Explore / Category guide
AI Security & DevSecOps
Discover the top AI Security & DevSecOps in 2026. Compare architecture, pricing tiers, performance benchmarks, and open-source developer alternatives.
Category overviewAbout AI Security & DevSecOpsRead guideClose guide
This category holds the 103 tools that find security problems in code, in dependencies, in pipelines and — a newer job — in the models and agents a team now ships. If you are responsible for what a scan reports on Monday morning, this is your shelf. The page renders 48 of the 103, so it helps to know which of five jobs you are hiring for.
Secrets. Gitleaks (84/100, Gitleaks, MIT and free) and TruffleHog (86/100, TruffleHog) both scan git history for credentials; TruffleHog's distinguishing move is verifying whether a found secret is still live, which is what separates a real incident from noise. Code. Semgrep (87/100, Semgrep) and SonarQube (87/100, SonarQube) sit in CI and enforce rules; SonarQube's Community Build is free, Semgrep's free tier stops at 10 repos and 10 contributors. Consolidated platforms. Snyk (86/100, Snyk, free tier, Team from $25/mo) and Aikido Security (86/100, free for 2 users, Basic $300/mo) cover several attack surfaces at once, which is a procurement decision as much as a technical one. Code health as a gate. DeepSource (84/100) and CodeAnt AI (82/100) blend static analysis with AI review and reporting.
The fifth job is the one that changed in 2026: securing the AI itself. Of the six most recently touched entries here, five belong to that wave, all verified on 2026-08-16 — MCP-Scan, which scans MCP servers for tool poisoning and prompt injection; DeepTeam, an open-source LLM red-teaming framework covering 40+ adversarial attack types; Giskard, for bias, drift and model vulnerability testing; Microsandbox, which gives agents hardware-isolated microVMs to run code in; and Inspect AI, the UK AI Security Institute's MIT-licensed evaluation framework. NVIDIA's garak (verified 2026-04-21) sits in the same group and already appears in 3 stacks. None of these replace a SAST tool. They answer a question a SAST tool was never asked.
Two caveats before you browse. First, review coverage here is thin: 30 of the 103 tools carry a scored review, so absence of a score is not a verdict — it usually means the tool has not reached the review queue yet. Second, nothing in this category is currently in the graveyard, which is unusual on this site and worth reading as a sign that the field is still adding rather than consolidating.
If you are starting from zero, the cheapest useful sequence is a secret scanner in pre-commit, a rules engine in CI, and only then a platform contract — in that order, because the first two are free and catch the failures that actually get exploited.

showing 9 of 105 tools
Comprehensive open-source vulnerability scanner
Trivy is an open-source vulnerability scanner with 24K+ GitHub stars by Aqua Security that scans container images, file systems, Git repositories, Kubernetes clusters, and IaC configurations for security issues. Detects OS package and language-specific vulnerabilities, misconfigurations, secrets, and license violations in a single tool. Runs as a simple CLI with zero configuration needed. Supports SBOM generation, VEX for vulnerability filtering, and CI/CD integration.
AI-native SAST with automated PR security reviews
ZeroPath is an AI-native SAST and AppSec platform recognized as an RSAC 2026 finalist that provides automated pull request security reviews with contextual feedback and natural-language fix suggestions. It catches secrets, IaC misconfigurations, and logic flaws in code changes, competing directly with established code review tools but with a security-first AI-native architecture.
AI-automated pentesting with zero false positives
ZeroThreat is an automated penetration testing platform that uses AI to conduct comprehensive security audits, claiming to identify 500+ vulnerability types with zero false positives. It automates the traditionally expensive and manual red-teaming process, providing continuous security assessment for web applications with detailed remediation guidance and compliance-ready reporting.
Sandbox any command with file, network, and credential controls
Zerobox is a security-focused command sandboxing tool that isolates command execution with fine-grained controls over file system access, network connectivity, and credential exposure. It wraps any shell command in a secure container that enforces policy restrictions, preventing unauthorized file reads, network calls, or environment variable leaks during execution.
Google's application kernel for container sandboxing and security
gVisor is Google's open-source container runtime sandbox that provides an additional layer of isolation between containerized applications and the host kernel. It implements a user-space application kernel that intercepts system calls, preventing container escapes and limiting the attack surface. Used in Google Cloud Run, GKE Sandbox, and other Google Cloud services. Over 18,000 GitHub stars.
NVIDIA's LLM vulnerability scanner and red-teaming tool
garak is NVIDIA's open-source LLM vulnerability scanner for red-teaming AI models and applications. Probes for prompt injection, data leakage, hallucination, toxicity, encoding-based attacks, and dozens of other vulnerability categories. Runs automated attack sequences against any LLM endpoint and generates detailed vulnerability reports. Features a modular probe/detector architecture that is extensible with custom attack patterns. Named after the Star Trek character known for deception.
Open-source diagnostic for AI operational misalignment
iFixAi is an Apache-2.0 diagnostic tool for scoring AI agents and models against operational-misalignment risks such as hallucination, manipulation, sabotage, sandbagging, and oversight evasion.
Google's vulnerability scanner using the OSV database
OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.
Static linter that catches production bugs in AI-generated code
prodlint is a zero-config static analysis tool with 52 rules targeting production bugs that AI coding tools consistently produce. It catches hallucinated npm imports, missing authentication checks, Prisma writes outside transactions, exposed secrets via NEXT_PUBLIC prefixes, and other patterns specific to code generated by Cursor, Claude Code, Bolt, and v0. Runs in one second via npx with no configuration needed.