Home / Application and API Security / Software Development Lifecycle (SDLC) Security

Software Development Lifecycle (SDLC) Security

Secure your software from code to deployment with SDLC security best practices.

Try these 313 AI Software Development Lifecycle (SDLC) Security Tools

360Logica
Free

360Logica View 360Logica

360Logica is a premier software testing company dedicated to elevating your software and IT system quality. We provide comprehensive testing services designed to enhance performance, uncover vulnerabilities, and ensure seamless functionality across your applications. Partner with us to achieve superior product quality and robust IT security.

Component & Unit Testing
Core Testing Services
Database & Platform Testing
4ARMED
Free

4ARMED View 4ARMED

4ARMED is a leading provider of advanced security services for modern, cloud-native applications, with deep expertise in public cloud platforms like AWS, GCP, and Azure, and a specialization in Kubernetes security. We deliver end-to-end application security solutions, encompassing design, build, deployment, and testing, to ensure your software is robust and protected against evolving threats. Our CREST-accredited penetration testing and expert training empower organizations to achieve and maintain the highest security standards.

Cloud-Native Application Security
Kubernetes Penetration Testing
CREST Accredited Application Security Testing
a1qa
Free

a1qa View a1qa

a1qa is a leading provider of independent software quality assurance and testing services, partnering with over 500 global clients, including Fortune 500 enterprises, to deliver comprehensive, full-cycle QA and application testing solutions. Our commitment to expert-level QA is driven by a passion for operational excellence, leveraging state-of-the-art techniques and proprietary training through our QA Academy to address complex challenges in emerging technologies like AI and IoT.

Full-cycle QA and application testing
Services for emerging technologies (AI, IoT)
Independent offshore and nearshore QA
achelos
Free

achelos View achelos

achelos is a leading independent software development company specializing in security-critical applications. We provide comprehensive technical solutions from concept to testing for micro-processor and security chips, and embedded systems. Our cross-industry expertise spans electronic ID, health cards, digital tachographs, driving licenses, secure payment cards, and compliance with the electronic signature act, ensuring robust security and project management.

Full lifecycle software development for security chips and embedded systems
Expertise in electronic ID, health cards, and secure payment solutions
Specialized security testing against international standards (Common Criteria, FIPS)
AdaCore
Free

AdaCore View AdaCore

AdaCore is a leading provider of tools and services dedicated to building safe, secure, and reliable software. Leveraging over two decades of experience with high-integrity systems in aerospace, defense, and transportation, AdaCore empowers developers to navigate the complexities of critical software development. As the demand for secure and dependable applications grows across automotive, medical, energy, and IoT sectors, AdaCore extends its proven technologies and expertise to a new generation of developers.

High-integrity software development tools
Expert services for critical systems
Solutions for aerospace, defense, and railways
Ahope
Free

Ahope View Ahope

Ahope is a leading Korean provider of mobile security solutions, combining extensive experience in security development with robust offerings like App Shield for integrated mobile network security. Recognizing the escalating vulnerabilities and threats inherent in mobile-first digital landscapes, Ahope delivers essential mobile platform protection, secure corporate network frameworks, and expert security consulting, including penetration testing, to safeguard sensitive private data and ensure regulatory compliance. Their commitment is to foster a secure business environment, empowering organizations to navigate the complexities of mobile security with confidence.

App Shield integrated mobile network security
Comprehensive mobile platform protection
Secure corporate network framework development
Anvil Secure
Free

Anvil Secure View Anvil Secure

Anvil Secure pioneers advanced penetration testing, embedded systems analysis, and in-depth security research to proactively identify and mitigate complex vulnerabilities. We employ attacker methodologies to uncover hidden weaknesses in your systems, applications, and cloud infrastructure, ensuring robust defenses. Our specialized embedded security services meticulously examine each layer of your devices, providing tailored solutions to safeguard against emerging threats and bolster operational confidence.

Expert Penetration Testing
Comprehensive Application & Cloud Security
In-Depth Embedded Systems Analysis
apiiro
Free

apiiro View apiiro

Apiiro reinvents the Secure Development Lifecycle (SDL) with its industry-first Code Risk Platform™. By analyzing developer behavior and code interactions, Apiiro accelerates secure software delivery and automates product risk remediation before production. Trusted by global enterprises, Apiiro analyzes millions of developer activities across vast codebases, fundamentally transforming how security is integrated into development.

Industry-first Code Risk Platform™
Developer and code behavior analysis
Automated product risk remediation
Appdome
Free

Appdome View Appdome

Appdome is the leading Mobile Integration Platform as a Service (MiPaaS) empowering enterprises to seamlessly integrate security, fraud prevention, and other essential mobile capabilities into their applications. Our Cyber Defense Automation platform offers robust Mobile Release Orchestration, enabling swift deployment of cutting-edge defenses without altering the app's source code. Appdome provides customizable solutions designed to consolidate costs, mitigate operational risks, and accelerate mobile app protection for businesses worldwide.

Code-Free Mobile App Security & Compliance
Cyber Defense Automation Platform
Mobile Release Orchestration
Appknox
Free

Appknox View Appknox

Appknox offers a robust and automated plug-and-play security platform designed to empower developers, security researchers, and enterprises in building and deploying secure mobile applications at speed. By integrating their advanced automated vulnerability assessment tools (SAST, DAST, API Security Testing) and expert penetration testing services directly into the SDLC, Appknox ensures comprehensive security for your mobile ecosystem. Accelerate your development lifecycle while minimizing risk with a proactive and efficient mobile app security solution.

Automated Vulnerability Assessment (SAST, DAST, API Security Testing)
Expert Penetration Testing Services
Seamless SDLC Integration
Applause
Free

Applause View Applause

Applause empowers businesses to deliver exceptional digital experiences through comprehensive, real-world software testing. Leveraging a global community of over 250,000 skilled QA testers and an unparalleled device coverage of 1 million+ devices across all configurations, Applause validates functionality, usability, accessibility, performance, localization, and security. Ensure your applications meet the highest quality standards by testing in authentic environments, reflecting your actual customer usage.

Global community of 250,000+ experienced QA testers
Testing across 1M+ devices and configurations
Comprehensive testing for functionality, usability, and accessibility
AppSec Labs
Free

AppSec Labs View AppSec Labs

AppSec Labs is a premier application security firm dedicated to embedding robust security practices throughout the software development lifecycle. Leveraging extensive experience in penetration testing, secure coding, and advanced hacking techniques, we empower diverse industries—from finance and government to e-commerce and high-tech—to fortify their digital assets. Our commitment extends to continuous research and development of innovative professional tools, ensuring cutting-edge penetration testing capabilities across a multitude of platforms to proactively defend against evolving threats.

Expert Penetration Testing Services
Secure Coding and Hacking Training
Application Security Consulting
AppSOC
Free

AppSOC View AppSOC

AppSOC redefines Application Security Posture Management (ASPM) and Code-to-Cloud Vulnerability Management by unifying fragmented security data from hundreds of tools. We empower DevSecOps teams with actionable insights, prioritizing vulnerabilities by actual business risk to streamline remediation and enhance security precision. Our platform offers comprehensive visibility, from source code to cloud infrastructure, enabling rapid identification and efficient resolution of critical threats, ultimately reducing risk, ensuring compliance, and optimizing security spend.

Comprehensive Application Security Posture Management (ASPM)
End-to-End Code-to-Cloud Vulnerability Management
Automated Data Consolidation from Hundreds of Tools
Archipelo
Free

Archipelo View Archipelo

Archipelo provides intelligent Developer Security Posture Management (DSPM) to proactively strengthen software security and compliance throughout the entire development lifecycle. By capturing critical SDLC insights directly tied to developer actions and AI code usage, Archipelo empowers organizations to monitor and mitigate risks, including those introduced by human error and emerging AI coding assistants. Our platform enables Developer Detection and Response (DevDR) and Automated Tool Governance, establishing a vital system of record for secure software development from inception to deployment.

Developer Security Posture Management (DSPM)
Developer Detection and Response (DevDR)
Automated Tool Governance
Arksentry
Free

Arksentry View Arksentry

ArkSentry redefines Penetration Testing as a Service (PTaaS) by seamlessly integrating a global network of elite, vetted ethical hackers with AI-driven automation. We streamline the pentesting lifecycle, accelerating vulnerability discovery and remediation through real-time collaboration and native integrations with popular development and communication tools. Gain unparalleled security visibility and proactively address business-critical risks with efficient, high-quality, and cost-effective penetration testing.

Network of Vetted Ethical Hackers
Automated Pentesting Workflow
Real-time Vulnerability Tracking
ArmorCode
Free

ArmorCode View ArmorCode

ArmorCode delivers an intelligent application security platform designed for comprehensive AppSec posture management and streamlined DevSecOps workflows. It provides unified visibility across your application security landscape, enabling proactive vulnerability management, compliance adherence, and automated remediation. Empower your development teams with the world's first AppSecOps platform, acting as your 10X AppSec Force Multiplier™ by integrating security seamlessly into the software development lifecycle.

Unified AppSec Posture Visibility
Automated DevSecOps Workflows
Comprehensive Vulnerability Management
Artjoker
Free

Artjoker View Artjoker

Artjoker is a premier full-cycle software development partner with a specialized focus on blockchain technology and intricate smart contract creation. We provide end-to-end information security solutions, ensuring the integrity and safety of your blockchain projects from inception to deployment. Recognizing the critical importance of blockchain security, our expert team offers comprehensive services to safeguard your digital assets and transactions against emerging threats, guaranteeing a secure implementation lifecycle.

Full-cycle blockchain software development
Expert smart contract development and auditing
Comprehensive information security for blockchain projects
Arxan Technologies
Free

Arxan Technologies View Arxan Technologies

Arxan, now part of Digital.ai, is the premier provider of application attack-prevention and self-protection solutions, safeguarding applications across IoT, mobile, desktop, and beyond. Our patented technology proactively defends applications, detects runtime threats, and deters attacks, ensuring robust security and resilience against financial loss, fraud, IP theft, and compliance violations. Trusted globally, Arxan protects applications on over 500 million devices across diverse industries like financial services, automotive, healthcare, and digital media.

Application Attack Prevention
Runtime Self-Protection
Proactive Threat Defense
Aryon Security
Free

Aryon Security View Aryon Security

Aryon Security offers proactive cloud infrastructure protection by embedding security into your development lifecycle, ensuring policies are enforced at deployment. Our AI-powered system intelligently identifies and mitigates risks before they impact production, regardless of your cloud management strategy (IaC, ClickOps, or SaaS providers). Experience consistent, adaptive security that prevents issues rather than reacting to them, empowering your organization to innovate with confidence.

AI-Powered Risk Assessment and Policy Generation
Shift-Left Security: Enforcement at Deployment
Consistent Protection Across All Cloud Environments
astarios
Free

astarios View astarios

Astarios is a Swiss-based organization with over two decades of expertise in delivering near-shore software development solutions and top-tier tech talent globally. We specialize in building dedicated software development teams and offer comprehensive value-added services including rigorous quality assurance, secure DevSecOps practices, and strategic business process optimization consulting to enhance your operational efficiency.

Dedicated Software Development Teams
Near-Shore Software Development Services
Quality Assurance and Testing
Auria
Free

Auria View Auria

Auria delivers visionary solutions and expert-driven software for intricate space, missile, and cyber operations. We empower organizations to overcome the most demanding challenges in these critical sectors through unparalleled expertise and innovative technology. Specializing in cybersecurity and DevSecOps, Auria provides advanced strategies to safeguard vital networks, analyze vulnerabilities, and implement secure, efficient development pipelines.

Advanced Cybersecurity Strategies
Vulnerability Analysis and Reduction
Custom DevSecOps Pipeline Design
AutoRABIT
Free

AutoRABIT View AutoRABIT

AutoRABIT empowers Salesforce developers with a comprehensive DevSecOps suite engineered to accelerate release cycles, ensure superior code quality, and fortify data security. Offering unparalleled flexibility with self-hosted, public, and private cloud deployment options, AutoRABIT provides end-to-end automation for your entire development pipeline. Critically, AutoRABIT enables development independent of the Salesforce platform, safeguarding your operations from platform outages and security vulnerabilities.

Automated CI/CD for Salesforce
End-to-end pipeline automation
Data security and protection
Avatao
Free

Avatao View Avatao

Avatao is a comprehensive online training platform empowering software engineers to build secure applications through extensive hands-on IT security exercises. It covers fundamental and advanced topics including web security, secure coding in Java and C/C++, incident response, threat analysis, secure API design, and DevSecOps, embedding security throughout the entire Software Development Lifecycle (SDLC). Designed for full-stack developers and DevOps engineers, Avatao's exercises span design, coding, testing, and operations, ensuring robust security practices from inception to deployment.

Extensive library of hands-on IT security exercises
Covers classic and emerging security topics
Focuses on secure coding practices
Backslash Security
Free

Backslash Security View Backslash Security

Backslash Security empowers AppSec teams by providing unparalleled visibility into critical application risks through advanced reachability and exploitability analysis. By focusing on actionable attack paths and eliminating noise from traditional tools, Backslash significantly reduces Mean Time to Remediate (MTTR) and transforms AppSec ROI. Gain decisive control over your application security posture and achieve a more efficient, effective, and impactful security program.

Prioritize risks based on reachability and exploitability
Discover critical attack paths within applications
Reduce Mean Time to Remediate (MTTR) with actionable insights