Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Take stock of your applications, APIs, and hidden assets within your expansive multi-cloud framework. Develop tailored policies for various asset categories, utilize automated attack tools, and evaluate security weaknesses. Address security concerns prior to launching into production, ensuring compliance for both applications and cloud data. Implement automatic remediation processes for vulnerabilities, with options to revert changes to prevent data leaks. Effective security identifies issues swiftly, while exceptional security eliminates them entirely. Data Theorem is dedicated to creating outstanding products that streamline the most complex aspects of contemporary application security. At the heart of Data Theorem lies the Analyzer Engine, which empowers users to continuously exploit and penetrate application vulnerabilities using both the analyzer engine and proprietary attack tools. Furthermore, Data Theorem has created the leading open-source SDK, TrustKit, which is utilized by countless developers. As our technology ecosystem expands, we enable customers to easily safeguard their entire Application Security (AppSec) stack. By prioritizing innovative solutions, we aim to stay at the forefront of security advancements.

Description

open-appsec is an open-source initiative that builds on machine learning to provide pre-emptive web app & API threat protection against OWASP-Top-10 and zero-day attacks. It can be deployed as add-on to Kubernetes Ingress, NGINX, Envoy and API Gateways. The open-appsec engine learns how users normally interact with your web application. It then uses this information to automatically detect requests that fall outside of normal operations, and sends those requests for further analysis to decide whether the request is malicious or not. open-appsec uses two machine learning models: 1. A supervised model that was trained offline based on millions of requests, both malicious and benign. 2. An unsupervised model that is being built in real time in the protected environment. This model uses traffic patterns specific to the environment. open-oppsec simplifies maintenance as there is no threat signature upkeep and exception handling, like common in many WAF solutions.

API Access

Has API Yes 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

Amazon Web Services (AWS) Yes 
F5 NGINX Ingress Controller No 
Google Cloud Platform Yes 
Kubernetes No 
Microsoft Azure Yes 
NGINX No 
Objective-C Yes 
Swift Yes 

Integrations

Amazon Web Services (AWS) No 
F5 NGINX Ingress Controller Yes 
Google Cloud Platform No 
Kubernetes Yes 
Microsoft Azure No 
NGINX Yes 
Objective-C No 
Swift No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version Yes 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux Yes 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours Yes 
Live Rep (24/7) Yes 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person No 

Vendor Details

Company Name

Data Theorem

Founded

2013

Country

United States

Website

www.datatheorem.com

Vendor Details

Company Name

open-appsec

Founded

2022

Country

Israel

Website

www.openappsec.io

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Vulnerability Scanners

Asset Discovery No 
Black Box Scanning No 
Compliance Monitoring No 
Continuous Monitoring No 
Defect Tracking No 
Interactive Scanning No 
Logging and Reporting No 
Network Mapping No 
Perimeter Scanning No 
Risk Analysis No 
Threat Intelligence No 
Web Inspection No 

Product Features

Application Security

Analytics / Reporting Yes 
Open Source Component Monitoring Yes 
Source Code Analysis No 
Third-Party Tools Integration Yes 
Training Resources Yes 
Vulnerability Detection Yes 
Vulnerability Remediation Yes 

Web Application Firewalls (WAF)

Access Control / Permissions No 
Alerts / Notifications Yes 
Automate and Orchestrate Security Yes 
Automated Attack Detection Yes 
DDoS Protection No 
Dashboard Yes 
IP Reputation Checking Yes 
Managed Rules Yes 
OWASP Protection Yes 
Reporting / Analytics Yes 
Secure App Delivery No 
Server Cloaking No 
Virtual Patching No 
Zero-Day Attack Prevention Yes 

Alternatives

Alternatives

Traceable Reviews

Traceable

Harness
AppTrana Reviews

AppTrana

Indusface
AppScan Reviews

AppScan

HCLSoftware
Traceable Reviews

Traceable

Harness