SaaS Ranking

Alternatives to Wiz

Other Vulnerability management vendors we measure, sorted by how much they publish that Wiz does not. This is a comparison of disclosure, not of features or fitness.

12 shown of 24 that differ from Wiz on at least one criterion we measured for both. Public transparency score, not a product or security rating.

Wiz has 5 gaps in what we could measure: Subprocessor list, Public pricing, Uptime SLA with a figure, No third-party tracking before consent, Notice before subprocessors change. The column “publishes and Wiz does not” is the one that closes them.

VendorScorePublishes, and Wiz does notWiz publishes, and they do not
Invictiinvicti.com 83/100 4 Subprocessor list, Public pricing, Uptime SLA with a figure, +1 1 Status page with history Compare
Snyksnyk.io 61/100 2 Public pricing, Notice before subprocessors change 1 Data location stated Compare
Intruderintruder.io 57/100 2 Public pricing, Notice before subprocessors change 3 Status page with history, security.txt (RFC 9116), Named privacy contact Compare
SonarSourcesonarsource.com 48/100 2 Subprocessor list, Public pricing 4 Data location stated, Status page with history, security.txt (RFC 9116), +1 Compare
Holm Securityholmsecurity.com 52/100 1 Subprocessor list 2 Data processing agreement, security.txt (RFC 9116) Compare
Mendmend.io 50/100 1 Public pricing 1 Data processing agreement Compare
Semgrepsemgrep.dev 48/100 1 Public pricing 2 Data processing agreement, Named privacy contact Compare
Detectifydetectify.com 43/100 1 Public pricing 2 Data location stated, Status page with history Compare
Acunetixacunetix.com 39/100 1 Public pricing 3 Data processing agreement, Status page with history, Certifications named Compare
Aqua Securityaquasec.com 39/100 1 Subprocessor list 3 Data processing agreement, Data location stated, security.txt (RFC 9116) Compare
JFrogjfrog.com 39/100 1 Public pricing 3 Data processing agreement, Status page with history, Certifications named Compare
StackHawkstackhawk.com 30/100 1 Public pricing 3 Data processing agreement, Data location stated, HTTPS enforced with HSTS Compare

Only criteria we could measure for both are counted. Where we could measure one and not the other, the row is silent: that would be a statement about our measurement, not about either vendor. Every single result with its source is on the two profiles.