Latka logo

Top 9 Interactive Application Security Testing (IAST) Software SaaS Companies in May 2026

As of May 2026, there are 9 SaaS companies in Interactive Application Security Testing (IAST) Software. They have combined revenues of $264.4M and employ 1.7K people. They have raised $245M and serve 2.8M customers combined.

Interactive Application Security Testing (IAST) Software is a security testing methodology designed to identify vulnerabilities within applications in real time. By monitoring application behavior during various testing processes, such as quality assurance (QA) or automated testing, IAST tools analyze code execution, data flow, and system responses, providing immediate feedback on security issues. The primary use cases of IAST include vulnerability detection during the application development cycle, production monitoring, and integration with continuous integration/continuous deployment (CI/CD) pipelines. Typical features include automated scanning, real-time risk assessment, and reporting capabilities that assist development and security teams in ensuring the security posture of applications. Common buyer personas include security analysts, application developers, and quality assurance professionals who seek to enhance application security measures throughout the software development lifecycle.

Companies
9
Revenue
$264.4M
Funding
$245M
Employees
1.7K

Filters

Sorting: Highest -> Lowest

Filters

Top Interactive Application Security Testing (IAST) Software Companies

Showing 10 of 9 companies ranked by annual revenue.

1
Contrast Security

Los Altos, California, United States

Contrast Security is the only Application and API Security platform purpose-built to detect and stop live application-layer attacks. It delivers real-time and always-on application security inside applications and APIs.

Revenue
$91.7M
Customers
-
Year founded
2014
Funding
$245M
Team size
240
Growth
-
2
Positive Technologies

United States

Positive Technologies is a leading developer of products, solutions and services for result-driven cybersecurity that enable detection and prevention of attacks before they cause unacceptable damage to businesses and entire economic sectors. The company's technology portfolio covers most categories of information security tools and continues to expand. We create meta-products โ€” a new generation of tools for achieving effective cybersecurity with minimal human involvement. For over 20 years, we've been creating and implementing technologies that demonstrate real results in cybersecurity and radically improve our clients' security levels.

Revenue
$78.3M
Customers
-
Year founded
-
Funding
-
Team size
712
Growth
-
3
PortSwigger

Knutsford, Cheshire, United Kingdom

PortSwigger is a global leader in cybersecurity, specializing in web application security testing. They created Burp Suite, the leading toolkit for web application security testing.

Revenue
$35.7M
Customers
-
Year founded
2008
Funding
-
Team size
254
Growth
-
4
Semgrep

San Francisco, California, United States

Semgrep is an application security platform that scans code for bugs and security vulnerabilities, helping developers to write secure code.

Revenue
$33.6M
Customers
-
Year founded
2017
Funding
-
Team size
210
Growth
-
5
NowSecure

Chicago, Illinois, United States

NowSecure is the leader in Mobile Application Risk Management, providing automated and human-augmented testing solutions that deliver speed, depth, and accuracy to protect the mobile ecosystem. Trusted by hundreds of enterprises, government agencies, and global brands, NowSecure helps organizations accelerate mobile innovation while managing security and privacy risks with confidence.

Revenue
$11.7M
Customers
-
Year founded
2009
Funding
-
Team size
106
Growth
-
6
eShard

Pessac, Nouvelle-Aquitaine, France

Expertise in cybersecurity testing takes years to build but can be lost in seconds. When tools are disconnected, teams work in silos, and critical knowledge isnโ€™t shared, security weakens. We believe in a holistic approach, where tools, teams, and expertise are interconnected in a single environment to ensure efficiency, consistency, and long-term knowledge retention. At eShard, we help industrial leaders and government agencies take control of ๐—ฐ๐—ต๐—ถ๐—ฝ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด and ๐—ฏ๐—ถ๐—ป๐—ฎ๐—ฟ๐˜† ๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€. Our platform provides a dedicated testing environment where teams can analyze vulnerabilities, assess security risks, and refine their expertise without the risk of losing critical knowledge when key people move on. Alongside our software platform, we provide hardware equipment, training services, and security assessments to ensure teams have the right resources and skills to tackle real-world security challenges. We are fully independent and self-funded company, committed to equipping security teams all around the world with the right tools and expertise to master risks, strengthen systems, and make informed decisions.

Revenue
$5.3M
Customers
-
Year founded
2015
Funding
-
Team size
48
Growth
-
7
Data Theorem

Palo Alto, California, United States

Developer of a cloud based mobile application scanner designed to scan and secure mobile applications. The company's cloud based mobile application scanner automatically detects security breaches, flaws and data privacy gaps and locks down the high-risk areas of mobile applications, enabling individuals to secure and protect their mobile applications.

Revenue
$3.9M
Customers
2.8M
Year founded
2013
Funding
-
Team size
93
Growth
84.28%
8
Akto.io

San Francisco, California, United States

Built for Modern AI Security Teams. Akto is the Agentic AI Security platform for your teams to secure AI agents, MCPs, and LLMs in your organization. Akto's platform helps teams build their Agentic AI Security program through Discovery, Governance, red teaming, monitoring, and enforcing guardrails on Agentic AI assets. 100+ Modern AI Security teams globally trust Akto for: - MCP Security - AI Agent Security Akto is headquartered in San Francisco and backed by leading venture capital firms, including Accel Partners and Alumni Ventures, with angel and advisory from Tenable Founder, Notion Founder, Sentry CEO, Jim Manico, and Synack CTO, among others. Akto has been featured in Forbes, Nasdaq, Dark Reading, Venture Beat, and CSO Online as one of the cybersecurity startups to watch. Akto is a representative vendor in Gartnerยฎ Market Guide for API Protection, Gartnerยฎ Hype Cycle for APIs, and Gartnerยฎ Hype Cycle for Application Security.

Revenue
$2.8M
Customers
-
Year founded
2022
Funding
-
Team size
25
Growth
-
9
GuardRails

Singapore, Singapore, Singapore

GuardRails is a continuous application security verification platform that empowers modern development teams to find, fix and prevent vulnerabilities related to source code, open source libraries, secret management and cloud configuration.

Revenue
$1.4M
Customers
-
Year founded
2017
Funding
-
Team size
13
Growth
-

Inclusion Criteria

- The software must provide real-time monitoring of applications to identify vulnerabilities during runtime. - It should integrate with existing development workflows and tools, such as CI/CD pipelines. - The product must offer automated scanning capabilities to assess application security continuously. - It should provide detailed reporting on vulnerabilities and security risks discovered. - The tool must support both static and dynamic analysis techniques, not just one method exclusively. - It must cater to software development teams, including application developers and security analysts.

Interactive Application Security Testing (IAST) Software SaaS Companies | GetLatka