In August 2026, 27 listings were added to the directory, compared with 8 in July 2026. The directory total at the end of August was 218, and the listings span 15 categories.
Five of the additions are uncategorised. Among the categorised listings, Tier 2 SOC Automation has the most with 4, followed by SBOM Analysis with 3.
The month in numbers
- 27 listings added in August 2026, against 8 in July 2026. The directory held 218 tools and companies at the end of the month.
- Categories: 15, led by Tier 2 SOC Automation (4), SBOM Analysis (3), Application Security (2), Automotive Cybersecurity (2). 5 listings sit outside any category guide.
- Pricing: 14 not published, 8 free tier plus paid plans, 3 published pricing, 2 open source. 13 of 27 let a buyer see a price or a free tier without asking.
- Deployment: 21 cloud-hosted, 8 with a self-hosted option, 2 open source.
- Founded: of the 24 with a sourced founding year, 7 were founded in 2024 or later; the oldest dates from 1988.
- Most common capabilities (fixed-vocabulary tags, 27 of 27 tagged): ai soc agent (8), alert triage (8), incident response (6), penetration testing (5), soar automation (4), vulnerability management (4).
What was added in August 2026
| Listing | Category | Pricing | What it does |
|---|---|---|---|
| A-LIGN | Penetration Testing Firms | Not published | A-LIGN is a compliance audit firm that helps organisations start and grow their compliance programmes across SOC 2, ISO 27001, CMMC and ISO 42001. |
| Andesite AI | Tier 2 SOC Automation | Not published | Human-AI SOC platform for alert investigation, threat hunting, scoping and remediation |
| AtlasCyber | Tier 2 SOC Automation | Not published | Agentic threat detection and investigation platform for critical infrastructure IT and OT |
| Ausculte Scan | Uncategorised | Not published | Free external WordPress audit covering TLS, headers, exposure, DNS and performance |
| Command Zero | Uncategorised | Not published | Question-led autonomous investigation platform for escalated cases, root cause and threat hunting |
| Conifers.ai | Tier 2 SOC Automation | Not published | CognitiveSOC agentic platform for multi-tier investigation, hunting and reviewable remediation |
| CVD Portal | Cyber Resilience Act Compliance | Free tier plus paid plans | CRA compliance platform with a free whitelabel vulnerability disclosure portal for EU manufacturers |
| D3 Security Morpheus | Uncategorised | Published pricing | Agentic SOC platform doing autonomous triage, attack-path investigation and response execution |
| Dropzone AI | Tier 1 SOC Automation | Published pricing | AI SOC analyst that autonomously investigates tier-1 security alerts |
| Eclypsium | Product Threat Intelligence Providers | Not published | Firmware and hardware integrity monitoring across a bank's own device estate. |
| Exaforce | Tier 2 SOC Automation | Not published | Agentic SOC platform with separate agents for detection, triage, investigation and response |
| GuardNest | Vulnerability Management | Free tier plus paid plans | GuardNest is the vulnerability management and engagement platform of WorkNest Secure, the UK penetration testing provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, combining live pen test reporting with continuous external and web scanning. |
| Keysight (Riscure Device Security) | PCI PTS Compliance Testing Companies | Not published | Accredited payment device security lab: side-channel, fault injection, EMVCo and PCI MPoC. |
| Mailinblack | Email Security | Not published | French email security suite filtering phishing, malware and spam for organisations |
| NetRise | SBOM Analysis | Not published | Binary-derived SBOMs that show what actually executes, rather than what a manifest declares. |
| Opsis OSINT | Uncategorised | Published pricing | OSINT platform searching usernames, emails and domains across public sources |
| PII Crawler | Data Security & Governance | Free tier plus paid plans | Local, air-gapped desktop and CLI scanner that finds SSNs and 30+ PII types in files and databases |
| Prophet Security | Tier 1 SOC Automation | Not published | Agentic AI platform for autonomous security alert triage and investigation |
| RoboShadow | Vulnerability Management | Free tier plus paid plans | Vulnerability scanning and automated third-party patching with Microsoft 365 sync |
| Scalefusion OneIdP | Identity & Access Management | Free tier plus paid plans | UEM-linked IAM suite with SSO, MFA, conditional access and just-in-time admin |
| SurfaceDiff | Uncategorised | Free tier plus paid plans | External attack surface monitoring focused on change detection and historical snapshots |
| UnderDefense | Managed Security Service Providers | Free tier plus paid plans | MDR, managed SOC and compliance services delivered from the US, Poland and Ukraine |
| Vector Informatik | Automotive Cybersecurity | Not published | Automotive embedded security stacks, fuzz testing tools and ISO 21434 consulting |
| Vulert | Application Security, SBOM Analysis | Free tier plus paid plans | Agentless SCA that monitors dependencies from uploaded manifests or SBOMs |
| VxLabs | Automotive Cybersecurity, SBOM Analysis | Not published | Automotive TARA, SBOM and compliance platform plus security engineering services |
| Warpgate | Privileged Access Management | Open source | Open-source clientless bastion for SSH, HTTPS, RDP, VNC, Kubernetes and databases |
| WebSlurp | Application Security | Open source | Chrome DevTools extension to capture, edit and replay HTTP requests |
What they have in common
A clear shared theme is SOC automation. Tier 2 SOC Automation has 4 listings and Tier 1 SOC Automation has 2. Prophet Security and Dropzone AI are in the Tier 1 category, while Exaforce, Conifers.ai and Andesite AI are in Tier 2. Eight of the new listings are tagged with AI SOC agent, and 8 are tagged with alert triage.
Pricing is more often absent than present: 14 listings do not publish pricing, while 13 do. Among those 13, 2 are open source, 8 offer a free tier plus paid plans, and 3 have published pricing. Cloud hosting applies to 21 listings, and 8 offer a self hosted option. Of the 24 listings with a known founding year, 7 were founded in 2024 or later. Vector Informatik, founded in 1988, has the earliest founding year in this group.
How this is counted
Listings are counted by the date they were added to the directory, which is not a launch date: some were founded years earlier and some were listed within weeks of appearing. Every listing cites its sources on its own page, and free listings are placed in the one category guide that genuinely fits, so the category counts reflect editorial placement rather than vendor self-description. Pricing is read from each listing's published pricing: a listing counts as published if a figure or a free tier is visible without contacting sales. Capability tags are assigned from a fixed vocabulary of 60 terms and checked by an editor; the figures above come from the directory database and none are estimated.
All editions
Every month's additions are listed at New cybersecurity tools, month by month. Vendors can submit a tool for a free listing; Featured listings are the paid product.