Listing Thumbnail

    Jit Security

     Info
    Sold by: Jit 
    Deployed on AWS
    Accelerate your Product Security program with a native and dev-friendly experience. Jit's DevSecOps Management Platform provides full Security Posture visibility and success KPIs, orchestrating and unifying dozens of security tools covering your whole SDLC.

    Overview

    Jit provides a single-pane-of-glass of all AppSec & DevSecOps tooling, with a native developer experience and fast & simple rollout, thanks to its orchestration framework. Get to 100% coverage of all repos, cloud, WebApps and API assets, across dozens of security tools - in minutes, by selecting from various security plans.

    Developers enjoy a unified experience of smart in-PR security tests and auto-remediation, without suffering from a vulnerability flood. Measure your Product Security program with a consolidated dashboard and DevSecOps performance metrics.

    Developers enjoy a unified experience of smart in-PR security tests and auto-remediation, without suffering from a vulnerability flood. Measure your Product Security program with a consolidated dashboard and DevSecOps performance metrics.

    Highlights

    • Unified Platform of your Entire AppSec & DevSecOps Toolchain (Code, CI/CD pipeline, Infrastructure & Runtime).
    • Native Developer Experience and Fix 1st Mindset. In-PR feedback loop, with the vulnerability location, severity, context & (auto-)remediation, as a comment on your PRs in your native workflow.
    • Full Security Posture Visibility and DevSecOps Program Success KPIs. Get visibility into your engineering organization's ongoing security posture, as well as trends and actionable items to follow.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Jit Security

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (10)

     Info
    Dimension
    Description
    Cost/12 months
    Initial subscription
    Up to 5 developers, , Unlimited Scans, Remediation capabilities
    $3,000.00
    Getting Started
    5 developers, Unlimited Scans, Remediation capabilities
    $3,000.00
    Startup Team
    20 developers, Unlimited Scans, Remediation capabilities
    $12,000.00
    Small Team
    30 developers, Unlimited Scans, Remediation capabilities
    $18,000.00
    Intermediate Team
    40 developers, Unlimited Scans, Remediation capabilities
    $24,000.00
    Medium Team
    50 developers, Unlimited Scans, Remediation capabilities
    $30,000.00
    Growth Team
    75 developers, Unlimited Scans, Remediation capabilities
    $45,000.00
    Large Team
    100 developers, Unlimited Scans, Remediation capabilities
    $60,000.00
    X-large Team
    200 developers, Unlimited Scans, Remediation capabilities
    $160,000.00
    Enterprise Subscription
    Custom Seats, Unlimited Scans, Remediation capabilities
    $200,000.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/user/hour
    Extra Developers
    $600.00

    Vendor refund policy

    All fees are non-cancellable and non-refundable except as required by law. In any case, contact us at support@jit.io .

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Continuous Integration and Continuous Delivery
    Top
    100
    In Testing
    Top
    50
    In Infrastructure as Code

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Security Tool Orchestration
    Unified platform integrating multiple security tools across code, CI/CD pipeline, infrastructure, and runtime environments
    Automated Vulnerability Detection
    Smart in-PR security testing with contextual vulnerability identification and severity assessment
    Continuous Security Monitoring
    Comprehensive security posture tracking with real-time visibility into engineering organization's security status
    Remediation Workflow
    Automated vulnerability remediation with contextual feedback and suggested fixes directly in pull request workflow
    Multi-Asset Security Coverage
    Comprehensive security scanning across repositories, cloud infrastructure, web applications, and API assets
    Application Security Testing
    Comprehensive security testing approach including static (SAST), dynamic (DAST), interactive (IAST), and mobile (MAST) application testing methodologies
    DevOps Integration
    Seamless integration into existing development toolchains with support for CI/CD pipelines, RESTful APIs, and plugins for ecosystem partners
    Multi-Language Vulnerability Detection
    Detects vulnerabilities across 29 programming languages with coverage of over 1 million individual APIs
    Software Supply Chain Security
    Precise identification and matching of risks in custom code and third-party components with proprietary research data
    Compliance Certification
    FedRAMP certified and JAB authorized security solution with Department of Defense Enterprise DevSecOps compliance
    Vulnerability Correlation and Traceability
    Risk Intelligence Graph provides comprehensive code to cloud traceability, enabling correlation, prioritization, and root cause identification of vulnerabilities across software development lifecycle
    Code Security Scanning
    Native and integrated scanning capabilities for multiple security domains including Secrets, Leakage, SAST, SCA, and Container security
    Threat Intelligence
    Proactive security notifications with out-of-the-box policies for zero-day attacks and threats, supported by research team analysis
    Security Integration Framework
    Flexible platform allowing integration of custom scanners or replacement of legacy AppSec tools with native scanning capabilities
    Automated Remediation
    Controlled shift-left approach enabling automated vulnerability remediation with focus on critical security issues

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    1 AWS reviews
    |
    39 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Program Development

    Integration Engineer

    Reviewed on Oct 01, 2025
    Review provided by G2
    What do you like best about the product?
    utomates security controls: It provides pre-built security plans (for cloud, code, dependencies, CI/CD, etc.), so teams don’t have to reinvent the wheel.

    Developer-first approach: Security is embedded directly into workflows (like GitHub, CI/CD pipelines) so engineers can continue working in their usual environment.

    Continuous & lightweight: Unlike traditional security tools, it doesn’t overload teams with alerts—it prioritizes and integrates seamlessly.

    Open-source friendly: Works well with open-source security tools (like Trivy, Semgrep, OWASP tools).
    What do you dislike about the product?
    While it integrates well with GitHub and some CI/CD tools, its integrations may not cover all enterprise environments yet.
    What problems is the product solving and how is that benefiting you?
    it helping a lot with many things :
    Financial Services

    Fullstack Software Engineer at Turkish Biggest National Bank.

    Reviewed on Oct 01, 2025
    Review provided by G2
    What do you like best about the product?
    Jit simplifies the management of security controls right within our development workflow. I appreciate how lightweight and easy the setup is, especially when compared to other security tools. Its seamless integration with GitHub and CI/CD pipelines helps us save time and minimizes the need to switch contexts. The automated checks provide reassurance that our code complies with security and compliance standards, all without introducing unnecessary complexity.
    What do you dislike about the product?
    While Jit is quite helpful, I sometimes find the documentation lacking, particularly when it comes to more advanced configuration scenarios. Additionally, the reporting features could be improved to provide more detailed information, which would make it easier to share results with non-technical stakeholders. I also hope to see more integrations with third-party tools added in the future.
    What problems is the product solving and how is that benefiting you?
    Jit has been instrumental in helping us automate and centralize the management of our application security posture. By making it easier to detect vulnerabilities early in the development process, we are able to address issues before they make it to production. This not only lowers our risk but also saves valuable engineering time and enhances our overall compliance. Its seamless integration with our CI/CD workflow allows our team to stay productive while consistently meeting security standards.
    Ali A.

    Helpful Tool for Integrating Security in Mobile App Development

    Reviewed on Oct 01, 2025
    Review provided by G2
    What do you like best about the product?
    As a Flutter developer, I really value that Jit integrates security practices into CI/CD pipelines without adding too much complexity. It helps me catch vulnerabilities early while still focusing on building features. I especially appreciate the lightweight setup compared to traditional enterprise tools, which makes it practical for smaller teams and freelance projects too.
    What do you dislike about the product?
    Some of the more advanced integrations feel limited, especially when connecting with third-party services or mobile-specific pipelines. For example, I would like to see stronger documentation and examples for Flutter/Dart projects. Also, the onboarding process could be more beginner-friendly for developers who are not yet experienced with DevSecOps.
    What problems is the product solving and how is that benefiting you?
    Jit helps me integrate security checks into the development lifecycle without relying on multiple, separate tools. As a mobile developer working with Flutter and backends like Laravel/Firebase, it’s useful for scanning dependencies and monitoring overall security posture. This reduces the risk of vulnerabilities slipping into production and saves me time compared to managing security manually.
    Mohamed M.

    Simple and efficient DevSecOps solution

    Reviewed on Sep 30, 2025
    Review provided by G2
    What do you like best about the product?
    Jit makes it very easy to integrate security into the development workflow without adding too much overhead. I like that it centralizes different security checks and tools in one place, so I don’t have to manage multiple integrations separately. The automation and pre-built pipelines save a lot of time and ensure consistency across projects.
    What do you dislike about the product?
    Sometimes the initial setup can feel a bit limited for very complex environments, and more customization options would be helpful. Also, the dashboard could provide deeper analytics and reporting to give teams a clearer picture of vulnerabilities over time.
    What problems is the product solving and how is that benefiting you?
    Jit is helping us integrate security directly into the development workflow, so vulnerabilities are detected and fixed early in the lifecycle instead of after deployment. It centralizes multiple security practices (SAST, DAST, SCA, and supply chain checks) into one platform, which reduces tool sprawl and simplifies management. This saves the team time, ensures consistency, and helps us maintain a strong security posture without slowing down development.
    Andrew K.

    Jit automates our security posture

    Reviewed on Feb 27, 2025
    Review provided by G2
    What do you like best about the product?
    - Sleek, modern and configurable SaaS security platform
    - Embedded directly in our Pull Request workflow
    - Built on top of open source components which Jit teams elevates core capabilities
    - Gives actionable intelligence and one-click next steps for our engineers & security team
    - Support is fantastic and they keep regularly enhancing the product
    - Incredibly easy integration and sophisticated onboarding with GitHub, etc.
    What do you dislike about the product?
    - Product has so many powerful components that the UX can be a bit overwhelming
    - Google Cloud has slightly fewer out of box blueprints than AWS
    - Although fantastic for Application and Cloud security doesn't entirely replace other tools such as Nessus
    What problems is the product solving and how is that benefiting you?
    Jit is enabling my security team to assess and improve our security posture as well as to save time by bringing numerous capabilities under one tool.

    Jit is empowering my engineering team to have more ownership and insight into the security of the applications they develop and the infrastructure they maintain. It gives them the feedback where they need it just in time.
    View all reviews