# StackHawk vs TruffleHog

**Leader by Vioscale score:** TruffleHog

| Attribute | StackHawk | TruffleHog |
|---|---|---|
| **Vioscale score** | 50.5 (73% (medium)) | 60.3 (48% (low)) |
| activity.commits_last_30d | - | 52 |
| adoption.dependent_repos | - | 519 |
| adoption.github_stars | - | 27,596 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | A platform that enables AI coding agents (such as Claude, GitHub Copilot, Cursor) to automatically identify, analyze, and remediate security vulnerabilities in applications during development, eliminating context switching and manual handoffs to security teams. | A security tool that scans code repositories, chat systems, artifact storage, and other SDLC platforms for leaked credentials. It verifies which secrets remain active and provides continuous monitoring and remediation guidance. |
| features.capabilities | `{"dast":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true}` | `{"sca":false,"hosting":"both","ci_native":true,"open_source":true,"reachability":true,"secret_scanning":true,"container_scanning":true}` |
| integrations.count | 11 | 23 |
| integrations.list | `[{"name":"Claude Code"},{"name":"Codex"},{"name":"Gemini CLI"},{"name":"GitHub Copilot"},{"name":"OpenCode"},{"name":"Cursor"},{"name":"Snyk"},{"name":"Auth0"},{"name":"GitHub Actions"},{"name":"GitLab"},{"name":"Jenkins"},{"name":"CircleCI"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Gerrit"},{"name":"Git"},{"name":"Docker"},{"name":"Artifactory"},{"name":"Jenkins"},{"name":"Buildkite"},{"name":"Azure Repos"},{"name":"Travis CI"},{"name":"Circle CI"},{"name":"Slack"},{"name":"Teams"},{"name":"Jira"},{"name":"Vector"},{"name":"Confluence"},{"name":"Google Drive"},{"name":"S3"},{"name":"SharePoint"},{"name":"Splunk"},{"name":"Webhook"},{"name":"Email"}]` |
| language.primary | - | Go |
| license.spdx | - | AGPL-3.0 |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"subscription","plans":[{"free":false,"name":"Wingman","summary":"$10/user/month","features":["Works inside Claude Code, Cursor, GitHub Copilot","Auto-configures and boots app","Runtime testing against running app","Finds and fixes vulnerabilities in same session","Auto-rescanning to verify fix","Pre-PR security attestation","Unlimited apps","50 scans/user/month"],"commitment":"monthly","components":[{"kind":"per_unit","unit":"user","amount":10,"period":"month","currency":"USD"}],"description":"For individuals and teams shipping with AI coding agents","contactSales":false,"includedLimits":{"apps":"unlimited","scans":"50/user/month"}},{"free":false,"name":"Scale","summary":"Custom pricing. Contact sales.","features":["Everything in Wingman","Attack surface discovery","Sensitive data detection","Deeper, broader scan coverage","Program reporting (coverage, fix rates by team)","Teams, roles, and enterprise support","Unlimited agentic scans"],"description":"For security teams needing attack surface discovery, coverage, and proof across every app","contactSales":true,"includedLimits":{"apps":"unlimited","scans":"unlimited"}}],"summary":"From $10/user/month (Wingman). 14-day free trial. Scale plan available via sales consultation.","currency":"USD","freeTier":true,"sourceUrl":"https://www.stackhawk.com","retrievedAt":"2026-08-03T22:45:21.019Z","freeTrialDays":14,"startingPrice":{"amount":10,"period":"month","currency":"USD"},"billingPeriods":["month"]}` | `{"type":"free","plans":[{"free":true,"name":"Open Source","summary":"Free","features":["GitHub, S3, directory, GCS, and Docker scanning","800+ secret detectors","GitHub actions, pre-commit, and pre-receive hooks","Custom regex and secrets verification","Automatic updates"],"description":"GitHub, S3, directory, GCS, and Docker scanning with 800+ secret detectors","contactSales":false,"includedLimits":{"sources":"GitHub, S3, GCS, Docker, directory","detectors":"800+"}}],"addOns":[{"name":"TruffleHog Analyze for SaaS"},{"name":"TruffleHog Analyze for Cloud"},{"name":"Forager (Public Dataset Monitoring)"}],"summary":"Free core product; enterprise features and add-ons available via contact sales","freeTier":true,"sourceUrl":"https://trufflesecurity.com/pricing","retrievedAt":"2026-08-14T15:25:30.270Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | free |
| pricing.transparent | no | no |
| release.cadence_days | - | 7 |
| release.history | - | `[{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.97.1","date":"2026-08-24T16:53:20Z","type":"stable","version":"v3.97.1"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.97.0","date":"2026-08-14T18:35:16Z","type":"stable","version":"v3.97.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.96.0","date":"2026-07-24T18:23:23Z","type":"stable","version":"v3.96.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.9","date":"2026-07-09T23:09:52Z","type":"stable","version":"v3.95.9"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.8","date":"2026-07-02T18:54:37Z","type":"stable","version":"v3.95.8"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.7","date":"2026-06-29T15:50:35Z","type":"stable","version":"v3.95.7"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.6","date":"2026-06-18T14:38:38Z","type":"stable","version":"v3.95.6"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.5","date":"2026-06-02T16:10:06Z","type":"stable","version":"v3.95.5"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.4","date":"2026-06-02T06:20:51Z","type":"stable","version":"v3.95.4"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.3","date":"2026-05-11T18:38:34Z","type":"stable","version":"v3.95.3"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.2","date":"2026-04-21T20:29:49Z","type":"stable","version":"v3.95.2"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.1","date":"2026-04-21T18:12:48Z","type":"stable","version":"v3.95.1"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.95.0","date":"2026-04-21T17:39:24Z","type":"stable","version":"v3.95.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.3","date":"2026-04-08T17:02:29Z","type":"stable","version":"v3.94.3"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.2","date":"2026-04-01T13:03:44Z","type":"stable","version":"v3.94.2"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.1","date":"2026-03-25T16:18:15Z","type":"stable","version":"v3.94.1"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.94.0","date":"2026-03-20T14:51:55Z","type":"stable","version":"v3.94.0"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.93.8","date":"2026-03-09T20:04:03Z","type":"stable","version":"v3.93.8"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.93.7","date":"2026-03-04T15:58:48Z","type":"stable","version":"v3.93.7"},{"url":"https://github.com/trufflesecurity/trufflehog/releases/tag/v3.93.6","date":"2026-02-27T15:09:47Z","type":"stable","version":"v3.93.6"}]` |
| reliability.sla_pct | - | 99 |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | - |
| security.gdpr | - | yes |
| security.scorecard | - | 7.4 |
| security.soc2 | yes | - |

## Capabilities (DevSecOps Tools)

| Capability | StackHawk | TruffleHog |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | - | - |
| DAST (dynamic analysis) | ✓ | - |
| SCA / dependency scanning | - | ✗ |
| Secret scanning | - | ✓ |
| Container / image scanning | - | ✓ |
| IaC misconfiguration scanning | - | - |
| **Governance** |  |  |
| OSS licence compliance | - | - |
| SBOM generation (SPDX/CycloneDX) | - | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | ✓ | - |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | - | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | - |
| **Licensing** |  |  |
| OSS engine available | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T15:21:25.592Z. "-" = undocumented, not absent.*
