Security Scanning

Vulnerability scanning, SAST, dependency scanning, and security testing.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
Prowler Top Pick
Prowler is the worldโ€™s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
OSI-approved OSS
14k stars Active 100
02
Zero-configuration mesh VPN for business.
OSI-approved OSS
25.8k stars Active 100
03
Open-source API security platform for discovery, posture, and CI/CD testing.
OSI-approved OSS
1.5k stars Active 99

Proprietary targets

Replacement targets, not open-tool picks

01
Cloud-native security platform for protecting build and runtime environments.
Active 96
02
Self-hostable secrets management platform and open-source Doppler alternative.
Active 86
03
Agent-based Docker security audit platform with CIS benchmark compliance and remediation.
Warning 81

1 tool is on Evidence Watch.

Identity & Access Management

Authentication, authorization, SSO, identity, and access management tools.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
Authentik Top Pick
The authentication glue you need.
OSI-approved OSS
21.9k stars Active 99
02
Identity and access management product by WSO2.
OSI-approved OSS
228 stars Active 97
03
Open Source Identity and Access Management For Modern Applications and Services
OSI-approved OSS
34.8k stars Active 96

Proprietary targets

Replacement targets, not open-tool picks

01
Password manager for teams and individuals
Active 98
02
Open-source Auth0/Clerk alternative
Active 96
03
Password manager for teams and families
Active 78

1 tool is on Evidence Watch.

VPN & Network Security

VPNs, tunnels, zero-trust networking, and secure access tools.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
Tailscale Top Pick
Zero-config VPN built on WireGuard
OSI-approved OSS
32.3k stars Active 98
02
Identity-aware VPN and tunneled reverse proxy for remote access.
OSI-approved OSS
21k stars Active 94
03
Enterprise-ready zero-trust access platform built on WireGuardยฎ.
OSI-approved OSS
8.6k stars Active 93

Proprietary targets

Replacement targets, not open-tool picks

01
๐Ÿ’š Secure remote browsing anywhere, any way you like it.
Warning 75

Governance, Risk & Compliance

Tools for GRC workflows including evidence collection, control mapping, compliance auditing, risk management, and gap analysis.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
The Open Lane Top Pick
Open source compliance automation for SOC 2, GDPR, ISO27001, NIST 800-53, and more
OSI-approved OSS
258 stars Active 96
02
AI Native platform to get companies compliant - Vanta & Drata Alternative
OSI-approved OSS
1.6k stars Active 95
03
Open source solutions for SOC 2, GDPR, and ISO27001.
OSI-approved OSS
1.1k stars Active 93

Proprietary targets

Replacement targets, not open-tool picks

01
Open-source GRC platform for risk management, compliance, audit, TPRM, privacy, and reporting.
Active 99
02
AI governance and evaluation platform for policy and compliance frameworks.
Active 94
03
CLI for AI code attribution and governance.
Warning 75

Secrets Management

Tools for storing, managing, rotating, and distributing application secrets, certificates, keys, and privileged credentials.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
Infisical Top Pick
Infisical is the open-source platform for secrets, certificates, and privileged access management.
OSI-approved OSS
27.3k stars Active 97
02
Open-source credential vault for AI agents.
OSI-approved OSS
2.3k stars Active 96
03
Application secrets and configuration management for developers.
OSI-approved OSS
868 stars Active 94

Proprietary targets

Replacement targets, not open-tool picks

01
High-performance secrets management system.
Warning 66

Security Monitoring & Threat Hunting

Security operations tools for monitoring logs and networks, investigating incidents, detecting intrusions, and hunting threats.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
InnerWarden Top Pick
Autonomous EDR for Linux with kernel-level eBPF detection and AI triage.
OSI-approved OSS
155 stars Active 90
02
Private-cloud XDR and SIEM platform for detection engineering and SOC workflows.
OSI-approved OSS
1 stars Active 88
03
Open-source unified security operations & threat intelligence platform for OT/ICS environments with ontology-driven dashboards
OSI-approved OSS
โ€” stars Warning 75

Proprietary targets

Replacement targets, not open-tool picks

01
Open platform for threat hunting, security monitoring, and log management.
Active 89
02
SEKOIA.IO Documentation - The Intelligence-Driven SaaS SIEM
Active 81

Password Management

Password managers and credential vaults for generating, storing, syncing, and managing user passwords.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
LessPass Top Pick
:key: stateless open source password manager
OSI-approved OSS
6k stars Warning 54
02
Open-source cross-platform password manager.
OSI-approved OSS
0 stars Critical 46
03
Open-source cross-platform password manager.
OSI-approved OSS
0 stars Critical 34

Proprietary targets

Replacement targets, not open-tool picks

01
Open-source password manager and encrypted data management platform.
Critical 23

Secure Secret Sharing

Tools for securely sending sensitive information through expiring, encrypted, single-use, or access-limited links.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
PasswordPusher Top Pick
๐Ÿ” Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.
OSI-approved OSS
โ€” stars Active 96
02
Share sensitive information once and then destroy the secret link.
OSI-approved OSS
2.8k stars Active 90
03
Keep your sensitive information out of chat logs, emails, and more with encrypted secrets.
OSI-approved OSS
โ€” stars Warning 68

AI Agent Governance

Tools for controlling AI agent permissions, consent, spend limits, policy enforcement, and auditability.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
ArifOS Top Pick
Governed AI execution platform with architect, auditor, and agent roles.
OSI-approved OSS
45 stars Active 91
02
Control layer for AI agents covering permissions, consent, spending limits, and audit logging.
OSI-approved OSS
3 stars Warning 83

Video Surveillance

Tools for monitoring security cameras and surveillance footage with NVR, object detection, alerts, tracking, and video search.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
clearcam Top Pick
Add object detection, tracking, mobile notifications, and search to any security camera.
OSI-approved OSS
724 stars Warning 75
02
Open-source AI camera skills platform and AI NVR for CCTV surveillance.
OSI-approved OSS
2.8k stars Warning 61

Email Security

Tools for detecting, preventing, and investigating email-based threats such as phishing and malicious messages.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
sublime-rules Top Pick
Sublime rules for email attack detection, prevention, and threat hunting.
OSI-approved OSS
364 stars Active 79

Pentest & Red Team Operations

Platforms for managing collaborative penetration testing and red team workflows, including findings, reporting, and coordination.

Open ranking โ†’

Open/source-visible picks

Health-first ToolVitals score, then adoption

01
Cervantes Top Pick
Open-source collaborative platform for pentesters and red teams.
OSI-approved OSS
438 stars Critical 35

Awaiting Use-Case Review

These tools fit this broad category, but still need a more specific use-case assignment.

No scored tools in this use case yet.

23 tools are on Evidence Watch.