DragonJAR

Last updated: Aug 13, 2026


How does Fluid Attacks' solution compare to DragonJAR's?

The following comparison table enables you to discern the performance of both providers across various attributes essential for meeting your company's cybersecurity needs. To better understand each attribute, read their descriptions in the dedicated page.

Organization

AttributeEssentialAdvancedDragonJAR
Focus

Native ASPM with in-house scanners

AI-powered PTaaS on top of native ASPM with in-house scanners

MPT
ExtrasNoneNone

Digital risk protection, red team, security training and social engineering testing

Headcount

157

Same

16
Headcount distribution

Engineering 40%, IT 14%, sales 15%, marketing 2%, operations 4% and others 25%

Same

Engineering 13%, IT 44%, marketing 6%, operations 6% and others 31%

Headcount growth

+14%, +15%, -1%

Same

-6%, +14%, +7%
Headquarters

CO and US

Same

CO
Countries

AR, BO, CA, CL, CO, DO, MX, PA, PE and US

Same

CO and UY
Reputation

9.44 from 228 reviews over 8 years on Gartner and Clutch

SameNo reviews
Followers

22K based on the following: Facebook, Instagram, LinkedIn, X and YouTube

Same

679K based on the following: Facebook, Instagram, LinkedIn, X and YouTube

Research firmsNoneNoneNone
Founded2001Same2001
FundingBootstrappedSameNo information available
AcquisitionsNoneNoneNone
Revenue

10M to 15M

Same

1M to 10M
Third-Party CVEs Discovered

289 CVEs reported to MITRE, ranked in the top 10 CVE labs worldwide

Same

None
Compliance

GDPR, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, PCI DSS, SOC 2 Type II and SOC 3

SameNone
Bug bounty

Yes

Yes

No
Visits

64K per month. Top 3: 18% CO, 9% US, 5% BR. Others 68%

Same

26K per month. Top 3: 23% CO, 15% ES and 15% MX. Others 47%

Authority

33 out of 100

Same

28 out of 100
Public vulnerability DB

Discovered and third-party

SameNone
Content

Blog, documentation, e-books, glossary, reports, success stories, videos, webinars and white papers

Same

Blog, books, community, conference, courses, newsletters, reports and videos

Comprehensive documentation

13 documentation sections

Same

No
CommunityForumSameChat(Discord)
Sync training

1 workshop

Same

1 live security education course (paid)
Async training

3 product use courses, all free

Same

Security education platform (subscription-based)

Distribution

Direct or with any of its 14 partners

SameDirect
Marketplaces

AWS

Same

None
FreemiumNoNoNo
Free trial

21-day free trial

PoVNo
DemoYesYesNo
Open demoNoNoNo
Pricing

Contact sales and marketplace

Contact sales

Contact sales
Pricing tiers1 plan1 planNo information available
Minimum termMonthlyMonthlyNo information available
Minimum payment periodMonthlyMonthlyNo information available
Minimum capabilities

ASPM, binary SAST, containers, CSPM, DAST, IaC, SAST, SCA and secrets

Same plus: AI SAST, API security testing, MAST, PTaaS, RE and SCR

MPT
Minimum scope1 authorSameNo information available
Pricing driversAuthorsSameNo information available
Free implementationYesYesNo information available
Free supportYesYesNo information available

Service

AttributeEssentialAdvancedDragonJAR
PTaaSNoYesNo. MPT
Reverse engineeringNo

Yes

No information available
Secure code reviewNo

Yes

Yes
PivotingNoYesNo information available
ExploitationNoYesYes
Manual reattacksNot applicable

Unlimited reattacks

No information available
Zero-day vulnerabilities

Scanner-based zero-day vulnerability detection

Continuous zero-day vulnerability research

None
SLA

Availability

Accuracy, availability and response

No information available
Minimum availability

99.95% per year

Same

No information available
After-sale guaranteesNoYesNo
Accreditations

CNA, Penetration Testing by CREST and OpenSSF Gold Badge

Same

None
Pentester certificationsNot applicable

202 from 59 different types

6 from 6 different types
Type of contractEmployeeSameEmployee or freelance
Endpoint controlNo

Total

No information available
Channel controlNoTotalNo information available
Standards

Some requirements from 67 standards, 10 in common and 57 additional

All requirements from the same standards

13 standards, 10 in common and 3 additional

Detection method

Automated tools

AI, automated tools and human intelligence

Automated tools and human intelligence

Remediation

5, 1 in common and 4 additional

Same, plus 1

1 in common
Output

5, 1 in common and 4 additional

Same, plus 2

1 in common

Product

AttributeEssentialAdvancedDragonJAR
ASPM

Yes

Yes

No
API

GraphQL with JSON

Same

No
IDE5 functionalities

Same, plus 1 functionality

No
CLIYesYesNo
CI/CD

Breaks the build

Same

Does not break the build
Vulnerability sources

18 sources

Same

No information available
Threat model alignment

Yes

Yes

No
Priority criteria

CVSS v4.0, CVSSF, EPSS and KEV

SameNo information available
Custom prioritization

Priority score

Same

No
Scanner originIn-houseIn-houseNone
SCA

19 package managers

Same

No
AI securityNoYesNo
Reachability

12 languages

Same

No
Reachability type

Deterministic

Same

Not applicable
SBOM

22 package managers

Same

No
Malware detectionYesYesNo
Autofix on componentsNoNoNo
Containers

4 distributions

Same

No
Source SAST (languages)

12

Same

No
Source SAST (frameworks)

23

Same

No
Custom rulesNoNoNo
IaC

6

2

No
Binary SAST

1 type of binary

Same, plus 2 types of binaries

No
DAST

7 attack surface types

Same

No
API security testingNo

4 types of APIs

Yes. No information available
MASTNoYesNo
IASTNoNoNo
CSPMYesYesNo
Secrets

171 secrets types

Same, plus verify other attack vectors and secrets exploitability

No
AI

4 functions

Same, plus 1 function

No
AI SASTNoYesNo
MCPYesYesNo
Open-sourceNoNoNo
Deployment

SaaS (multi-tenant)

SameNo information available
RegionsUSSameNo information available
StatusYesYesNo
Incidents3 per yearSameNo information available

Integrations

AttributeEssentialAdvancedDragonJAR
SCM

6

Same

None
Binary repositoriesNoneNoneNone
Ticketing

3

Same

None
ChatOpsNoneNoneNone
IDE3

Same

None
CI/CD21

Same

None
SCANativeSameNone
ContainerNativeSameNone
SASTNativeSameNone
DASTNativeSameNone
MASTNoneNativeNone
IASTNoneNoneNone
Cloud1SameNone
CSPMNativeSameNone
Secrets

Native

Same

None
RemediationNoneNoneNone
Bug bountyNoneNoneNone
Vulnerability managementNoneNoneNone
ComplianceNoneNoneNone

More like DragonJAR

Tags

apicompareexploitationmptrtscr

On this page