Top Free API Security Tools

How Many API Security Tools Products Does G2 Track?

Total Products under this Category: 73

Category Stats (Oct 2026)

  • Average Rating: 4.57/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Chronoloq (+1.16%) - Among all products in this category, Chronoloq recorded the largest rating increase compared to last month

Last updated: October 08, 2026

How Does G2 Rank API Security Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,300+ Authentic Reviews
  • 73+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for API Security Tools

G2 Grid® for API Security Tools plotting products by satisfaction and market presence

Highlighted products: Cloudflare Application Security and Performance, Postman, Check Point WAF (formerly CloudGuard WAF), apisec.ai, Fastly's Web Application and API Security, Astra Pentest, Rakuten SixthSense Observability, and Orca Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/api-security/grids.json?focus%5B%5D=cloudflare-application-security-and-performance&focus%5B%5D=postman&focus%5B%5D=check-point-waf-formerly-cloudguard-waf&focus%5B%5D=apisec-ai&focus%5B%5D=fastly-s-web-application-and-api-security&focus%5B%5D=astra-pentest&focus%5B%5D=rakuten-sixthsense-observability&focus%5B%5D=orca-security)

Postman

Postman is the world’s leading API platform, used by more than 40 million developers and 500,000 organizations to build, test, and manage APIs at scale. With Postman, teams collaborate efficiently across the entire API lifecycle, including design, development, testing, security, documentation, and governance. The platform helps ensure consistency, quality, and enterprise-grade control. Postman also offers Agent Mode (beta), built on AWS Bedrock and trained with AWS SageMaker. Agent Mode enables developers to use natural language to debug requests, organize collections, document APIs, and automate workflows without switching tools or writing custom scripts.

Average Rating: 4.6/5.0

Total Reviews: 1,754

How Do G2 Users Rate Postman?

  • API Testing: 9.5/10 (Category avg: 9.1/10)
  • API Monitoring: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind Postman?

  • Seller: Postman
  • Year Founded: 2014
  • HQ Location: San Francisco, CA
  • Twitter: @getpostman
    55,430 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,580 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Software Developer
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 39% Medium, 35% Small

What Do G2 Reviewers Say About Postman?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Postman for testing APIs, enabling quick requests and seamless collaboration.
  • Users appreciate the ease of API testing with Postman, enabling quick requests, responses, and debugging without extra code.
  • Users value the ease of API testing with Postman, appreciating its intuitive interface and comprehensive features.
  • Users appreciate the ease of testing APIs with Postman, benefiting from its intuitive interface and collaboration features.
  • Users value the testing efficiency of Postman, enjoying quick debugging and seamless API management across environments.
Cons
  • Users often face slow performance with Postman, especially when dealing with large projects or validation processes.
  • Users often face performance issues with Postman, experiencing slowdowns and unexpected bugs that disrupt their workflow.
  • Users find Postman slow to load at times, especially with large collections and multiple tabs open, affecting performance.
  • Users experience resource limitations with Postman, as the app can slow down and consume significant memory during use.
  • Users find the limited features in Postman's free tier challenging, especially for smaller teams needing advanced tools.

What Are Recent G2 Reviews of Postman?

What Are G2 Users Discussing About Postman?

apisec.ai

APIsec automated API testing platform automatically analyzes applications, simulates sophisticated attacks across the full spectrum of OWASP threats, and uncovers vulnerabilities and exploits before they reach production. By eliminating the need for time-consuming manual testing, APIsec helps security and development teams strengthen their security posture with continuous, preventative API protection. In addition, APIsec operates APIsec University, the world’s most popular API security education platform, offering dozens of free courses and a vibrant community of over 100,000 members. Together, our advanced security solutions and educational resources enable organizations to build, deploy, and maintain secure applications with confidence.

Average Rating: 4.7/5.0

Total Reviews: 227

How Do G2 Users Rate apisec.ai?

  • API Testing: 9.0/10 (Category avg: 9.1/10)
  • API Monitoring: 8.7/10 (Category avg: 8.9/10)

Who Is the Company Behind apisec.ai?

  • Seller: apisec.ai
  • Year Founded: 2018
  • HQ Location: San Francisco, US
  • LinkedIn® Page: www.linkedin.com
    41 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Consultant, Cyber Security Analyst
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 64% Small, 23% Medium

What Do G2 Reviewers Say About apisec.ai?

AI-generated summary from verified user reviews

Pros
  • Users commend the robust security features of Apisec.ai, effectively addressing API vulnerabilities and enhancing protection.
  • Users appreciate the ease of use of APISec.ai, making API scanning and navigation quick and efficient.
  • Users appreciate the automatic endpoint discovery of apisec.ai, enhancing visibility and streamlining API security assessments.
  • Users praise the testing efficiency of apisec.ai, benefiting from its automated and user-friendly API scanning capabilities.
  • Users value the automation of API scanning in apisec.ai, enabling effortless security testing and efficient problem resolution.
Cons
  • Users find API issues challenging, particularly regarding authentication setup and insufficient guidance for new users.
  • Users find the complex setup challenging, especially without clear guides or documentation for API security features.
  • Users express concern over the poor documentation, highlighting insufficient details and a lack of resources for internal developers.
  • Users note a difficult learning curve with APIsec.ai, especially for beginners navigating its extensive features.
  • Users feel the pricing is high for exams and wish for more affordable options tailored to their needs.

What Are Recent G2 Reviews of apisec.ai?

Fastly's Web Application and API Security

Fastly’s AppSec solutions empower teams to mitigate threats and control bots while helping the business move faster, confidently. Protect Your Apps and APIs While Accelerating Growth with Fastly’s Next-Gen WAF, DDoS Protection, Bot Management, API Security, and more. Our solutions are designed to help you stop cyber threats from derailing your biggest moments, accelerate innovation while minimizing new risk, and govern bots without increasing user friction.

Average Rating: 4.2/5.0

Total Reviews: 29

Who Is the Company Behind Fastly's Web Application and API Security?

  • Seller: Fastly
  • Year Founded: 2011
  • HQ Location: San Francisco, California, United States
  • Twitter: @Fastly
    29,199 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,456 employees on LinkedIn®
  • Ownership: NYSE: FSLY

Who Uses This Product?

  • Top Industries: Computer Software
  • Company Size: 50% Medium, 37% Large

What Do G2 Reviewers Say About Fastly's Web Application and API Security?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of setup with Fastly's Web Application and API Security, enjoying excellent support and a user-friendly interface.
  • Users praise Fastly's Web Application and API Security for its robust protection against all types of attacks.
  • Users commend the excellent customer support provided by Fastly, enhancing their experience and implementation process.
  • Users value the effective DDoS protection of Fastly, ensuring robust security against various web application threats.
  • Users appreciate the excellent security protection Fastly's solution offers against a wide range of application attacks.
Cons
  • Users note that the pricing can be a barrier for smaller projects, with additional costs for support and multiple hostnames.
  • Users report poor customer support, highlighting issues with responsiveness and difficulty in obtaining assistance for configurations.
  • Users find the complex configuration of Fastly's WAF overwhelming and time-consuming, especially for rule management.
  • Users find the complex setup of Fastly's WAF cumbersome, making rule management and configurations time-consuming.
  • Users find the management complex, as the cumbersome interface and poor support hinder effective rule setup.

What Are Recent G2 Reviews of Fastly's Web Application and API Security?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Astra Pentest

Astra Security is a leading continuous penetration testing platform that combines AI-powered autonomous pentesting with certified expert-led assessments. Powered by Attack AI, trained on 6.8M+ security findings and insights from 5,000+ real-world pentests. Astra deploys intelligent agents that continuously discover, validate, prioritize, and help remediate vulnerabilities at scale. While AI handles speed and scale, Astra’s certified security experts focus on what automation alone cannot: complex business logic flaws, multi-step attack chains, advanced exploit paths, and emerging AI/LLM-specific threats. Built for modern engineering teams, Astra integrates directly into CI/CD workflows, enabling continuous security validation between releases instead of relying on outdated annual pentests. The platform delivers comprehensive Autonomous Pentest powered by AI agents, DAST vulnerability scanner and human-driven pentests across web apps, AI/LLMs, mobile apps, APIs, cloud infrastructure. Astra is CREST-accredited, CERT-IN empaneled, and a PCI ASV-certified vendor. Our team also led the development of the OWASP APTS framework, helping shape the industry standard for continuous security testing. Today, 1,500+ organizations across 70+ countries trust Astra Security, including Ford, Loom, CompTIA, Hitachi, HackerRank, and OLX.

Average Rating: 4.7/5.0

Total Reviews: 249

G2 Deal: For G2 users: 10% off across all pentest plans

Avail Astra Pentest at 10% off, our comprehensive pentest suite scans for 8000+ security tests including OWASP Top 10, SANS 25, known CVEs & security best practices. This offer is exclusive to G2 users!

Price: ~~$5999~~ → $5400

View this exclusive G2 deal

How Do G2 Users Rate Astra Pentest?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Astra Pentest?

  • Seller: ASTRA IT, Inc.
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Bengaluru, IN
  • Twitter: @getastra
    694 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    154 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, CEO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 67% Small, 28% Medium

What Do G2 Reviewers Say About Astra Pentest?

AI-generated summary from verified user reviews

Pros
  • Users commend Astra Pentest's excellent customer support, noting their responsiveness and flexibility throughout the process.
  • Users praise the comprehensive vulnerability detection of Astra Pentest, which simplifies tracking and prioritizing security issues.
  • Users appreciate the user-friendly interface of Astra Pentest, enhancing their experience with clear and efficient vulnerability management.
  • Users commend Astra Pentest for its efficient scanning and penetration testing, enhancing security preparedness and team responsiveness.
  • Users value the vulnerability identification of Astra Pentest, enhancing confidence in security and business growth.
Cons
  • Users report poor customer support with Astra Pentest, noting slow email responses and lack of instant messaging options.
  • Users find the poor interface design of Astra Pentest frustrating, leading to confusion and difficulties in usage.
  • Users report slow performance with Astra Pentest, citing delays in results and instability during use.
  • Users find the UI challenging, particularly with note-taking and clarity on rescan needs during pentests.
  • Users face a lack of information with Astra Pentest, as documentation and updates are often insufficient or slow to arrive.

What Are Recent G2 Reviews of Astra Pentest?

What Are G2 Users Discussing About Astra Pentest?

Rakuten SixthSense Observability

In today's digital landscape, businesses need a powerful and comprehensive Application Performance Monitoring (APM) solution to stay ahead of the curve. Introducing Rakuten SixthSense Observability - a next-generation APM tool that transforms the way you monitor, analyze, and optimize your applications and infrastructure. With its robust suite of features and advanced analytics, Rakuten SixthSense Observability empowers you to proactively identify and resolve issues, streamline operations, and enhance customer experiences. Key Capabilities: • Comprehensive Monitoring and Alerting: Rakuten SixthSense Observability offers end-to-end monitoring of your applications, infrastructure, and network performance. With real-time alerting and customizable dashboards, you can quickly detect issues and gain actionable insights into the health and performance of your systems. • Distributed Tracing and Correlation: Gain full visibility into your application's performance with distributed tracing, which tracks transactions and requests across multiple services and components. This feature helps you identify bottlenecks, latency issues, and errors, making it easier to optimize your application and enhance customer experiences. • Anomaly Detection and Machine Learning: Leverage Rakuten SixthSense's advanced machine learning capabilities to automatically identify unusual patterns and deviations in application performance and resource utilization. This proactive approach enables you to detect and resolve issues before they impact your business and customers. • Advanced Analytics and Visualization: Rakuten SixthSense's rich data visualization and analytics tools allow you to dive deep into your application performance data. Generate custom reports, analyze trends, and uncover hidden patterns that can drive continuous improvement and optimization. • Log Management and Integration: Effortlessly collect, analyze, and store logs from various sources with Rakuten SixthSense's integrated log management feature. This seamless integration enables you to correlate log data with performance metrics and traces, providing a comprehensive understanding of your application's behaviour. • Scalability and Flexibility: Rakuten SixthSense Observability is built to scale with your growing business needs, supporting a wide range of applications, services, and infrastructure. Its flexible architecture allows you to customize the tool to your specific requirements and integrate it with other monitoring and observability solutions. Current Feature set: • Application Performance Monitoring: Full stack visibility across Java, PHP, Node.js, Python, Go and a lot more! Key Features include, Distributed Tracing, Profiling, Database Monitoring • Infrastructure Monitoring: Get a birds-eye view of your infrastructure health and gain granular insights with easy deployment Key Features include Kubernetes, VMs, Web Servers, Cloud Integrations • Digital Experience Monitoring: Improve the end-user experience of your applications mapped with contextual information of application performance metrics • Browser Monitoring: Metrics to optimize end users’ experience and help in improving application performance. • Mobile Monitoring: Monitor crashes, performance & usage metrics for your mobile applications • Synthetic Monitoring: Stimulate end-user transactions using low code, no code test scripts • VM Monitoring: VM monitoring capability lets you view your infrastructure performance and health of servers, virtual machines, containers, databases etc. at a glance. • SixthSense Cognitive Engine: Modern observability and the proactive approach using artificial intelligence. The application uses different AI/ML algorithms that can predict performance metrics with an accuracy of up to 98% and a confidence level of 90%.

Average Rating: 4.6/5.0

Total Reviews: 52

How Do G2 Users Rate Rakuten SixthSense Observability?

  • API Testing: 9.3/10 (Category avg: 9.1/10)
  • API Monitoring: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Rakuten SixthSense Observability?

Who Uses This Product?

  • Who Uses This: Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer Games
  • Company Size: 47% Large, 38% Medium

What Do G2 Reviewers Say About Rakuten SixthSense Observability?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the deep visibility offered by Rakuten SixthSense, enhancing application performance and proactively managing issues.
  • Users value the effective alerting system for seamless monitoring and quick resolution of issues in one dashboard.
  • Users value the excellent customer support of Rakuten SixthSense, enhancing their overall experience and productivity.
  • Users appreciate the ease of use of Rakuten SixthSense Observability, enabling quick identification of issues without hassle.
  • Users find the implementation ease of Rakuten SixthSense Observability impressive, allowing quick access to essential monitoring tools.
Cons
  • Users find the complex setup of Rakuten SixthSense Observability requires significant onboarding effort for optimal use.
  • Users find the documentation lacking, making onboarding and setup more challenging than necessary.
  • Users often face false positive alerts and desire better functionality for error monitoring and dashboard notifications.
  • Users report experiencing inefficient alerts, citing false positives and a lack of preferred error record displays.
  • Users note that the documentation needs improvement, which impacts their ability to utilize the tool effectively.

What Are Recent G2 Reviews of Rakuten SixthSense Observability?

Orca Security

The Orca Cloud Security Platform identifies, prioritizes, and remediates risks and compliance issues in workloads, configurations, and identities across your cloud estate spanning AWS, Azure, Google Cloud, Kubernetes, Alibaba Cloud, and Oracle Cloud. Orca offers the industry’s most comprehensive cloud security solution in a single platform — eliminating the need to deploy and maintain multiple point solutions. Orca is agentless-first, and connects to your environment in minutes using Orca’s patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca can integrate with third-party agents for runtime visibility and protection for critical workloads. Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation – reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes. As a Cloud Native Application Protection Platform (CNAPP), Orca consolidates many point solutions in one platform, including: CSPM, CWPP, CIEM, Vulnerability Management, Container and Kubernetes Security, DSPM, API Security, CDR, Multi-cloud Compliance, Shift Left Security, and AI-SPM.

Average Rating: 4.7/5.0

Total Reviews: 313

How Do G2 Users Rate Orca Security?

  • API Testing: 7.5/10 (Category avg: 9.1/10)
  • API Monitoring: 8.5/10 (Category avg: 8.9/10)

Who Is the Company Behind Orca Security?

  • Seller: Orca Security
  • Company Website:
  • Year Founded: 2019
  • HQ Location: Portland, Oregon
  • Twitter: @orcasec
    4,835 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    523 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer, Senior Security Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 54% Large, 36% Medium

What Do G2 Reviewers Say About Orca Security?

AI-generated summary from verified user reviews

Pros
  • Users highly value the ease of use of Orca Security, enabling quick setup and intuitive navigation.
  • Users value the great visibility provided by Orca Security, enabling effective vulnerability management and prioritization of alerts.
  • Users value the agentless feature and intuitive interface of Orca Security, enhancing their security management experience.
  • Users praise the visibility provided by Orca Security, gaining comprehensive insights into their cloud environment effortlessly.
  • Users praise Orca Security for its comprehensive security features, offering great visibility and ease of implementation.
Cons
  • Users express concerns about security vulnerabilities, especially regarding API security and detection of vulnerable packages.
  • Users experience dashboard issues like clutter, slow performance, and quirks that hinder efficient navigation and usability.
  • Users face challenges with delayed detection of vulnerabilities, impacting timely response and troubleshooting efforts in Orca Security.
  • Users report many false positives, complicating the assessment of actual vulnerabilities in Orca Security.
  • Users note that the reporting capabilities and customization options of Orca Security need significant improvement.

What Are Recent G2 Reviews of Orca Security?

What Are G2 Users Discussing About Orca Security?

Harness Platform

Simplify your developer experience with the world's first AI-augmented software delivery platform. Upgrade your software delivery with Harness' innovative CI/CD, Feature Flags, Infrastructure as Code Management, and Chaos Engineering tools. We are a software delivery platform that helps developers and infrastructure engineers build and ship code for cloud and on-premise projects. We automate the continuous integration and continuous delivery (CI/CD) process to help teams build faster, ship more frequently, and improve quality, efficiency, and governance. We help companies in four key areas: Number one, we accelerate innovation through DevOps modernization. We provide an approach for software delivery that automates processes, reduces manual interventions, consolidates tools, and accelerates time-to-market for new products, features, and fixes. Number two, we improve developer experience. We give you the ability to attract, retain, and onboard high-caliber engineering talent while fostering a culture of continuous innovation and improvement. Number three, we secure software delivery. We give you the ability to integrate security into every phase of the SDLC. And last but not least is, we optimize cloud costs. We give you the ability to eliminate waste and to ensure that appropriate cloud resources are allocated at the right place at the right time.

Average Rating: 4.6/5.0

Total Reviews: 329

How Do G2 Users Rate Harness Platform?

  • API Testing: 8.9/10 (Category avg: 9.1/10)
  • API Monitoring: 9.8/10 (Category avg: 8.9/10)

Who Is the Company Behind Harness Platform?

  • Seller: Harness
  • Company Website:
  • Year Founded: 2018
  • HQ Location: San Francisco
  • Twitter: @HarnessWealth
    1,389 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,832 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Computer Software, Financial Services
  • Company Size: 41% Large, 40% Medium

What Do G2 Reviewers Say About Harness Platform?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Harness Platform essential for streamlining their development projects effectively.
  • Users highlight the easy integration and comprehensive documentation of Harness Platform, streamlining project implementation and feature management.
  • Users value the ease of managing feature flags across environments, enhancing flexibility and control in deployment.
  • Users appreciate the easy setup of Harness Platform, allowing quick implementation of feature flags and A/B testing.
  • Users find the easy integrations in Harness Platform enhance their workflow and improve productivity significantly.
Cons
  • Users note the missing features in Harness Platform, particularly regarding multiple filters and flexibility compared to other tools.
  • Users find the activation and deactivation clarity lacking, causing confusion in managing feature flags effectively.
  • Users express frustration over limited features, including SDK options and difficulties with traffic splitting and flag management.
  • Users note a steep learning curve with Harness Platform, requiring time to master its extensive features and tools.
  • Users criticize the poor UI of Harness Platform, finding it difficult to manage feature flags effectively.

What Are Recent G2 Reviews of Harness Platform?

What Are G2 Users Discussing About Harness Platform?

Azion

Azion is the web platform that enables businesses to build, secure, and scale modern applications on a fully managed global infrastructure, with a robust suite of solutions for Application Development, cybersecurity, and AI. Azion allows developers to deploy applications closer to users, ensuring ultra-low latency and high availability. With Functions, you can run distributed serverless code, enhancing performance and reducing costs. For enhanced security, Azion’s Web Application Firewall (WAF) protects against cyber threats. Azion also provides SQL Storage, Object Storage and KV Storage, enabling fast, distributed data storage and retrieval. With Real-Time Metrics and Real-Time Events, businesses gain actionable insights into their applications and infrastructure, ensuring optimal performance and security. Global leaders like Prime Video, Neon, Global Fashion Group, and Radware trust Azion to deliver high-performance, secure digital experiences worldwide. Whether you're building AI-driven applications, securing your digital assets, or scaling globally, Azion provides the fastest path to modern applications. Discover how Azion can transform your digital experiences and empower your business to thrive in the digital age. Visit www.azion.com to learn more about our innovative solutions.

Average Rating: 4.7/5.0

Total Reviews: 34

How Do G2 Users Rate Azion?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 9.2/10 (Category avg: 8.9/10)

Who Is the Company Behind Azion?

  • Seller: Azion
  • Year Founded: 2011
  • HQ Location: Palo Alto, California, United States
  • LinkedIn® Page: www.linkedin.com
    192 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Retail, Information Technology and Services
  • Company Size: 33% Large, 33% Medium

What Do G2 Reviewers Say About Azion?

AI-generated summary from verified user reviews

Pros
  • Users highly value Azion's responsive and knowledgeable customer support, ensuring smooth and efficient business operations.
  • Users value the ease of use of Azion, praising its quick implementation and seamless integration into daily operations.
  • Users value the easy integrations with Azion, praising its simple setup and seamless functionality for daily operations.
  • Users highlight Azion's consistent reliability and performance, making it a trusted partner for critical operations.
  • Users praise Azion for its excellent performance, significantly improving latency and enhancing user experience.
Cons
  • Users are concerned about the missing features in Azion for Web3 and related service integrations.
  • Users find the complexity of the administration console challenging, requiring significant time to learn and navigate.
  • Users find the difficult learning curve in Azion's administration console frustrating and time-consuming to navigate.
  • Users find the difficult learning curve of Azion's administration console frustrating and time-consuming to navigate.
  • Users desire more flexible pricing and product offerings, as the current costs feel too high for many.

What Are Recent G2 Reviews of Azion?

Intruder

Intruder's continuous exposure management platform helps security, IT, and engineering teams stop breaches before they start. By unifying AI penetration testing, attack surface monitoring, cloud security, and vulnerability management in one intuitive platform, Intruder gives stretched teams an always-on security source of truth. Our approach focuses on continuous automated scanning using expertise and agentic solutions to ensure that the findings we deliver are accurate, prioritized by real-world risk, and ready to act on. Founded in 2015 by Chris Wallis, a former ethical hacker turned corporate blue teamer, Intruder is now protecting over 3,000 companies worldwide. Intruder has been awarded multiple accolades, was selected for GCHQ’s Cyber Accelerator, included on Deloitte’s Tech Fast 50 2023 list as the fastest-growing cybersecurity company in the UK and was named in G2’s 2026 Best Software Awards.

Average Rating: 4.8/5.0

Total Reviews: 221

How Do G2 Users Rate Intruder?

  • API Testing: 8.7/10 (Category avg: 9.1/10)
  • API Monitoring: 8.9/10 (Category avg: 8.9/10)

Who Is the Company Behind Intruder?

  • Seller: Intruder
  • Company Website:
  • Year Founded: 2015
  • HQ Location: London
  • Twitter: @intruder_io
    979 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    81 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO, Director
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 56% Small, 37% Medium

What Do G2 Reviewers Say About Intruder?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Intruder, with quick setup and intuitive system design enhancing their experience.
  • Users value the clarity and prioritization of Intruder's findings, enabling effective risk management and actionable insights.
  • Users value the quick and efficient customer support from Intruder, enhancing their overall scanning experience.
  • Users appreciate the intuitive interface of Intruder, finding it easy to set up and navigate.
  • Users value the efficient vulnerability identification from Intruder, enhancing their cybersecurity management effortlessly.
Cons
  • Users find the product expensive due to high costs for add-ons and fees per endpoint scanned.
  • Users find the slow scanning process frustrating, leading to inefficiencies and missed vulnerabilities during security assessments.
  • Users find licensing issues challenging, particularly regarding costs and constraints that affect system configurations.
  • Users experience false positives which can obscure the detection of critical vulnerabilities in security monitoring.
  • Users find the limited features of Intruder less accommodating for specific reporting and customization needs.

What Are Recent G2 Reviews of Intruder?

What Are G2 Users Discussing About Intruder?

Qodex.ai

Qodex is a continuous testing platform built for teams shipping software at AI speed. It runs real tests across APIs, browser UIs, and security workflows, and reviews pull requests with execution evidence instead of model guesses. Teams can create reusable HTTP and Playwright scenarios from plain-language briefs, OpenAPI or Swagger specifications, Postman collections, spreadsheets, and existing tests. Scenarios can run on demand, on schedules, in CI/CD, through webhooks, and on pull requests. Findings include failing requests and responses, browser screenshots, and the context needed to distinguish a product defect from a stale test or environment issue. Qodex helps engineering teams catch breaking changes earlier while keeping tests readable, editable, and owned by the team.

Average Rating: 4.9/5.0

Total Reviews: 60

How Do G2 Users Rate Qodex.ai?

  • API Testing: 10.0/10 (Category avg: 9.1/10)
  • API Monitoring: 8.3/10 (Category avg: 8.9/10)

Who Is the Company Behind Qodex.ai?

  • Seller: QodexAI
  • Year Founded: 2023
  • HQ Location: San Francisco, California
  • LinkedIn® Page: linkedin.com
    13 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 75% Small, 20% Medium

What Do G2 Reviewers Say About Qodex.ai?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use of Qodex.ai, enabling quick learning and efficient API testing for all skill levels.
  • Users appreciate the automation of testing in Qodex.ai, greatly reducing testing time and enhancing reliability.
  • Users value the easy interface for writing test cases, streamlining the testing process and enhancing efficiency.
  • Users appreciate the testing efficiency of Qodex.ai, streamlining the testing process and reducing shipment time significantly.
  • Users appreciate the effortless automation of Qodex.ai, which streamlines API testing and enhances team productivity.
Cons
  • Users note that the slow loading of the UI can hinder their experience and requires improvement.
  • Users find the poor documentation hampers their ability to fully utilize Qodex.ai's advanced features effectively.
  • Users report slow performance with Qodex.ai, noting delays in UI loading and chatbot response times.
  • Users report bug issues including repeated test cases, and suggest improvements in bug classification and accuracy.
  • Users report bugs related to test cases and suggest improvements for prioritizing and flagging issues effectively.

What Are Recent G2 Reviews of Qodex.ai?

FortiAppSec Cloud

FortiAppSec Cloud - the next evolution of FortiWeb Cloud - simplifies and strengthens web application security and delivery across your cloud environments. This SaaS platform secures network availability and accelerates application performance while delivering consistent security against web-based threats. The AI-driven engine detects zero-day exploits and unknown threats, maximizing detection accuracy while securing the user experience and minimizing false positives. FortiAppSec Cloud is unified platform that provides comprehensive web application and API protection (WAAP) with a single management interface. It includes: • GenAI-ready protection for known and zero-day threat detection • ML-driven bad bot behavioral analysis to fend off sophisticated bots • Advanced API discovery and security • Built-in DAST allows for vulnerability scanning and patching in advance • Global server load balancing and CDN provide optimized application availability and performance. • Threat analytics helps prioritize security events for operational efficiency.

Average Rating: 4.4/5.0

Total Reviews: 29

How Do G2 Users Rate FortiAppSec Cloud?

  • API Testing: 6.7/10 (Category avg: 9.1/10)
  • API Monitoring: 8.3/10 (Category avg: 8.9/10)

Who Is the Company Behind FortiAppSec Cloud?

  • Seller: Fortinet
  • Company Website:
  • Year Founded: 2000
  • HQ Location: Sunnyvale, CA
  • Twitter: @Fortinet
    151,422 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16,564 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 61% Medium, 19% Large

What Do G2 Reviewers Say About FortiAppSec Cloud?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the comprehensive security FortiAppSec Cloud provides, enhancing visibility and efficiency in threat management.
  • Users value the automatic security and centralized dashboard of FortiAppSec Cloud for enhanced protection and efficiency.
  • Users appreciate the automated AI-driven protection of FortiAppSec Cloud, enhancing web application security with minimal manual effort.
  • Users value the ease of use of FortiAppSec Cloud, finding it straightforward and highly user-friendly for implementation.
  • Users value the automatic security and centralized dashboard of FortiAppSec Cloud, enhancing visibility and response efficiency.
Cons
  • Users find the user experience challenging due to complex initial setup and a need for more intuitive design.
  • Users experience occasional slow performance with FortiAppSec Cloud, particularly under high traffic and complex rule management.
  • Users find the user interface issues in FortiAppSec Cloud hinder navigation and overall user experience, especially for beginners.
  • Users struggle with complex configuration, making initial setup challenging and impacting ease of use for newcomers.
  • Users find the complex setup process challenging, especially for first-time configurations and fine-tuning security policies.

What Are Recent G2 Reviews of FortiAppSec Cloud?

What Are G2 Users Discussing About FortiAppSec Cloud?

Tenable Nessus

Built for security practitioners, by security professionals, Nessus products by Tenable are the de-facto industry standard for vulnerability assessment. Nessus performs point-in-time assessments to help security professionals quickly and easily identify and fix vulnerabilities, including software flaws, missing patches, malware, and misconfigurations - across a variety of operating systems, devices, and applications. With features such as pre-built policies and templates, customizable reporting, group “snooze” functionality, and real-time updates, Nessus is designed to make vulnerability assessment simple, easy, and intuitive. The result: less time and effort to assess, prioritize, and remediate issues.

Average Rating: 4.5/5.0

Total Reviews: 302

Who Is the Company Behind Tenable Nessus?

  • Seller: Tenable
  • Company Website:
  • HQ Location: Columbia, MD
  • Twitter: @TenableSecurity
    87,752 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,361 employees on LinkedIn®
  • Ownership: NASDAQ: TENB

Who Uses This Product?

  • Who Uses This: Security Engineer, Network Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 41% Medium, 33% Large

What Do G2 Reviewers Say About Tenable Nessus?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the extensive vulnerability identification capabilities of Tenable Nessus, enhancing their security risk management efforts.
  • Users value the comprehensive vulnerability detection in Tenable Nessus, enhancing their ability to manage security risks effectively.
  • Users praise the automated scanning of Tenable Nessus for its thoroughness and comprehensive vulnerability reporting.
  • Users value the ease of use of Tenable Nessus, appreciating its simple setup and user-friendly interface.
  • Users value the extensive reporting and automation capabilities of Tenable Nessus for better asset scanning.
Cons
  • Users note that slow scanning can take 2-3 days and may disrupt production environments due to high resource usage.
  • Users highlight the high costs of maintaining Tenable Nessus, which can be a barrier for many organizations.
  • Users find the limited features of Tenable Nessus restrictive, especially regarding host capacity and mobile app testing.
  • Users find the complexity of licensing and features in Tenable Nessus challenging, impacting overall usability and resource management.
  • Users report that false positives from Nessus can create additional workload and complicate vulnerability management processes.

What Are Recent G2 Reviews of Tenable Nessus?

What Are G2 Users Discussing About Tenable Nessus?

Edgescan

What Is Edgescan? Edgescan is a cybersecurity company that helps organizations proactively identify, validate, and prioritize vulnerabilities across their applications, API’s and digital landscape. The company specializes in continuous vulnerability assessment, automated penetration testing, Attack Surface Management and Penetration Testing as a Service (PTaaS). Edgescan also delivers Autonomous Penetration Testing via "Edgescan Atomic". Atomic is an AI powered autonomous penetration testing capability available exclusively to Edgescan customers. Each Atomic Attack Credit provides an autonomous penetration test, allowing organizations to perform an additional autonomous penetration test when required Atomic complements PTaaS by providing another way to assess security as environments evolve. (Supercharge your security with AI) Edgescan combines advanced automation with certified security experts, including professionals holding credentials such as CREST and OSCP, to deliver highly accurate and actionable security testing. This hybrid approach allows organizations to move beyond traditional point-in-time penetration tests and operate a continuous proactive cybersecurity program. The Edgescan platform is designed primarily for web application and API security, enabling organizations to continuously assess their attack surface and identify vulnerabilities throughout the development lifecycle but also delivers “full stack” coverage to detect host layer CVE’s. With a client retention rate of over 90%, Edgescan has built long-term partnerships by delivering measurable improvements in security efficiency, risk visibility, and vulnerability management. Key Features and Capabilities of Edgescan Automated Penetration Testing Edgescan uses intelligent automation to continuously assess applications, APIs, hosts, and cloud environments for vulnerabilities. This enables frequent, scalable security testing across modern and distributed architectures. Human‑Validated Testing Findings are reviewed and manually validated by certified security experts to eliminate false positives and provide deeper insight into real‑world exploitability. Each result is accurate, contextual, and actionable. Penetration Testing as a Service (PTaaS) Edgescan’s PTaaS model extends beyond automated testing by allowing expert testers to focus on vulnerabilities that require human analysis, including: • Business logic flaws • Authentication and authorization weaknesses • Context-dependent exposures • Complex attack chains and privilege escalation paths Cyber Analytics and AI‑Assisted Validation AI-driven analysis enhances detection, verifies exploitability, and increases accuracy. This reduces noise and gives security teams a clearer picture of genuine threats. Integrated Threat Intelligence Edgescan correlates vulnerabilities with real-world threat intelligence, including known exploits and ransomware activity to help organizations prioritize the most dangerous exposures first. Risk‑Based Prioritization Findings are prioritized based on exploitability, severity, threat context, and business impact, ensuring teams focus on the issues that matter most. Primary Value: What Edgescan Solves for Clients Edgescan enables organizations to shift from reactive vulnerability management to a continuous, proactive security model. Traditional scanners and periodic penetration tests frequently produce large volumes of unvalidated findings. This creates noise and forces security teams to spend hours determining which issues are real and critical. Edgescan solves this by combining: Automation for continuous testing Human expertise for validation and complex analysis Cyber analytics and AI for accuracy and prioritization Key Benefits Significant efficiency gains: reducing thousands of hours spent on manual validation. Higher accuracy, thanks to expert‑validated findings and reduced false positives. Clear prioritization, using threat intelligence and ransomware insights to highlight the highest‑risk exposures. Continuous security improvement, enabling rapid detection, faster remediation, and scalable vulnerability management. By unifying automation, human expertise, AI, and threat intelligence, Edgescan empowers organizations to maintain a continuous cybersecurity program that strengthens overall security posture while dramatically reducing operational burden.

Average Rating: 4.6/5.0

Total Reviews: 58

How Do G2 Users Rate Edgescan?

  • API Testing: 9.0/10 (Category avg: 9.1/10)
  • API Monitoring: 8.9/10 (Category avg: 8.9/10)

Who Is the Company Behind Edgescan?

  • Seller: Edgescan
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Dublin, Dublin
  • Twitter: @edgescan
    2,256 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    88 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 38% Large, 28% Medium

What Do G2 Reviewers Say About Edgescan?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Edgescan, highlighting its intuitive interface and straightforward navigation.
  • Users value the automated vulnerability detection features of Edgescan for efficient risk assessment and remediation support.
  • Users value the excellent customer support from Edgescan, noting their responsiveness and proactivity in addressing queries.
  • Users value the detailed vulnerability identification from Edgescan, enabling effective risk management and threat mitigation strategies.
  • Users value Edgescan for its intuitive interface and comprehensive functionality that streamlines security assessments and support.
Cons
  • Users find the complex UI of Edgescan challenging, often requiring guidance to navigate key functions effectively.
  • Users find limited customization options frustrating, particularly with filtering systems and administrative functionalities.
  • Users find the poor interface design of Edgescan challenging, causing navigation and task completion difficulties.
  • Users experience slow performance with Edgescan as manual reviews lead to longer scan completion times.
  • Users find the user interface challenging and unintuitive, leading to difficulties in navigation and task completion.

What Are Recent G2 Reviews of Edgescan?

What Are G2 Users Discussing About Edgescan?

Wallarm API Security Platform

Protect any API. In any environment. Against any threats. Wallarm is the platform security teams choose to protect cloud-native APIs. The Wallarm platform gives teams the ability to detect and block API attacks. Customers choose Wallarm because it delivers a complete inventory of their APIs, AI apps, and agentic AI, along with patented AI/ML API abuse detection, real-time blocking on day zero, and an API SOC-as-a-service. Whether you protect legacy or brand new cloud-native APIs, Wallarm’s multi-cloud platform delivers the capabilities to secure your business against emerging threats. -> Robust protection for the entire API and AI portfolio Mitigate the OWASP API Top 10 threats and more; business logic abuse, bad bots, account takeover (ATO), and more. Get the robust API protection that no other tool can provide. -> Native inline blocking Wallarm is built from the ground up for inline blocking. Why deploy API security that can’t actually defend against API attacks? -> Unparalleled visibility into malicious traffic Gain full insights about attacks and attackers in the responsive Wallarm Console. Enjoy the Dashboard, search, and reporting capabilities, including visibility into API sessions. -> Complete API inventory Wallarm API Discovery provides full visibility into all your APIs, AI apps, and AI agents, including sensitive data flows, risk posture, shadow APIs and change detection. -> Understand Your Attack Surface You can’t protect what you don’t know about. Wallarm provides a comprehensive view of your API attack surface, including assessment of security controls and leaked sensitive API data. -> Quick integrations Setup cross-team collaboration with seamless integrations to your SIEM/SOAR, messaging applications, and workflow management.

Average Rating: 4.7/5.0

Total Reviews: 93

How Do G2 Users Rate Wallarm API Security Platform?

  • API Testing: 9.2/10 (Category avg: 9.1/10)
  • API Monitoring: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind Wallarm API Security Platform?

  • Seller: Wallarm
  • Company Website:
  • Year Founded: 2016
  • HQ Location: San Francisco, California
  • Twitter: @wallarm
    3,197 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    142 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, CTO
  • Top Industries: Mechanical or Industrial Engineering, Information Technology and Services
  • Company Size: 43% Medium, 42% Small

What Do G2 Reviewers Say About Wallarm API Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the accurate real-time threat detection of Wallarm API Security Platform, ensuring robust API protection.
  • Users value the accurate real-time threat detection of Wallarm API Security Platform, ensuring minimal false positives.
  • Users appreciate the simple integration and effective API threat prevention of Wallarm API Security Platform for enhanced security.
  • Users appreciate the simple cloud integration of Wallarm, enhancing API threat prevention effectively.
  • Users value the comprehensive security of Wallarm API Security Platform, ensuring robust protection and minimizing false positives.
Cons
  • Users often face API issues with unclear pricing during the trial, impacting their decision-making process.
  • Users find the configuration process complex, making it a challenge for newcomers to effectively utilize the platform.
  • Users find the configuration and tuning process complex, which can be challenging and time-consuming, especially for newcomers.
  • Users find the complex setup of Wallarm API Security Platform to be time-consuming, particularly for newcomers.
  • Users find the configuration and tuning process difficult, particularly facing challenges as new users of the platform.

What Are Recent G2 Reviews of Wallarm API Security Platform?

What Are G2 Users Discussing About Wallarm API Security Platform?

StackHawk

StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.

Average Rating: 4.6/5.0

Total Reviews: 67

How Do G2 Users Rate StackHawk?

  • API Testing: 8.9/10 (Category avg: 9.1/10)
  • API Monitoring: 9.1/10 (Category avg: 8.9/10)

Who Is the Company Behind StackHawk?

  • Seller: StackHawk
  • Year Founded: 2019
  • HQ Location: Denver, CO
  • Twitter: @StackHawk
    1,137 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 46% Small, 35% Medium

What Do G2 Reviewers Say About StackHawk?

AI-generated summary from verified user reviews

Pros
  • Users value the easy integrations of StackHawk, facilitating seamless setups with major CI tools and configurations.
  • Users praise the excellent customer support from StackHawk, highlighting their responsiveness and helpfulness in addressing queries.
  • Users value the customizability of StackHawk, appreciating its flexibility and integration options for unique workflows.
  • Users find that StackHawk greatly enhances efficiency, enabling quicker identification and resolution of security vulnerabilities.
  • Users commend StackHawk for its scanning efficiency, enabling quick identification of vulnerabilities and seamless CI/CD integration.
Cons
  • Users find the complex setup challenging, particularly with the YAML configurations and onboarding processes for applications.
  • Users find the high learning curve of StackHawk challenging due to its complex scripting and setup process.
  • Users find StackHawk lacking features, specifically in API management and vulnerability reproducibility, hindering its usability.
  • Users find the limited scope of StackHawk restricts functionality and automation in vulnerability management.
  • Users find the setup complexity of StackHawk frustrating due to YAML configuration and onboarding challenges.

What Are Recent G2 Reviews of StackHawk?

What Are G2 Users Discussing About StackHawk?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024