Top Free Runtime Application Self-Protection (RASP) Tools

How Many Runtime Application Self-Protection (RASP) Tools Products Does G2 Track?

Total Products under this Category: 32

Category Stats (Oct 2026)

  • Average Rating: 4.58/5 (↑0.01 vs Sep 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Appdome (+0.69%) - Among all products in this category, Appdome recorded the largest rating increase compared to last month

Last updated: October 07, 2026

How Does G2 Rank Runtime Application Self-Protection (RASP) Tools Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,800+ Authentic Reviews
  • 32+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Runtime Application Self-Protection (RASP) Tools

G2 Grid® for Runtime Application Self-Protection (RASP) Tools  plotting products by satisfaction and market presence

Highlighted products: Appdome, Zimperium Mobile Application Protection Suite (MAPS), Dynatrace, APP SHIELDING, Contrast Security, Jscrambler, OpenText Core Application Security, and DexGuard.

Underlying data: [Grid® JSON](https://www.g2.com/categories/runtime-application-self-protection-rasp-tools/grids.json?focus%5B%5D=appdome&focus%5B%5D=zimperium-mobile-application-protection-suite-maps&focus%5B%5D=dynatrace&focus%5B%5D=app-shielding&focus%5B%5D=contrast-security-contrast-security&focus%5B%5D=jscrambler&focus%5B%5D=opentext-core-application-security&focus%5B%5D=dexguard)

Appdome

Appdome is an agentic platform that protects mobile apps and the mobile business at scale. Trusted by enterprises worldwide, Appdome automates mobile app security, fraud prevention, bot defense, and threat detection and response across Android and iOS applications. Unlike legacy SDK-based approaches that require manual implementation and ongoing maintenance, Appdome uses AI agents to embed protections directly into mobile apps, analyze threats in real time, and continuously adapt defenses without code or complex integration. Organizations use Appdome to protect mobile apps, APIs, identities, accounts, transactions, and users from fraud, bots, malware, account takeover, deepfakes, and other cyber threats. Appdome’s agentic mobile defense platform includes: Identity and reputation protection Fraud and account takeover (ATO) prevention Bot and API defense Mobile app security (RASP and app shielding) DevSecOps and CI/CD integration Threat management and response (including ThreatScope™ Mobile XDR, ThreatEvents™, and Threat Resolution Center™)

Average Rating: 4.8/5.0

Total Reviews: 96

Who Is the Company Behind Appdome?

  • Seller: Appdome
  • Company Website:
  • Year Founded: 2012
  • HQ Location: Redwood City, California, United States
  • Twitter: @appdome
    2,107 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    184 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Banking
  • Company Size: 48% Large, 34% Medium

What Do G2 Reviewers Say About Appdome?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent customer support from Appdome, highlighting their responsiveness and helpfulness throughout the process.
  • Users value the extensive security features of Appdome, enhancing mobile app protection effectively and efficiently.
  • Users value the ease of use with Appdome, praising its intuitive GUI for securing mobile applications effortlessly.
  • Users value the runtime application protection of Appdome, appreciating its ease and comprehensive security without coding.
  • Users appreciate the ease of implementation with Appdome, enabling fast and efficient integration without coding.
Cons
  • Users note that the licensing costs can be prohibitive, making it challenging for smaller companies to afford Appdome.
  • Users find the complexity of features in Appdome overwhelming, requiring time to understand proper integration and configuration.
  • Users find the initial learning curve challenging due to the extensive features, requiring time to understand configurations.
  • Users face a challenging learning difficulty due to the complexity of configurations and initial integration guidance required.
  • Users often struggle with poor documentation, leading to confusion during integration and configuration of Appdome.

What Are Recent G2 Reviews of Appdome?

Dynatrace

Dynatrace is advancing observability for today’s digital businesses, helping to transform the complexity of modern digital ecosystems into powerful business assets. By leveraging AI-powered insights, Dynatrace enables organizations to analyze, automate, and innovate faster to drive their business forward. To learn more about how Dynatrace can help your business, visit www.dynatrace.com, visit our blog and follow us on LinkedIn and X @dynatrace.

Average Rating: 4.5/5.0

Total Reviews: 1,238

Who Is the Company Behind Dynatrace?

  • Seller: Dynatrace
  • Year Founded: 2005
  • HQ Location: Boston, MA
  • Twitter: @Dynatrace
    18,668 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,181 employees on LinkedIn®
  • Ownership: NYSE: DT

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 69% Large, 23% Medium

What Do G2 Reviewers Say About Dynatrace?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Dynatrace, enjoying seamless application instrumentation and comprehensive support.
  • Users value the insightful dashboarding of Dynatrace, enhancing executive views and simplifying monitoring processes.
  • Users value the comprehensive monitoring capabilities of Dynatrace, enhancing problem identification and prevention effectively.
  • Users value the effective debugging capabilities of Dynatrace, enhancing their ability to identify and resolve issues promptly.
  • Users value the robust analytics and integration features of Dynatrace, enhancing their monitoring and debugging capabilities.
Cons
  • Users find the steep learning curve of Dynatrace challenging, making it hard to fully utilize its features.
  • Users find that missing features in Dynatrace hinder detailed analysis and communication regarding updates and fixes.
  • Users find Dynatrace's complexity overwhelming, with a steep learning curve and costly pricing affecting usability.
  • Users find the learning difficulty challenging due to overwhelming information and inconsistencies in functionality.
  • Users find the costly nature of Dynatrace challenging, making it more suitable for large enterprises only.

What Are Recent G2 Reviews of Dynatrace?

What Are G2 Users Discussing About Dynatrace?

Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

Average Rating: 4.5/5.0

Total Reviews: 49

Who Is the Company Behind Contrast Security?

  • Seller: Contrast Security
  • Year Founded: 2014
  • HQ Location: Pleasanton, CA
  • Twitter: @contrastsec
    5,468 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Insurance, Information Technology and Services
  • Company Size: 67% Large, 20% Medium

What Do G2 Reviewers Say About Contrast Security?

AI-generated summary from verified user reviews

Pros
  • Users value the accuracy of findings from Contrast Security, ensuring greater precision in identifying vulnerabilities.
  • Users value the accuracy of results from Contrast Security, benefiting from precise vulnerability monitoring and analysis.
  • Users commend the real-time vulnerability detection of Contrast Security, appreciating its quick feedback and agile support.
Cons
  • Users experienced performance issues with Contrast Security, particularly with Java applications, but found support helpful in resolving them.

What Are Recent G2 Reviews of Contrast Security?

What Are G2 Users Discussing About Contrast Security?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Jscrambler

Jscrambler is the leader in Client-Side Security for the modern, composable web. As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces. Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled according to enterprise policy at the point of creation — before they leave the client environment. Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.

Average Rating: 4.4/5.0

Total Reviews: 31

Who Is the Company Behind Jscrambler?

  • Seller: Jscrambler
  • Company Website:
  • Year Founded: 2014
  • HQ Location: San Francisco, California
  • Twitter: @Jscrambler
    1,161 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    89 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 35% Medium, 29% Small

What Do G2 Reviewers Say About Jscrambler?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Jscrambler, highlighting its intuitive navigation and user-friendly interface.
  • Users find Jscrambler's automation capabilities beneficial for seamless integration and enhanced security within development workflows.
  • Users commend the rapid and helpful customer support of Jscrambler, enhancing their overall experience significantly.
  • Users value the robust security features of Jscrambler, effectively safeguarding their intellectual property during deployment.
  • Users value the comprehensive overview of Jscrambler, enhancing security and performance while enabling features gradually.
Cons
  • Users experience slow performance with Jscrambler, requiring tuning and noting insufficient documentation for improvement.
  • Users suggest that the dashboard can be improved to display more detailed information from each installation.
  • Users experience a difficult initiation due to a complex setup process requiring substantial understanding of application deployment.
  • Users face challenges with obfuscated pages not working and project file limits in large applications.
  • Users struggle with limited guidance and often face issues when exporting reports, hindering their experience.

What Are Recent G2 Reviews of Jscrambler?

What Are G2 Users Discussing About Jscrambler?

PreEmptive

PreEmptive secures apps against IP theft, hacking, and tampering with multi-layered protection for .NET, Android, Java, and JavaScript. PreEmptive protects mobile, web and desktop applications to deliver secure, compliant applications across platforms and devices. PreEmptive expertly balances cost, convenience, & functionality to secure your applications, making them more resistant against AI assisted attacks, data & IP theft, hacking, & tampering. Our quick-to-implement, premium solutions provide multilayered in-app protection: Dotfuscator for .NET, C# & MAUI DashO for Java, Kotlin & Android JSDefender for JavaScript Our multi-layered approach to binary code protection employs obfuscation, encryption, root detection, shielding, & tamper-proofing to defend against exploitation by both humans and machines. PreEmptive offers passive & active defense capabilities, safeguarding trade secrets & intellectual property (IP), reducing piracy & counterfeiting, & preventing tampering of code & sensitive data inspection. Easily integrating into .NET, MAUI, Java, & Android applications, PreEmptive helps you manage application risks and ensure regulatory compliance. PreEmptive protection is easy to implement and use, so your team can secure source code from the very start of development. Meet regulatory standards while protecting sensitive data across finance, healthcare, government, and other high-risk industries. Choose PreEmptive for comprehensive, intelligent app security

Average Rating: 4.6/5.0

Total Reviews: 49

Who Is the Company Behind PreEmptive?

  • Seller: Sembi
  • Company Website:
  • Year Founded: 2023
  • HQ Location: Austin, US
  • LinkedIn® Page: www.linkedin.com
    114 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 44% Small, 40% Medium

What Are Recent G2 Reviews of PreEmptive?

What Are G2 Users Discussing About PreEmptive?

OpenText Core Application Security

Fortify on Demand (FoD) is a complete Application Security as a Service solution. It offers an easy way to get started with the flexibility to scale. In addition to static and dynamic, Fortify on Demand covers in-depth mobile app security testing, open-source analysis, and vendor application security management. False positives are removed for every test and test results can be manually reviewed by application security experts.

Average Rating: 4.1/5.0

Total Reviews: 34

Who Is the Company Behind OpenText Core Application Security?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 41% Large, 32% Small

What Are Recent G2 Reviews of OpenText Core Application Security?

What Are G2 Users Discussing About OpenText Core Application Security?

DoveRunner

DoveRunner, formerly known as AppSealing, is a comprehensive mobile app and content security platform designed to help businesses protect both their mobile applications and premium video content against evolving digital threats. The platform combines advanced mobile app shielding technologies with enterprise-grade video content protection solutions, enabling organizations to secure their digital ecosystem through a unified security approach. DoveRunner offers robust Runtime Application Self-Protection (RASP) capabilities for mobile apps helping businesses safeguard their intellectual property without requiring extensive coding or complex integrations. One of the standout strengths of DoveRunner is its ability to protect applications from tampering, reverse engineering, repackaging, and unauthorized modifications while simultaneously securing premium video content from piracy and illegal distribution. Through advanced security protocols, the platform actively detects and neutralizes threats targeting mobile applications and streaming environments, ensuring the integrity of both the app experience and the content delivery pipeline. DoveRunner’s user-friendly implementation process allows businesses to integrate powerful security capabilities into their existing applications and content workflows with minimal operational complexity. Its no-code and low-code deployment capabilities enable organizations to secure mobile apps and video services quickly, without lengthy development cycles or heavy infrastructure requirements. This combination of ease of use, scalability, and enterprise-grade protection makes DoveRunner an ideal choice for businesses seeking to strengthen both their mobile app security and premium content protection strategies. In summary, DoveRunner provides a unified security platform that addresses the critical challenges faced by modern app-driven and content-centric businesses. By delivering advanced mobile app shielding alongside robust video content protection and anti-piracy solutions, DoveRunner helps organizations defend their applications, protect premium content, preserve revenue streams, and create a safer digital experience for users worldwide.

Average Rating: 4.7/5.0

Total Reviews: 48

Who Is the Company Behind DoveRunner?

  • Seller: DoveRunner
  • Company Website:
  • Year Founded: 2000
  • HQ Location: San Jose, US
  • Twitter: @doverunner_inc
    12 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    63 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 46% Small, 42% Medium

What Do G2 Reviewers Say About DoveRunner?

AI-generated summary from verified user reviews

Pros
  • Users value the intuitive interface and real-time performance tracking of DoveRunner for efficient data management.
  • Users appreciate the intuitive interface of DoveRunner, finding it efficient for analyzing and managing data seamlessly.
  • Users love the clean, intuitive interface of DoveRunner, enhancing their efficiency in data management and analysis.
Cons
  • Users find that some advanced features have a steep learning curve and lack clear in-app guidance for newbies.

What Are Recent G2 Reviews of DoveRunner?

What Are G2 Users Discussing About DoveRunner?

Waratek

Waratek is the only Security-as-Code automation platform, enabling control through policy to scale security with modern development. The world’s largest companies trust Waratek products to deliver application security at scale. Work with us to accelerate your transition from manual processes to self-service automation and DevSecOps excellence.

Average Rating: 4.7/5.0

Total Reviews: 11

Who Is the Company Behind Waratek?

  • Seller: Waratek
  • Year Founded: 2009
  • HQ Location: Dublin, County Dublin
  • Twitter: @waratek
    749 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    18 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 64% Large, 27% Medium

What Do G2 Reviewers Say About Waratek?

AI-generated summary from verified user reviews

Pros
  • Users find the configuration ease of Waratek ideal for quickly securing applications without disruptive changes.
  • Users appreciate the effective application security of Waratek, which seamlessly protects unsecure programs and supports compliance.
  • Users find Waratek exceptionally easy to use, appreciating its user-friendly design and efficient configuration options.
  • Users appreciate Waratek for its user-friendly application security, effectively protecting unsecure programs without extensive changes.
  • Users value the application security provided by Waratek, finding it user-friendly and effective for their needs.

What Are Recent G2 Reviews of Waratek?

LIAPP

LIAPP is a specialized mobile application shielding and runtime application self-protection (RASP) solution designed to secure Android and iOS environments from unauthorized access and cyber threats. This security tool allows developers and enterprises to protect their mobile applications by applying robust security layers to the final application binary, ensuring protection against tampering and reverse engineering without requiring changes to the existing source code. The primary function of LIAPP is to maintain the integrity of mobile applications in high-stakes industries, including mobile banking, fintech, and global gaming. By implementing LIAPP, organizations can defend against various attack vectors such as rooting, jailbreaking, debugging, and memory manipulation. This solution is particularly effective for businesses that need to align their mobile services with international security standards and regional financial regulations. In addition to its core shielding capabilities, LOCKIN Company offers supplementary security modules that can be implemented alongside or independently of LIAPP to address specific vulnerabilities: LISS (Screen Protection): A dedicated solution designed to block unauthorized screen captures, screen recording, and remote access attempts to protect visual data integrity. LIKEY (Security Keypad): A specialized virtual keypad that encrypts and secures sensitive user input to prevent data interception from keyloggers and other malicious methods. LIAPP’s deployment model is optimized for rapid integration into the development lifecycle, minimizing the technical burden on engineering teams. This allows organizations to maintain their scheduled release cycles while providing a secure environment for their end-users. The solution provides several key technical advantages: Comprehensive App Shielding: Prevents unauthorized modification and repackaging of the application to ensure the software functions as originally intended. Dynamic Runtime Protection: Actively detects and blocks security threats during the application's execution to prevent data breaches in real-time. Modular Security Expansion: Enables users to enhance their security posture by adding LISS for screen protection or LIKEY for secure data entry based on specific operational needs. Regulatory Compliance Support: Provides the necessary technical infrastructure to assist financial institutions in meeting stringent mobile transaction security and fraud prevention requirements. Through its specialized focus on application integrity, LIAPP assists users in managing the security lifecycle of their mobile products. It offers monitoring capabilities and threat intelligence, allowing stakeholders to identify emerging risks and maintain a resilient mobile presence.

Average Rating: 4.8/5.0

Total Reviews: 20

Who Is the Company Behind LIAPP?

Who Uses This Product?

  • Top Industries: Computer Games
  • Company Size: 60% Medium, 35% Small

What Are Recent G2 Reviews of LIAPP?

What Are G2 Users Discussing About LIAPP?

Approov

Approov provides a robust mobile app and API security solution designed to prevent unauthorized access, fraud, and API abuse. By ensuring that only genuine, untampered mobile applications can communicate with backend services, Approov protects businesses across industries such as finance, healthcare, eCommerce, and connected vehicles. The solution combines app attestation and runtime application self-protection (RASP) to detect and block threats from scripts, bots, and modified apps in real time. Approov also secures API keys, secrets, and certificates at runtime, preventing leakage and unauthorized use. Unlike traditional security measures that rely on static defenses, Approov dynamically adapts to evolving threats, providing scalable, developer-friendly protection without generating false positives.

Average Rating: 4.8/5.0

Total Reviews: 5

Who Is the Company Behind Approov?

  • Seller: Approov Limited
  • Year Founded: 2001
  • HQ Location: Edinburgh, GB
  • Twitter: @approov_io
    1,200 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    30 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Approov?

Imperva Runtime Application Self-Protection (RASP)

As cyber threats evolve, organizations need more than just perimeter defenses to protect their applications. Imperva Runtime Application Self-Protection (RASP) takes application security to the next level by embedding protection directly into the application itself. Unlike traditional security solutions, RASP continuously monitors and protects applications from within, identifying and blocking attacks in real time without affecting performance or requiring changes to application code. Imperva RASP provides comprehensive protection against a wide range of threats, including SQL injections, cross-site scripting, and other OWASP Top 10 vulnerabilities. By analyzing application behavior and understanding the context of each request, RASP can accurately differentiate between legitimate activity and attacks, reducing false positives and allowing legitimate traffic to flow uninterrupted. This capability ensures that applications remain secure without slowing down operations or impacting user experience. One of RASP's key benefits is its ability to protect new and legacy applications, as well as third-party components, without the need for expensive and time-consuming code modifications. This makes it an ideal solution for organizations looking to enhance their security posture without disrupting their development pipeline. Additionally, RASP seamlessly integrates into DevOps workflows, ensuring continuous protection even in fast-paced development environments. Imperva RASP is backed by continuously updated threat intelligence, allowing it to defend against zero-day attacks and emerging threats as they surface. With RASP, organizations can reduce their reliance on perimeter defenses, which may not be enough to protect against sophisticated, targeted attacks. Instead, RASP provides real-time, in-application security that stops attacks at the source, ensuring your applications remain safe and your business can continue to operate without disruption. By providing proactive, real-time defense with minimal operational impact, Imperva RASP offers a powerful solution to protect critical applications in today’s dynamic threat landscape.

Average Rating: 5.0/5.0

Total Reviews: 2

Who Is the Company Behind Imperva Runtime Application Self-Protection (RASP)?

  • Seller: Thales Group
  • HQ Location: Austin, Texas
  • Twitter: @ThalesCloudSec
    6,935 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    46 employees on LinkedIn®
  • Ownership: EPA:HO
  • Total Revenue (USD mm): $15,854

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Imperva Runtime Application Self-Protection (RASP)?

Bugsmirror MASST (Mobile Application Security Suite & Tools)

Bugsmirror Mobile Application Security Suite & Tools (MASST) is designed specifically for your business, providing scalable, end-to-end security for your mobile app. From detection to protection, MASST ensures your app is safeguarded against evolving security threats. With MASST, you can focus on growing your business, knowing your app is fully protected at every stage.

Who Is the Company Behind Bugsmirror MASST (Mobile Application Security Suite & Tools)?

Verimatrix XTD

Verimatrix XTD stands at the forefront of application security, offering unmatched protection for mobile, web desktop and embedded applications in critical industries while streamlining implementation to empower innovation. Verimatrix delivers an amazing cybersecurity experience with XTD; allowing customers to prevent, detect, respond and predict threats to their mobile applications and the devices that connect to their critical infrastructure. We have expanded our detection capabilities to the network, beyond application and device level detections. We can access risk per application to protect the connection to the company critical infra. Verimatrix XTD’s Application Protection Suite includes: - XTD Enterprise Suite - XTD Protect for Mobile (iOS and Android) - XTD Protect for Desktop and Embedded Applications (Windows, MacOS and Linux) - XTD Protect for Native Applications (C/C++) - XTD Key Shield (whitebox cryptography) - XTD Protect for Web Applications - XTD Managed Services

Who Is the Company Behind Verimatrix XTD?

  • Seller: Verimatrix
  • Year Founded: 1995
  • HQ Location: Meyreuil, FR
  • Twitter: @VerimatrixInc
    4,743 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    205 employees on LinkedIn®
Lauren Worth
LW
Researched and written by Lauren Worth
Updated January 8, 2025