---
description: Page 2 - Compare the best Static Application Security Testing (SAST) Software in Canada. Capterra offers software reviews from verified users, pricing, and features. Find the top rated software for your business.
image: https://gdm-localsites-assets-gfprod.imgix.net/images/capterra/og_logo-e5a8c001ed0bd1bb922639230fcea71a.png?auto=format%2Cenhance%2Ccompress
title: Page 2 - Static Application Security Testing (SAST) Software - Prices & Reviews - Capterra Canada 2026
---

Breadcrumb: [Home](/) > [Static Application Security Testing (SAST) Software](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software) > [Page 2](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2)

# Static Application Security Testing (SAST) Software

Canonical: https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software

Page: 2 / 3\
Prev: [Previous page](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software)\
Next: [Next page](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3)

> Static Application Security Testing (SAST) automatically scans coding environments for security vulnerabilities during the application development process.

-----

## Products

1. [Xygeni Security](https://www.capterra.ca/software/1043740/xygeni) — 5.0/5 (5 reviews) — AI-powered SAST with low noise, exploit-focused detection, smart prioritization, in-IDE guidance, fully integrated into CI/CD and ASPM.
2. [Jsmon](https://www.capterra.ca/software/1076821/Jsmon) — 4.8/5 (5 reviews) — Jsmon is a SAST platform that detects vulnerabilities and uncovers hidden API endpoints in code.
3. [Sonatype Lifecycle](https://www.capterra.ca/software/171030/nexus-lifecycle) — 4.0/5 (4 reviews) — Pair Sonatype Lift with your favorite SAST tool to find and fix performance, reliability, and style issues deep in your code.
4. [OWASP ZAP](https://www.capterra.ca/software/1025564/owasp-zap) — 5.0/5 (4 reviews) — A web security software application that provides English-language vulnerability assessments and other online safeguarding measures.
5. [Apiiro](https://www.capterra.ca/software/1020206/apiiro) — 4.3/5 (3 reviews) — Apiiro helps organizations secure their Software Development Lifecycle (SDLC).
6. [OX Security](https://www.capterra.ca/software/1043847/ox-security) — 4.7/5 (3 reviews) — OX Security provides full visibility and end-to-end traceability over your entire software supply chain from code to cloud.
7. [DoveRunner](https://www.capterra.ca/software/182094/appsealing) — 5.0/5 (2 reviews) — DoveRunner is a mobile app security software that protects digital assets from threats and piracy through content protection features.
8. [OpenText Application Security Aviator](https://www.capterra.ca/software/1036935/fortify) — 5.0/5 (2 reviews) — Fortify is an application security platform that protects applications from breaches, malware, and malicious insiders.
9. [Qwiet AI](https://www.capterra.ca/software/1050452/qwiet-ai) — 5.0/5 (2 reviews) — SAST solution that helps developers scan and analyze vulnerabilities across code libraries in real-time, ensuring application security.
10. [TRU PULSE](https://www.capterra.ca/software/1079017/TRU-PULSE) — 5.0/5 (2 reviews) — Trusys AI is an enterprise AI assurance platform that enables Responsible AI through integrated risk management.
11. [Veracode](https://www.capterra.ca/software/1011010/veracode) — 4.0/5 (1 reviews) — Veracode is a cybersecurity tool that helps businesses identify \&amp; remediate vulnerabilities across the software development lifecycle.
12. [Argon](https://www.capterra.ca/software/1013319/argon) — 5.0/5 (1 reviews) — Holistic Security For Your CI/CD Pipeline. Prevent software supply chain attacks and vulnerabilities, from commit to release.
13. [IDA Pro](https://www.capterra.ca/software/1015457/ida-pro) — 5.0/5 (1 reviews) — IDA Pro is a powerful disassembler and a versatile debugger.
14. [CodeSonar](https://www.capterra.ca/software/1017252/codesonar) — 4.0/5 (1 reviews) — CodeSonar is a static analysis tool that detects security vulnerabilities and quality issues in source code.
15. [Conviso](https://www.capterra.ca/software/1029255/conviso) — 4.0/5 (1 reviews) — SaaS-based tool that helps businesses secure application development pipelines via vulnerability scanning, automated testing, and more.
16. [Jit](https://www.capterra.ca/software/1061762/jit) — 5.0/5 (1 reviews) — Jit's platform is the easiest way to secure your code and cloud, providing full application and cloud security coverage in minutes.
17. [Bearer](https://www.capterra.ca/software/202800/bearer) (0 reviews) — Bearer enables security and engineering teams to implement data security policies and mitigate risks throughout the DevOps lifecycle.
18. [Mayhem](https://www.capterra.ca/software/210683/mayhem) (0 reviews) — Advanced fuzzing solution that combines guided fuzzing with symbolic execution, a patented technology from CMU.
19. [ThunderScan](https://www.capterra.ca/software/214854/thunderscan) (0 reviews) — Static Application Security Testing, WhiteBox Testing solution.
20. [Ostorlab](https://www.capterra.ca/software/1031004/ostorlab) (0 reviews) — Cloud-based vulnerability management platform to detect, monitor, and remediate risks across enterprises' external attack surfaces.
21. [Moderne](https://www.capterra.ca/software/1050736/moderne) (0 reviews) — Your code, always better. Automate source code remediation and migration, freeing your developers to deliver more value all the time.
22. [Akto](https://www.capterra.ca/software/1053906/Akto) (0 reviews) — Akto is an industry-leading solution for API discovery, API security posture management, sensitive data exposure, API security testing.
23. [Heeler](https://www.capterra.ca/software/1073091/Heeler) (0 reviews) — Real-time application security solution that assists businesses with runtime threat modeling and lifecycle management.
24. [Axivion](https://www.capterra.ca/software/1073138/Axivion-Static-Code-Analysis) (0 reviews) — Static code analysis tool that helps developers check standard compliance, security vulnerabilities, and code quality issues.
25. [Coco](https://www.capterra.ca/software/1073704/Coco) (0 reviews) — Coco is an embedded device code coverage analysis software that enables developers to assess how much of their code is being tested.

-----

Page: 2 / 3\
Prev: [Previous page](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software)\
Next: [Next page](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=3)

## Related Categories

- [Source Code Management Software](https://www.capterra.ca/directory/31420/source-code-management/software)
- [Cloud Security Software](https://www.capterra.ca/directory/31344/cloud-security/software)
- [Vulnerability Management Software](https://www.capterra.ca/directory/31062/vulnerability-management/software)
- [DevOps Software](https://www.capterra.ca/directory/31120/devops/software)
- [Continuous Integration Software](https://www.capterra.ca/directory/31119/continuous-integration/software)

## Links

- [View on Capterra](https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software)
- [All Categories](https://www.capterra.ca/directory)

-----

## Structured Data

<script type="application/ld+json">
  {"@context":"https://schema.org","@graph":[{"name":"Capterra Canada","address":{"@type":"PostalAddress","addressLocality":"Toronto","addressRegion":"ON","postalCode":"M2N 7E9","streetAddress":"5000 Yonge Street 14th Floor, Suite 1402 Toronto ON M2N 7E9"},"description":"Capterra Canada helps millions of people find the best business software. With software reviews, ratings, infographics and a comprehensive list of business software.","email":"info@capterra.ca","url":"https://www.capterra.ca/","logo":"https://dm-localsites-assets-prod.imgix.net/images/capterra/logo-a9b3b18653bd44e574e5108c22ab4d3c.svg","@id":"https://www.capterra.ca/#organization","@type":"Organization","parentOrganization":"G2.com, Inc.","sameAs":["https://twitter.com/Capterra","https://www.facebook.com/Capterra/","https://www.linkedin.com/company/capterra/","https://www.instagram.com/capterra/","https://www.youtube.com/channel/UCyUw9-HIkKiYcTqcFDUcxPA"]},{"name":"Capterra Canada","url":"https://www.capterra.ca/","@id":"https://www.capterra.ca/#website","@type":"WebSite","publisher":{"@id":"https://www.capterra.ca/#organization"},"potentialAction":{"query":"required","target":"https://www.capterra.ca/search/?q={search_term_string}","@type":"SearchAction","query-input":"required name=search_term_string"}},{"name":"Static Application Security Testing (SAST) Software","description":"Page 2 - Compare the best Static Application Security Testing (SAST) Software in Canada. Capterra offers software reviews from verified users, pricing, and features. Find the top rated software for your business.","url":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2","about":{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2#itemlist"},"breadcrumb":{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2#breadcrumblist"},"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2#webpage","@type":["WebPage","CollectionPage"],"mainEntity":{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2#itemlist"},"isPartOf":{"@id":"https://www.capterra.ca/#website"},"publisher":{"@id":"https://www.capterra.ca/#organization"},"inLanguage":"en-CA"},{"@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2#breadcrumblist","@type":"BreadcrumbList","itemListElement":[{"name":"Home","position":1,"item":"/","@type":"ListItem"},{"name":"Static Application Security Testing (SAST) Software","position":2,"item":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software","@type":"ListItem"},{"name":"Page 2","position":3,"item":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2","@type":"ListItem"}]}]}
</script><script type="application/ld+json">
  {"name":"Page 2 - Static Application Security Testing (SAST) Software - Prices &amp; Reviews - Capterra Canada 2026","@context":"https://schema.org","@id":"https://www.capterra.ca/directory/32818/static-application-security-testing-%28sast%29/software?page=2#itemlist","@type":"ItemList","itemListElement":[{"name":"Xygeni Security","position":1,"description":"Xygeni SAST delivers AI-powered static analysis designed for precision and low noise in modern, AI-driven development environments. It detects exploitable vulnerabilities such as injection flaws, access-control issues, and insecure configurations while excluding non-exploitable findings.\n\nIntelligent prioritization uses reachability and contextual risk analysis to focus developers on what truly matters. DevAI provides interactive, in-IDE guidance and safe Auto-Fix recommendations with Remediation Risk awareness.\n\nFully integrated into CI/CD pipelines and unified within Xygeni ASPM, SAST findings are correlated with supply chain signals to maintain a continuous application security posture from the first line of code.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/89af94ed-f3da-45da-bf77-00bd8539d976.jpeg","url":"https://www.capterra.ca/software/1043740/xygeni","@type":"ListItem"},{"name":"Jsmon","position":2,"description":"Jsmon works like a SAST for Javascript files present in modern webapps. The platform features an AI-powered analysis engine that performs in-depth examination of JavaScript code to detect hardcoded keys, API secrets, and credentials within files. Jsmon offers automated JavaScript discovery capabilities, change detection functionality that tracks modifications in code over time, and a comprehensive notification system that delivers security alerts through various channels including Slack, email, and Discord. The software includes JavaScript reconnaissance scanning, secrets detection, custom regex support, domain to JavaScript extraction, and authenticated JavaScript scanning capabilities. Jsmon allows users to monitor domains, compare code changes, and access data programmatically through API integration.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/fc05a66d-6f89-4d63-aaf1-a7b02d058da8.png","url":"https://www.capterra.ca/software/1076821/Jsmon","@type":"ListItem"},{"name":"Sonatype Lifecycle","position":3,"description":"Sonatype's Nexus Platform scales open source security monitoring across the software supply chain and reclaims time spent fighting risks in the software development life cycle.\n\nSoftware developers, application security professionals, and DevSecOps experts are empowered with the highest quality Nexus vulnerability intelligence to drive faster releases, decrease false positives, and deliver in-depth, developer remediation guidance.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/235422da-fc87-4523-bcc0-32eaad933197.jpeg","url":"https://www.capterra.ca/software/171030/nexus-lifecycle","@type":"ListItem"},{"name":"OWASP ZAP","position":4,"description":"OWASP ZAP is an open-source web content scanning program that helps businesses with online materials perform security assessments. Along with code reviews that specifically look for security vulnerabilities, the English-language utility features penetration testing tools that simulate hacker attacks. Designed for businesses of all kinds that want to provide online materials for employees and clients, it undertakes security testing and assessments from an end-user perspective n real-time. The system is designed to embed itself between the user's browser interface and the web applications offered by companies. However, it can also work in setups that utilize a network proxy. The system can perform security assessments with all major operating systems. The program aims to exploit known cyber threats and identify vulnerabilities that are already known, then reports those with any potential use to malicious users.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/275a67e4-ca21-4766-a7b6-454bec142600.jpeg","url":"https://www.capterra.ca/software/1025564/owasp-zap","@type":"ListItem"},{"name":"Apiiro","position":5,"description":"Apiiro performs deep code risk assessment across all source control systems and CI/CD pipelines and uses context across multiple data sources to remediate critical risks such as design flaws, misconfigurations, vulnerabilities, drifts & supply chain attacks before production.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/5d1b5a5a-c21c-4234-b7e5-7fa790f52638.png","url":"https://www.capterra.ca/software/1020206/apiiro","@type":"ListItem"},{"name":"OX Security","position":6,"description":"OX Security provides full visibility and end-to-end OX Security's Active ASPM platform unifies application security practices and prevents risks across the software supply chain, empowering organizations to take the first step toward eliminating manual practices while confidently enabling scalable and secure development.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/6172ed09-fe03-4356-abe9-c7d7e95bf53a.png","url":"https://www.capterra.ca/software/1043847/ox-security","@type":"ListItem"},{"name":"DoveRunner","position":7,"description":"DoveRunner is a security software that protects mobile applications and digital content from cyber threats. The system integrates code encryption, runtime application self-protection, anti-tampering, and anti-reverse engineering capabilities to maintain application integrity and prevent unauthorized access.\n\nFor content security, DoveRunner includes multi-DRM licensing, forensic watermarking, and anti-piracy monitoring tools that help prevent unauthorized distribution of digital assets. The platform combines both mobile application and content security into a comprehensive protection system.\n\nDoveRunner features an integration-friendly design with SDKs, APIs, and cloud-based deployment options that work alongside existing systems. The security solution maintains functionality without disrupting user experience while providing real-time threat analytics and monitoring capabilities. A free trial period allows organizations to test the security features before implementation.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/e63231f0-c13d-4231-92bf-189102d30422.jpeg","url":"https://www.capterra.ca/software/182094/appsealing","@type":"ListItem"},{"name":"OpenText Application Security Aviator","position":8,"description":"Fortify provides a suite of application security solutions that help organizations analyze their open source code, detect vulnerabilities earlier in their development lifecycle, protect against advanced threats and safeguard their data. Fortify delivers extra layers of protection for the most vulnerable application attack surfaces—servers, web applications and data sources like databases, message queues and big data stores.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/8e69a1f6-e956-4f36-8cfa-a48818fd3fd6.jpeg","url":"https://www.capterra.ca/software/1036935/fortify","@type":"ListItem"},{"name":"Qwiet AI","position":9,"description":"SAST solution that helps developers scan and analyze vulnerabilities across code libraries in real-time, ensuring application security.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/6f5d91fd-debc-4083-b3dc-56046cc78d40.jpeg","url":"https://www.capterra.ca/software/1050452/qwiet-ai","@type":"ListItem"},{"name":"TRU PULSE","position":10,"description":"Trusys AI is a unified enterprise AI assurance platform designed to make Responsible AI practical, scalable, and measurable. As organizations rapidly adopt artificial intelligence, they face growing challenges around AI hallucinations, model drift, compliance risk, security vulnerabilities, and governance gaps. Trusys addresses these challenges by integrating AI risk management, AI evaluation, and governance into one centralized platform.\n\nThe platform enables enterprises to validate AI models across text, voice, and vision systems, ensuring reliability before deployment. Through structured AI evaluation, continuous monitoring, and governance enforcement, Trusys helps organizations detect anomalies, prevent production failures, and maintain compliance with emerging standards such as NIST AI RMF and the EU AI Act.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/b1d821e1-94b1-46dd-9071-59b41eba4b2f.png","url":"https://www.capterra.ca/software/1079017/TRU-PULSE","@type":"ListItem"},{"name":"Veracode","position":11,"description":"Veracode is a software security platform that provides comprehensive solutions to help organizations secure their applications across the software development lifecycle. The platform offers capabilities including education, static analysis, software composition analysis, dynamic analysis, penetration testing, and remediation to detect vulnerabilities, enforce policies, and empower developers to fix flaws before releasing code into production. Veracode aims to help customers reduce risk, increase the speed of secure software delivery, and promote application security best practices.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/b4c86757-7621-46d6-9eab-7c365d8025aa.jpeg","url":"https://www.capterra.ca/software/1011010/veracode","@type":"ListItem"},{"name":"Argon","position":12,"description":"Argon provides security for software development environments' CI/CD pipelines, eliminating the risk from misconfigurations, vulnerabilities and preventing supply chain attacks.\n\nThis new bread of attacks is an issue all enterprises are dealing with and Argon's solution materially solves the problem in a meaningful way.\n\nArgon provides end-to-end AppSec visibility and security platform for the development process and boost your overall security posture.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/db31363e-cafe-42b9-ad3c-fac1e05377e4.jpeg","url":"https://www.capterra.ca/software/1013319/argon","@type":"ListItem"},{"name":"IDA Pro","position":13,"description":"The source code of the software we use on a daily basis isn’t always available. A disassembler like IDA Pro is capable of creating maps of their execution to show the binary instructions that are actually executed by the processor in a symbolic representation called assembly language. This disassembly process allows software specialists to analyze programs that are suspected to be nefarious in nature, such as spyware or malware.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/dc625d1a-47fe-42e7-9ebb-3074fc2ad3ed.png","url":"https://www.capterra.ca/software/1015457/ida-pro","@type":"ListItem"},{"name":"CodeSonar","position":14,"description":"CodeSonar is static application security testing software that analyzes source code to find and understand quality and security defects. Developed by CodeSecure, CodeSonar integrates static analysis into the development process to improve code quality and security for software written in languages like C, C++, and Java. The tool provides whole-program analysis to identify issues that other tools may miss and generates detailed reports to help developers rapidly prioritize, understand, and remediate problems. CodeSonar supports major coding standards like MISRA and CWE and can be deployed on-premises, in the cloud, or in air-gapped environments.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/53aa5995-e7a8-4949-8628-b7f45ae21d27.jpeg","url":"https://www.capterra.ca/software/1017252/codesonar","@type":"ListItem"},{"name":"Conviso","position":15,"description":"Conviso Platform has got the whole security pipeline covered to empower developers to build secure applications. Because Security shouldn't be an isolated part of your development pipeline — it should be an ongoing, collaborative activity between all teams. Conviso now presents five products within its platform to help you in this mission.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/dd4bb240-c141-4041-9846-a965b8e48b84.jpeg","url":"https://www.capterra.ca/software/1029255/conviso","@type":"ListItem"},{"name":"Jit","position":16,"description":"Jit's platform is the easiest way to secure your code and cloud, providing full application and cloud security coverage in minutes. Tailor a developer security toolchain to your use case and implement it across your repos in a few clicks.\n\nJit empowers developers to own the security of their code without ever leaving their workflow, prioritizing the alerts that matter. Using your current security toolset with Jit, your devs can deliver secure code faster than ever.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/4f1d6749-7e32-4eef-86af-590c50ea2eaa.jpeg","url":"https://www.capterra.ca/software/1061762/jit","@type":"ListItem"},{"name":"Bearer","position":17,"description":"Bearer is a Static Application Security Testing (SAST) tool that brings the principles and the benefits of the DevSecOps model to the data security practice.\n\nBearer enables security and engineering teams to implement data security policies and mitigate risks of data leaks, data breaches, regulatory fines, and revenue loss throughout the development lifecycle.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/c2d6b241-8c88-495a-887f-f7c6f07f136a.png","url":"https://www.capterra.ca/software/202800/bearer","@type":"ListItem"},{"name":"Mayhem","position":18,"description":"Advanced fuzzing solution that combines guided fuzzing with symbolic execution, a patented technology from CMU.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/70980216-edcf-4132-8f6b-82bc46b47693.png","url":"https://www.capterra.ca/software/210683/mayhem","@type":"ListItem"},{"name":"ThunderScan","position":19,"description":"DefenseCode ThunderScan® is a SAST (Static Application Security Testing, WhiteBox Testing) solution for performing deep and extensive security analysis of application source code. ThunderScan® is easy to use, requires almost no user input and can be deployed during or after development with easy integration into your DevOps environment and CI/CD pipeline.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/9b8cdc3e-be32-44bb-8796-455dffb1f686.png","url":"https://www.capterra.ca/software/214854/thunderscan","@type":"ListItem"},{"name":"Ostorlab","position":20,"description":"Cloud-based vulnerability management platform to detect, monitor, and remediate risks across enterprises' external attack surfaces.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/c301a066-8007-4f5d-9c4c-f8393ad8c679.jpeg","url":"https://www.capterra.ca/software/1031004/ostorlab","@type":"ListItem"},{"name":"Moderne","position":21,"description":"Moderne is a next-generation automated code insights and remediation platform that secures and maintains your source code at scale. It’s a place to get complete visibility into your complex enterprise codebase, to reason about what needs to be accomplished, and to automate those remediations accurately, safely, and fast. Static analysis fixes and dependency upgrades that can take many months of manual work can be done in minutes. Why just scan for issues when you can find and fix all at once.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/feb1038c-03eb-42f3-9170-53c641c6d7e5.png","url":"https://www.capterra.ca/software/1050736/moderne","@type":"ListItem"},{"name":"Akto","position":22,"description":"Akto is a leading API security platform trusted by over 1,000 application security teams worldwide. Designed for modern appsec and product security teams, Akto enables organizations to build enterprise-grade API security programs throughout their DevSecOps pipeline. \n\nIts comprehensive suite includes API discovery, sensitive data and PII exposure detection, API security testing, CI/CD integration, and continuous security posture management. Akto provides deep authentication and authorization testing, monitors API changes, and offers the largest API security test library. \n\nRecognized by Forbes, Nasdaq, and Gartner®, Akto is your all-in-one solution to discover APIs, find sensitive data, test vulnerabilities, and prioritize critical findings—ensuring complete DevSecOps coverage.\n\nAkto is also a High performer in API Security and DAST Categories by G2 and has 4.7 overall rating by customers on Gartner Peer Insights.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/ec77bf0b-42aa-4b22-9056-3c0af90dbd0e.jpeg","url":"https://www.capterra.ca/software/1053906/Akto","@type":"ListItem"},{"name":"Heeler","position":23,"description":"Heeler is an application security software that provides application security posture management (ASPM), software composition analysis (SCA), and runtime threat modeling. The platform integrates with existing technology stacks to provide visibility into potential vulnerabilities and automation around remediation workflows between security and development teams.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/52a218e6-223a-4485-9a72-0be51000f680.jpeg","url":"https://www.capterra.ca/software/1073091/Heeler","@type":"ListItem"},{"name":"Axivion","position":24,"description":"Axivion Static Code Analysis is a static code analysis tool that helps developers check standard compliance, security vulnerabilities, and code quality issues for C and C++ code. It performs automated analysis to identify violations of coding guidelines like MISRA C and detect clones, dead code, and security vulnerabilities. Key features include coding standards compliance checking, metric monitoring, defect analysis, and certification for safety-critical software development.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/80fef66b-dfb3-4003-838e-c577f6cf894e.png","url":"https://www.capterra.ca/software/1073138/Axivion-Static-Code-Analysis","@type":"ListItem"},{"name":"Coco","position":25,"description":"Coco is a cross-platform and cross-compiler code coverage analysis tool for C, C++, SystemC, Tcl, and QML code. It works on Linux, Windows, RTOS, and other operating systems and supports compilers including gcc, Visual Studio, and embedded toolchains. Coco provides statement, branch, and MC/DC coverage at multiple testing levels. It offers analysis features such as merging multiple execution reports, built-in function profiling, test data generation, and integrations with testing frameworks including CPPUnit and GoogleTest.","image":"https://gdm-catalog-fmapi-prod.imgix.net/ProductLogo/519bc0c5-e459-49d1-b86c-160237ef66f5.png","url":"https://www.capterra.ca/software/1073704/Coco","@type":"ListItem"}],"numberOfItems":25}
</script>
