Cycode logo

    Cycode

    Sold by
    Cycode is the only AppSec and Posture Management (ASPM) platform that provides visibility, prioritization, & remediation for Sec, Dev, & Ops teams to secure applications from code to cloud.

    Ratings and reviews

    3.9
    4 ratings
    5 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    0 AWS reviews
    |
    4 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (4)
    reviewer2014131

    Secret scanning has strengthened our code security and now needs better container integration

    Reviewed on May 27, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Cycode is used for multiple types of scanning including secrets, SAST scanning, and IAC misconfiguration scanning. Secret scanning was one of the first services launched using Cycode and is integrated into product teams' CI/CD pipelines for identifying hard-coded secrets within the code.

    Cycode is used for infrastructure as code misconfiguration scanning and SAST scanning to find code weaknesses. Both engines are solid with no complaints.

    As a policy, hard-coding secrets is prohibited. Cycode helps identify pieces of code that might be out of compliance. When the organization pivoted to GitHub Enterprise Cloud, this became a strong requirement for all product teams to comply with, and Cycode definitely assisted in that process.

    Cycode is used for secret scanning, IAC misconfiguration scanning, and SAST. Other tools are used for software composition analysis and container image scanning.

    What is most valuable?

    Cycode excels in secret scanning and is brilliant at finding and identifying secrets within code. The GitHub integration helps product teams run scans on their code during pull requests without requiring a task in their pipeline, allowing them to identify issues much earlier in the software development life cycle.

    The GitHub integration allows scanning to be performed as early as possible. Whenever product teams raise a pull request or commit to a GitHub repository, the integration identifies issues even before the scan runs in the pipeline. Since scanning happens in the version control system in GitHub rather than in the pipeline, it keeps the load on the pipeline simple and reduces the overall pipeline load.

    Measurable improvements and faster development are outcomes of using Cycode. Since it is integrated into GitHub as a GitHub app and performs PR scans, it makes the development process not just faster but more secure. It prohibits users from hard-coding secrets and pushes them to use secret vaults and managers, which is a much more secure method of handling credentials.

    Cycode helps with visibility into application security posture by having arguably the best dashboards and reporting among all the other tools in use, with different kinds of remediation funnels and MTTR data available in Cycode's dashboard that helps with overall application security posture management.

    Cycode helps prioritize vulnerabilities or findings with a custom risk score that can help prioritize findings. Even within secrets, it helps identify the severities associated with those secrets.

    Cycode supports collaboration between development and security teams well. The integration with GitHub makes it quite seamless.

    What needs improvement?

    Regarding container scanning, Cycode can be improved as it does not have a CLI. As a DevSecOps professional, having a CLI is a must-have for any tool to integrate it into systems. Although Cycode does have a CLI, specifically for the container scanning module, a CLI does not exist. This is why all the modules that Cycode offers cannot be fully leveraged.

    A CLI for the container scanning module is believed to be on Cycode's roadmap, but it is not available today.

    As a big enterprise dealing with many assets, Cycode being faster would be beneficial. With many assets on-boarded on Cycode, the tool sometimes becomes slow. Making Cycode faster would definitely help. Other than that, things are good.

    For how long have I used the solution?

    Cycode has been in use for almost three years.

    What do I think about the stability of the solution?

    Cycode is stable and scales as needed.

    What do I think about the scalability of the solution?

    The scalability of Cycode as the organization grows or adds more assets is managed well. At the scale at which the enterprise operates, which is quite large, Cycode scales as needed. Being a vendor SaaS tool on an elastic server, it scales effectively.

    How are customer service and support?

    Cycode's customer support is good. Regular connects are maintained with the customer support team.

    Which solution did I use previously and why did I switch?

    Secret scanning was not available prior to Cycode. Cycode was the first solution for secret scanning and still is to this day.

    How was the initial setup?

    Adoption and initial use of Cycode was fairly simple for the team. The GitHub integration made the process quite smooth as all assets in GitHub had to be bulk on-boarded to Cycode. Although the on-boarding and adoption were smooth and Cycode was scanning everything in GitHub, as a DevSecOps team, assets had to be mapped individually in order to perform application security posture management (ASPM), which took a good amount of time and remains an ongoing challenge.

    What was our ROI?

    A return on investment has been seen with Cycode. Overall, the security of assets and preventing the exposure of secret data is where Cycode excels. No specific metrics can be shared beyond that.

    What's my experience with pricing, setup cost, and licensing?

    Cycode is aggressively priced across the board with respect to other tools when it comes to pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    I was not part of the decision before choosing Cycode, so I am not aware of which options were evaluated. However, GitHub Advanced Security was believed to have been considered.

    What other advice do I have?

    Cycode excels mainly in secret scanning, and if CLI was available in other types of scans like container scanning, the overall experience would have been better. Cycode's governance and security are good, and the AI remediation abilities through integrations like Secure Code Warrior are beneficial.

    The accuracy and reliability of Cycode's AI capabilities have not been fully tested. Others looking into using Cycode should move forward with it. It is a strong and robust tool for secret scanning.

    Overall, I rate Cycode a 7.5 out of 10. The rating reflects limitations such as the lack of a CLI for container scanning and some concerns about forced secret scanning, balanced against Cycode's excellence in secret scanning capabilities.

    J P.

    Totally impressed with cycode

    Reviewed on Apr 23, 2024
    Review provided by G2
    What do you like best about the product?
    I've found CyCode to be an easy tool to use and integrate into our environment. I look forward to completing my work onboarding the tool into our production. we internally discussed the risk of exposing a system that actively provides easy access to secrets and shortly thereafter we noticed a new feature that allows us to limit this exposure through the use of roles.
    What do you dislike about the product?
    lacks integrations with many AWS services to make it easy to track application vulnerabilities in terms of the systems hosting our applications rather than just the code & artifacts.
    What problems is the product solving and how is that benefiting you?
    I've seen new valuable security features and customization options open up that increase its potential value to our organization. So overall I think they take customer feedback seriously and are looking at ways to improve the product.
    Sachin P.

    Cycode abilities

    Reviewed on Dec 08, 2022
    Review provided by G2
    What do you like best about the product?
    1) Product setup is extremely quick.
    2) Cycode defaults provide immediate value by highlighting improper storage secrets in source control and data leakage visibility, i.e. Violations - Asset mapping in knowledge graphs.
    3) The new workflow functionality enhances the user experience, as custom behavior is now easily implemented from a central point in the system.
    What do you dislike about the product?
    1) The violations which need manual re-scan have to be improved.
    2) Display the proper error message when the queries for an extensive knowledge graph are in progress.
    What problems is the product solving and how is that benefiting you?
    1) Great platform for SCM.
    2) Visibility on the compliance and audit requirements increased.
    3) Single view for all my policy violations and asset details which can significantly help audit.
    Dipak P.

    Best software for SDLC process

    Reviewed on Dec 02, 2022
    Review provided by G2
    What do you like best about the product?
    Easy to understand and hadel all tools for use.intrrfaceeasy to use.
    What do you dislike about the product?
    Littel bit complicated to extensively work on that.
    What problems is the product solving and how is that benefiting you?
    Very beneficial for SDLC process.Tracking etc.