The tools we build and secure with — grouped by the job each one does.
Every product on this page sits under the work it does, from gathering audit evidence to screening what reaches an AI model. Next to them are the stacks we build software in.
The tools we use for security work and the stacks we build software in, each listed under the job it does.
Why it matters
You can see which tools a piece of work runs on, and compare them with the tools your own team already licenses.
What you get
Plain, current product names, checked on each maker's own pages. No partnership claimed, and no product ranked above a rival.
Security tools by job
What each group of security tools is used for.
Where two products are joined by “or”, they are alternatives for one job, not a pair run side by side.
Compliance evidence and remediation
Drata or Vanta gathers evidence continuously, and Jira tracks remediation. One shows that a control works; the other keeps each gap on record until it is fixed. To run this as an ongoing service, see compliance as a service.
Cloud security posture
Wiz, Palo Alto Networks Cortex Cloud, or native setups of AWS Security Hub and Google Cloud Security Command Center. These CSPM (cloud security posture management) tools flag cloud settings that leave data or access exposed.
Vulnerability assessment and scanning
Burp Suite Professional, Nuclei and ZAP by Checkmarx. They check a running application, API or network, and we use them in our vulnerability management work.
Code and pipeline scans
Semgrep, plus Snyk for scans in your CI/CD pipeline (the automated steps that build and release your code). SAST (static application security testing) reads the code your team writes; SCA (software composition analysis) checks the open source packages that code pulls in.
Identity, EDR and SIEM
CrowdStrike Falcon, Microsoft Defender for Endpoint and Defender for Cloud, SentinelOne, Datadog and Elastic Security. EDR (endpoint detection and response) watches laptops and servers for attacker behavior. A SIEM (security information and event management system) gathers security logs for investigation.
AI governance and security
Prompt-injection test scripts and harnesses we write ourselves, plus Check Point AI Guardrails (formerly Lakera Guard) for LLM (large language model) safety. Prompt injection is text that tries to make a model ignore its instructions. The scripts check an AI application's defenses in LLM security testing; the guardrail protects it while it runs.
Naming a product here is not a partnership. We don't present ourselves as a partner, reseller, certified provider or authorized provider for any vendor named on this page, and every trademark belongs to its owner. A product appears because we use it for the job it is listed under. That is all it means.
Tools and judgment
A tool flags problems. People decide what they mean.
A dashboard shows only what it was set up to read. It doesn't tell you what a finding means or who acts on it. Each question below is a separate piece of work.
How serious is a finding? In vulnerability assessment, we check each one by hand. No severity rating is copied from a tool's output.
What we build in
The stacks we build software in.
Taken from our web, mobile and AI development pages.
Building a system and securing it are separate jobs, so the build stacks sit apart from the security tools. When your existing stack does the job, the build stays on it.
Web. React or Next.js, Node or Python, and PostgreSQL.
Native mobile. Swift and SwiftUI, Kotlin and Jetpack Compose.
Cross-platform mobile. React Native or Flutter.
AI models. Claude, GPT, Gemini and Llama through hosted APIs, or self-hosted on vLLM.
AI orchestration and retrieval. LangGraph, LlamaIndex or a plain state machine to run the steps, with pgvector, Qdrant or Weaviate to find the right documents.
AI evaluation. A golden set (a fixed set of test questions) built from real user queries.
The same four checks apply to every group of tools.
01
Check the maker's own pages
We read each name on the maker's site, press release or documentation, because security products get renamed, merged into larger platforms and acquired.
02
Print the current name
Where a maker has renamed a product, merged it or changed its owner, we print today's name and set out the change in the table below.
03
Describe the job, not the product
Each card says what a group of tools is for. Vendor claims stay on vendor sites, and no product is ranked above a rival built for the same job.
04
Leave out what goes stale
Release numbers, edition lists and service tiers change faster than this page is edited, so we print none. Check them on the vendor's site before buying.
Renamed and acquired
Products whose name or owner has changed.
Each row pairs a name printed on this page with what its publisher says changed. If you know a product by its old name, look for it here.
Source: each publisher's own website, press release or documentation, named in the row.
Name printed here
What the publisher says
ZAP by Checkmarx
The ZAP team took ZAP out of OWASP in September 2023
Palo Alto Networks Cortex Cloud
Palo Alto Networks: the next version of Prisma Cloud
AWS Security Hub and Security Hub CSPM
AWS runs them as two separate, complementary services
Wiz
In Google Cloud since March 11, 2026, keeping its brand
Check Point AI Guardrails
Check Point completed its acquisition of Lakera in 2025
Which tools do which job, and what a listing means. For questions across all our services, see the main FAQ or ask us directly.
SecWiz groups its technology stack by job: Drata or Vanta and Jira for compliance; Wiz, Palo Alto Networks Cortex Cloud, AWS Security Hub or Google Cloud Security Command Center for cloud posture; Burp Suite Professional, Nuclei, ZAP by Checkmarx, Semgrep and Snyk for vulnerability assessment; CrowdStrike Falcon, Microsoft Defender, SentinelOne, Datadog and Elastic Security for EDR and SIEM. On web builds, SecWiz pairs React or Next.js with Node or Python and a PostgreSQL database.
No. Naming a product on this page is not a partnership, reseller, certification or authorization claim for Drata, Vanta, Wiz, PortSwigger, CrowdStrike, Check Point or any other vendor named. The names are listed so a buyer can see which tools a piece of work runs on and compare them with tools its own team already licenses.
For vulnerability assessment, SecWiz uses Burp Suite Professional from PortSwigger, Nuclei from ProjectDiscovery and ZAP by Checkmarx, with Semgrep and Snyk for source code and CI/CD pipeline scans. The first three check a running application, API or network; Semgrep and Snyk read code and its dependencies before release.
SecWiz uses Drata or Vanta for continuous evidence gathering and Jira for tracking remediation. Drata and Vanta are alternatives for one job, not a pair run side by side, and Jira holds each remediation item until it closes. How that work runs as an ongoing service is covered on SecWiz's compliance as a service page.
SecWiz works with Wiz, Palo Alto Networks Cortex Cloud, or native setups of AWS Security Hub and Google Cloud Security Command Center. A native setup means configuring the security service that AWS or Google Cloud already offers inside its own platform, rather than adding a separate security platform such as Wiz or Cortex Cloud.
SecWiz uses custom prompt-injection test scripts and harnesses, and Check Point AI Guardrails, formerly Lakera Guard, for LLM safety. Custom means SecWiz writes those scripts rather than buying them. On the build side, SecWiz names Claude, GPT, Gemini and Llama as models it works with, and LangGraph, LlamaIndex or a plain state machine for orchestration.
Let's talk
Already running some of these?
Tell us which tools your team already runs and what you need them to show. We reply within one working day.