Alternatives to SecurityPal

Compare SecurityPal alternatives for your business or organization using the curated list below. SourceForge ranks the best alternatives to SecurityPal in 2026. Compare features, ratings, user reviews, pricing, and more from SecurityPal competitors and alternatives in order to make an informed decision for your business.

  • 1
    Wing Security

    Wing Security

    Wing Security

    Wing empowers organizations to harness the full potential of SaaS while ensuring a robust security posture. In addition to a free version that provides a list of an organization's SaaS inventory, with insightful details regarding application usage and user information, Wing’s complete SSPM solution offers unparalleled visibility, control, and compliance capabilities, strengthening any organization's defense against modern SaaS-related threats. With Wing’s automated security capabilities, CISOs, security teams, and IT professionals save weeks of work previously spent on manual and error-prone processes. Trusted by hundreds of global companies, Wing provides actionable security insights derived from our industry-leading SaaS application database, covering over 280,000 SaaS vendors. This results in the safest and most efficient way to leverage SaaS.
  • 2
    Accountable

    Accountable

    Accountable HQ

    Accountable can supercharge your risk management and empower your team by simplifying the process of managing risk across all levels of your organization, become compliant with HIPAA, GDPR, CCPA and more privacy laws, and build trust with your customers and partners. Easily comply with global privacy laws such as HIPAA, GDPR, CPRA and more using Accountable's easy-to-use solution for privacy compliance. Manage risk by identifying and mitigating vulnerabilities by using Accountable's security risk and data protection impact assessments, giving you confidence in risk management. Monitor 3rd and 4th party vendor risk with ease with built in questionnaires and business agreement templates. The employee portal gives your team a way to stay up to date on security awareness and HIPAA training as well as the ability to review policies or report potential security issues. Share compliance, security, and privacy reports with those inside and outside your organization.
    Starting Price: $399.00/month
  • 3
    Cynomi

    Cynomi

    Cynomi

    MSSPs, MSPs, and consulting firms leverage Cynomi's AI-powered, automated vCISO platform to continuously assess client cybersecurity posture, build strategic remediation plans, and execute them to reduce risk. SMBs and mid-market companies increasingly need proactive cyber resilience, and ongoing vCISO services to assess their security posture, enhance compliance readiness, and reduce cyber risk. Yet managed service providers and consulting firms have limited resources and expertise to handle the work involved in providing virtual CISO services. Cynomi enables its partners to offer ongoing vCISO services at scale, without scaling their existing resources. With Cynomi’s AI-driven platform, modeled after the expertise of the world’s best CISOs, you get automated risk and compliance assessments, auto-generated tailored policies, and actionable remediation plans with prioritized detailed tasks, task management tools, progress tracking, and customer-facing reports.
  • 4
    ThreatAdvice Breach Prevention Platform
    Data security is your business’ biggest threat & the one that is the hardest to manage... Reduce your security burden with ThreatAdvice vCISO, our flagship comprehensive cybersecurity solution. The vCISO solution provides oversight into all of your cybersecurity needs, and ensures that the proper protocols are in place so that the likelihood of a cybersecurity event is significantly reduced. ThreatAdvice vCISO provides employee cybersecurity training and education, intelligence on potential cyber threats & a comprehensive cybersecurity monitoring solution delivered through our proprietary dashboard. Sound interesting? Sign up for a no-pressure demo today!
  • 5
    GetCybr

    GetCybr

    GetCybr

    GetCybr is an AI-powered vCISO and GRC platform built for MSPs and security consultancies delivering cybersecurity services at scale. It gives service providers the infrastructure to run a scalable, repeatable, and high-quality vCISO practice without relying on spreadsheets, point tools, compliance checklists, and manually assembled board reports. It supports the full service delivery lifecycle, from initial client assessment through ongoing compliance, remediation, reporting, and executive communication. Its AI engine maps each client’s risks, compliance gaps, and security maturity, then generates a prioritized roadmap that can be presented from day one. GetCybr replaces weeks of manual assessment work with AI-powered gap analysis, control mapping, compliance scoring, and remediation planning across frameworks such as SOC 2, ISO 27001, NIST CSF, HIPAA, CMMC, NIS2, and DORA.
  • 6
    HyperComply

    HyperComply

    HyperComply

    HyperComply is an AI-powered platform designed to streamline security questionnaires and evidence-sharing processes. It automates the completion of security questionnaires, enabling responses up to 18 times faster by utilizing advanced AI alongside a team of certified experts. The platform offers a secure trust page for proactive sharing of security information, allowing organizations to control document access and reduce the need for repetitive questionnaires. Additionally, HyperComply provides data rooms for the secure sharing of sensitive documents like SOC 2 reports and contracts, complete with access controls, auto-expiry dates, and audit trails. By consolidating security and compliance information into a centralized repository, HyperComply enhances efficiency and accelerates sales cycles. The platform integrates with various tools to support seamless workflows and is trusted by leading teams to improve turnaround times and accuracy in security reviews.
  • 7
    VeriRFP

    VeriRFP

    VeriRFP

    VeriRFP is a full-lifecycle platform for RFPs, security questionnaires, DDQs, and vendor risk assessments — built for B2B revenue and security teams. Evidence-backed AI drafting cites specific passages from your approved evidence library (SOC 2 reports, policies, pen tests) and flags for human review when evidence is insufficient. A full buyer-delivery surface includes trust centers, procurement portals, deal rooms, and compliance-pack exports. CSA Agentic Trust Framework-aligned AI agent governance with signed audit records and anomaly monitoring. Native integrations with Salesforce, HubSpot, and Jira. Three deployment paths: cloud SaaS, Bring-Your-Own-Key (BYOK), and on-device Private Edition for Mac. Headquartered in Columbus, Ohio.
  • 8
    Cybriant

    Cybriant

    Cybriant

    Cybriant assists companies in making informed business decisions and sustaining effectiveness in the design, implementation, and operation of their cyber risk management programs. We deliver a comprehensive and customizable set of strategic and managed cybersecurity services. These services include; Risk Assessments and vCISO Counseling, 24/7 Managed SIEM with LIVE Monitoring, Analysis, and Response, 24/7 Managed EDR, Real-Time Vulnerability Scanning, and Patch Management. We make enterprise grade cyber security strategy and tactics accessible to the Mid-Market and beyond. Cybriant /sī-brint/: The state of being cyber resilient We deliver enterprise-grade cybersecurity services that are comprehensive, customizable, and address the entire security landscape. Protect Your Clients with Cybriant’s 24/7 Security Monitoring Services. Join our Strategic Alliance Partner Program today. Expand your reputation by delivering these services to your customers under your own brand.
  • 9
    AuditCue

    AuditCue

    AuditCue

    Built for companies moving out of generic compliance automation software and auditors tired of pay-per-audit apps. We take security, compliance, and risk seriously, and are proud to partner with like-minded customers, auditors & vCISOs. Not to mention a phenomenal set of advisors who've helped us built a better product. Complex GRC requirements, cross-border data privacy regulations and transforming email+shared drive based Internal Audit & Risk processes, are some areas in which customers have leveraged AuditCue and seen value first-hand.
  • 10
    Whistic

    Whistic

    Whistic

    The best way to assess, publish, and share vendor security information. Automate vendor assessments, share security documentation, and create trusted connections—all from the Whistic Vendor Security Network. Once companies start using Whistic, they can’t imagine how they managed vendor security assessments or responded to questionnaire requests before. Avoid the black box security reviews of the past by openly sharing vendor security requirements and publishing profiles. Focus on establishing trust rather than chasing down spreadsheets. Initiate assessments, assign inherent risk, engage vendors, calculate risk scores and trigger reassessments—automatically. In the fast-paced business environment we’re living in, no one has time for the slow, outdated security review processes of the past. Access the security posture of thousands of businesses immediately with Whistic.
  • 11
    Trustpage

    Trustpage

    Trustpage

    Hundreds of teams use Trustpage to automate questionnaires, share documents, manage security reviews, and more. Determine if vendors meet your security requirements and compare solutions to determine which tools you can trust with your data. No need for contractors to answer security questionnaires, leverage Trustpage's question-answering extension to complete entire questionnaires in minutes. Empower everyone on your team to accurately answer security questions when they source approved answers using the Trustpage browser extension. Beat out the competition when you streamline the review process and provide a seamless InfoSec experience from start to finish. Automate NDAs, gain visibility into the security process, and reduce back-and-forth between teams so deals move more quickly. Connect your Trust Center with Slack, Salesforce, and Hubspot to incorporate security processes into the tools your team is already using.
    Starting Price: $50 per month
  • 12
    ActZero

    ActZero

    ActZero

    ActZero's adaptive, intelligent MDR service empowers you to harden your security, scale and optimize your defense capabilities, measurably reducing risk over time. Through Artificial Intelligence (AI) and Machine Learning (ML), we increase the likelihood of identifying and preventing attacks while reducing the duration and impact of security incidents should they occur. We help you remediate vulnerabilities and mitigate risks so your team can focus on its core competencies and on driving business growth. For businesses with advanced compliance requirements, our virtual Chief Information Security Officers (vCISO) can advise you on how to build the policies, frameworks, and KPIs you need to reduce risk. With real-time monitoring, multiple sensors, a proprietary platform, and a well-honed threat detection and response strategy, we partner with you to see and stop threats before they put your operations, data, people, or brand at risk.
  • 13
    Rivial Data Security

    Rivial Data Security

    Rivial Data Security

    The Rivial platform is an all‑in‑one, end‑to‑end cybersecurity management solution designed for busy security leaders and vCISOs, delivering continuous real‑time monitoring, quantifiable risk, and seamless compliance across your entire program. Assess, roadmap, monitor, manage, and report, all from one intuitive, customizable single pane of glass with easy‑to‑use tools, templates, automations, and thoughtful integrations. Upload evidence or vulnerability scan data in one place to auto‑populate multiple frameworks and update posture in real time. Its algorithms use Monte Carlo analysis, Cyber Risk Quantification, and real‑world breach data to assign accurate dollar values to risk exposures and predict financial losses, so you can speak to the board in hard numbers, not vague “high/medium/low” ratings. Rivial’s governance module includes standardized workflows, alerts, reminders, policy management, calendar functions, and one‑click reporting loved by boards and auditors.
  • 14
    Scytale

    Scytale

    Scytale

    Scytale is an AI GRC platform supported by a team of dedicated GRC experts, designed to help organizations achieve and maintain compliance across more than 80 security and privacy frameworks, including SOC 2, ISO 27001, ISO 42001, PCI DSS, GDPR, HIPAA, and SOX ITGC. The platform and its multi-agent suite centralize GRC workflows by automating evidence collection, continuous control monitoring, user access reviews, vendor risk management, policy management, and audit preparation within a unified platform. Scytale also provides penetration testing, AI security questionnaires, and customizable Trust Center solutions to help organizations strengthen security transparency and maintain continuous compliance. Built for organizations at every stage, from fast-growing startups to established enterprises managing complex GRC programs, Scytale combines AI-powered automation with dedicated GRC expertise to help organizations reduce manual effort, streamline operations, and scale
  • 15
    CyberArrow

    CyberArrow

    CyberArrow

    Automate the implementation & certification of 50+ cybersecurity standards without having to attend audits. Improve and prove your security posture in real-time. CyberArrow simplifies the implementation of cyber security standards by automating as much as 90% of the work involved. Obtain cybersecurity compliance and certifications quickly with automation. Put cybersecurity on autopilot with CyberArrow’s continuous monitoring and automated security assessments. Get certified against leading standards via a zero-touch approach. The audit is carried out by auditors using the CyberArrow platform. Get expert cyber security advice from a dedicated virtual CISO through the chat function. Get certified against leading standards in weeks, not months. Safeguard personal data, comply with privacy laws, and earn the trust of your users. Secure cardholder information and instill confidence in your payment processing systems.
  • 16
    DocFlow

    DocFlow

    Obiyen

    DocFlow is a secure document workflow and management solution that streamlines the entire document lifecycle—from creation and review to approval, distribution, and archiving. It automates repetitive tasks using configurable workflows and standardized templates, reducing manual effort and minimizing errors. With role-based access, audit trails, and seamless integration with enterprise systems, DocFlow enhances collaboration, improves transparency, and ensures compliance with organizational and regulatory requirements. Designed for government agencies and businesses alike, it helps organizations digitize document-intensive processes, accelerate approvals, and maintain secure, centralized records for greater operational efficiency.
  • 17
    SafeBase

    SafeBase

    SafeBase

    Share your security program the easy way. Smart trust center that simplifies security and compliance reviews. Slash time spent on questionnaires and NDAs by 90%. Showcase completed questionnaires that satisfy most needs. Be quicker to fill out any custom questionnaires. Automate NDA signing and streamline approvals. Scale your security knowledge and answer fewer repetitive Qs. Offer instant access to the security information for sales and CS. Maintain a searchable database with click-to-copy responses. Update your public trust center with ease. Speed up the sales cycle by 7 days. Impress potential customers from the jump. Make procurement easy for accounts. Get new leads from your security page. Save time for buyers, security, and sales. Self-serve access for customers. Fewer tasks for you. Reports, requests, and a lot less manual work. Achieve time savings and better customer relationships.
    Starting Price: $100 per month
  • 18
    Mexty

    Mexty

    Mexty

    Mexty is an AI-native platform for creating, delivering, assessing, and tracking interactive learning experiences. It combines AI-native authoring, interactive learning design, LMS capabilities, assessments, learner analytics, AI Agents, and trusted knowledge bases (Source of Truth) into one secure platform. Organizations can create simulations, branching scenarios, quizzes, adaptive learning paths, and conversational learning experiences while maintaining full instructional control. Mexty supports SCORM compatibility, GDPR-aligned practices, AI governance, and enterprise security. Built for education, corporate training, and workforce development, Mexty simplifies the entire learning lifecycle—from content creation and delivery to assessment, learner tracking, analytics, and continuous improvement—helping organizations build engaging, reliable, and AI-native learning systems.
  • 19
    Validfor

    Validfor

    Validfor

    Validfor is a secure, modular digital validation platform that centralizes the entire validation lifecycle on a single, paperless system. Designed specifically for regulated industries, Validfor enables efficient validation while ensuring full compliance with GAMP 5, 21 CFR Part 11, and EU Annex 11. The platform supports electronic records and advanced electronic signatures with full audit trails, role-based workflows (Author, Reviewer, Approver), and complete CSV compliance. All documents and records are securely managed in a centralized repository, capturing every change with full traceability to protect data integrity and Quality Assurance. Validfor offers integrated modules for Change Management, Deviations, Testing, and Periodic Reviews, enabling seamless impact assessments, CAPA tracking, Computer Software Assurance (CSA), and audit-ready lifecycle management.
  • 20
    teamthink

    teamthink

    Athenium Analytics

    Optimize your claims and underwriting QA review processes. Quality assurance drives quality results. teamthink® is a powerful SaaS insurance audit suite for claims and underwriting reviews. It replaces spreadsheets, databases and legacy audit systems forever. The teamthink QA software helps quality assurance teams manage audit reviews with greater speed, volume and accuracy. Its comprehensive measurement, analysis and reporting tools deliver actionable information that benefits QA, business managers and company-wide performance. Measure performance and analyze results against your best practices, KPIs and compliance requirements. Develop reviewer questionnaires and audit forms that fully support your specific quality assurance goals. Visualize results using standard reports and dashboards to quickly understand key metrics. Increase productivity with questionnaires that display only pertinent information based on the facts of the file.
  • 21
    Truepic

    Truepic

    Truepic

    Truepic Vision is a virtual inspection solution that simplifies the way businesses manage inspections, surveys, and audits through the use of verified digital media. By leveraging trusted photos and videos, Truepic allows you to request, capture, and review authentic photos and videos remotely, bypassing the need for costly and time-intensive onsite visits. Patented security features assure authenticity, making Truepic Vision a trusted choice for scenarios requiring precise visual documentation, such as in insurance, lending, and warranty workflows. Through its intuitive interface, Truepic Vision lets you request, capture, and review secure digital media from any location, at any time. This streamlines claims processing, accelerates audits, and simplifies collaboration across all stakeholders. By collecting both end-user responses and tamper-proof visual evidence in one place, Truepic Vision delivers confidence, efficiency, and trust throughout every inspection process.
    Starting Price: $50/inspection
  • 22
    Zania

    Zania

    Zania

    Zania is an agentic AI platform for enterprise GRC. It helps security, risk, and compliance teams execute critical work with greater speed, consistency, and accuracy. Zania's AI agents autonomously run complex workflows across third-party risk, internal risk, and compliance, with full explainability. The platform supports risk assessments, controls testing, evidence collection, security questionnaires, and gap analyses across frameworks like SOC 2, ISO 27001, HIPAA, ISO 42001, PCI DSS, GDPR, and more. Trusted by Fortune 500 companies and leading audit and advisory firms, Zania is backed by $18M in Series A funding led by NEA, with participation from Anthropic and Menlo Ventures. The platform is built to help organizations scale rigor across their GRC programs without scaling manual overhead.
    Starting Price: Contact Zania for pricing
  • 23
    ByteChek

    ByteChek

    ByteChek

    Simplify compliance with ByteChek’s advanced and easy-to-use compliance platform. Build your cybersecurity program, automate evidence collection, and earn your SOC 2 report so you can build trust faster, all from a single platform. Self-service readiness assessment and reporting without auditors. The only compliance software that includes the report. Complete risk assessments, vendor reviews, access reviews, and much more. Build, manage, and assess your cybersecurity program to build trust with your customers and unlock sales. Establish your security program, automate your readiness assessment, and complete your SOC 2 audit faster, all from a single platform. HIPAA compliance software to help you prove your company is securing protected health information (PHI) and building trust with healthcare companies. Information security management system (ISMS) software to help you build your ISO-compliant cybersecurity program and earn your ISO 27001 certification.
    Starting Price: $9,000 per year
  • 24
    Secure.com

    Secure.com

    Secure.com

    Secure.com is a cybersecurity platform that helps organizations operationalize security through governed workflows—covering SOC operations and incident response, exposure remediation (vulnerability/patch + cloud/config), and continuous compliance evidence. It’s built for CISOs and SOC/SecOps leaders who need consistent execution and accountability, CTOs/engineering leaders who want security embedded into operational workflows, GRC/compliance teams who need audit-ready evidence without scrambles, and fractional CISOs/consultants standardizing security programs.
  • 25
    Eyako

    Eyako

    Eyako

    Eyako is a cybersecurity management platform designed to help CISOs and security leaders centralize cyber operations, risks, compliance, vulnerabilities, incidents, and governance into one unified control center. The platform acts as a “CISO Command Platform” that consolidates cybersecurity signals from multiple tools and systems into a single operational dashboard. Eyako helps organizations prioritize remediation actions based on risk impact, enabling security teams to focus on the most critical threats and compliance tasks first. The platform covers key cybersecurity domains including governance, risk management, compliance tracking, vulnerability management, supplier security, incidents, projects, and data protection. Security leaders can generate executive-ready board reports automatically, reducing the time spent manually preparing presentations and status summaries.
  • 26
    Entrust IoT Agent
    Ensure a trusted Internet of Things by establishing a secure, connected ecosystem – from device manufacturing through the entire IoT lifecycle – with our IoT Security Solutions. The Internet of Things has the ability to transform business and create value, but only if the IoT ecosystem is secure. With IoT Agent from Entrust, you can leverage high-assurance IoT security to drive innovation. Our IoT Security Solutions software platform assigns unique digital identities to connected “things” using enterprise-grade cryptography to build an end-to-end chain of trust in IoT environments across industries. We offer secure, remote, on-demand upgrades and updates that enable you to take advantage of new capabilities, comply with changing security requirements, and maximize your IoT investments. Leverage the provisioning of identities to facilitate fast enrollment of devices in the supply chain ecosystem.
  • 27
    Vendict

    Vendict

    Vendict

    Vendict empowers the privacy and compliance industry, helping security experts become enablers within their company by providing them with cutting-edge, AI-led technology, designed to solve the most complicated of compliance issues, at scale. Leveraging Vendict's cutting-edge technology, CISOs, tech executives, security teams, and risk management professionals use Vendict to address their compliance questionnaires and security assessment challenges.
    Starting Price: $90 per month
  • 28
    Sekorti

    Sekorti

    Sekorti

    Sekorti--> Enterprise Trust, Built in Minutes. Scan your domain and get a live security report with attack paths. Build a free Trust Center. Answer security questionnaires, RFPs, DDQs, and SIG, CAIQ, and VSAQ frameworks in seconds with AI. Prove SOC 2, ISO 27001, GDPR, ISO 42001, and EU AI Act readiness, without spreadsheets, without delays, without losing deals. Sekorti is the security trust platform for B2B SaaS teams who are tired of losing enterprise deals to compliance friction. 📍 Copenhagen, Denmark
    Starting Price: $25/month
  • 29
    BlocTrust

    BlocTrust

    BlocWatch

    BlocTrust provides independent, third-party verification, and assurance along with continuous awareness of the health of your blockchain for private blockchains and DLTs. BlocTrust runs as an endorsement node within a private blockchain network: verifying and endorsing blockchain transactions, providing assurance to all blockchain participants, and demonstrating the accuracy and legitimacy of endorsed transactions. BlocTrust maintains an independent, validated ledger of blockchain transactions. This authoritative record proves vital for following compliance mandates and meeting audit requirements. Designed to be both comprehensive and impartial, you can turn to BlocTrust for addressing disputes among Blockchain participants. BlocTrust generates monthly attestations that summarize the health and activity of the blockchain and display the blockchain operation metrics.
    Starting Price: $2,500 per month
  • 30
    Mobb

    Mobb

    Mobb

    Mobb automates vulnerability remediations to significantly reduce security backlogs and free developers to focus on innovation. Mobb lets organizations take control of securing applications with trusted, automated fixes that are informed and verified by the developers who own the source code. Organizations are able to act fast to significantly reduce the chances of being impacted by a security vulnerability exploit. CISOs can finally start reporting reductions in vulnerability backlogs, security teams can streamline processes and policies, and developers can quickly execute fixes with more trust and less friction.
  • 31
    Scribe Security Trust Hub
    Scribe is a SaaS solution that provides continuous assurance for the security and trustworthiness of software artifacts, acting as a trust hub between software producers and consumers. Scribe centralized SBOM management system allows to effortlessly manage and share products SBOMs along with all their associated security aspects in a controlled and automated manner. SCRIBE KEY FEATURES: *Gain visibility and control the risk of all your products’ security aspects. *Trust but verify: streamline security guardrails to verify secure SDLC policy, based on trusted evidence. *Simplify secure SDLC processes, balancing responsibilities between dev and security teams. *Detect code tampering and software factory exploitations. *Enforce and demonstrate compliance with regulations and best practices. *Share SBOMs and security insights in a controlled manner with stakeholders.
  • 32
    Osto

    Osto

    Osto

    Osto is the complete cybersecurity platform for startups. Most companies in this category solve half the problem. Compliance platforms automate the paperwork. Security vendors run the protection. Founders end up buying both, then a third vendor for VAPT, then struggle with security questionnaires. Osto gives all of it on one platform. Osto runs your entire security stack: WAF and API protection, CSPM across AWS, Azure, and GCP, ZTNA for network access, endpoint protection across your team's devices, and code security across your repos. 20modules, all built in house. Compliance automation runs as a byproduct. Controls are continuously mapped and evidence flows from the security modules into your audit trail, so SOC 2 Type II, ISO 27001, HIPAA, and PCI-DSS readiness becomes live data, not screenshots from last quarter. VAPT delivered by OSCP-certified engineers in 2 weeks. AI Security Q&A pre-fills enterprise questionnaires from live platform data.
    Starting Price: $999/month
  • 33
    TrustMAPP

    TrustMAPP

    TrustMAPP

    TrustMAPP provides customers with a continuous process of measuring, reporting, planning and cintinuous improvement. Provides information security leaders with a real-time view of the effectiveness of their cybersecurity program while aligning to business objectives and risk. TrustMAPP provides the story of where you are, where you’re going, and what it will take to get there. From a single source of data, or from multiple integrations, an organization’s security posture is visible based on stakeholder perspectives: CISO, C-Suite, and Board. TrustMAPP gives organizations the ability to manage security as a business, quantifying and prioritizing remediation actions and costs.
  • 34
    Alinity

    Alinity

    Softworks Group

    Alinity is advanced, cloud-based regulatory management software purpose-built for professional regulators. It centralizes all core functions—registration and renewal, complaint and discipline, continuing competence, quality assurance, and more—into one secure, configurable platform. Key features include customizable workflows, online applications, and automated renewals with real-time validation. The complaints module tracks every step from intake to resolution, while continuing competence tools manage self-assessments, learning plans, audits, and peer reviews. Alinity also offers role-specific portals for registrants, staff, committee members, and the public. Robust reporting and analytics, integrated payment processing, and secure document storage ensure your organization remains efficient and audit-ready. With continuous updates and over 60 Canadian regulators onboard, Alinity is the trusted solution for secure, modern, and responsive regulation.
  • 35
    ReversingLabs

    ReversingLabs

    ReversingLabs

    ReversingLabs is a software supply chain security platform that helps organizations identify hidden threats within software components. It uses AI-driven binary analysis to detect malware, tampering, secrets, and other active threats that traditional tools often miss. ReversingLabs analyzes first-party, open-source, and third-party software to provide complete visibility into software risk. Its flagship solution, Spectra Assure®, identifies security issues in final builds before release. The platform leverages one of the world’s largest threat intelligence repositories to improve accuracy and reduce false positives. ReversingLabs helps organizations move from reactive threat detection to proactive risk management. It delivers trusted insights that strengthen software trust and security operations.
  • 36
    Medcurity

    Medcurity

    Medcurity

    Medcurity is a HIPAA compliance platform built for healthcare. From solo practices to large health systems, Medcurity guides organizations through their Security Risk Analysis and keeps them audit-ready year-round. Trusted by 1,000+ healthcare organizations since 2018. What Medcurity offers: - Security Risk Analysis (SRA) aligned with current OCR standards, with guided walkthroughs and audit-ready reporting - Small Practice SRA for practices with 1 to 20 employees, starting at $499/year - PolicyScan to scan your existing policies and auto-fill SRA questions - Medcurity Academy HIPAA training for employees and compliance officers - Network Vulnerability Assessments with a live dashboard and Attack Path Visualization - BAA management with centralized tracking and e-signature - Vendor risk management - Customizable policies and procedures with review reminders A dedicated support team works alongside your organization throughout the year, not just at assessment time.
    Starting Price: $499/year
  • 37
    Peer Mountain

    Peer Mountain

    Peer Mountain

    Peer Mountain goes beyond providing users with ownership and control over their cryptographically secure identities. It is an end-to-end application ecosystem that facilitates secure commerce and exchange of digital and physical services. Gain assurance of reliable and secure independent audits and claim verification. Only share and validate encrypted data according to transaction requirements. Segment services across Peer Mountain deployments securely and transparently. Control your data in a distributed system that makes hacking unfeasible. Peer Mountain serves consumers who want self-sovereign identity, service providers who need continuous, reliable compliance, and trust providers offering validation services who need trust interoperability and portability.
  • 38
    iProov

    iProov

    iProov

    We authenticate remote users online for onboarding and verification using Genuine Presence Assurance. Organizations using iProov’s biometric authentication for onboarding or authenticating are realizing significant benefits. Clean bill of health from US Government Penetration Review. Unique active threat management system for certified resilience. Independent of platform, format or device. iProov is the world leader in Genuine Presence Assurance. Banks, governments, travel and healthcare providers around the world are using our unique patented technology to verify the online identity of customers and citizens more securely and more effortlessly than ever before. GDPR compliant & eIDAS certified. Credentials not stored on devices. Deployed by the world’s most security conscious organizations. Deployed on five continents. Delivering millions of authentications worldwide.
  • 39
    FraudGuard

    FraudGuard

    First American Data & Analytics

    FraudGuard® is the most intelligent decision tool on the market today, leveraging advanced analytics, reporting, defect trending and audit trails that are essential to a compliant loan origination process. No other automated solution can match the depth of data sources or capabilities FraudGuard marshals into a single solution quality assurance platform. Lenders can trust FraudGuard to provide top tier analytics backed by veteran product support and development teams. Leveraging public, private and proprietary data sources, the FraudGuard platform helps lenders identify potential fraud risk and errors in mortgage applications, comply with regulations, improve the application review process through greater speed and efficiency, and increase loan quality. Enhanced reporting of findings and recommendations provides the actionable insight needed to support loan decisions.
  • 40
    Entrust Identity Enterprise
    The world's most proven on-prem identity & access management (IAM) solution for strong digital security. Identity Enterprise is an integrated IAM platform that supports a full suite of workforce, consumer, and citizen use cases. Ideally suited for high-assurance applications that require a Zero Trust approach for thousands or millions of users, Identity Enterprise can be deployed on-premises or as a virtual appliance. Never trust, always verify. Protect your organization and user communities both inside and outside the perimeter. Secure workforce, consumer, and citizen identities with high assurance use case coverage including credential-based access, smart card issuance, and best-in-class MFA. Limit user friction with adaptive risk-based authentication, passwordless login, and cloud app federation. Option to use digital certificates (PKI) for a higher level of security when and where warranted, either with a physical smart card or a virtual smart card.
  • 41
    Intel Trust Authority
    Intel Trust Authority is a zero-trust attestation service that ensures the integrity and security of applications and data across various environments, including multiple clouds, sovereign clouds, edge, and on-premises infrastructures. It independently verifies the trustworthiness of compute assets such as infrastructure, data, applications, endpoints, AI/ML workloads, and identities, attesting to the validity of Intel Confidential Computing environments, including Trusted Execution Environments (TEEs), Graphical Processing Units (GPUs), and Trusted Platform Modules (TPMs). ​ Provides assurance of the environment's authenticity, irrespective of data center management, addressing the need for separation between cloud infrastructure providers and verifiers. Enables workload expansion across on-premises, edge, multiple cloud, or hybrid deployments with a consistent attestation service rooted in silicon.
  • 42
    Tandem

    Tandem

    Tandem

    Tandem is a comprehensive information security GRC (Governance, Risk, and Compliance) software designed to help organizations manage regulatory compliance and strengthen their cybersecurity posture. Built by experts, it provides tools for audit management, risk assessment, business continuity planning, vendor management, and policy creation. Tandem simplifies compliance by keeping programs current with evolving regulations while automating document generation, tracking, and reporting. Its platform enables organizations to streamline security processes, prepare for audits, and maintain readiness year-round. Trusted by over 1,600 customers and 41,000 users, Tandem supports banks, credit unions, and other regulated industries in managing complex compliance programs efficiently. With over 17 years of industry experience, Tandem helps teams enter audits with confidence and clarity.
  • 43
    Enpass

    Enpass

    Enpass Technologies Inc.

    Enpass believes your data belongs to you. Compliance-friendly Enpass Business secures passwords and passkeys in vaults on your organization’s own infrastructure or trusted business cloud, providing greater security than proprietary, SaaS-hosted solutions. Enpass is highly customizable for users, and a powerful Admin Console provides fine-grained control over vault sharing, password generation, and employee security. ISO 27001 certified, zero-knowledge AES-256 encryption on 100% of data.
    Starting Price: $2.99/month
  • 44
    Auditive

    Auditive

    Auditive

    Auditive is a Third-Party Risk Management (TPRM) platform with continuous monitoring, empowering buyers and sellers to confidently engage with each other, like never before. Auditive's unique network approach eliminates 80% of the risk review work for businesses and their vendors. Buyers can complete third-party risk reviews four times faster, continuously monitor risk across their entire vendor portfolio, and gain near-instant visibility into third-party risk, resulting in a 35% increase in vendor response rates. Sellers benefit by avoiding repetitive questionnaires, focusing on high-value initiatives, marketing their security posture on the Auditive network, and building trust with customers. The platform supports evaluation against industry-specific frameworks, ensuring accurate risk assessment. Auditive integrates seamlessly with procurement and productivity workflows, enabling rapid onboarding and continuous monitoring of all vendors in one place.
    Starting Price: $800 per month
  • 45
    Becrypt

    Becrypt

    Becrypt

    For endpoint devices you can't afford to have compromised. High Assurance products and services for organizations that face elevated threat. High assurance solutions for desktops, laptops and thin clients. Architectures based on government-backed research and development. From managed services and security monitoring to specialist R&D. Zero trust architectures provide enhanced protection for cloud and online services, combining device health and identity measurements fo service access. Allowing access to corporate services from unmanaged endpoints remains a frequent source of supply chain vulnerabilities. Robust device health and identity management can transform 3rd party IT risks. Proven cloud and mobile architectures delivered through managed service to simplify secure 3rd party collaboration.
  • 46
    RightOrigins by CIED
    RightOrigins is a supply chain intelligence platform leveraging agentic AI to streamline workflows and centralize data management. It consolidates product details, quality assurance documents, supplier information, ESG metrics, and compliance records into an AI-ready knowledge base. AI agents handle tasks like responding to information requests, sustainability questionnaires, audits, and regulatory documentation. The platform automates supplier data collection, reducing manual effort by directly gathering ESG and compliance information. Custom dashboards provide real-time insights, while automated alerts flag data issues. It generates sustainability reports and identifies risks across supply chain operations. RightOrigins adheres to GDPR and ISO 27001 standards, with privacy controls ensuring organizations retain full authority over their data. Flexible hosting options meet diverse security and jurisdictional needs.
  • 47
    Fluentd

    Fluentd

    Fluentd Project

    A single, unified logging layer is key to make log data accessible and usable. However, existing tools fall short: legacy tools are not built for new cloud APIs and microservice-oriented architecture in mind and are not innovating quickly enough. Fluentd, created by Treasure Data, solves the challenges of building a unified logging layer with a modular architecture, an extensible plugin model, and a performance optimized engine. In addition to these features, Fluentd Enterprise addresses Enterprise requirements such as Trusted Packaging. Security. Certified Enterprise Connectors, Management / Monitoring, and Enterprise SLA-Based Support, Assurance, and Enterprise Consulting Services
  • 48
    ThirdPartyTrust

    ThirdPartyTrust

    ThirdPartyTrust

    TPRM by ThirdPartyTrust is your one pane of glass risk dashboard: An end-to-end document repository and workflow automation tool to scale your vendor risk management program. Leverage a network of 17,000+ existing vendor profiles to fast forward your reviews and stay proactive with continuous monitoring. Beacon is the one source of truth for third party vendors: A centralized security profile comprising all your questionnaires, certifications, and attestations. Answer them once and easily share the latest versions any time your team receives a security assessment request. The tool will help you manage your end-to-end process, reducing the time spent on requesting and reviewing security documents.
    Starting Price: $120000.00/year
  • 49
    Copla

    Copla

    Copla

    Copla is a compliance automation platform designed to help organizations manage complex regulatory requirements more efficiently. The platform supports frameworks such as DORA, NIS2, ISO 27001, SOC2, and other security and governance standards. Copla automates tasks like evidence collection, control monitoring, and policy generation to reduce the manual workload involved in compliance management. By continuously monitoring systems and collecting documentation automatically, the platform ensures businesses remain audit-ready at all times. Copla also cross-maps controls across multiple frameworks, allowing companies to complete compliance work once and apply it to several standards. In addition to automation, the platform provides guidance from experienced CISOs who help organizations build effective compliance strategies. Through a combination of expert support and intelligent automation, Copla enables companies to meet regulatory requirements with less effort and greater confidence.
  • 50
    SAGE

    SAGE

    HolistiCyber

    SAGE, an AI-driven, cyber defense platform, supports the CISOs mission to build and operate an effective and efficient cyber defense plan. It keeps the defense plan relevant and dynamic, automatically ingesting all reports and assessments by various vendors, and its AI connects and analyzes the variables in the defense plan. SAGE is purpose-built for CISOs. It considers the needs of the organization: business impact analysis, risk tolerance, cyber posture, attack surface, etc., then considers attack vectors and analyzes everything with HolistiCyber’s unique methods in seeing the attack surface the way an attacker would. SAGE includes a context map of everything that matters – risks, vulnerabilities, assets, cyber threats, and how they impact the business. The platform provides simple presentation options for management, translating cyber risks into business risks, and includes “what-if” analysis to optimize budget usage for cyber security.