|
Attribute
|
Essential
|
Advanced
|
DataDog
|
|
Focus
|
Application monitoring
|
||
|
Extras
|
None
|
None
|
App and API Protection, App builder,
Cloudcraft, Cloud security, Cloud SIEM, Code security, Continuous testing, Event
management, Incident response, Internal developer portal, LLM observability, Test
optimization, Workflow Automation and Workload protection
|
|
Headcount
|
10,357 | ||
|
Headcount distribution
|
Engineering 42%, IT 13%, sales 13%,
marketing 2%, operations 4% and others 26%
|
Engineering 34%, IT 10%, sales 21%,
marketing 2%, operations 3% and others 30%
|
|
|
Headcount growth
|
+8%, +10%, -8%
|
+12%, +31%, +79%
|
|
|
Headquarters
|
CO and US
|
ES, IE, IT, FR, NL, UK, US and SE
|
|
|
Countries
|
AR, BO, CA, CL, CO, DO, MX, PA, PE and
US
|
FR and US
|
|
|
Reputation
|
Same
|
8.91 from 1,263 reviews over 11 years
on Capterra, G2, Gartner, PeerSpot and TrustRadius
|
|
|
Followers
|
Same
|
620K based on the following: Facebook,
Instagram, LinkedIn, X and YouTube
|
|
|
Research firms
|
None
|
None
|
451 Research, Everest Group, Forrester,
Frost & Sullivan, Gartner, GigaOM, IDC, Info-Tech Research Group, Nucleus Research
and Omdia
|
|
Founded
|
2001 |
2010
|
|
|
Funding
|
Bootstrapped
|
Same
|
$1B USD in 9 rounds from 16 investors |
|
Acquisitions
|
None
|
None
|
Acquired 0 times and made 16
acquisitions
|
|
Revenue
|
10M to 15M
|
1B to 10B
|
|
|
CVEs as CNA Researcher
|
Not applicable, as it is not a CNA
Researcher
|
||
|
Compliance
|
SOC 2 Type II and SOC 3
|
CSA STAR Level 1, DORA, EU-US DPF, FedRAMP, HIPAA, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, PCI DSS, SOC 2, SOC 2 Type I and TISAX | |
|
Bug bounty
|
Yes
|
||
|
Visits
|
21K
per month. Top 3: 26% CO, 8% FR, 7% US. Others 59%
|
3.2M per month. Top 3: 39% US, 7% BR,
6% IN. Others 48%
|
|
|
Authority
|
52 out of 100
|
||
|
Public vulnerability DB
|
Discovered and third-party
|
None
|
|
|
Content
|
Same
|
Blog, documentation, events, news and
webinars
|
|
| Comprehensive documentation |
13 documentation sections, 2 in common
and 11 additional
|
7 documentation sections, 2 in common
and 5 additional
|
|
|
Community
|
Chat (slack)
|
||
|
Sync training
|
1 workshop
|
No
|
|
|
Async training
|
3 product use courses, all free
|
Security education platform
(subscription based)
|
|
|
Distribution
|
Same
|
Direct or with any of its 1,161
partners
|
|
| Marketplaces |
AWS, Azure, GCP and GitHub
|
||
|
Freemium
|
No
|
No
|
Yes
|
|
Free trial
|
14-day free trial
|
||
|
Demo
|
Yes
|
||
|
Open demo
|
No
|
No
|
No
|
|
Pricing
|
Contact sales, marketplaces and public
web
|
||
|
Pricing tiers
|
1 plan
|
1 plan
|
1 plan
|
|
Minimum term
|
Monthly
|
||
|
Minimum payment period
|
Monthly
|
||
|
Minimum capabilities
|
ASPM, binary SAST, containers, CSPM, DAST, IaC, SAST, SCA and
secrets
|
Same plus: API
security testing, PTaaS, RE and SCR
|
IAST, SAST, dynamic SCA and run-time
SCA
|
|
Minimum scope
|
1 author
|
1 developer
|
|
|
Pricing drivers
|
Developers
|
||
|
Free implementation
|
No
|
||
|
Free support
|
No
|
|
Attribute
|
Essential
|
Advanced
|
DataDog
|
|
PTaaS
|
No
|
No
|
|
|
Reverse engineering
|
No
|
No | |
|
Secure code review
|
No
|
No
|
|
|
Pivoting
|
No
|
No
|
|
|
Exploitation
|
No
|
No
|
|
|
Manual reattacks
|
Not applicable
|
Not applicable
|
|
|
Zero-day
vulnerabilities
|
None
|
Continuous zero-day vulnerability research
|
None
|
|
SLA
|
Availability and support | ||
|
Minimum availability
|
>=99.95% per minute LTM
|
>= 99.8% per month
|
|
|
After-sale guarantees
|
No
|
Yes
|
Yes
|
|
Accreditations
|
None
|
||
|
Hacker certifications
|
Not applicable
|
Not applicable
|
|
|
Type of contract
|
Employee
|
Same
|
Employee
|
|
Endpoint control
|
Not applicable
|
Total
|
Not applicable
|
|
Channel control
|
Not applicable
|
Total
|
Not applicable
|
|
Standards
|
Some requirements from 67 standards, 17 in common and 50
additional
|
All requirements from the same standards
|
26 standards, 17 in common and 9
additional
|
|
Detection method
|
Automated tools, AI and human intelligence
|
Automated tools and AI | |
|
Remediation
|
5, 4 in common and 1 additional
|
Same, plus 1
|
4, all in common
|
|
Outputs
|
5, 2 in common and 3
additional
|
Same, plus 2
|
9, 2 in common and 7 additional
|
|
Attribute
|
Essential |
Advanced
|
DataDog
|
|
ASPM
|
No
|
||
|
API
|
REST with JSON
|
||
|
IDE
|
5 functionalities, 2 in common and 3
additional
|
Same, plus 1 functionality
|
3 functionalities, 2 in common and 1
additional
|
|
CLI
|
Yes
|
||
|
CI/CD
|
Breaks the build
|
||
|
Vulnerability sources
|
4 sources, 2 in common and 2 additional
|
3 sources, 2 in common and 1 additional
|
|
|
Threat model alignment
|
No
|
||
|
Priority criteria
|
CVSS 4, EPSS and KEV
|
||
|
Custom prioritization
|
No
|
||
|
Scanner origin
|
In-house
|
||
|
SCA
|
23 package managers, 11 in common and 12
additional
|
14 package managers, 11 in common and 3
additional
|
|
|
AI security
|
No
|
Yes
|
|
|
Reachability
|
12 languages
|
No
|
|
|
Reachability type
|
Not applicable
|
||
|
SBOM
|
22 package managers, 11 in common and 11
additional
|
13 package managers, 11 in common and 2
additional
|
|
|
Malware detection
|
Yes
|
Yes
|
Yes
|
|
Autofix on components
|
No
|
No
|
No
|
|
Containers
|
4 distributions, 3 in common and 1 additional
|
16 distributions, 3 in common and 13 additional
|
|
|
Source SAST
(languages)
|
12, 9 in common and 3 additional
|
10, 9 in common and 1 additional
|
|
|
Source SAST
(frameworks)
|
No information available
|
||
|
Custom rules
|
No
|
No
|
Compliance rules
|
|
IaC
|
6, 3 in common and 3 additional
|
3, all in common
|
|
|
Binary SAST
|
1 type of binary
|
Same, plus 2 types of binaries
|
No
|
|
DAST
|
No
|
||
|
API security testing
|
No
|
4 types of APIs, 1 in common and 3
additional
|
1 type of API
|
|
IAST
|
No
|
No
|
Yes. No information available
|
|
CSPM
|
Yes |
Yes
|
|
|
ASM
|
No
|
No
|
No
|
|
Secrets
|
15 secrets types, 5 in common and 10
additional
|
Same, plus verify other attack vectors
and secrets exploitability
|
7 secrets types, 5 in common and 2
additional
|
|
AI
|
3 functions, 2 in common and 1
additional
|
3 functions, 2 in common and 1
additional
|
|
|
MCP
|
Yes
|
||
|
Open-source
|
Not applicable
|
No
|
|
|
Provisioning as code
|
No
|
||
|
Deployment
|
SaaS (multi-tenant)
|
||
| Regions |
AP, EU and US
|
||
|
Status
|
Yes
|
||
|
Incidents
|
3 per year
|
|
Attribute
|
Essential
|
Advanced
|
DataDog
|
|
SCM
|
6, 4 in common and 2 additional
|
4, all in common
|
|
|
Binary repositories
|
None
|
None
|
9
|
|
Ticketing
|
3, all in common
|
7, 3 in common and 4 additional
|
|
|
ChatOps
|
None |
None
|
4 |
|
IDE
|
3, all in common
|
7, 3 in common and 4 additional
|
|
|
CI/CD
|
21, 13 in common and 8 additional
|
21, 13 in common and 8 additional
|
|
|
SCA
|
Native and 5 integrations
|
||
|
Container
|
18 | ||
|
SAST
|
Native and 2 integrations
|
||
|
DAST
|
1
|
||
|
IAST
|
None |
None
|
Native and 1 integration
|
|
Cloud
|
3, all in common
|
Native and 6 integrations
|
|
|
CSPM
|
Native and 14 integrations | ||
|
Secrets
|
5
|
||
|
Remediation
|
None
|
None
|
2
|
|
Bug bounty
|
None
|
None
|
None
|
|
Vulnerability management
|
None
|
None
|
3
|
|
Compliance
|
None
|
None
|
1
|