Application Security — enterprise stack.
For each requirement below, pick the option that fits your build — recommended first, then free and cheaper alternatives — or skip what your project doesn't need. Tap the info icon next to any requirement to see why it matters.
SAST Platform (Static Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: SonarQube CE $0 self-host unlimited LOC, CodeQL $0 public repos unlimited | SonarCloud Team $150/mo for 100k LOC + $50 per extra 100k, Free tier 50k LOC | Snyk Code Free 200 scans/mo, Team $25/dev/mo ($300/yr) unlimited | Semgrep Pro Team $40/dev/mo | Checkmarx One Enterprise $50k/yr (~$4167/mo) for 25 devs, overage $2k per 5 devs
SCA Dependency Scanning (Software Composition Analysis)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Dependabot $0 unlimited alerts/PRs, npm audit $0, OSV-Scanner $0 | Snyk Free 200 tests/mo 1 org, Team $25/dev/mo unlimited tests + fix PRs | Socket Free 100 repos 50k installs/mo, Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo | Mend $30k/yr base (~$2500/mo), overage $50 per extra dev
Secrets Scanning & Detection
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: TruffleHog OSS $0 unlimited repos, Gitleaks OSS $0, GitHub Secret Scanning $0 public + private | GitGuardian Free 25 devs/history scan, $20/dev/mo after ($500/mo for 25 devs), Business $40/dev/mo ($1000/mo for 25), overage $25 per 1000 extra secrets | Doppler Free 250 secrets 25 devs
DAST Scanning (Dynamic Application Security Testing)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ZAP $0 unlimited scans, self-hosted | StackHawk Free 1 app 1 scan/mo, Pro $99/mo 5 apps 5 scans/mo, $399/mo Team 20 apps | Burp Suite Pro $449/yr per user (~$37/mo) one-time license, Enterprise $6,999/yr (~$583/mo) for 10 scan slots + 1 agent $0.10 per extra scan hour | Invicti $25k/yr
Web Application Firewall (WAF) for App Protection
Controls and protects your APIs — quotas, abuse prevention, and firewalls. Important once you have real traffic or many clients.Pricing & free-tier limitsFree: Cloudflare Free 1 custom rule + unmetered DDoS $0 | Cloudflare Pro $20/mo 20 rules + $5/mo managed ruleset, Business $200/mo 100 rules + managed, Enterprise $5000/mo custom ruleset unlimited | AWS WAF $5/mo per WebACL + $1/mo per rule + $1 per 1M req, overage $0.60 per M after 10M | Imperva $1200/mo avg 10M req, Fastly NGWAF $2000/mo base + $0.10 per 1000 reqs over
Container Image Vulnerability Scanning
Where you keep files users upload or you serve — images, videos, documents — and how fast they reach visitors around the world.Pricing & free-tier limitsFree: Trivy OSS $0 unlimited images, Grype OSS $0, Docker Scout Free 3 repos | Snyk Container Free 200 tests/mo, Team $25/dev/mo unlimited | Docker Scout Pro $20/mo 25 repos $0.50 per extra repo | Anchore Enterprise $35k/yr (~$2916/mo) 100 hosts, Wiz $30k/yr base
Infrastructure-as-Code (IaC) Security Scanning
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Checkov OSS $0 unlimited IaC, tfsec OSS $0, KICS OSS $0 1000 scans/mo | Snyk IaC Free 200 tests/mo, Team $25/dev/mo | Prisma Cloud Code Security $24k/yr (~$2000/mo) 100 IaC repos $100 per extra repo, Wiz IaC included in $30k/yr
CI/CD Pipeline Security & Supply Chain Hardening
Automates testing and deploying your code. Saves enormous time and prevents “works on my machine” releases.Pricing & free-tier limitsFree: Scorecard $0 unlimited, Dependabot Review $0, StepSecurity Free 1 repo | GitHub Advanced Security $3.67/user/mo ($44/user/yr) minimum 10 users $36.70/mo, Enterprise $6.50/user/mo | StepSecurity Pro $50/mo 10 repos $100/mo Team, Enterprise $500/mo 100 repos | GitLab Ultimate $99/user/mo
Software Bill of Materials (SBOM) Generation Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Syft OSS $0 unlimited artifacts, CycloneDX $0, Trivy $0 unlimited SBOM gen | Anchore Cloud Free 50 SBOMs/mo $0, Pro $50/mo 500 SBOMs $0.10 per extra SBOM | Mend SBOM module $15k/yr ($1250/mo) | Chainguard SBOM $0 with images
Static Secrets Management & Vault
Stores API keys and credentials safely, separate from your code. Leaking secrets is one of the most common breaches.Pricing & free-tier limitsFree: Vault OSS $0 self-host unlimited secrets, Infisical OSS $0 self-host, Doppler Free 25 devs 250 secrets | Infisical Cloud Free 1000 secrets $12/mo Starter, Doppler Pro $20/dev/mo | HCP Vault $1.58/hr dev cluster ~$1150/mo + $0.03/secret/mo $0.05 per 10k API calls | AWS Secrets Manager $0.40/secret/mo + $0.05 per 10k calls, overage same
Code Security Linting / Pre-commit Security Hooks
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Semgrep OSS $0 unlimited scans, pre-commit.com $0, Gitleaks hook $0 | Semgrep Pro Team $40/dev/mo ($30 annual) includes 1000 Pro scans, Business $60/dev/mo | Snyk Code $25/dev/mo unlimited includes pre-commit hook
Dependency Firewall / Malicious Package Detection (Supply Chain Firewall)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Socket Free 100 repos 50k package installs/mo $0, npm audit $0 | Socket Pro $20/mo org + $5/dev/mo up to 500 repos, Team $20/dev/mo unlimited installs, Enterprise $50k/yr (~$4167/mo) unlimited | Sonatype Firewall $40k/yr, Mend Defender $30k/yr | overage $0.01 per extra install after 500k
Open Source License Compliance Scanning
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsFree: ScanCode $0 OSS unlimited files, FOSSology $0, ORT $0 | FOSSA Free 1 project 1000 deps $0, Team $100/mo 5 projects + $0.10 per dep over 2k, Enterprise $30k/yr | Snyk License included in $25/dev/mo, Mend License $20k/yr base
API Security Platform & Discovery
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Akto OSS $0 self-host 1000 endpoints, Amass $0 | Wallarm Free 1 app 50 endpoints $0, Pro $500/mo 5 apps 500 endpoints, $1500/mo Team 20 apps 2000 endpoints | Salt Security $50k/yr base (~$4167/mo) up to 1000 APIs $50 per extra API/mo | Noname $100k/yr (~$8333/mo)
API Fuzzing & Schema Validation Testing
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Schemathesis OSS $0 unlimited tests, RESTler OSS $0, APIFuzzer OSS $0 | Akto Fuzz Free 1 API 100 tests/mo, Pro $150/mo 10 APIs 10k tests | 42Crunch $300/mo per API unlimited tests, Platform $900/mo 5 APIs | Burp Enterprise API $6999/yr
Software Supply Chain Attestation (SLSA / Sigstore)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Sigstore Public Instance $0 unlimited signing/verifying, Cosign $0, Fulcio $0, Rekor $0 | Chainguard Enforce Free 25 images $0, Team $350/mo 100 images + $3 per extra image, Enterprise $1500/mo 1000 images | in-toto $0 OSS
Penetration Testing as a Service (PTaaS) Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: HackerOne Community platform fee $0 (Bounties $500-$5000 per bug typical), Open Bug Bounty $0 | Cobalt Starter $5000/test 1-week test (one-time), $15k/mo for 3 tests/mo ($5000/test avg) | HackerOne Pentest $25k/test one-time, $100k/yr program fee, Synack $120k/yr ($10k/mo) 4 tests/yr + crowdsourced | Intigriti $2000/test
API Gateway with Security Policy Enforcement
Controls and protects your APIs — quotas, abuse prevention, and firewalls. Important once you have real traffic or many clients.Pricing & free-tier limitsFree: Kong OSS $0 unlimited routes, APISIX OSS $0, KrakenD CE $0 | Kong Konnect Free 1M gateway calls/mo $0, Team $250/mo 10M calls + $0.02 per 10k over | AWS API Gateway Free 1M calls/mo first 12 mo then $3.50 per M HTTP + WAF $5/mo per ACL $1/rule | Apigee $500/mo base 1M + $40 per M over | Azure APIM $150/mo Developer
Secure Code Review / PR Security Automation
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: CodeQL OSS $0 public repos, SonarQube CE $0 PR decoration, Semgrep OSS $0 unlimited PR comments | GitHub Advanced Security $3.67/user/mo, SonarQube Cloud Team $150/mo | Semgrep Pro PR $40/dev/mo | Snyk $25/dev/mo PR checks, Checkmarx $50k/yr PR flow
Interactive Application Security Testing (IAST)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Contrast CE Free 1 app 2 users $0 | Contrast Team $50k/yr (~$4167/mo) 10 apps, $5k per extra app, Enterprise $150k/yr unlimited apps $12.5k/mo | Hdiv Enterprise $40k/yr ($3333/mo) | Checkmarx IAST included in One $50k/yr | overage $500/mo per extra agent
RASP Runtime Application Self-Protection
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: OpenRASP OSS $0 unlimited agents, last updated 2022 but functional | Contrast Protect $50k/yr ($4167/mo) 10 apps, Enterprise $120k/yr 50 apps | Imperva RASP $30k/yr ($2500/mo) base 10 apps $200 per extra app/mo | Hdiv Protection $40k/yr | overage $300/agent/mo
API Rate Limiting & Bot Protection for Applications
Stops bots, scrapers, and spam signups from abusing your service and inflating costs.Pricing & free-tier limitsFree: Cloudflare Free 1 rate-limit rule + Bot Fight $0, 100k good reqs free | Cloudflare Pro $20/mo 10 rules + $5 per 100k over 100k, Business $200/mo 20 rules, Enterprise Bot Management $5000/mo + $0.05 per 1k bot reqs | DataDome $2500/mo base 5M reqs + $0.30 per 1k over | Fastly Bot $2000/mo
Coverage-Guided Fuzz Testing Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: AFL++ OSS $0 unlimited fuzzing, libFuzzer $0, OSS-Fuzz Public $0 for OSS (Google-hosted) | ClusterFuzzLite OSS $0 self-host | Mayhem $1000/mo base 5 targets 100 CPU hrs + $100 per extra target $10 per extra 10 hrs | Code Intelligence $1500/mo 10 targets 500 hrs, Enterprise $5000/mo | CI Fuzz $500/mo
Application Security Posture Management (ASPM)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: DefectDojo OSS $0 self-host unlimited findings, Cycode Free 10 devs $0 | DefectDojo Cloud Pro $250/mo 5000 findings, $500/mo Team 20k | Cycode Team $500/mo 20 devs ($25/dev) Enterprise $60k/yr ($5000/mo) 100 devs | ArmorCode $60k/yr ($5000/mo) | Apiiro $80k/yr ($6666/mo)
Vulnerability Management & Orchestration
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsFree: DefectDojo OSS $0 unlimited vulns, Faraday OSS $0 1 workspace | DefectDojo Cloud Free 100 findings $0, Pro $250/mo 5k findings, $500/mo Team 20k | Nucleus $50k/yr ($4167/mo) base 500 assets + $5 per extra asset/mo | Kenna $40k/yr ($3333/mo) | ThreadFix $35k/yr ($2916/mo)
Bug Bounty & Vulnerability Disclosure Platform
Keeps you secure and compliant with regulations. Required for enterprise customers and handling sensitive data.Pricing & free-tier limitsFree: HackerOne Community platform $0 + bounty budget (Customer sets $10k-$100k/yr) per bug $500-$10k typical, Open Bug Bounty $0 | Intigriti Free platform fee $0 + bounties $500/bug min, YesWeHack Free | Bugcrowd Enterprise $50k/yr platform + bounties, HackerOne Enterprise $100k/yr platform + $50k min bounty pool | Synack $120k/yr crowdsourced + PTaaS | overage bounty dependent
Threat Modeling Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Threat Dragon OSS $0 unlimited models, pytm $0 | IriusRisk CE Free 1 project $0, Starter $200/mo 10 projects, Professional $1000/mo 50 projects $25 per extra project, Enterprise $3000/mo unlimited | ThreatModeler $1500/mo Team 25 users | SD Elements $70k/yr (~$5833/mo)
Container Runtime Protection & Workload Hardening
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: Falco OSS $0 unlimited nodes, Tetragon OSS $0, KubeArmor OSS $0 | Sysdig Secure Free 1 cluster 10 hosts $0, Team $700/mo 50 hosts + $10 per extra host, Enterprise $2000/mo | Aqua Free 1 cluster $0, Enterprise $100/node/mo $10k/mo 100 nodes | Prisma Compute $40k/yr ($3333/mo) | Wiz Runtime $30k/yr
Mobile Application Security Testing (MAST)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: MobSF OSS $0 unlimited APK/IPA scans self-host, QARK $0, Drozer $0 | NowSecure Free 1 app scan/mo $0, Starter $500/mo 5 app scans/mo $100 per extra scan, Pro $2000/mo 25 scans + $50 per extra | Guardsquare AppSweep Free 5 scans/mo Pro $800/mo per app | Checkmarx MAST $50k/yr included
Application Security Orchestration & Correlation (ASOC)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: DefectDojo OSS $0 unlimited correlations, Faraday OSS $0 1 workspace, Shuffle OSS $0 self-host unlimited workflows | DefectDojo Cloud $250/mo 5k findings correlation | Cortex XSOAR $50k/yr (~$4167/mo) 10k actions/mo $0.10 per extra action | Splunk SOAR $60k/yr ($5000/mo) | ServiceNow SecOps $80k/yr
Software Supply Chain Firewall & Private Registry Protection
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Verdaccio OSS $0 unlimited packages self-host, Harbor OSS $0, Nexus OSS $0 | Cloudsmith Free 2GB storage 5k requests $0, Team $100/mo 20GB + $0.50 per GB over, JFrog Free 2GB $0 Team $100/mo 10GB Enterprise $1500/mo (~50GB) | Chainguard Registry $500/mo 100 images $2 per extra image, Sonatype Firewall $40k/yr
Client-Side Protection / Magecart / Formjacking / JS Supply Chain Protection
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: Cloudflare Page Shield Free 50 scripts $0, SRI $0 | Cloudflare Pro $20/mo 100 scripts, Business $200/mo 500 scripts, Enterprise custom (5000 scripts) $2000/mo | Jscrambler $800/mo base 1M pageviews + $0.50 per 1000 extra, Enterprise $2500/mo 5M | Feroot $1000/mo 5 domains $200 per extra domain
Application Hardening & Obfuscation Platform
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ProGuard OSS $0 unlimited classes, JavaScript-Obfuscator OSS $0 | Jscrambler Starter $800/mo 1M pageviews, Enterprise $2500/mo 5M + $0.50 per 1k over | Guardsquare DexGuard $2000/mo per app ($24k/yr) + $500/mo ThreatCast, iXGuard $3000/mo per app, PreEmptive Dotfuscator $5000/yr one-time license per dev
Runtime Dependency Reachability Analysis
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: GitHub Dependency Review $0 reachability flag, Snyk Free limited reachability | Socket Free 1000 functions $0, Pro reachability $20/mo | Snyk Team Reachability included in $25/dev/mo, Enterprise $40/dev/mo advanced reachability | Endor Free 1000 functions $0, Team $2500/mo 10k functions, Enterprise $60k/yr ($5000/mo) 100k functions + $0.05 per extra function | Mend Reachability $30k/yr
Runtime Software Integrity & Anti-Tamper Protection
Where your code actually runs and serves requests. Picking the right host affects speed, scaling, and how much ops work you do.Pricing & free-tier limitsFree: Sigstore verify $0 unlimited integrity checks, in-toto $0 | Jscrambler Anti-Tamper included in $800/mo base | Guardsquare ThreatCast $1000/mo base 1 app + $500/mo per extra app, Enterprise $5000/mo 10 apps | Arxan Digital.ai $100k/yr ($8333/mo) per app family unlimited builds | overage $1000 per extra app/yr
Secure Coding Training Platform Integration (AppSec Education)
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: WebGoat OSS $0 unlimited users, Juice Shop $0, Secure Code Warrior Free 10 devs + 15 languages, Snyk Learn Free $0 | HackEDU Free 5 devs $0, Team $25/dev/mo ($20 annual = $240/yr) | Secure Code Warrior Team $40/dev/mo ($35 annual = $420/yr) $400/mo 10 devs, Enterprise $35/dev/mo 100+ devs ($3500/mo) | Immersive Labs $50k/yr
CSPM for Application Layer / Serverless Security Posture
A piece of your stack you may or may not need, depending on scope. Pick the option that fits — or skip it if your project doesn’t require this capability yet.Pricing & free-tier limitsFree: ScoutSuite $0 OSS unlimited accounts, Prowler OSS $0 1000 accounts free scan, CloudSploit $0 | Wiz Free 100 workloads $0, Team $2500/mo 500 workloads $5 per extra workload/mo, Enterprise $30k/yr baseline 500 workloads + $10 per extra | Prisma Cloud $50k/yr (~$4167/mo) 500 workloads | Orca Serverless $40k/yr ($3333/mo)
Application Layer DDoS & Abuse Prevention Platform
Stops bots, scrapers, and spam signups from abusing your service and inflating costs.Pricing & free-tier limitsFree: Cloudflare Free DDoS unmetered $0, Fail2Ban OSS $0 unlimited IPs, ModSecurity OSS $0 | Cloudflare Pro $20/mo includes DDoS + 20 WAF rules, Business $200/mo 100 WAF + DDoS, Enterprise $5000/mo custom DDoS + Magic Transit | AWS Shield Standard $0 included, Advanced $3000/mo + $0.05 per 1M requests DDoS + DRT $1500/mo | Akamai Prolexic $3000/mo base 10Gbps + $500 per extra 1Gbps, Fastly DDoS $2000/mo
How this enterprise application security checklist works.
Each requirement below is something a enterprise application security build typically needs. Pick one of the four researched options — recommended, free, cheaper or paid — add your own with "Other", or skip the requirement if your project doesn't need it. Nothing is mandatory; the plan on the right tracks what you've decided so nothing gets forgotten.
Your picks are saved in this browser automatically, so you can come back anytime. Options are researched per build level and refreshed as vendors change their plans — always verify details on the provider's page before committing.