Developer tools

Security & compliance tools: the tech stack of 43 real products

Application security, secrets, compliance automation and audits.

What sets them apart

Picks at least twice as common here as among products overall, in decisions at least 10 of them show.

The typical stack

The leading pick where at least 8 of them show the decision and the leader has at least a quarter of it.

DecisionMost common pickShareAt default usage
Frontend FrameworkReact18 of 28 · 64%—
DatabasePostgreSQL11 of 25 · 44%—
Backend FrameworkExpress6 of 17 · 35%—
LLM APIOpenAI API12 of 17 · 71%$10/mo · GPT-6 Luna
HostingCloudflare8 of 16 · 50%$12/mo · Workers Paid
AI SDK & Agent FrameworkLangChain6 of 13 · 46%—
Transactional EmailResend5 of 12 · 42%$20/mo · Pro 50k
Background Jobs & CronCelery4 of 9 · 44%—

Monthly bills add up to about $42 at the calculators' default usage, list prices. Set your own usage →

What they chose, decision by decision

Among the security & compliance tools that show each choice, from makers' products and open-source code alike.

Small samples, fewer than 8 products: Database Access & ORMs (SQLAlchemy 4, Prisma 2) · Vector Database (pgvector 2, Chroma 2) · AI App Builders (Lovable 3, Bolt 2) · Authentication (Clerk 2, Auth0 1) · Error Monitoring (Sentry 4) · File Storage (Amazon S3 2, MinIO 2) · Payments (Stripe 2, Polar 1) · Web Analytics (Plausible Analytics 1, Umami 1) · Image & Video Hosting (sharp 3)

Security & compliance tools we track

25 makers' products and 18 open-source projects. Makers' products first.

LaunchSafeAutonomous Pentesting for Modern Applications+2
Perfai SecurityFind & fix live vulnerabilities in Vibe Apps with 1-prompt.+2
ZenVeilFind, understand and fix security issues faster
StrixOpen-source AI hackers for your apps
APIRadarReal-time leaked API key scanner for public GitHub repos
KastraRuntime authorization for Claude, Cursor, Codex and OpenClaw
MultifactorA password manager built for secure sharing with humans & AI
SeyftAIA real-time multi-modal content moderation platform
TruelinkReal-time mobile security with AI & VPN to stop threats
tracecatOpen-source security automation platform for teams and AI agents+14
deepteamDeepTeam is a framework to red team LLMs and AI agents.
firewall-nodeZen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.+15
ballerineOpen-source infrastructure and data orchestration platform for risk decisioning+9
aktoAkto is the fastest growing AI Security platform for your teams to secure AI agents, MCPs, LLMs, Agent skills, Gen AI apps in your organization.+4
ai-bomAI Bill of Materials — discover every AI agent, model, and API in your infrastructure
isms-builderSelf-hosted Information Security Management System — ISO 27001, NIS2, GDPR/DSGVO, BSI IT-Grundschutz
varlockAI-safe .env files: Schemas for agents, Secrets for humans.
OpenOSINTAI-powered OSINT agent with interactive REPL, MCP server, and CLI. 20 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
strixOpen-source AI penetration testing tool to find and fix your app’s vulnerabilities.
ez-ai-agentAutomated Penetration Testing with EZ and Agents+6
crossfeedExternal monitoring for organization assets+2
lunasecLunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTra+2
garakthe LLM vulnerability scanner
hunterHunter作为中通DevSecOps闭环方案中的一环,扮演着很重要的角色,开源之后希望能帮助到更多企业。
beelzebubA secure low code deception runtime framework, leveraging AI for System Virtualization.
FIRFast Incident Response
forensixGoogle Chrome forensic tool to process, analyze and visualize browsing artifacts
Taranis-NGTaranis NG is an OSINT gathering and analysis tool for CSIRT teams and organisations. It allows team-to-team collaboration, and contains a user portal for simple self asset management. Taranis NG was
zentralZentral is a control plane for secure, observable Apple endpoints in enterprises. Configure, observe, and enforce the desired state of every Apple endpoint. Manage that desired state as code through G
cowrieCowrie SSH/Telnet Honeypot https://docs.cowrie.org/
cve-lite-cliFast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
lunaLuna is the JumpServer workspace.
proboOpen source solutions for SOC2, GDPR, and ISO27001