"Efficient and Responsive"
We use OX as our code security solution. The platform automatically scans our codebase and Pull Requests, and creates Jira tickets for security findings based on multiple criteria, routing them directly to the responsible teams. This automation has made OX our single source of truth for code security, enabling our RnD, SecOps, and Product teams to effectively manage the security fix lifecycle. OX could be even more effective with the ability to rescan specific code after Jira issues are marked as resolved, and by adding an option to scan individual repositories or projects rather than requiring full codebase scans. OX Security solves two critical challenges in our code security management: automated vulnerability detection (including licensing issues, IaC misconfigurations, exposed secrets) and streamlined remediation workflow.
"Essential Platform for Streamlined Security and Development"
OX Security has significantly enhanced our security posture with its seamless integrations, especially with GitLab, Jira, and Slack, which keep our team proactive and efficient. The platform's combination of SAST and open-source checks under one tool is a major win, streamlining security processes and offering in-depth insights across our cloud and CI/CD environments. While the platform already covers a lot, there are a few features we'd love to see in future updates, like enhanced reporting options and more GCP integrations. These would make an already excellent tool even more robust, and I'm excited to see how OX Security evolves over time! OX Security addresses several critical challenges in our security workflow. By integrating seamlessly with our CI/CD pipeline, it helps us identify vulnerabilities and security issues early in the development process, reducing the likelihood of vulnerabilities reaching production.
"The Best ASPM with a Native Application Security Tool"
Ox Security brings together various tools into a single dashboard by integrating with multiple vendors, offering holistic visibility and seamless AI-powered integrations to aid in issue resolution. Additionally, OX Security offers an on-premises solution, which I find especially valuable since many organizations prefer not to upload their code to third-party platforms. With the on-premises option, code scanning happens locally, keeping code secure within the organization's own infrastructure. If OX had a data center in India, it would be fantastic for the Indian market, but it's still manageable due to the certifications they hold to ensure data security. Plus, they offer on-premises solutions. It helped me correlate issues and eliminate duplication, leading to a more streamlined workflow. Instead of jumping between multiple tools, OX Security provides a single dashboard that consolidates everything into one clear, accessible view.
"Outstanding Performance and Support from OX Security"
OX Security delivers unmatched precision and support, outperforming competitors in all areas. The technical support is exceptional, with quick responses and genuine assistance throughout integration and management. The tool's comprehensive nature ensures robust protection with minimal setup, making it efficient and easy to implement. The deployment process is fast and intuitive, enabling seamless implementation of the full security suite in a production environment. The only downside is the lack of full GCP integration, but we're set to access the beta version soon, and they're already working on it—amazing! OX Security replaces dozens of open-source tools, centralizing results and management in one powerful platform. This consolidation improves efficiency and effectiveness by providing a unified view of security across all repositories, enhancing oversight and simplifying vulnerability management. With OX Security, we see higher detection accuracy and streamlined operations, allowing our team to focus on the most critical security issues.
C
CTO, Lead Developer, Software Architect, Team Lead
"It Simply Works!"
I have to admit it has many features we've only begun to explore. But from the initial scans, we were already impressed by the number of detections it made. It's advanced if you need it, but also straightforward to use. If something is missing, they're happy to add it to the scanning. We mainly use it for GitLab repo code security scanning, but you can also use it in your CI/CD pipeline. What's great about OX is they let you do a POC first, and if you're satisfied, you can continue. Integration is as simple as pointing it to your Git repository, and it can generate Jira tickets for you if desired. When you start using it, they provide onboarding sessions, and afterward, you can have recurring calls to resolve issues or discuss new features. It's been a great experience from start to finish with OX. No downsides yet. We're enjoying the product. It speeds up code security checks, reducing the need for extensive penetration testing.
"Revolutionary for SSDLC and SAST"
1. The platform's smooth integration with our current tools enables quick team adoption.
2. It covers static code analysis and supply chain risks, ensuring thorough security coverage.
3. The intuitive interface makes it easy for diverse teams to navigate and extract insights.
4. Customizable Workflows: The ability to adjust certain aspects of the scanning process helps align with our internal security policies.
5. Detecting vulnerabilities at the time of code commits is a game-changer, allowing us to address risks early in the development cycle.
6. Clean and Intuitive UI: The dashboard is straightforward, making it easy to move between modules and access actionable insights without overload.
7. Excellent Customer Support: The support teams are responsive and proactive, ensuring smooth onboarding and timely assistance with configuration or technical issues.
1. Language Coverage Gaps: The platform is robust but lacks full support for C++ (currently being added gradually) and .NET, which could limit usability in some environments.
2. SIEM Integration: Connecting OX Security to SIEM systems could be improved, as not all SIEM platforms are listed in connectors, requiring support contact. OX Security helps us reduce risks and vulnerabilities in our code and repositories by identifying issues early and managing third-party dependency risks, ensuring our software is secure and minimizing supply chain threats.
S
Small-Business (50 or fewer emp.)
"OX is Truly Impacting Security"
Setting up was a breeze. It allows our DevSecOps and development teams to focus on actual problems rather than checking boxes. We receive excellent customer success support that helps us integrate OX into our company's practices. We check the OX dashboard and related Jira dashboards every morning to monitor for potential issues. Jira integration still has room for improvement, but it gives us confidence that we're catching security flaws before attackers do.
"A Revolutionary Shift in Application Security Posture Management"
OX Security's ASPM solution is outstanding at providing a comprehensive, end-to-end perspective on security posture throughout the entire software development lifecycle. The platform's straightforward interface makes it simple to spot vulnerabilities early, prioritize critical issues, and streamline remediation efforts. I especially value the seamless integrations with existing DevOps tools, which ensure that security insights flow naturally into development workflows without causing delays. The real-time visibility and actionable insights from OX Security promote a security-first culture, boosting both our development team's confidence and the resilience of our applications. Although OX Security's ASPM platform is robust and feature-rich, it can be slightly overwhelming for newcomers. The abundance of options and detailed analytics may require a short learning period for new team members. However, with a bit of time and the helpful documentation, our team quickly adapted and now fully utilizes all the platform's capabilities. OX Security addresses the fundamental challenge of maintaining a consistent and holistic security approach throughout the software lifecycle. Traditionally, teams had to manage disparate tools, decipher complex vulnerability reports, and align security measures with rapid development cycles. OX Security's ASPM consolidates these efforts into a single integrated platform, eliminating the need to switch between multiple dashboards, guess which vulnerabilities to fix first, or deal with miscommunication between development and security teams. This integrated visibility dramatically improves our efficiency, flagging potential issues at the earliest stages so the team can address them before they escalate. By simplifying our security workflows, OX Security not only saves valuable engineering time but also significantly reduces the risk of critical vulnerabilities reaching production. The result is faster, more secure releases, greater confidence, and a stronger security posture as we continue to grow.
M
Mid-Market (51-1000 emp.)
"A Robust, All-Encompassing Tool Meeting Security Testing Standards"
OX provides thorough security testing and evaluation features that fulfill the essential needs of a security-conscious organization. The user-friendly dashboard offers a centralized, consistent method for handling issues, ensuring smooth tracking and resolution. A broad range of plugins allows effortless integration with various ticketing systems for issue management and also enables the import of results from other security tools. Most of these integrations are straightforward to set up. A standout feature is the pipeline functionality, which enables the creation of custom workflows based on scan results, making prevention and notification processes highly flexible. In addition, OX is supported by a well-organized and responsive support team, ensuring constant availability and fast handling of questions and feedback. Some features lack proper documentation, and certain testing capabilities are not fully developed yet. Moreover, adding more external security testing tool plugins would improve functionality, but many of these enhancements are already on the roadmap. The platform offers comprehensive security visibility across the entire development lifecycle, from code creation and storage to testing, deployment, and infrastructure management. With all features integrated into a single, well-designed platform, issue management becomes effortless. The tool recalculates issue priorities in real time based on insights from the development and deployment process, ensuring context-aware risk assessment. Its powerful pipeline system allows for automated notifications to relevant teams depending on the issue's source and type, while also enforcing security policies by blocking new code when forbidden issue types are detected.
"Comprehensive Security Solution with Smooth Integration"
The Agentic Pentester carried out a white-box security review of our applications and uncovered several serious issues. This deep testing was enabled by OX's scanning of our code repositories and analysis of the source code, leading to more precise and potent penetration testing. The Agentic Pentester and DAST modules are steadily improving and are becoming valuable for an all-in-one, integrated view. I rely on OX Security for monitoring GitHub security status and managing vulnerabilities. It fits seamlessly with our existing tools, improving efficiency and cost-effectiveness through a unified approach. Moving from Snyk was driven by the desire for better integration and automation, which has simplified our security management.