SaaS Ranking

Certifications named in Vulnerability management

Naming SOC 2 or ISO 27001 publicly is the low bar; not naming them is a signal.

5 of 11 vendors we measured here publish it, that is 45%. Last checked 2026-09-02.

45% here against 33% across every category we measure. Vulnerability management sits above the overall share for this criterion.

Back to Certifications named across all categories, or to Vulnerability management.

Published

SOC 2 or ISO 27001 named on a public page.

VendorWhat we found
Aqua Security https://www.aquasec.com/trust/trust-center/
Checkmarx https://checkmarx.com/trust/
Mend https://www.mend.io/trust/
StackHawk https://www.stackhawk.com/security
Wiz https://www.wiz.io/trust-center

No named certification found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
Acunetix 6 addresses checked
Black Duck 6 addresses checked
Bright Security 6 addresses checked
Brinqa 6 addresses checked
Greenbone 6 addresses checked
JFrog 6 addresses checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Balbix The vendor’s server blocked or rate-limited our crawler, so this was not measured.

Found something we missed? Tell us and the next run picks it up.