Off the Bit
Tools: Security and secrets
Category: Catalogue
Count: 45 catalogued, 3 not answering
Security and secrets
Scanning, identity and secret handling.
45 tools, described from their own homepages and last
checked 2026-09-04. 3 of those homepages did not answer. None of them is used to build this site. A row is a description, not an endorsement.
All 45
Alphabetical. Checked on 2026-09-04; anything that did not answer says so.
- Fine-grained authorization as a service, so permission checks stop being scattered if-statements.Pulls authorization out of the handlers.
- Hosted identity: login, federation, multi-factor and the standards work nobody wants to implement twice.Made buying authentication respectable.
- Amazon's managed identity for consumer applications, priced and scaled for very large user pools.Identity, if you are already inside AWS.
- Static analysis for security and privacy risk, focused on where sensitive data flows. Acquired by Cycode.Absorbed: the page now belongs to the acquirer.
- The open-source scanner behind Bearer. Finds and ranks security and privacy risk in source, and still runs on its own.The engine outlived the company page.
- Open-source SAML and OIDC single sign-on, so enterprise login is not a rewrite. The address now serves Ory.The enterprise SSO checkbox, as a library.
- Enterprise application security, combining several scan types and consolidating findings into one risk view.Sold to the security organisation, not the developer.
- Authentication with the interface components included, built for React and Next.js first.Ships the login screen, not only the endpoint.
- Code Intelligence CI Fuzz the domain does not resolveAutomated fuzz testing for C and C++ in CI. The domain no longer resolves.Gone: the domain does not resolve.
- Passkey rollout and analytics on top of an existing identity provider rather than in place of one.Adds passkeys without replacing what you already run.
- Finds, triages and fixes vulnerabilities across code, packages, infrastructure and containers.Triage is the product; detection is table stakes.
- Secret management that syncs into every environment and runtime, so configuration stops living in a shared file.Kills the .env everyone emailed each other.
- Application security aimed at reachability: whether a vulnerable function is actually called, not only present.Answers whether the vulnerability is reachable.
- Envkey the domain does not resolveEnd-to-end encrypted environment and secret syncing. The domain no longer resolves.Gone: the domain does not resolve.
- Firebase's authentication, including federated providers and phone sign-in, usable without the rest of the suite.The part of Firebase people adopt on its own.
- Full identity and user management, downloadable and self-hostable with no per-user pricing pressure.Auth you can run on your own hardware and read the source of.
- Security analysis that reasons about a codebase as a whole rather than matching patterns file by file.Argues that context is what pattern matching lacks.
- Secret detection across repositories, history and connected tools, plus an inventory of the non-human identities those secrets belong to.Finds the key you committed in 2019 and forgot.
- Continuous secure code review from a company whose main business is paying people to break software.Backed by an actual bug bounty population.
- Open-source passkey and passwordless authentication, self-hostable, with the data staying yours.Passkeys without handing identity to a vendor.
- Open-source secret and identity management covering people, machines and agents, self-hostable.Secrets for the machines as well as the staff.
- Scans artifacts in the repository for open-source risk, with lineage across the build chain.Scans the artifact, not only the manifest.
- Extends Postgres row-level security to cover API key authentication, keeping authorization in the database.Auth stays in the place that holds the data.
- Authentication, access management and billing together, on the argument that a SaaS needs all three on day one.Bundles the two things every SaaS builds twice.
- Customer identity and access management with residency and privacy compliance as the selling point.Sold on where the identity data is allowed to sit.
- Formerly WhiteSource. Application and dependency security, now extended to cover model and agent risk.Renamed once, repositioned twice.
- Passwordless authentication that stores no passwords at all, removing the credential database as a target.Nothing to breach if nothing is stored.
- Finds vulnerabilities, proves they are real, and pushes each fix to the owner until it merges.Chases the fix, not just the finding.
- Enterprise identity and single sign-on, the default in organisations large enough to have an identity team.The identity provider your customer's security review expects.
- Open-source identity and access management, API-first and self-hostable, assembled from separate services.Identity as components you can run yourself.
- Authorization for agents in production: access control, monitoring and least privilege applied automatically.Answers what the agent is allowed to touch.
- Authorization as a service with policy as code, covering role, attribute and relationship models.Permissions as a policy file, not scattered checks.
- Business-to-business authentication with organisations, roles and self-service admin built in.Multi-tenancy assumed from the start.
- Identity built for agents: delegated identity, scoped permissions, tool calling and an audit trail.Answers who the agent is acting as.
- Socket the site refused an automated requestSupply chain security that inspects what a dependency actually does, rather than only checking it against a vulnerability list. The site refused an automated request.Reads the package's behaviour, not just its version.
- Adds enterprise single sign-on to an existing product without rewriting its authentication.The enterprise checkbox, without the rebuild.
- Listed as open-source authentication. The address now presents Hexclave, a broader platform including payments and analytics.Widened its scope and its name.
- Authentication APIs with fraud and device intelligence attached, covering passwordless and enterprise flows.Auth with the fraud problem included.
- Open-source authentication you self-host, with the session logic readable rather than opaque.Auth you can step through in a debugger.
- Finds sensitive data, maps who can reach it, and enforces policy while the system is running.Data security applied at runtime, not in a report.
- API key management, rate limiting and gateway observability as one platform.The key-handling code you were about to write again.
- Listed as authentication infrastructure. The address now presents a compliance-focused AI productivity product.Repositioned into a different market.
- HashiCorp's secret management: dynamic credentials, leases and encryption as a service. Set the pattern for the category.Made short-lived credentials a realistic thing to run.
- Software composition analysis from manifest files alone, with no agent to install.Scans the lockfile, installs nothing.
- The enterprise feature set as APIs: single sign-on, directory sync and audit logs, sold as the fastest route through a security review.Sells the enterprise checklist as a library.
Other shelves
115AI assistants and agents 88Workflow and productivity 66Testing and code quality 41Models and AI infrastructure 41Monitoring and analytics 35Data, APIs and backends 34CI, CD and infrastructure 31Docs and content 29Payments and messaging 22Hosting and cloud 18Terminal and CLI 16Design and media 10Editors and IDEs
ImranTools[Security and secrets]