# Cyber Vendor Guide Cyber Vendor Guide is a directory and comparison site for cybersecurity tools and companies. We aggregate publicly available information and add editorial commentary. Organic listings are ordered by reader upvotes, most-voted first, with ties broken alphabetically, and are not scored or rated by us. Featured listings are paid placements, boosted above the organic list and clearly labelled "Featured"; being featured never changes the organic listings or the comparisons. Cyber Vendor Guide was formerly known as CyberSecTool, published at cybersectool.com until August 2026. Listings, methodology and editorial team are unchanged; only the name and domain moved. ## Buying guides - [AI Agent Security](https://www.cybervendorguide.com/guides/ai-agent-security): AI agent security tools in 2026: runtime guardrails, prompt-injection defence, MCP and tool-call control and LLM red-teaming, compared on public information. - [Application Security](https://www.cybervendorguide.com/guides/application-security): Compare the best application security tools in 2026. SCA, SAST, and open-source alternatives. Language support, CI/CD integration, and pricing compared. - [Automotive Cybersecurity](https://www.cybervendorguide.com/guides/automotive-cybersecurity): Best automotive cybersecurity companies in 2026. Compare PCA Cyber Security, Upstream Security and VicOne on services, in-vehicle protection, and ISO/SAE 21434 and UNECE R155 compliance. - [Cloud Security & CNAPP](https://www.cybervendorguide.com/guides/cloud-security-cnapp): Compare the best CNAPP vendors and cloud security tools in 2026: Wiz, Prisma Cloud, Orca Security, Aqua, Sysdig, Lacework and more, with agentless scanning, workload protection and pricing side by side. - [Cyber Resilience Act Compliance](https://www.cybervendorguide.com/guides/cra-compliance): Compare EU Cyber Resilience Act (CRA) compliance companies and tools in 2026: pi3g, Bureau Veritas, CVD Portal, DEKRA, ONEKEY, SGS and TUV SUD. Services, conformity assessment and standards. - [Data Security & Governance](https://www.cybervendorguide.com/guides/data-security): Compare the best data security platforms in 2026. Enterprise DLP, cloud data protection, and data discovery. Classification, compliance, and pricing compared. - [Email Security](https://www.cybervendorguide.com/guides/email-security): Compare the best email security platforms in 2026. Cloud email security, AI-powered detection, enterprise gateways, and encryption. Features, detection rates, and pricing compared. - [Endpoint & EDR](https://www.cybervendorguide.com/guides/endpoint-edr): Compare the best EDR and endpoint security platforms in 2026. Enterprise EDR, XDR, and SMB alternatives. Detection rates, response automation, and pricing compared. - [Firewall & NGFW](https://www.cybervendorguide.com/guides/firewall-ngfw): Compare the best firewall and NGFW platforms in 2026. Enterprise next-gen firewalls, cloud-native firewalls, and SMB alternatives. Throughput, features, and pricing compared. - [Identity & Access Management](https://www.cybervendorguide.com/guides/identity-access-management): Best identity and access management (IAM) tools in 2026. Compare Okta, Microsoft Entra ID, Auth0, JumpCloud, Keycloak, and more for SSO, MFA, and user lifecycle management. - [Managed Security Service Providers](https://www.cybervendorguide.com/guides/mssps): Compare the top MSSPs and MDR providers in 2026. Arctic Wolf, Secureworks, Red Canary, Expel, eSentire, Critical Start. Services, EDR-neutrality, and delivery models. - [Network Detection & Response (NDR)](https://www.cybervendorguide.com/guides/ndr): Compare network detection and response (NDR) tools and vendors: Corelight, Darktrace, Vectra AI, ExtraHop, Stamus Networks, Arista NDR, and Fidelis. Capabilities, deployment, and sources for each. - [Observability Pipelines](https://www.cybervendorguide.com/guides/observability-pipelines): Observability pipeline tools in 2026: general-purpose telemetry routing for logs, metrics and traces, compared on cost control, deployment and destinations. - [PCI PTS Compliance Testing Companies](https://www.cybervendorguide.com/guides/payment-device-security-testing): PCI PTS compliance testing companies in 2026: PCI Recognized evaluation laboratories and offensive security firms for payment device pre- and post-compliance testing, compared. - [Penetration Testing Firms](https://www.cybervendorguide.com/guides/penetration-testing-firms): Compare the top penetration testing firms in 2026. Mandiant, NCC Group, Bishop Fox, Trail of Bits, IOActive, Praetorian, SBS CyberSecurity. Services, specialisms, and delivery models. - [Privileged Access Management](https://www.cybervendorguide.com/guides/privileged-access-management): Best privileged access management (PAM) tools in 2026: SplitSecure, BeyondTrust, CyberArk, Delinea, HashiCorp Boundary, StrongDM, Teleport and more, for session recording, JIT access and credential vaulting. - [Product Threat Intelligence Providers](https://www.cybervendorguide.com/guides/product-threat-intelligence): Product threat intelligence providers in 2026: vulnerability intelligence, SBOM validation, and product-specific threat monitoring for automotive, payment, and embedded device makers. - [SASE & Zero Trust](https://www.cybervendorguide.com/guides/sase-zero-trust): Compare the best SASE and zero trust vendors in 2026: Zscaler, Palo Alto Prisma Access, Netskope, Cisco, Fortinet, Cloudflare and Cato, with ZTNA, global coverage and pricing side by side. - [SBOM Analysis](https://www.cybervendorguide.com/guides/sbom-analysis): SBOM analysis tools and providers in 2026: Black Duck, Finite State, ONEKEY, PCA Cyber Security, Trivy and more, compared on how they build, validate and act on a software bill of materials. - [Secrets Management](https://www.cybervendorguide.com/guides/secrets-management): Compare secrets management tools in 2026: SplitSecure, HashiCorp Vault, AWS Secrets Manager, Doppler, Infisical, CyberArk Conjur and more, with pricing, open-source and enterprise options side by side. - [Security Data Pipeline](https://www.cybervendorguide.com/guides/security-data-pipeline): Compare security data pipeline tools in 2026: Realm.Security, CeTu, Cribl and Tenzir, on routing, SIEM cost control, deployment and detection-data quality. - [SIEM & Security Analytics](https://www.cybervendorguide.com/guides/siem): Compare the best SIEM platforms in 2026. Enterprise SIEM, cloud-native analytics, and open-source alternatives. Detection, scalability, and pricing compared. - [Tier 1 SOC Automation](https://www.cybervendorguide.com/guides/tier-1-soc-automation): Tier 1 SOC automation tools in 2026: Legion Security, Dropzone AI, Intezer, Prophet Security, Qevlar AI, Radiant Security, Simbian and Torq compared on autonomy, integrations and deployment. - [Tier 2 SOC Automation](https://www.cybervendorguide.com/guides/tier-2-soc-automation): Tier 2 SOC automation tools in 2026: Legion Security, Andesite AI, Conifers.ai and Exaforce, compared on investigation depth, blast radius and response actions. - [Vulnerability Management](https://www.cybervendorguide.com/guides/vulnerability-management): Compare the best vulnerability management platforms in 2026. Enterprise scanners, cloud-native tools, and open-source alternatives. Coverage, accuracy, and pricing compared. ## Best-of lists - [AI SOC Agents](https://www.cybervendorguide.com/best/ai-soc-agents): AI SOC agents in 2026: eleven agentic SOC platforms compared on autonomy, integration model, reasoning transparency, deployment and pricing. - [Best CASB for Unified SASE](https://www.cybervendorguide.com/best/sase-casb-platforms): Best CASB for unified SASE in 2026. Compare Netskope, Zscaler, Skyhigh, Palo Alto, and Cisco for shadow IT discovery, inline DLP, and app risk scoring. - [Best Cloud-Native SWG](https://www.cybervendorguide.com/best/cloud-native-swg): Best cloud-native secure web gateways in 2026. Replace legacy proxies with cloud-delivered web security ranked by performance and threat detection. - [Best Code Security & Secret Scanning Tools](https://www.cybervendorguide.com/best/code-security-scanning-tools): Best code security and secret scanning tools in 2026. Compare Semgrep, SonarQube, Snyk, GitHub Advanced Security, and Checkmarx for SAST, SCA, and secret detection. - [Best CrowdStrike Alternatives](https://www.cybervendorguide.com/best/crowdstrike-alternatives): Compare the best CrowdStrike alternatives in 2026. Expert-ranked endpoint protection platforms evaluated on detection, deployment, pricing, and support. - [Best CrowdStrike Alternatives 2026](https://www.cybervendorguide.com/best/crowdstrike-alternatives-2026): Updated for 2026: the best CrowdStrike alternatives ranked by detection, price, and deployment. Expert picks for enterprise endpoint protection. - [Best CrowdStrike Alternatives for Endpoint Deployment](https://www.cybervendorguide.com/best/crowdstrike-alternatives-endpoint-deployment): CrowdStrike alternatives ranked by deployment ease. Find endpoint protection that deploys faster with less operational overhead across all platforms. - [Best CrowdStrike Alternatives for Enterprise EDR](https://www.cybervendorguide.com/best/crowdstrike-alternatives-enterprise-edr): Find the best enterprise EDR alternatives to CrowdStrike Falcon. Ranked by telemetry depth, scalability, SIEM integration, and large-scale deployment capabilities. - [Best CrowdStrike Alternatives for Incident Response](https://www.cybervendorguide.com/best/crowdstrike-alternatives-incident-response): Top CrowdStrike alternatives for incident response and forensics. Evaluated on containment speed, forensic depth, remediation automation, and IR workflow support. - [Best CrowdStrike Alternatives for SMBs](https://www.cybervendorguide.com/best/crowdstrike-alternatives-smb): Best CrowdStrike alternatives for SMBs in 2026. Compare cost-effective endpoint protection platforms with simpler deployment, MSP support, and SMB-friendly pricing. - [Best CrowdStrike Alternatives With Cheaper Licensing](https://www.cybervendorguide.com/best/crowdstrike-alternatives-cheaper-licensing): Find CrowdStrike alternatives with cheaper licensing. Ranked by value: same detection quality at 20-60% lower cost with fewer add-on charges. - [Best CrowdStrike Competitors in Independent Tests](https://www.cybervendorguide.com/best/crowdstrike-competitors-independent-tests): CrowdStrike competitors ranked by independent test results. See which EDR platforms beat CrowdStrike in AV-TEST, SE Labs, and MITRE ATT&CK evaluations. - [Best CyberArk Alternatives With Faster Deployment](https://www.cybervendorguide.com/best/cyberark-alternatives-faster-deployment): CyberArk alternatives ranked by deployment speed and support quality. Find PAM solutions that deploy in days instead of months with simpler architecture. - [Best Email Data Loss Prevention Solutions](https://www.cybervendorguide.com/best/email-dlp-solutions): The best email DLP solutions in 2026: Fortra Data Security and other platforms for preventing data loss through email, compared on policy controls and content inspection. - [Best Email Encryption for HIPAA Compliance](https://www.cybervendorguide.com/best/email-encryption-hipaa-compliance): Compare the best email encryption tools for HIPAA compliance in 2026. Expert-ranked platforms evaluated on BAA availability, encryption method, audit logging, and ease of use. - [Best Email Security Tools](https://www.cybervendorguide.com/best/best-email-security-tools): The best email security tools in 2026: Proofpoint, Mimecast, Abnormal Security, Microsoft Defender for Office 365, IRONSCALES, Barracuda Email Security and more, compared on detection, deployment and pricing. - [Best Firewalls for Remote Branch Offices](https://www.cybervendorguide.com/best/firewalls-remote-branch-offices): Best firewalls for remote branch offices in 2026. Ranked by zero-touch deployment, SD-WAN integration, centralized management, and branch security features. - [Best open-source application security tools](https://www.cybervendorguide.com/best/best-open-source-application-security-tools): Best open-source application security tools: Semgrep, SonarQube, Trivy. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best open-source IAM tools](https://www.cybervendorguide.com/best/best-open-source-identity-access-management-tools): Best open-source IAM tools: authentik, Bitwarden (Business), Keycloak. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best open-source PAM tools](https://www.cybervendorguide.com/best/best-open-source-privileged-access-management-tools): Best open-source PAM tools: CyberArk Conjur, HashiCorp Boundary, Teleport. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best open-source secrets management tools](https://www.cybervendorguide.com/best/best-open-source-secrets-management-tools): Best open-source secrets management tools: Bitwarden (Business), cert-manager, CyberArk Conjur, External Secrets Operator, and more. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best open-source security data pipeline tools](https://www.cybervendorguide.com/best/best-open-source-security-data-pipeline-tools): Best open-source security data pipeline tools: Fluentd, Tenzir, Vector. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best open-source SIEM tools](https://www.cybervendorguide.com/best/best-open-source-siem-tools): Best open-source SIEM tools: Elastic Security, Graylog, Wazuh. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best open-source vulnerability management tools](https://www.cybervendorguide.com/best/best-open-source-vulnerability-management-tools): Best open-source vulnerability management tools: Greenbone OpenVAS, Nuclei, Trivy. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Best Palo Alto Alternatives for SMB Endpoint Security](https://www.cybervendorguide.com/best/palo-alto-alternatives-smb-endpoint): Top Palo Alto alternatives for SMB endpoint security. Simpler, more affordable endpoint protection ranked for small and midsize businesses. - [Best Platforms for Eliminating Static Credentials in Kubernetes](https://www.cybervendorguide.com/best/kubernetes-secrets-platforms): The best platforms for Kubernetes secrets management in 2026: SplitSecure and others that replace static credentials with dynamic secrets, workload identity and zero-trust access. - [Best SASE Platforms for Government & FedRAMP](https://www.cybervendorguide.com/best/sase-government-fedramp): Best SASE platforms for government and FedRAMP in 2026. Compare iboss, Zscaler, Palo Alto, Cisco, and Cloudflare for FedRAMP authorization and federal zero trust. - [Best Secret Scanning Tools](https://www.cybervendorguide.com/best/secret-scanning-tools): The best secret scanning tools in 2026: SplitSecure and others, compared on detection accuracy, CI/CD integration, false positive rates and remediation. - [Best Secrets Management for Developers](https://www.cybervendorguide.com/best/secrets-management-developers): The best secrets management tools for developers in 2026: SplitSecure, Doppler, Infisical and more, compared on developer experience, SDK quality, local dev integration and workflow simplicity. - [Best Secrets Management Tools](https://www.cybervendorguide.com/best/secrets-management-tools): The best secrets management tools in 2026: SplitSecure, HashiCorp Vault, AWS Secrets Manager, Doppler, Infisical and more, for securing API keys, credentials and certificates. - [Best Secrets Management Tools for DevOps](https://www.cybervendorguide.com/best/secrets-management-devops): The best secrets management tools for DevOps teams in 2026: SplitSecure, HashiCorp Vault and more, compared on CI/CD integration, Kubernetes support, IaC compatibility and developer workflow. - [Best Secure Web Gateways for Unified SASE](https://www.cybervendorguide.com/best/secure-web-gateways): Compare the best secure web gateways for SASE in 2026. Ranked by cloud-native architecture, ZTNA integration, DLP, and unified platform capabilities. - [Best Security Data Pipelines](https://www.cybervendorguide.com/best/best-security-data-pipelines): The best security data pipeline tools in 2026: Realm.Security, CeTu, Cribl and Tenzir, compared on routing, cost control and SOC fit. - [Best Tier 1 SOC Automation Tools](https://www.cybervendorguide.com/best/best-tier-1-soc-automation-tools): The best tier 1 SOC automation tools in 2026: Legion Security, Dropzone AI, Intezer, Prophet Security, Qevlar AI, Radiant Security, Simbian and Torq compared on autonomy, integrations and deployment. - [Best Tier 2 SOC Automation Tools](https://www.cybervendorguide.com/best/best-tier-2-soc-automation-tools): The best tier 2 SOC automation tools in 2026: Legion Security, Andesite AI, Conifers.ai and Exaforce, compared on investigation depth, blast radius and response actions. - [Best UEBA Tools for SOC Using Splunk](https://www.cybervendorguide.com/best/ueba-tools-soc-splunk): Top UEBA tools for Splunk-based SOCs. Ranked by Splunk integration, behavioral analytics, insider threat detection, and SOC workflow enhancement. - [Best Unified SASE Platforms With Zero Trust](https://www.cybervendorguide.com/best/sase-platforms-zero-trust): Best unified SASE platforms with zero trust in 2026. Compare vendors for SD-WAN, SWG, CASB, ZTNA, and FWaaS in a single cloud-delivered platform. - [Best Wiz Alternatives for CSPM](https://www.cybervendorguide.com/best/wiz-alternatives-cspm): Top Wiz alternatives for cloud security posture management. Compare CSPM platforms ranked by agentless scanning, compliance, and multicloud coverage. - [Best XDR Platforms](https://www.cybervendorguide.com/best/xdr-platforms): Compare the best XDR platforms in 2026. Expert-ranked alternatives to CrowdStrike and Palo Alto for unified detection, investigation, and response. - [Best Zero Trust Network Access (ZTNA) for SASE](https://www.cybervendorguide.com/best/sase-ztna-platforms): Best ZTNA for SASE in 2026. Compare Zscaler, Cloudflare, Palo Alto, Cato Networks, and Netskope for identity-aware access, micro-segmentation, and VPN replacement. - [FedRAMP-authorized IAM tools](https://www.cybervendorguide.com/best/fedramp-authorized-identity-access-management-tools): FedRAMP-authorized IAM tools: Cloudflare Access, Duo Security, Microsoft Entra ID, Okta Workforce Identity, and more. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [FedRAMP-authorized PAM tools](https://www.cybervendorguide.com/best/fedramp-authorized-privileged-access-management-tools): FedRAMP-authorized PAM tools: BeyondTrust, BeyondTrust Password Safe, CyberArk Privilege Cloud, Saviynt Privileged Access. Compared on capabilities, deployment, and sources. Neutral directory, no rankings. - [Payment Device Security Testing and Threat Intelligence](https://www.cybervendorguide.com/best/payment-device-security-providers): Security testing and threat intelligence for payment infrastructure in 2026: PCA Cyber Security, Keysight (Riscure), SERMA, SGS Brightsight, SRC and UL Solutions, compared on accreditation and approach. - [Product Threat Intelligence Providers for Financial Services](https://www.cybervendorguide.com/best/product-threat-intelligence-financial-services): Product threat intelligence for financial services in 2026: PCA Cyber Security, IOActive, Eclypsium and NetRise, grouped by which part of the bank estate each one examines. ## Glossary - [CASB. Cloud Access Security Broker](https://www.cybervendorguide.com/definitions/casb): A security policy enforcement point placed between cloud service consumers and cloud service providers to monitor activity, enforce security policies, and prote - [CSPM. Cloud Security Posture Management](https://www.cybervendorguide.com/definitions/cspm): A category of security tools that continuously monitor cloud infrastructure configurations to identify misconfigurations, compliance violations, and security ri - [CNAPP. Cloud-Native Application Protection Platform](https://www.cybervendorguide.com/definitions/cnapp): An integrated security platform that combines cloud workload protection, cloud security posture management, infrastructure-as-code scanning, and runtime protect - [Cybersecurity Compliance Frameworks](https://www.cybervendorguide.com/definitions/compliance-frameworks): Structured sets of guidelines, standards, and best practices that organizations follow to manage cybersecurity risk, protect data, and meet regulatory requireme - [DLP. Data Loss Prevention](https://www.cybervendorguide.com/definitions/dlp): A set of tools and processes designed to detect and prevent the unauthorized transmission of sensitive data outside an organization's network, endpoints, or clo - [Email Security](https://www.cybervendorguide.com/definitions/email-security): The technologies and practices designed to protect email communications from threats including phishing, business email compromise (BEC), malware, spam, and dat - [EDR. Endpoint Detection and Response](https://www.cybervendorguide.com/definitions/edr): A security solution that continuously monitors endpoint devices (laptops, servers, workstations) to detect, investigate, and respond to cyber threats using beha - [XDR. Extended Detection and Response](https://www.cybervendorguide.com/definitions/xdr): A unified security platform that integrates detection and response across endpoints, networks, cloud workloads, email, and identity to provide correlated threat - [IAM. Identity and Access Management](https://www.cybervendorguide.com/definitions/iam): A framework of policies and technologies that ensures the right individuals have appropriate access to technology resources, encompassing authentication, author - [IGA. Identity Governance and Administration](https://www.cybervendorguide.com/definitions/iga): A framework of policies and technologies that manages digital identities and governs access rights, including access request workflows, access certification cam - [IR. Incident Response](https://www.cybervendorguide.com/definitions/incident-response): The organized approach to preparing for, detecting, containing, eradicating, and recovering from cybersecurity incidents, guided by a formal incident response p - [MITRE ATT&CK Framework](https://www.cybervendorguide.com/definitions/mitre-attack): A globally accessible, curated knowledge base of adversary tactics and techniques based on real-world observations, used as a common language for describing and - [MFA. Multi-Factor Authentication](https://www.cybervendorguide.com/definitions/mfa): A security mechanism that requires users to provide two or more independent verification factors. Something they know (password), something they have (phone/key - [NDR. Network Detection and Response](https://www.cybervendorguide.com/definitions/ndr): Network detection and response (NDR) is a category of security tools that monitor network traffic to detect, investigate, and respond to threats, using behavior - [NGFW. Next-Generation Firewall](https://www.cybervendorguide.com/definitions/ngfw): A network security device that combines traditional firewall capabilities (packet filtering, stateful inspection, NAT) with advanced features including applicat - [Penetration Testing](https://www.cybervendorguide.com/definitions/pentesting): A simulated cyberattack against an organization's systems, networks, or applications conducted by authorized security professionals to identify exploitable vuln - [PAM. Privileged Access Management](https://www.cybervendorguide.com/definitions/pam): A security discipline and set of tools that control, monitor, and audit access to critical systems by privileged users such as system administrators, database a - [Ransomware](https://www.cybervendorguide.com/definitions/ransomware): A type of malicious software that encrypts an organization's data or locks systems and demands payment (ransom) in exchange for the decryption key or restored a - [Secrets Management](https://www.cybervendorguide.com/definitions/secrets-management): The practice and tooling for securely storing, accessing, rotating, and auditing sensitive credentials such as API keys, database passwords, certificates, and e - [SASE. Secure Access Service Edge](https://www.cybervendorguide.com/definitions/sase): A cloud-delivered architecture that converges wide-area networking (SD-WAN) and network security services (SWG, CASB, ZTNA, FWaaS) into a single, globally distr - [Security Data Pipeline](https://www.cybervendorguide.com/definitions/data-pipeline): Infrastructure for collecting, transforming, routing, and delivering security telemetry (logs, metrics, traces) from sources to destinations like SIEMs, data la - [SIEM. Security Information and Event Management](https://www.cybervendorguide.com/definitions/siem): A platform that aggregates, correlates, and analyzes security event data from across an organization's IT infrastructure to detect threats, support incident res - [SOAR. Security Orchestration, Automation and Response](https://www.cybervendorguide.com/definitions/soar): A category of security tools that combine incident response case management, workflow automation, and threat intelligence aggregation to help security teams res - [SBOM. Software Bill of Materials](https://www.cybervendorguide.com/definitions/sbom): A comprehensive inventory of all components, libraries, and dependencies that make up a software product, analogous to a list of ingredients on food packaging, - [SCA. Software Composition Analysis](https://www.cybervendorguide.com/definitions/sca): A security practice and toolset that identifies open-source and third-party components in a codebase, detects known vulnerabilities in those dependencies, and m - [SAST. Static Application Security Testing](https://www.cybervendorguide.com/definitions/sast): A method of analyzing application source code, bytecode, or binaries for security vulnerabilities without executing the program, typically integrated into the d - [TI. Threat Intelligence](https://www.cybervendorguide.com/definitions/threat-intelligence): The evidence-based knowledge about existing or emerging cyber threats, including context about threat actors, their motivations, capabilities, and indicators of - [VM. Vulnerability Management](https://www.cybervendorguide.com/definitions/vulnerability-management): The continuous process of identifying, evaluating, prioritizing, and remediating security vulnerabilities across an organization's IT assets including software, - [ZTA. Zero Trust Architecture](https://www.cybervendorguide.com/definitions/zero-trust): A security model based on the principle of "never trust, always verify" that requires continuous authentication and authorization for every user, device, and ne ## Tools - [1Password (Business)](https://www.cybervendorguide.com/tools/1password-business): Secrets automation and password management for teams and CI/CD - [A-LIGN](https://www.cybervendorguide.com/tools/a-lign): A-LIGN is a compliance audit firm that helps organisations start and grow their compliance programmes across SOC 2, ISO 27001, CMMC and ISO 42001. - [Abnormal Security](https://www.cybervendorguide.com/tools/abnormal-security): AI-powered email security platform specializing in behavioral detection of social engineering attacks - [Acronis Cyber Protect](https://www.cybervendorguide.com/tools/acronis): Integrated backup, disaster recovery, and AI-based endpoint security (anti-ransomware, EDR) in one platform. - [Acronis Email Security](https://www.cybervendorguide.com/tools/acronis-email-security): Acronis Cyber Protect Cloud with Acronis Email Security protects Microsoft 365, Google Workspace, and other mailboxes against phishing, BEC, account takeover, malware, and zero-day threats, integrated with backup, endpoint protection, and DLP. - [AgentRidge](https://www.cybervendorguide.com/tools/agentridge): Local-first desktop app that runs autonomous, authorised pentest missions on macOS and Windows. - [AISafe Labs](https://www.cybervendorguide.com/tools/aisafe-labs): AI-driven source code audits and web application pentests, delivered as SaaS with a free tier. - [Akeyless](https://www.cybervendorguide.com/tools/akeyless): SaaS-based zero-knowledge secrets management platform - [Andesite AI](https://www.cybervendorguide.com/tools/andesite-ai): Human-AI SOC platform for alert investigation, threat hunting, scoping and remediation - [Aqua Security](https://www.cybervendorguide.com/tools/aqua-security): Cloud-native security platform specializing in container, Kubernetes, and serverless protection - [Arctic Wolf](https://www.cybervendorguide.com/tools/arctic-wolf): Managed security operations platform with concierge-delivered vulnerability management services - [Arista NDR](https://www.cybervendorguide.com/tools/arista-ndr): Agentless, AI-assisted network detection and response for campus, data center and cloud - [AtlasCyber](https://www.cybervendorguide.com/tools/atlascyber): Agentic threat detection and investigation platform for critical infrastructure IT and OT - [Ausculte Scan](https://www.cybervendorguide.com/tools/ausculte-scan): Free external WordPress audit covering TLS, headers, exposure, DNS and performance - [Auth0](https://www.cybervendorguide.com/tools/auth0): Developer-first CIAM with SDKs and docs - [authentik](https://www.cybervendorguide.com/tools/authentik): Open-source identity provider with modern UI and protocol support - [AWS Secrets Manager](https://www.cybervendorguide.com/tools/aws-secrets-manager): Native AWS secrets management service with automatic rotation - [Azure Data Explorer](https://www.cybervendorguide.com/tools/azure-data-explorer): Microsoft's fast data analytics service for real-time analysis of streaming security data - [Azure Key Vault](https://www.cybervendorguide.com/tools/azure-key-vault): Microsoft Azure's managed secrets, keys, and certificate service - [Barracuda CloudGen Firewall](https://www.cybervendorguide.com/tools/barracuda-cloudgen): Cloud-optimized next-generation firewall with native multi-cloud deployment and integrated SD-WAN - [Barracuda Email Security](https://www.cybervendorguide.com/tools/barracuda-email-security): Email threat protection platform available as gateway appliance or cloud service - [BeyondTrust](https://www.cybervendorguide.com/tools/beyondtrust): Unified privilege management and secure remote access platform - [BeyondTrust Password Safe](https://www.cybervendorguide.com/tools/beyondtrust-password-safe): Enterprise PAM with strong Unix/Linux/Mac coverage - [BigID](https://www.cybervendorguide.com/tools/bigid): Data intelligence platform using ML for discovery, classification, and privacy management - [Bishop Fox](https://www.cybervendorguide.com/tools/bishop-fox): Offensive security firm pairing high-end penetration testing with Cosmos, a continuous attack-surface management platform. - [Bitdefender GravityZone](https://www.cybervendorguide.com/tools/bitdefender): Unified endpoint security with top-rated protection efficacy and low performance impact - [Bitwarden (Business)](https://www.cybervendorguide.com/tools/bitwarden-business): Open-source enterprise password manager with self-hosting and transparent security - [Black Duck](https://www.cybervendorguide.com/tools/black-duck): Enterprise SCA platform with deep open-source detection, license compliance, and code origin analysis - [Bureau Veritas](https://www.cybervendorguide.com/tools/bureau-veritas): Global TIC group whose cybersecurity unit delivers end-to-end CRA compliance, RED testing, penetration testing, and conformity assessment for connected products. - [Cato Networks](https://www.cybervendorguide.com/tools/cato-networks): Single-vendor cloud-native SASE platform with private global backbone and converged architecture - [cert-manager](https://www.cybervendorguide.com/tools/cert-manager): Kubernetes certificate controller supporting Let's Encrypt, Vault, and more - [CeTu](https://www.cybervendorguide.com/tools/cetu): AI-powered security data pipeline for intelligent log ingestion, enrichment, and routing at scale - [Check Point CloudGuard](https://www.cybervendorguide.com/tools/check-point-cloudguard): Cloud security posture and network security platform backed by Check Point's threat prevention expertise - [Check Point Quantum](https://www.cybervendorguide.com/tools/check-point-quantum): Enterprise network security gateway with ThreatCloud AI intelligence and Maestro hyperscale orchestration - [Checkmarx](https://www.cybervendorguide.com/tools/checkmarx): Enterprise application security platform with deep SAST, SCA, DAST, and supply chain security - [Cisco Firepower](https://www.cybervendorguide.com/tools/cisco-firepower): Cisco's next-generation firewall with Talos threat intelligence and deep network infrastructure integration - [Cisco Secure Access](https://www.cybervendorguide.com/tools/cisco-secure-access): Cisco's unified SASE platform converging Umbrella, Duo, and Meraki into cloud-delivered security - [Cisco Secure Email](https://www.cybervendorguide.com/tools/cisco-secure-email): Enterprise email security gateway with Cisco Talos threat intelligence integration - [Cloudflare Access](https://www.cybervendorguide.com/tools/cloudflare-access): Zero trust network access that replaces VPNs with identity-aware policies - [Cloudflare Zero Trust](https://www.cybervendorguide.com/tools/cloudflare-zero-trust): Developer-friendly zero trust platform built on Cloudflare's global Anycast network - [Command Zero](https://www.cybervendorguide.com/tools/command-zero): Question-led autonomous investigation platform for escalated cases, root cause and threat hunting - [ConformOps](https://www.cybervendorguide.com/tools/conformops): Static repository analysis that produces EU Cyber Resilience Act evidence, SBOM inventory and draft technical documentation. - [Conifers.ai](https://www.cybervendorguide.com/tools/conifers-ai): CognitiveSOC agentic platform for multi-tier investigation, hunting and reviewable remediation - [Corelight](https://www.cybervendorguide.com/tools/corelight): Open NDR platform built on the open-source Zeek network monitoring framework - [Cribl](https://www.cybervendorguide.com/tools/cribl): Security data pipeline platform for routing, reducing, and transforming observability data - [Critical Start](https://www.cybervendorguide.com/tools/critical-start): MDR provider built around its Trusted Behavior Registry and MOBILESOC app, delivering managed detection across multiple EDR, XDR, and SIEM platforms. - [CrowdStrike](https://www.cybervendorguide.com/tools/crowdstrike): Cloud-native endpoint protection platform with AI-powered threat detection - [CrowdStrike Falcon Spotlight](https://www.cybervendorguide.com/tools/crowdstrike-falcon-spotlight): EDR-integrated scanless vulnerability assessment built on the CrowdStrike Falcon platform - [CVD Portal](https://www.cybervendorguide.com/tools/cvd-portal): CRA compliance platform with a free whitelabel vulnerability disclosure portal for EU manufacturers - [CVETodo](https://www.cybervendorguide.com/tools/cvetodo): Real-time CVE tracking with per-product alerts, CISA KEV status and remediation priority scoring. - [CyberArk](https://www.cybervendorguide.com/tools/cyberark): Enterprise privileged access management and identity security platform - [CyberArk Conjur](https://www.cybervendorguide.com/tools/cyberark-conjur): Enterprise privileged access and secrets management platform - [CyberArk Privilege Cloud](https://www.cybervendorguide.com/tools/cyberark-privilege-cloud): Enterprise PAM delivered as a SaaS - [Cybereason](https://www.cybervendorguide.com/tools/cybereason): AI-driven EDR with MalOp behavioral attack detection - [Cyera](https://www.cybervendorguide.com/tools/cyera): AI-powered data security platform providing agentless data discovery, classification, and risk assessment - [D3 Security Morpheus](https://www.cybervendorguide.com/tools/d3-security-morpheus): Agentic SOC platform doing autonomous triage, attack-path investigation and response execution - [Darktrace](https://www.cybervendorguide.com/tools/darktrace): AI-driven cyber defense using self-learning technology - [Dashlane (Business)](https://www.cybervendorguide.com/tools/dashlane-business): Business password management with built-in VPN, phishing protection, and SSO integration - [Datadog Observability Pipelines](https://www.cybervendorguide.com/tools/datadog-observability-pipelines): Managed observability pipeline for routing and transforming telemetry data at scale - [Datadog Security](https://www.cybervendorguide.com/tools/datadog-security): Unified security and observability platform with cloud SIEM and posture management - [DEKRA](https://www.cybervendorguide.com/tools/dekra): Major TIC organization offering CRA readiness, security evaluation, and certification, with EUCC accreditation and CRA notified-body status from June 2026. - [Delinea](https://www.cybervendorguide.com/tools/delinea): Cloud-ready PAM platform built on Secret Server and privilege management - [Delinea Secret Server](https://www.cybervendorguide.com/tools/delinea-secret-server): Enterprise password and privileged credential vault - [Doppler](https://www.cybervendorguide.com/tools/doppler): Developer-first universal secrets management platform - [Dropzone AI](https://www.cybervendorguide.com/tools/dropzone-ai): AI SOC analyst that autonomously investigates tier-1 security alerts - [Duo Security](https://www.cybervendorguide.com/tools/duo-security): Cisco's MFA and zero trust access platform known for ease of deployment - [Echoworx](https://www.cybervendorguide.com/tools/echoworx): Enterprise email encryption platform with seven delivery methods and brandable portals - [Eclypsium](https://www.cybervendorguide.com/tools/eclypsium): Firmware and hardware integrity monitoring across a bank's own device estate. - [Egress](https://www.cybervendorguide.com/tools/egress): Adaptive, AI-driven email encryption that adjusts protection based on risk - [Elastic Security](https://www.cybervendorguide.com/tools/elastic-security): Open-source SIEM and security analytics built on the ELK Stack - [Ermetic](https://www.cybervendorguide.com/tools/ermetic): Cloud identity security platform specializing in CIEM and entitlement management, now part of Tenable - [eSentire](https://www.cybervendorguide.com/tools/esentire): Canadian MDR pioneer delivering 24/7 SOC services on the Atlas security operations platform, with strong financial-services and legal-vertical specialisation. - [ESET PROTECT](https://www.cybervendorguide.com/tools/eset-protect): Lightweight multilayered endpoint security with 30+ years of threat research - [Exabeam](https://www.cybervendorguide.com/tools/exabeam): Behavioral analytics SIEM with automated investigation and response - [Exaforce](https://www.cybervendorguide.com/tools/exaforce): Agentic SOC platform with separate agents for detection, triage, investigation and response - [Expel](https://www.cybervendorguide.com/tools/expel): Vendor-neutral MDR founded by former Mandiant leaders, known for transparent operations and an API-only bring-your-own-tech model. - [External Secrets Operator](https://www.cybervendorguide.com/tools/external-secrets-operator): K8s operator that syncs secrets from external stores into Kubernetes Secrets - [ExtraHop](https://www.cybervendorguide.com/tools/extrahop): Cloud-native NDR with line-rate network traffic analysis - [Fendr](https://www.cybervendorguide.com/tools/fendr): Browser-extension DLP that controls pastes and uploads into ChatGPT, Copilot, Claude and other AI tools. - [Fidelis Network](https://www.cybervendorguide.com/tools/fidelis-network): Network detection and response component of the Fidelis Elevate XDR platform - [Finite State](https://www.cybervendorguide.com/tools/finite-state): AI-native Product Security OS analyzing firmware and binaries across connected devices, with exploit-based threat prioritization. - [Fluentd](https://www.cybervendorguide.com/tools/fluentd): Open-source unified data collector and log aggregator from the CNCF ecosystem - [Forcepoint DLP](https://www.cybervendorguide.com/tools/forcepoint-dlp): Enterprise DLP platform with risk-adaptive protection and multi-channel data loss prevention - [ForgeRock](https://www.cybervendorguide.com/tools/forgerock): Enterprise identity platform with AI-driven orchestration for complex deployments - [Fortinet FortiGate](https://www.cybervendorguide.com/tools/fortinet-fortigate): Integrated network security platform with ASIC-accelerated performance and Security Fabric ecosystem - [Fortinet FortiSASE](https://www.cybervendorguide.com/tools/fortinet-fortisase): Converged SASE platform powered by FortiOS with competitive pricing and integrated SD-WAN - [Fortra Data Security](https://www.cybervendorguide.com/tools/fortra): Unified, AI-native data security platform bringing together DSPM, data classification and DLP - [GitHub Advanced Security](https://www.cybervendorguide.com/tools/github-advanced-security): GitHub-native security scanning with CodeQL SAST, secret scanning, and Dependabot dependency management - [Google Cloud Secret Manager](https://www.cybervendorguide.com/tools/gcp-secret-manager): GCP-native secrets storage with versioning and audit - [Graylog](https://www.cybervendorguide.com/tools/graylog): Open-source log management and SIEM platform with intuitive analytics - [Greenbone OpenVAS](https://www.cybervendorguide.com/tools/greenbone-openvas): The most widely used open-source vulnerability scanner with 100,000+ network vulnerability tests - [GuardNest](https://www.cybervendorguide.com/tools/guardnest): GuardNest is the vulnerability management and engagement platform of WorkNest Secure, the UK penetration testing provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, combining live pen test reporting with continuous external and web scanning. - [HashiCorp Boundary](https://www.cybervendorguide.com/tools/hashicorp-boundary): Session broker from HashiCorp, pairs with Vault for JIT credential injection - [HashiCorp Vault](https://www.cybervendorguide.com/tools/hashicorp-vault): Industry-standard open-source secrets management platform - [HiddenLayer](https://www.cybervendorguide.com/tools/hiddenlayer): AI security platform with runtime guardrails, agentic and MCP policy enforcement, red teaming and model scanning. - [HOL Guard](https://www.cybervendorguide.com/tools/hol-guard): Open-source local guard that vets an AI coding agent's shell, file, package and MCP actions before they run. - [IBM QRadar](https://www.cybervendorguide.com/tools/ibm-qradar): AI-powered enterprise SIEM with automated threat detection and investigation - [iboss](https://www.cybervendorguide.com/tools/iboss): Cloud-native zero trust platform with FedRAMP authorization and competitive mid-market pricing - [Infisical](https://www.cybervendorguide.com/tools/infisical): Open-source end-to-end encrypted secrets management for teams - [Intezer](https://www.cybervendorguide.com/tools/intezer): AI SOC platform that autonomously investigates and triages alerts with forensic analysis - [IOActive, Inc.](https://www.cybervendorguide.com/tools/ioactive): Independent global research-driven security consultancy specialising in full-stack, hardware, embedded, and critical-infrastructure testing. - [IRONSCALES](https://www.cybervendorguide.com/tools/ironscales): AI-powered anti-phishing platform with crowdsourced threat intelligence - [JumpCloud](https://www.cybervendorguide.com/tools/jumpcloud): All-in-one directory, SSO, and device management for SMBs - [Juniper SRX](https://www.cybervendorguide.com/tools/juniper-srx): High-performance security gateway with advanced routing and Junos OS networking heritage - [Keeper (Business)](https://www.cybervendorguide.com/tools/keeper-business): Zero-knowledge enterprise password and secrets management with dark web monitoring - [Keycloak](https://www.cybervendorguide.com/tools/keycloak): A widely used open-source IAM platform, backed by Red Hat - [Keysight (Riscure Device Security)](https://www.cybervendorguide.com/tools/keysight-riscure): Accredited payment device security lab: side-channel, fault injection, EMVCo and PCI MPoC. - [KUMO](https://www.cybervendorguide.com/tools/kumo-domain-recon): Open-source domain reconnaissance and OSINT framework that runs 26 parallel scanning modules against a target domain. - [Lacework](https://www.cybervendorguide.com/tools/lacework): Data-driven cloud security platform using behavioral analytics for automated threat detection - [Lakera](https://www.cybervendorguide.com/tools/lakera): Check Point-owned runtime guardrails, agent tool governance and AI red teaming for LLM apps and agents. - [Lasso Security](https://www.cybervendorguide.com/tools/lasso-security): AI security platform with agent discovery, red teaming and runtime guardrails deployed via gateway, API or SDK. - [LastPass (Business)](https://www.cybervendorguide.com/tools/lastpass-business): Widely adopted enterprise password management with extensive SSO and MFA integration - [Legion Security](https://www.cybervendorguide.com/tools/legion-security): Agentic security operations platform that learns analyst workflows and turns them into agentic playbooks - [Lepide Data Security Platform](https://www.cybervendorguide.com/tools/lepide): Unstructured data security, access governance, auditing, threat detection and DSPM across AD, M365 and file servers. - [LogRhythm](https://www.cybervendorguide.com/tools/logrhythm): Unified SIEM platform with threat lifecycle management and built-in SOAR - [LuxSci](https://www.cybervendorguide.com/tools/luxsci): Combined HIPAA-compliant email hosting and encryption with multiple delivery methods - [Mailinblack](https://www.cybervendorguide.com/tools/mailinblack): French email security suite filtering phishing, malware and spam for organisations - [ManageEngine PAM360](https://www.cybervendorguide.com/tools/manageengine-pam360): Mid-market PAM from ManageEngine at a much lower price point than the leaders - [Mandiant (part of Google Cloud)](https://www.cybervendorguide.com/tools/mandiant): Elite incident response and offensive security consultancy operating as the threat-intelligence arm of Google Cloud Security. - [Mend.io](https://www.cybervendorguide.com/tools/mend-io): Open-source security and license compliance platform with comprehensive SCA and supply chain risk management - [Mezmo](https://www.cybervendorguide.com/tools/mezmo): Log management and observability pipeline platform with intelligent data routing - [Microsoft Defender for Endpoint](https://www.cybervendorguide.com/tools/microsoft-defender): Enterprise endpoint protection deeply integrated with Microsoft 365 security stack - [Microsoft Defender for Office 365](https://www.cybervendorguide.com/tools/microsoft-defender-office-365): Microsoft's native email security for Microsoft 365 with XDR integration - [Microsoft Defender Vulnerability Management](https://www.cybervendorguide.com/tools/microsoft-defender-vulnerability-management): Microsoft's built-in vulnerability management integrated with Defender for Endpoint - [Microsoft Entra ID](https://www.cybervendorguide.com/tools/microsoft-entra-id): Microsoft's cloud IAM, bundled with M365 and Azure - [Microsoft Purview](https://www.cybervendorguide.com/tools/microsoft-purview): Microsoft unified data governance and compliance platform with deep M365 integration - [Microsoft Sentinel](https://www.cybervendorguide.com/tools/microsoft-sentinel): Cloud-native Azure SIEM with AI-powered detection and automated response - [Mimecast](https://www.cybervendorguide.com/tools/mimecast): Cloud email security platform with threat protection, archiving, and continuity - [NCC Group](https://www.cybervendorguide.com/tools/ncc-group): FTSE 250 global cybersecurity and software resilience firm offering technical assurance, managed detection, and incident response. - [NetRise](https://www.cybervendorguide.com/tools/netrise): Binary-derived SBOMs that show what actually executes, rather than what a manifest declares. - [Netskope](https://www.cybervendorguide.com/tools/netskope): Cloud-native SASE platform with CASB and granular SaaS visibility - [Netwrix](https://www.cybervendorguide.com/tools/netwrix): Data security and auditing platform for change tracking, compliance, and user behavior monitoring - [Noma Security](https://www.cybervendorguide.com/tools/noma-security): Independent platform for agent discovery, MCP and tool access control, runtime detection and red teaming. - [Nuclei](https://www.cybervendorguide.com/tools/nuclei): Fast, template-based open-source vulnerability scanner with 8,000+ community-contributed detection templates - [Okta Workforce Identity](https://www.cybervendorguide.com/tools/okta): Cloud IAM with the broadest integration catalog - [One Identity](https://www.cybervendorguide.com/tools/one-identity): Unified identity security platform with PAM and governance - [One Identity Safeguard](https://www.cybervendorguide.com/tools/one-identity-safeguard): Enterprise PAM from Quest Software, hardened appliance deployment - [ONEKEY](https://www.cybervendorguide.com/tools/onekey): European product-cybersecurity platform automating SBOM generation, vulnerability management, and CRA compliance for connected-device makers. - [OneLogin](https://www.cybervendorguide.com/tools/onelogin): Mid-market cloud IAM at a lower price point than Okta - [Opsis OSINT](https://www.cybervendorguide.com/tools/opsis-osint): OSINT platform searching usernames, emails and domains across public sources - [Orca Security](https://www.cybervendorguide.com/tools/orca-security): Agentless cloud security platform using SideScanning technology for full-stack visibility - [OSINTLeak](https://www.cybervendorguide.com/tools/osintleak): Breach and stealer-log intelligence platform with multi-selector search, monitoring, API and a Python client. - [Palo Alto Cortex XDR](https://www.cybervendorguide.com/tools/cortex-xdr): XDR platform integrating endpoint, network, and cloud data from Palo Alto ecosystem - [Palo Alto Networks](https://www.cybervendorguide.com/tools/paloalto): Enterprise next-generation firewall platform with advanced threat prevention, application visibility, and centralized management - [Palo Alto Prisma Access](https://www.cybervendorguide.com/tools/palo-alto-prisma-access): Enterprise SASE platform extending Palo Alto's next-gen firewall to cloud-delivered security - [Paubox](https://www.cybervendorguide.com/tools/paubox): HIPAA-compliant email encryption built for healthcare with seamless delivery - [PCA Cyber Security](https://www.cybervendorguide.com/tools/pca): Offensive security and threat intelligence for payment devices, vehicles and embedded systems - [pfSense](https://www.cybervendorguide.com/tools/pfsense): Open-source firewall and router platform based on FreeBSD with zero licensing costs - [pi3g](https://www.cybervendorguide.com/tools/pi3g): German embedded-Linux and IoT specialist helping SME manufacturers make connected products compliant with the EU Cyber Resilience Act. - [PII Crawler](https://www.cybervendorguide.com/tools/pii-crawler): Local, air-gapped desktop and CLI scanner that finds SSNs and 30+ PII types in files and databases - [Pillar Security](https://www.cybervendorguide.com/tools/pillar-security): Platform to discover, red team, guard and govern AI agents, MCP servers and skills, deployable in your VPC. - [Ping Identity](https://www.cybervendorguide.com/tools/ping-identity): Enterprise-grade IAM with hybrid deployment and strong federation - [Praetorian](https://www.cybervendorguide.com/tools/praetorian): Offensive security firm delivering continuous penetration testing and attack-surface management through its Chariot platform. - [Prisma Cloud](https://www.cybervendorguide.com/tools/prisma-cloud): Comprehensive CNAPP from Palo Alto Networks securing applications from code to cloud - [Prompt Security](https://www.cybervendorguide.com/tools/prompt-security): SentinelOne-owned AI firewall, shadow AI discovery and agent/MCP scope control, plus open-source fuzzer. - [Proofpoint](https://www.cybervendorguide.com/tools/proofpoint): Enterprise email security platform for advanced threat protection, compliance, and data loss prevention - [Prophet Security](https://www.cybervendorguide.com/tools/prophet-security): Agentic AI platform for autonomous security alert triage and investigation - [Proton Mail Business](https://www.cybervendorguide.com/tools/protonmail-business): Swiss-hosted zero-access encrypted email with the strongest privacy protections - [Pulumi ESC](https://www.cybervendorguide.com/tools/pulumi-esc): Secrets composition layer: pull from Vault/AWS/Doppler and expose to any runtime - [Qevlar AI](https://www.cybervendorguide.com/tools/qevlar-ai): Autonomous alert investigation platform for SOC teams and MSSPs - [Qualys VMDR](https://www.cybervendorguide.com/tools/qualys-vmdr): Cloud-native vulnerability management platform with integrated detection, prioritization, and patch management - [Radiant Security](https://www.cybervendorguide.com/tools/radiant-security): AI SOC platform that triages, investigates, and responds to security alerts - [Rapid7 InsightVM](https://www.cybervendorguide.com/tools/rapid7-insightvm): Risk-based vulnerability management platform with live dashboards and remediation project tracking - [Realm.Security](https://www.cybervendorguide.com/tools/realm-security): Security data fabric platform for intelligent routing and optimization of security telemetry - [Red Canary (a Zscaler company)](https://www.cybervendorguide.com/tools/red-canary): MDR provider known for deep Microsoft Defender expertise and high-fidelity detection engineering, acquired by Zscaler in 2025. - [RoboShadow](https://www.cybervendorguide.com/tools/roboshadow): Vulnerability scanning and automated third-party patching with Microsoft 365 sync - [SailPoint](https://www.cybervendorguide.com/tools/sailpoint): AI-driven identity governance and administration platform - [Saviynt Privileged Access](https://www.cybervendorguide.com/tools/saviynt-pam): Cloud-native PAM built into Saviynt's converged identity platform - [Sawmills](https://www.cybervendorguide.com/tools/sawmills): AI telemetry pipeline that filters and optimises logs, metrics and traces pre-ingestion to cut observability cost. - [SBS CyberSecurity](https://www.cybervendorguide.com/tools/sbs-cybersecurity): US cybersecurity consulting, audit and testing firm founded in 2004, focused on community banks and credit unions, with penetration testing plus CMMC Level 1 and 2 readiness work for defense contractors. - [Scalefusion OneIdP](https://www.cybervendorguide.com/tools/scalefusion-oneidp): UEM-linked IAM suite with SSO, MFA, conditional access and just-in-time admin - [Sealed Secrets](https://www.cybervendorguide.com/tools/sealed-secrets): Encrypt Kubernetes secrets into a format safe to store in Git - [Secureworks (a Sophos company)](https://www.cybervendorguide.com/tools/secureworks): Long-established MDR and XDR provider built around the Taegis platform, now operating as part of Sophos. - [Securiti](https://www.cybervendorguide.com/tools/securiti): AI-powered data security, privacy, and governance platform with DSPM and compliance automation - [Securonix](https://www.cybervendorguide.com/tools/securonix): Cloud-native SIEM with advanced UEBA and analytics - [Semgrep](https://www.cybervendorguide.com/tools/semgrep): Lightweight, open-source static analysis with intuitive pattern-matching rules and fast scan performance - [SentinelOne](https://www.cybervendorguide.com/tools/sentinelone): AI-powered autonomous endpoint protection with one-click remediation - [SERMA Safety & Security](https://www.cybervendorguide.com/tools/serma-safety-security): French security evaluation lab (ITSEF); PCI Recognized for PTS, plus EMVCo and Common Criteria. - [SGS](https://www.cybervendorguide.com/tools/sgs): World-leading testing and certification company that, through SGS Brightsight, provides CRA and RED security evaluation, conformity assessment, and notified-body services. - [SGS Brightsight](https://www.cybervendorguide.com/tools/sgs-brightsight): Major PCI Recognized security evaluation lab for payment devices, EMVCo and Common Criteria. - [Simbian](https://www.cybervendorguide.com/tools/simbian): AI agents that triage, investigate, and respond to security alerts - [Skyhigh Security](https://www.cybervendorguide.com/tools/skyhigh-security): Data-aware SSE platform with pioneering CASB technology and deep cloud data protection - [Snyk](https://www.cybervendorguide.com/tools/snyk): Developer-first application security platform for finding and fixing vulnerabilities in code, dependencies, containers, and IaC - [SonarQube](https://www.cybervendorguide.com/tools/sonarqube): Open-source code quality and security analysis platform with broad language support - [SonicWall](https://www.cybervendorguide.com/tools/sonicwall): High-performance firewalls with advanced threat detection for SMB to enterprise - [Sophos Intercept X](https://www.cybervendorguide.com/tools/sophos-intercept-x): Endpoint protection with deep learning AI and synchronized security ecosystem - [Sophos XGS](https://www.cybervendorguide.com/tools/sophos-xgs): Synchronized security firewall with endpoint integration, Xstream TLS inspection, and cloud management - [SOPS](https://www.cybervendorguide.com/tools/sops): CLI tool for encrypting YAML/JSON/ENV files with KMS, age, or PGP - [SPIFFE / SPIRE](https://www.cybervendorguide.com/tools/spiffe-spire): Workload identity standard: short-lived SVIDs replace shared service secrets - [Spirion](https://www.cybervendorguide.com/tools/spirion): Sensitive data discovery and classification platform with high-accuracy identification of regulated data - [SplitSecure](https://www.cybervendorguide.com/tools/splitsecure): Distributed secrets management. No vault, no vendor dependency - [Splunk](https://www.cybervendorguide.com/tools/splunk): Enterprise SIEM and security analytics platform for threat detection and incident response - [Splunk Data Stream Processor](https://www.cybervendorguide.com/tools/splunk-dsp): Splunk's real-time stream processing engine for data optimization and routing - [SRC Security Research & Consulting](https://www.cybervendorguide.com/tools/src-security): German PCI Recognized lab for PCI PTS device evaluation and German payment terminal schemes. - [Stamus Networks](https://www.cybervendorguide.com/tools/stamus-networks): Suricata-based network detection and response with an open-source community edition - [Straiker](https://www.cybervendorguide.com/tools/straiker): Discovery, autonomous red teaming and runtime guardrails for AI agents, coding agents and MCP servers. - [StrongDM](https://www.cybervendorguide.com/tools/strongdm): Infrastructure access proxy with credential injection and session recording - [Sumo Logic](https://www.cybervendorguide.com/tools/sumo-logic): Cloud-native SIEM and security analytics with automated threat detection - [SurfaceDiff](https://www.cybervendorguide.com/tools/surfacediff): External attack surface monitoring focused on change detection and historical snapshots - [Sysdig](https://www.cybervendorguide.com/tools/sysdig): Cloud and container security platform built on open-source Falco for runtime threat detection - [Tanium](https://www.cybervendorguide.com/tools/tanium): Converged endpoint management platform with real-time vulnerability assessment at massive enterprise scale - [Teleport](https://www.cybervendorguide.com/tools/teleport): Modern identity-aware access for SSH, Kubernetes, databases, and apps - [Tenable](https://www.cybervendorguide.com/tools/tenable): Vulnerability management platform with Nessus scanning, cloud-native VM, and exposure management - [Tenzir](https://www.cybervendorguide.com/tools/tenzir): Open-source security data pipeline with native support for security-specific data formats - [Tessian](https://www.cybervendorguide.com/tools/tessian): Human layer security platform preventing inbound threats and outbound misdirected emails - [Torq](https://www.cybervendorguide.com/tools/torq): Hyperautomation platform with the HyperSOC agentic SOC and Socrates AI analyst - [Trail of Bits](https://www.cybervendorguide.com/tools/trail-of-bits): High-end security research and engineering firm known for deep code audits, cryptography reviews, and smart-contract security work. - [Trellix](https://www.cybervendorguide.com/tools/trellix): XDR platform combining McAfee Enterprise and FireEye capabilities - [Trend Micro Cloud One](https://www.cybervendorguide.com/tools/trend-micro-cloud-one): Multi-cloud security platform offering modular workload protection and posture management - [Trend Micro Email Security](https://www.cybervendorguide.com/tools/trend-micro-email-security): Cloud email security gateway with AI-powered BEC detection and XDR integration - [Trend Micro Vision One](https://www.cybervendorguide.com/tools/trend-micro): XDR platform with unified visibility across endpoints, email, cloud, and network - [Trivy](https://www.cybervendorguide.com/tools/trivy): Open-source vulnerability scanner for containers, file systems, IaC, and Kubernetes with zero-config setup - [Tuta](https://www.cybervendorguide.com/tools/tuta): Open-source end-to-end encrypted email with zero-access architecture - [TUV SUD](https://www.cybervendorguide.com/tools/tuv-sud): Global testing and certification body offering CRA readiness assessment, vulnerability-management support, third-party conformity assessment, and training. - [UL Solutions](https://www.cybervendorguide.com/tools/ul-solutions): Global TIC firm and PCI Recognized lab for payment terminal (PTS POI/HSM) and EMVCo testing. - [UnderDefense](https://www.cybervendorguide.com/tools/underdefense): MDR, managed SOC and compliance services delivered from the US, Poland and Ukraine - [Upstream Security](https://www.cybervendorguide.com/tools/upstream-security): Cloud-based, agentless connected-vehicle cybersecurity platform with a managed Vehicle SOC - [Varonis](https://www.cybervendorguide.com/tools/varonis): Data security and governance platform for access visibility, insider threat detection, and sensitive data protection - [Vector](https://www.cybervendorguide.com/tools/vector): High-performance open-source observability pipeline built in Rust by Datadog - [Vector Informatik](https://www.cybervendorguide.com/tools/vector-informatik): Automotive embedded security stacks, fuzz testing tools and ISO 21434 consulting - [Vectra AI](https://www.cybervendorguide.com/tools/vectra-ai): AI-powered NDR with Attack Signal Intelligence for hybrid cloud - [Veracode](https://www.cybervendorguide.com/tools/veracode): Cloud-based application security testing platform with SAST, SCA, DAST, and penetration testing - [veriBIMI](https://www.cybervendorguide.com/tools/veribimi): Swiss-jurisdiction DMARC audit and VMC/CMC certificate brokerage for brands implementing BIMI. - [VicOne](https://www.cybervendorguide.com/tools/vicone): Trend Micro subsidiary delivering end-to-end automotive cybersecurity across the vehicle lifecycle - [Virtru](https://www.cybervendorguide.com/tools/virtru): End-to-end encryption for Gmail and Outlook with persistent sender control - [VMware Carbon Black](https://www.cybervendorguide.com/tools/carbon-black): Behavioral EDR platform with continuous endpoint activity recording - [Vulert](https://www.cybervendorguide.com/tools/vulert): Agentless SCA that monitors dependencies from uploaded manifests or SBOMs - [VxLabs](https://www.cybervendorguide.com/tools/vxlabs): Automotive TARA, SBOM and compliance platform plus security engineering services - [Warpgate](https://www.cybervendorguide.com/tools/warpgate): Open-source clientless bastion for SSH, HTTPS, RDP, VNC, Kubernetes and databases - [WatchGuard Firebox](https://www.cybervendorguide.com/tools/watchguard-firebox): SMB-focused unified threat management with simplified deployment and MSP-friendly cloud management - [Wazuh](https://www.cybervendorguide.com/tools/wazuh): Open-source unified XDR and SIEM platform - [WebSlurp](https://www.cybervendorguide.com/tools/webslurp): Chrome DevTools extension to capture, edit and replay HTTP requests - [Wiz](https://www.cybervendorguide.com/tools/wiz): Agentless cloud security platform with full-stack visibility and risk prioritization across multi-cloud environments - [Zenity](https://www.cybervendorguide.com/tools/zenity): Independent agent discovery, posture and runtime enforcement for Copilot Studio, Agentforce and coding agents. - [Zix (OpenText)](https://www.cybervendorguide.com/tools/zix): Enterprise email encryption with the larger install base and policy-based automation - [Zscaler](https://www.cybervendorguide.com/tools/zscaler): Cloud-native SASE and zero trust platform for secure internet and private application access