Developer-Centric Enterprise DAST with Auto Remediation (STAR) logo

    Developer-Centric Enterprise DAST with Auto Remediation (STAR)

    Bright STAR (Security Testing & Auto Remediation) is an enterprise-grade, AI-powered AppSec platform that safeguards your applications and APIs against both technical and business logic vulnerabilities with minimal false positives. This developer-friendly DAST solution delivers security at the speed and efficiency of DevOps, eliminating the risk of security becoming an afterthought or bottleneck in your workflow. We help organizations replace legacy SAST & DAST solutions by automatically finding, fixing, & validating fixes for Web, APIs, business logic & LLMs vulnerabilities in both AI and human generated code.

    Ratings and reviews

    4.7
    29 ratings
    3 star
    2 star
    1 star
    86%
    14%
    0%
    0%
    0%
    0 AWS reviews
    |
    29 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (29)
    Gauri K.

    Modern, Insightful, and Seamlessly Fits Our Workflow

    Reviewed on Dec 30, 2025
    Review provided by G2
    What do you like best about the product?
    The best thing is that it actually fits into how we work. Most scanners feel like they were built in 2005, but Bright feels modern. It doesn't scream about 500 "vulnerabilities" that turn out to be nothing. It only pings us for stuff that actually matters. Also, the remediation tips are actually written for human beings, not just robots, so my team knows exactly what to fix without a three-hour meeting.
    What do you dislike about the product?
    The UI can feel a little dense at first. There’s a lot going on in the dashboard, and it took me a few tries to find exactly where some of the scan settings were buried.
    What problems is the product solving and how is that benefiting you?
    We needed a way to scale our security testing without hiring three more security engineers. This lets our current team handle way more code than they could manually.
    John R.

    Seamless Security Testing That Fits Perfectly Into Development

    Reviewed on Dec 30, 2025
    Review provided by G2
    What do you like best about the product?
    I really like how Bright Security makes dynamic application and API security testing feel seamless in a developer’s day-to-day, with an intuitive interface, fast scans, real-time vulnerability validation, and minimal false positives that let me focus on real issues rather than noise it’s what makes security actually usable during development rather than only at the end
    What do you dislike about the product?
    While Bright’s scans and reports are solid, I wish it had better built-in mapping of API endpoints and deeper support for single-page apps, and sometimes linking results into broader enterprise-wide tools feels a bit limited compared to some legacy platforms
    What problems is the product solving and how is that benefiting you?
    Bright Security solves the problem of finding critical web and API vulnerabilities early in the software development lifecycle so that security doesn’t become a bottleneck before release meaning our teams can ship safe features faster without having to do manual late-stage penetration tests.
    John S.

    Reliable and Developer-Friendly Security Solution

    Reviewed on Dec 29, 2025
    Review provided by G2
    What do you like best about the product?
    Bright Security has been a game-changer for our development workflow. The biggest advantage is how seamlessly it integrates into CI/CD pipelines without slowing down deployments. The platform is intuitive, and the automated scanning is fast yet thorough. I also appreciate the developer-focused approach issues are explained clearly with actionable remediation steps, which makes fixing vulnerabilities much easier. Their customer support has been responsive and helpful whenever we needed guidance.
    What do you dislike about the product?
    While the overall experience is great, the initial setup took a bit longer than expected because of the learning curve around configuring custom scan profiles. Also, the reporting dashboard could use more flexibility in customizing views for different stakeholders.
    What problems is the product solving and how is that benefiting you?
    Before Bright Security, we struggled with manual security checks that delayed releases and often missed critical vulnerabilities. Bright Security solved this by automating the entire process and embedding security into our development lifecycle. Now, we catch issues early in the pipeline, reducing risk and saving countless hours. This has improved both our product security and team efficiency significantly.
    Education Management

    Absolutely Flawless Experience

    Reviewed on Dec 24, 2025
    Review provided by G2
    What do you like best about the product?
    The "Shift-Left" capability is genuine here, not just a marketing term. The support for modern architectures like GraphQL and REST APIs is excellent, and the customer success team is incredibly responsive—they’ve actually helped us build out our custom integrations rather than just sending us a link to a FAQ page.
    What do you dislike about the product?
    actually, pretty mucI’d love to see them expand their ecosystem more. Currently, they are top-tier for DAST (Dynamic Testing), but I wish they offered native SCA or SAST modules so I could manage my entire application security posture under one single vendor/contract rather than juggling multiple tools.h nothing which i do not like.
    What problems is the product solving and how is that benefiting you?
    t’s solving the problem of "Application Blind Spots." We used to worry about "Shadow APIs"—endpoints our developers created but never documented. Bright’s discovery engine finds these automatically. It has essentially reduced our manual penetration testing costs because we’re catching the low-hanging fruit and even complex business logic flaws automatically before the auditors even show up.
    Nishant S.

    Enhancing Web App Security

    Reviewed on Aug 21, 2024
    Review provided by G2
    What do you like best about the product?
    Near real-time vulnerability detection as well as automated security testing.
    What do you dislike about the product?
    Complexity in setting up the tool where the appsec team is lean it gets difficult to scale.
    What problems is the product solving and how is that benefiting you?
    1. Real time scanning
    2. Reduction of FP
    3. Vulnerability detection.
    Kruthika H.

    Senior Product Security Engineer

    Reviewed on Aug 21, 2024
    Review provided by G2
    What do you like best about the product?
    Ease of use, Product efficiency, Support team on-ground
    What do you dislike about the product?
    As it is a DAST tool, sometimes the tool's necessity gets diluted because engineering team's consider it as a overhead.
    What problems is the product solving and how is that benefiting you?
    We are able to find out the vulnerabilities which really matter as Bright usually does not generate false positives.
    Security and Investigations

    Amazing Enterprise support with most options provided for running Authenticated Scans

    Reviewed on Aug 16, 2024
    Review provided by G2
    What do you like best about the product?
    Technical Support
    Options for Authenticated Scan
    Coverage
    What do you dislike about the product?
    Nothing specific but pointing out the overall market problem that DAST scans struggle with Authenticated scans running smoothly because of complex Auth flows like SSO, oAuth and of course the MFA conf options to be configured within any DAST tool
    What problems is the product solving and how is that benefiting you?
    Accomplishing mandatory requirements to have DAST coverage in our org.
    Transportation/Trucking/Railroad

    Excellent product

    Reviewed on Jun 10, 2024
    Review provided by G2
    What do you like best about the product?
    It helps to improve API security and provides good vulnerability assessment
    What do you dislike about the product?
    hard for the dev team lo learn hot to use
    What problems is the product solving and how is that benefiting you?
    API securety
    Dmitrey G.

    This company provides DAST scanning solution no other company can in a direct focused way

    Reviewed on Jun 09, 2024
    Review provided by G2
    What do you like best about the product?
    Scanning and testing capabilities for frontend of your application are next level
    Flexibility in reports generation
    Constant meaningful improvements in Ease of Use in last year, for example Incremental app that analyzes entrypoints and triggers scans without having to set up the parameters relevant to each.
    Customer Support is very helpful even when I am not from the security field. Support also are crucial for Ease of implementation, and follow up on a weekly basis on progress.
    What do you dislike about the product?
    More challenging for products that require frequent reinstall
    Could use better integration with API scanning, like entrypoint discovery with target's swagger page
    Need to improve flexibility in entrypoint management for a given project (mass edit, mass delete etc)
    I would also suggest diversifying the licensing options:
    I need to run multiple scans in short amount of time once every 2 months to test all products. Currently the license is for one engine, which means I can use it 24/7 but am limited to one running scan. Having an option for several engines that are time limited with frequency required would be useful, even a pay-as-you-go format would work well for these use cases.
    What problems is the product solving and how is that benefiting you?
    Bright helps me meet my company's security requirements for the product my group develops.
    Gabriel M.

    Professional Support , High Level Performance

    Reviewed on Jun 05, 2024
    Review provided by G2
    What do you like best about the product?
    Very good PS and support , high quality team and product in the DAST
    What do you dislike about the product?
    High learning curve, mode documentation.
    What problems is the product solving and how is that benefiting you?
    DAST scans for API security and Dev Applications