Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
OpenText Static Application Security Testing (SAST) provides precise identification and remediation of application security flaws directly within source code, helping organizations reduce risks early in development. The platform supports over 33 major programming languages and frameworks, enabling broad language coverage for diverse development environments. It integrates smoothly with widely used CI/CD pipelines and developer tools such as Jenkins, Atlassian Bamboo, Azure DevOps, and Microsoft Visual Studio, ensuring security fits naturally into existing workflows. AI-driven analysis prioritizes vulnerabilities and dramatically reduces false positives by customizing rules and scan depths, speeding up development cycles by up to 25%. OpenText SAST meets compliance benchmarks like OWASP 1.2b, offering developers detailed guidance to efficiently fix issues and improve code quality. Its flexible deployment options include multi-tenant SaaS, private cloud, and on-premises installations, allowing organizations to scale securely and according to their infrastructure needs. Backed by a dedicated Software Security Research team, the solution receives agile updates to stay current with emerging threats. Customers praise the tool for reducing manual code review efforts while increasing vulnerability detection accuracy.
Description
The YAG Suite is a French-made innovative tool that takes SAST to the next level. YAGAAN is a combination of static analysis and machine-learning. It offers customers more than a sourcecode scanner. It also offers a smart suite to support application security audits and security and privacy through DevSecOps design processes. The YAG-Suite supports developers in understanding the vulnerability causes and consequences. It goes beyond traditional vulnerability detection. Its contextual remediation helps them to quickly fix the problem and improve their secure coding skills. YAG-Suite's unique 'code mining' allows for security investigations of unknown applications. It maps all relevant security mechanisms and provides querying capabilities to search out 0-days and other non-automatically detectable risks. PHP, Java and Python are currently supported. Next languages in roadmap are JS, C and C++.
API Access
Has API
No
API Access
Has API
Yes
Integrations
GitHub
Yes
Jenkins
Yes
Amazon Web Services (AWS)
Yes
Bamboo
Yes
Bitbucket
Yes
Bugzilla
Yes
Harness
Yes
HivePro Uni5
Yes
Jira
Yes
Maverix
Yes
Integrations
GitHub
Yes
Jenkins
Yes
Amazon Web Services (AWS)
No
Bamboo
No
Bitbucket
No
Bugzilla
No
Harness
No
HivePro Uni5
No
Jira
No
Maverix
No
Pricing Details
No price information available.
Free Trial
Yes
Free Version
No
Pricing Details
From €500/token or €150/mo
Subscription: SaaS from €150/month/100kLoc
On premise from €215/month/100kLoc
Subscriptions are based on the number of lines of code to scan, no limit on the number of scans / users / projects.
Tokens are valid for per application
On premise from €215/month/100kLoc
Subscriptions are based on the number of lines of code to scan, no limit on the number of scans / users / projects.
Tokens are valid for per application
Free Trial
Yes
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
Yes
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
No
Vendor Details
Company Name
OpenText
Founded
1991
Country
Canada
Website
www.opentext.com/products/static-application-security-testing
Vendor Details
Company Name
YAGAAN
Founded
2017
Country
France
Website
yagaan.com
Product Features
Application Security
Analytics / Reporting
Yes
Open Source Component Monitoring
Yes
Source Code Analysis
Yes
Third-Party Tools Integration
Yes
Training Resources
Yes
Vulnerability Detection
Yes
Vulnerability Remediation
Yes
Static Application Security Testing (SAST)
Application Security
No
Dashboard
No
Debugging
No
Deployment Management
No
IDE
No
Multi-Language Scanning
No
Real-Time Analytics
No
Source Code Scanning
No
Vulnerability Scanning
No
Static Code Analysis
Analytics / Reporting
No
Code Standardization / Validation
No
Multiple Programming Language Support
No
Provides Recommendations
No
Standard Security/Industry Libraries
No
Vulnerability Management
No
Product Features
Static Application Security Testing (SAST)
Application Security
Yes
Dashboard
Yes
Debugging
No
Deployment Management
No
IDE
Yes
Multi-Language Scanning
Yes
Real-Time Analytics
No
Source Code Scanning
Yes
Vulnerability Scanning
Yes
Static Code Analysis
Analytics / Reporting
Yes
Code Standardization / Validation
Yes
Multiple Programming Language Support
Yes
Provides Recommendations
Yes
Standard Security/Industry Libraries
Yes
Vulnerability Management
Yes
Vulnerability Scanners
Asset Discovery
No
Black Box Scanning
No
Compliance Monitoring
No
Continuous Monitoring
No
Defect Tracking
No
Interactive Scanning
No
Logging and Reporting
No
Network Mapping
No
Perimeter Scanning
No
Risk Analysis
No
Threat Intelligence
No
Web Inspection
No