| 
                             Attribute 
                         | 
                        
                             Essential 
                         | 
                        
                             Advanced 
                         | 
                        
                             SonarQube 
                         | 
                    
| 
                             Focus 
                         | 
                        |||
| 
                             Extras 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        |
| Headcount | 806 | ||
| 
                             Headcount distribution
                                 
                             | 
                        |||
| 
                             Headcount growth 
                             | 
                        |||
| 
                             Headquarters 
                         | 
                        |||
| 
                             Countries 
                             | 
                        |||
| 
                             Reputation 
                         | 
                        
                             Same 
                         | 
                        ||
| 
                             Followers 
                         | 
                        
                             Same 
                         | 
                        ||
| 
                             Research Firms 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        |
| 
                             Founded 
                         | 
                        2001 | ||
| 
                             Funding 
                         | 
                        
                             Bootstrapped 
                         | 
                        
                             Same 
                         | 
                        
                             $457M
                                        USD
                                        in 2 rounds from 4 investors 
                         | 
                    
| 
                             Acquisitions 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        
                             Acquired 0 times and made 2
                                    acquisitions 
                         | 
                    
| 
                             Revenue 
                         | 
                        |||
| 
                             CVE 
                         | 
                        
                             0 CVEs reported to MITRE 
                         | 
                    ||
| 
                             Compliance 
                         | 
                        |||
| 
                             Bug bounty 
                         | 
                        
                             No 
                         | 
                    ||
| 
                             Visits 
                         | 
                        |||
| 
                             Authority 
                         | 
                        |||
| 
                             Vulnerability database
                                 
                             | 
                        Same | 
                             None 
                         | 
                    |
| 
                             Content 
                         | 
                        |||
| 
                             Knowledge base 
                         | 
                        
                             13 KB sections, 4
                                in common and 9 additional 
                         | 
                        
                             4 KB
                                        sections, all in common 
                         | 
                    |
| 
                             Community 
                         | 
                        Forum | ||
| 
                             Sync training 
                         | 
                        
                             1 workshop 
                         | 
                        No | |
| 
                             Async training 
                         | 
                        
                             3 product use
                                    courses, all free 
                         | 
                        
                             No 
                         | 
                    |
| 
                             Distribution 
                         | 
                        
                             Same 
                         | 
                        ||
| Marketplaces | AWS, Azure and GCP | ||
| 
                             Freemium 
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                        |
| 
                             Free trial 
                         | 
                        
                             14-day free
                                    trial and PoV
                             
                         | 
                    ||
| 
                             Demo 
                         | 
                        |||
| 
                             Open Demo 
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                    
| 
                             Pricing 
                         | 
                        |||
| 
                             Pricing tiers 
                         | 
                        
                             1 plan 
                         | 
                        
                             1 plan 
                         | 
                        
                             2 plans
                                        (team, enterprise). First transparent 
                         | 
                    
| 
                             Minimum term 
                         | 
                        |||
| 
                             Minimum payment period
                                 
                             | 
                        |||
| 
                             Minimum capabilities 
                         | 
                        API security testing, ASPM, binary SAST, containers, CSPM, DAST, IaC, SAST, SCA and secrets | Same plus: PTaaS, RE and SCR | Code quality, SAST and secrets | 
| 
                             Minimum scope 
                         | 
                        
                             1 group 
                         | 
                        
                             1 author 
                         | 
                        
                             100K LoCs 
                         | 
                    
| 
                             Pricing drivers 
                             | 
                        Groups | Authors | |
| 
                             Minimum monthly payment 
                         | 
                        
| 
                                 Attribute 
                             | 
                            
                                 Essential 
                             | 
                            
                                 Advanced 
                             | 
                            
                                 SonarQube 
                             | 
                        
| 
                                 
                                    PTaaS
                                 
                             | 
                            
                                 No 
                             | 
                            
                                 No 
                             | 
                        |
| 
                                 
                                    Reverse engineering
                                 
                             | 
                            
                                 No 
                             | 
                            No | |
| 
                                 
                                    Secure code review
                                 
                             | 
                            
                                 No 
                             | 
                            
                                 No 
                                 | 
                        |
| 
                                 
                                    Pivoting
                                 
                             | 
                            
                                 No 
                             | 
                            
                                 No 
                             | 
                        |
| 
                                 
                                    Exploitation
                                 
                             | 
                            
                                 No 
                             | 
                            
                                 No 
                             | 
                        |
| 
                                 Manual reattacks 
                                 | 
                            
                                 Not applicable 
                             | 
                            
                                 Not applicable 
                             | 
                        |
| 
                                 Zero-day
                                        vulnerabilities 
                             | 
                            
                                 None
                                 
                             | 
                            
                                 Continuous zero-day vulnerability research
                                 
                             | 
                            
                                 None 
                             | 
                        
| 
                                 
                                    SLA
                                 
                             | 
                            Availability | ||
| 
                                 Min availability 
                             | 
                            
                                 >=99.95%
                                    per minute LTM 
                             | 
                            >=99% per month | |
| 
                                 After-sale guarantees 
                             | 
                            
                                 No 
                             | 
                            
                                 Yes 
                             | 
                            
                                 No 
                             | 
                        
| 
                                 
                                    Accreditations
                                 
                             | 
                            
                                 None 
                             | 
                        ||
| 
                                 
                                    Hacker certifications
                                 
                             | 
                            
                                 Not
                                            applicable 
                                 | 
                            
                                 Not applicable 
                                 | 
                        |
| 
                                 
                                    Type of contract
                                 
                             | 
                            
                                 Employee 
                             | 
                            
                                 Same 
                             | 
                            |
| 
                                 Endpoint control 
                             | 
                            
                                 Not applicable 
                             | 
                            Total | 
                                 Not applicable 
                             | 
                        
| 
                                 Channel control 
                             | 
                            
                                 Not applicable 
                             | 
                            
                                 Total 
                             | 
                            
                                 Not applicable 
                             | 
                        
| 
                                 
                                    Standards
                                 
                             | 
                            
                                 Some
                                            requirements
                                            from 67 standards, 10 in common and
                                            57 additional 
                             | 
                            
                                 All requirements from
                                        the same
                                    standards
                                 
                             | 
                            
                                 10 standards, all
                                    in common 
                             | 
                        
| 
                                 
                                        Detection method
                                     
                                 | 
                            |||
| 
                                 False positives 
                                 | 
                            
                                 1.27 times better 
                             | 
                            2 times better | 
                                 46% F0.5 score per quantity 
                             | 
                        
| 
                                 False negatives 
                             | 
                            
                                 3.17 times better 
                             | 
                            
                                 1.10 times better 
                             | 
                            
                                 24% F2.0 score per severity 
                             | 
                        
| 
                                 
                                    Remediation
                                 
                             | 
                            
                                 5,
                                    3 in common and 2 additional 
                             | 
                            
                                 Same, plus 1 
                             | 
                            
                                 3, all in common
                                 
                             | 
                        
| 
                                 
                                    Outputs
                                 
                             | 
                            
                                 5, 2 in common and
                                            3
                                            additional 
                                 | 
                            
                                 Same, plus 2
                                 
                             | 
                            
                                 5, 2 in common and 3
                                        additional 
                             | 
                        
| 
                             Attribute 
                         | 
                        Essential | 
                             Advanced 
                         | 
                        
                             SonarQube 
                         | 
                    
| 
                             
                                ASPM
                             
                         | 
                        
                             No 
                         | 
                    ||
| 
                             API 
                         | 
                        |||
| 
                             
                                IDE
                             
                         | 
                        
                             Same, plus
                                1 functionality 
                         | 
                        ||
| 
                             
                                CLI
                             
                         | 
                        |||
| 
                             
                                CI/CD
                             
                         | 
                        |||
| 
                             Vulnerability sources 
                         | 
                        
                             4 sources
                             
                         | 
                        No information available | |
| 
                             Threat model alignment 
                         | 
                        
                             No 
                         | 
                    ||
| 
                             Priority criteria 
                         | 
                        Same | 
                             No information available 
                         | 
                    |
| 
                             Custom prioritization 
                         | 
                        Assign severity to rules | ||
| 
                             Scanner origin 
                             | 
                        |||
| 
                             
                                SCA
                             
                         | 
                        
                             No 
                         | 
                    ||
| 
                             AI security 
                             | 
                        
                             No 
                         | 
                        Yes | 
                             No 
                         | 
                    
| 
                             
                                Reachability
                             
                         | 
                        
                             12 languages 
                         | 
                        
                             No 
                             | 
                    |
| 
                             Reachability type 
                         | 
                        Same | 
                             Not applicable 
                         | 
                    |
| 
                             
                                SBOM
                             
                         | 
                        
                             No
                             
                         | 
                    ||
| 
                             Malware detection 
                             | 
                        Yes | 
                             Yes 
                         | 
                        
                             No 
                         | 
                    
| 
                             Autofix on components 
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                        No | 
| 
                             
                                Containers
                             
                         | 
                        
                             No 
                             | 
                    ||
| 
                             
                                Source SAST 
                            
                                (languages)
                                 
                         | 
                        
                             12,
                                    all in common 
                         | 
                        
                             26,
                                12 in common and 14 additional 
                         | 
                    |
| 
                             
                                Source SAST 
                            
                                (frameworks)
                                 
                         | 
                        
                             22, none in common 
                         | 
                        ||
| 
                             Custom rules 
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                        |
| 
                             IaC 
                         | 
                        
                             6,
                                3 in common and 3 additional 
                         | 
                        4, 3 in common and 1 additional | 
                             6,
                                all in common 
                         | 
                    
| 
                             
                                Binary SAST
                             
                         | 
                        
                             1 type of
                                    binary
                             
                         | 
                        
                             Same,
                                plus 2 types of binaries 
                         | 
                        
                             No 
                         | 
                    
| 
                             
                                DAST
                             
                         | 
                        
                             No  | 
                    ||
| 
                             API security testing 
                             | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                    |
| 
                             
                                IAST
                             
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                        
                             No 
                         | 
                    
| 
                             
                                CSPM
                             
                         | 
                        Yes | 
                             No 
                         | 
                    |
| ASM | No | 
                             No 
                         | 
                        
                             No 
                         | 
                    
| 
                             
                                Secrets
                             
                         | 
                        
                             Same, plus verify other attack
                                    vectors and
                                    secrets exploitability 
                         | 
                        
                             Yes.
                                No information available 
                         | 
                    |
| 
                             
                                AI
                             
                         | 
                        |||
| 
                             MCP 
                         | 
                        Yes | ||
| 
                             
                                    Open source
                                 
                             | 
                        
                             Not applicable 
                         | 
                        ||
| 
                             Provisioning as Code 
                         | 
                        Yes | ||
| 
                             
                                Deployment
                             
                         | 
                        |||
| Regions | |||
| 
                             
                                Status
                             
                         | 
                        |||
| 
                             
                                Incidents
                             
                         | 
                        
| 
                             Attribute 
                         | 
                        
                             Essential 
                         | 
                        
                             Advanced 
                         | 
                        
                             SonarQube 
                         | 
                    
| 
                             
                                SCM
                             
                         | 
                        
                             2,
                                    none in common 
                         | 
                    ||
| 
                             
                                Binary repositories
                             
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                    
| 
                             
                                Ticketing
                             
                         | 
                        
                             None  | 
                    ||
| 
                             
                                ChatOps
                             
                         | 
                        None | 
                             None 
                         | 
                        
                             None  | 
                    
| 
                             
                                IDE
                             
                         | 
                        
                             3,
                                    2 in common and 1 additional 
                         | 
                        
                             12, 2 in common and 10 additional  | 
                    |
| 
                             
                                CI/CD
                             
                         | 
                        
                             21, 5 in common and 16 additional 
                         | 
                        
                             5, all in common 
                             | 
                    |
| 
                             
                                SCA
                             
                         | 
                        
                             None  | 
                    ||
| 
                             
                                Container
                             
                         | 
                        
                             None  | 
                    ||
| 
                             SAST
                             
                         | 
                        |||
| 
                             
                                DAST
                             
                         | 
                        
                             None  | 
                    ||
| 
                             
                                IAST
                             
                         | 
                        None | 
                             None 
                         | 
                        
                             None 
                         | 
                    
| 
                             
                                Cloud
                             
                         | 
                        
                             None 
                         | 
                    ||
| 
                             
                                CSPM
                             
                         | 
                        None | ||
| 
                             
                                Secrets
                             
                         | 
                        |||
| 
                             Remediation 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        |
| 
                             Bug bounty 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                    
| 
                             Vulnerability management 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                    
| 
                             
                                Compliance
                             
                         | 
                        
                             None 
                         | 
                        
                             None 
                         | 
                        
                             None 
                         |