Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

CodeSonar uses a unified dataflow with symbolic execution analysis to examine the entire application's computations. CodeSonar's static analyze engine is extremely deep and does not rely on pattern matching or similar approximations. It finds 3-5 times more defects than other static analysis tools. SAST tools are able to be easily integrated into any team's software development process, unlike many other tools such as testing tools and compilers. SAST technologies such as CodeSonar attach to existing build environments to add analysis information. CodeSonar works in the same way as a compiler. However, CodeSonar creates an abstraction model of your entire program, instead of creating object codes. CodeSonar's symbolic execution engine analyzes the derived model and makes connections between them.

Description

The YAG Suite is a French-made innovative tool that takes SAST to the next level. YAGAAN is a combination of static analysis and machine-learning. It offers customers more than a sourcecode scanner. It also offers a smart suite to support application security audits and security and privacy through DevSecOps design processes. The YAG-Suite supports developers in understanding the vulnerability causes and consequences. It goes beyond traditional vulnerability detection. Its contextual remediation helps them to quickly fix the problem and improve their secure coding skills. YAG-Suite's unique 'code mining' allows for security investigations of unknown applications. It maps all relevant security mechanisms and provides querying capabilities to search out 0-days and other non-automatically detectable risks. PHP, Java and Python are currently supported. Next languages in roadmap are JS, C and C++.

API Access

Has API Yes 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Eclipse IDE Yes 
GitHub Yes 
GitLab Yes 
Jenkins Yes 
Python Yes 
Visual Studio Code Yes 
AWS GovCloud Yes 
Amazon Web Services (AWS) Yes 
C Yes 
C# Yes 
C++ Yes 
CodeSentry Yes 
Go Yes 
Java Yes 
JavaScript Yes 
Jira Yes 
Kotlin Yes 
Rust Yes 
Seeker Yes 
Visual Studio Yes 

Integrations

Eclipse IDE Yes 
GitHub Yes 
GitLab Yes 
Jenkins Yes 
Python Yes 
Visual Studio Code Yes 
AWS GovCloud No 
Amazon Web Services (AWS) No 
C No 
C# No 
C++ No 
CodeSentry No 
Go No 
Java No 
JavaScript No 
Jira No 
Kotlin No 
Rust No 
Seeker No 
Visual Studio No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

From €500/token or €150/mo
Subscription: SaaS from €150/month/100kLoc
On premise from €215/month/100kLoc

Subscriptions are based on the number of lines of code to scan, no limit on the number of scans / users / projects.
Tokens are valid for per application
Free Trial Yes 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux Yes 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person No 

Vendor Details

Company Name

CodeSecure

Country

United States

Website

www.grammatech.com/products/source-code-analysis

Vendor Details

Company Name

YAGAAN

Founded

2017

Country

France

Website

yagaan.com

Product Features

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Static Code Analysis

Analytics / Reporting No 
Code Standardization / Validation No 
Multiple Programming Language Support No 
Provides Recommendations No 
Standard Security/Industry Libraries No 
Vulnerability Management No 

Product Features

Static Application Security Testing (SAST)

Application Security Yes 
Dashboard Yes 
Debugging No 
Deployment Management No 
IDE Yes 
Multi-Language Scanning Yes 
Real-Time Analytics No 
Source Code Scanning Yes 
Vulnerability Scanning Yes 

Static Code Analysis

Analytics / Reporting Yes 
Code Standardization / Validation Yes 
Multiple Programming Language Support Yes 
Provides Recommendations Yes 
Standard Security/Industry Libraries Yes 
Vulnerability Management Yes 

Vulnerability Scanners

Asset Discovery No 
Black Box Scanning No 
Compliance Monitoring No 
Continuous Monitoring No 
Defect Tracking No 
Interactive Scanning No 
Logging and Reporting No 
Network Mapping No 
Perimeter Scanning No 
Risk Analysis No 
Threat Intelligence No 
Web Inspection No 

Alternatives

Flawnter Reviews

Flawnter

CyberTest
SonarQube Cloud Reviews

SonarQube Cloud

SonarSource
SonarQube Server Reviews

SonarQube Server

SonarSource
PT Application Inspector Reviews

PT Application Inspector

Positive Technologies