UL Solutions | Manufacturers needing PCI PTS and EMVCo evaluation from a large, globally accredited lab | Project-based engagements |
Penetration Testing Firms
See all 10 tools →Independent penetration testing firms compared on services, specialisms, delivery model, and standards coverage. From global FTSE 250 consultancies to boutique research-driven firms.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| A-LIGN | Companies running testing alongside a formal audit who want one accredited firm across both | Project-based testing + audit engagements |
| PCA Cyber Security | Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434 | Project-based engagements |
| SBS CyberSecurity | Community banks, credit unions and other regulated financial institutions that want testing, audit and governance from one firm, plus organizations preparing for a CMMC Level 1 or Level 2 assessment | Project-based testing and advisory engagements |
| Bishop Fox | Mid-to-large enterprises wanting continuous offensive testing rather than annual point-in-time pentests | Project + Cosmos subscription |
| IOActive, Inc. | OEMs, semiconductor vendors, automotive, and critical-infrastructure operators that need silicon-to-cloud security expertise | Project-based engagements |
| Lorikeet Security | Engineering-led companies that want continuous testing between annual pentests, with human sign-off on findings and published pricing. | Annual programs, prepaid credits and per-service pricing |
Privileged Access Management
See all 13 tools →Controlling who can access privileged accounts, servers, databases, and cloud infrastructure. PAM is what you reach for when secrets management alone is not enough: when you need session recording, ju…
| Tool | Best fit for | Pricing model |
|---|---|---|
| SplitSecure | Highest-sensitivity accounts, regulated industries, and MSPs needing zero vendor dependency | Tiered (free / per-seat / enterprise) |
| Delinea Secret Server | Enterprises focused on privileged access management and compliance | Annual license |
| BeyondTrust Password Safe | Enterprises with mixed Unix/Linux/Windows estates needing unified privilege management | Enterprise (contact sales) |
| CyberArk | Enterprise privileged access management and identity security platform | Per-user subscription + modules |
| CyberArk ConjurOSS | Large enterprises with complex compliance and PAM requirements | Enterprise license |
| CyberArk Privilege Cloud | Large enterprises and government agencies with complex legacy environments and compliance requirements | Enterprise (contact sales) |
Product Threat Intelligence Providers
See all 6 tools →Companies that provide threat intelligence focused on specific products and devices, rather than general enterprise or network threat intelligence. This covers vulnerability intelligence tailored to a…
| Tool | Best fit for | Pricing model |
|---|---|---|
| PCA Cyber Security | Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434 | Project-based engagements |
| Eclypsium | Banks needing firmware-level integrity assurance across a large estate of laptops, servers and network devices | Enterprise subscription |
| Finite State | Manufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence. | Not publicly disclosed |
| PCA Cervus | Manufacturers, importers and operators of embedded and connected products in payment, automotive, industrial and IoT markets that need to track vulnerabilities device by device against supplier SBOMs and produce evidence for regulations such as the Cyber Resilience Act, PCI PTS and UNECE R155 | . |
| Upstream Security | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets | Subscription (custom) |
| VicOne | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent | Subscription (custom) |
SASE & Zero Trust
See all 0 tools →Secure access service edge and zero trust platforms for securing distributed workforces and cloud applications. Compare enterprise SASE, cloud-native, and SMB zero trust solutions.…
| Tool | Best fit for | Pricing model |
|---|
SBOM Analysis
See all 11 tools →Tools and providers that build, validate or act on a software bill of materials. They differ most in what they start from: some read source code, manifests or an existing SBOM, while others reconstruc…
| Tool | Best fit for | Pricing model |
|---|---|---|
| ONEKEY | Device manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle | Platform subscription + advisory |
| PCA Cyber Security | Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434 | Project-based engagements |
| Black Duck | Enterprises needing the deepest open-source detection including undeclared components, M&A due diligence, and regulatory compliance for software supply chain | Enterprise license (project-based) |
| CRACI | Product teams selling into the EU that want Cyber Resilience Act evidence produced by the build, with the SBOM and vulnerability tracking inside the CI pipeline rather than a separate scan | Subscription by user band and monitored SBOM, plus metered build minutes |
| Finite State | Manufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence. | Not publicly disclosed |
| NetRise | Financial institutions and device makers needing a binary-derived component inventory where source code is not available | Enterprise subscription |
Secrets Management
See all 19 tools →Managing API keys, database credentials, certificates, and machine identities across CI/CD pipelines, Kubernetes clusters, and cloud infrastructure. Whether you need enterprise-grade compliance, open-…
| Tool | Best fit for | Pricing model |
|---|---|---|
| SplitSecure | Highest-sensitivity accounts, regulated industries, and MSPs needing zero vendor dependency | Tiered (free / per-seat / enterprise) |
| Bitwarden (Business)OSS | Security-conscious organizations wanting an affordable, auditable, and self-hostable password manager | Per-user |
| Delinea Secret Server | Enterprises focused on privileged access management and compliance | Annual license |
| HashiCorp VaultOSS | Teams needing flexible, self-hosted secrets management with extensive plugin ecosystem | Open Source + Enterprise |
| Keeper (Business) | Compliance-focused enterprises needing zero-knowledge security and dark web monitoring | Per-user |
| 1Password (Business) | Teams wanting combined password management and developer secrets automation | Per-user |
Security Data Pipeline
See all 4 tools →Platforms built specifically for security telemetry: collecting, filtering, normalising and routing security data before it reaches a SIEM or data lake. This category covers tools their own vendors po…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Realm.Security | Security teams wanting a purpose-built security data fabric with centralized visibility and policy-based routing across their entire security stack | Custom |
| CeTu | Security teams seeking an AI-driven, no-code approach to managing and optimizing security data pipelines without dedicated data engineering resources | Custom |
| Cribl | Security data pipeline platform for routing, reducing, and transforming observability data | Credit-based (per GB ingested) |
| TenzirOSS | Security teams wanting an open-source, security-native data pipeline with transparent code and no vendor lock-in | Open source with commercial support |
SIEM & Security Analytics
See all 1 tools →Security information and event management platforms for log analysis, threat detection, and incident response. Compare enterprise, cloud, and open-source SIEM solutions.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| Splunk | Enterprise SIEM and security analytics platform for threat detection and incident response | Workload-based or ingest-based |
SOC Automation
See all 0 tools →SOC automation covers the tools that take work off the security operations team: triaging and investigating alerts, gathering context, and running the response steps an analyst would run by hand. We …
| Tool | Best fit for | Pricing model |
|---|
Vulnerability Management
See all 6 tools →Vulnerability scanning and management platforms for identifying, prioritizing, and remediating security weaknesses. Compare enterprise, cloud, and open-source vulnerability management tools.…
| Tool | Best fit for | Pricing model |
|---|---|---|
| CVETodo | Small teams and MSPs that want CVE alerting tied to a live software inventory without an enterprise scanner | Freemium; monthly or annual subscription |
| GuardNest | Organisations using WorkNest Secure for penetration testing who want continuous scanning, live reporting, and retesting in the same platform | Subscription |
| RoboShadow | Small and mid-sized organisations and MSPs running Microsoft-centric estates that want vulnerability scanning and automated third-party patching from a single console, with a usable free tier for evaluation. | Freemium with a paid subscription tier priced per account plus per-agent overage, and a quoted enterprise tier |
| Codename Sonar | Small security teams and consultants who want low cost, web based scans of hosts they own or are authorised to test. | Freemium subscription |
| KUMOOSS | Security researchers and pentesters who want fast, free domain reconnaissance from the command line. | Open Source |
| Tenable | Vulnerability management platform with Nessus scanning, cloud-native VM, and exposure management | Per-asset (annual subscription) |
Wire Transfer Verification
See all 6 tools →A wire transfer verification tool confirms that the person sending a wire is who they say they are, and that the payment is genuine. There are not many on the market. At many banks, verifying a wire i…
| Tool | Best fit for | Pricing model |
|---|---|---|
| BioCatch | Banks and financial institutions that want to detect scams, account takeover and mule activity in online and mobile banking sessions before a transfer is sent. | Custom quote via sales |
| Eftsure | Finance, accounts payable and treasury teams that pay suppliers by ACH, wire or EFT and want each payee verified before funds are released. | Subscription priced on annual expenditure and the number of new vendors onboarded each month |
| IronVest | Banks and fintechs that want customers to approve wires and other payments in their own app with a biometric check tied to the exact transaction details. | Annual contract (AWS Marketplace) or custom quote |
| Pindrop | Banks that take or confirm transfer requests by phone and want caller authentication and deepfake voice checks inside their contact centre platform. | Annual contract by call volume (AWS Marketplace) or private offer |
| SurePay | Banks and payment service providers that must offer Verification of Payee or Confirmation of Payee, and corporates checking supplier IBANs before payment. | Annual subscription for portal plans; API and bank services quoted on request |
| Trustpair | Finance, treasury and accounts payable teams at large companies that want supplier bank details checked inside their ERP, treasury or procurement system before payment. | Quote based packages with a fixed number of vendor evaluations per year |
Get the full 2026 report
All 163tool listings, pricing, and deployment notes in one downloadable spreadsheet (CSV) you can sort and filter. We'll email you the download link.
You'll also get future editions as we add categories. No spam, unsubscribe any time.