StackHawk

Integrates security vulnerability scanning into AI coding agents and development workflows

Also known as
stackhawk

Available worldwide

What is StackHawk?

A platform that enables AI coding agents (such as Claude, GitHub Copilot, Cursor) to automatically identify, analyze, and remediate security vulnerabilities in applications during development, eliminating context switching and manual handoffs to security teams.

Independently observed

StackHawk pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
from $10/moSubscriptionFree tier14-day trial

From $10/user/month (Wingman). 14-day free trial. Scale plan available via sales consultation.

Wingman

$10/user/month
monthly

For individuals and teams shipping with AI coding agents

apps
unlimited
scans
50/user/month
  • Works inside Claude Code, Cursor, GitHub Copilot
  • Auto-configures and boots app
  • Runtime testing against running app
  • Finds and fixes vulnerabilities in same session
  • Auto-rescanning to verify fix
  • Pre-PR security attestation
  • Unlimited apps
  • 50 scans/user/month

Scale

Contact sales
Contact sales

For security teams needing attack surface discovery, coverage, and proof across every app

apps
unlimited
scans
unlimited
  • Everything in Wingman
  • Attack surface discovery
  • Sensitive data detection
  • Deeper, broader scan coverage
  • Program reporting (coverage, fix rates by team)
  • Teams, roles, and enterprise support
  • Unlimited agentic scans

What StackHawk does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
-
DAST (dynamic analysis)
SCA / dependency scanning
-
Secret scanning
-
Container / image scanning
-
IaC misconfiguration scanning
-
Governance
OSS licence compliance
-
SBOM generation (SPDX/CycloneDX)
-
Remediation
Automated fix / upgrade PRs
Prioritisation
Reachability / exploitability prioritisation
-
Deployment
Hosting
Cloud only
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
Licensing
OSS engine available
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS

Integrations (12)

Independently observed
  • Claude Code
  • Codex
  • Gemini CLI
  • GitHub Copilot
  • OpenCode
  • Cursor
  • Snyk
  • Auth0
  • GitHub Actions
  • GitLab
  • Jenkins
  • CircleCI

StackHawk FAQ

Common questions about StackHawk, answered from independent, dated evidence.

What is StackHawk?

A platform that enables AI coding agents (such as Claude, GitHub Copilot, Cursor) to automatically identify, analyze, and remediate security vulnerabilities in applications during development, eliminating context switching and manual handoffs to security teams. It is indexed under DevSecOps Tools.

Source: https://www.stackhawk.com/pricing-old/

Is StackHawk free?

StackHawk offers a free tier, so you can start without paying. Paid plans start at $10 per user per month. Pricing changes often, so verify at source before relying on it.

Source: https://www.stackhawk.com

What platforms does StackHawk support?

StackHawk supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.

Source: https://www.stackhawk.com/pricing-old/

Can StackHawk be self-hosted?

We have only confirmed a cloud / SaaS deployment for StackHawk, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.

Source: https://www.stackhawk.com/pricing-old/

What does StackHawk integrate with?

We have confirmed 12 integrations for StackHawk, including Claude Code, Codex, Gemini CLI, GitHub Copilot, OpenCode, Cursor, Snyk and Auth0, plus 4 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.

Source: https://www.stackhawk.com/pricing-old/

What security certifications does StackHawk have?

We have independently confirmed SOC 2 for StackHawk. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as StackHawk not holding them. Always confirm compliance directly before you rely on it.

Source: https://www.stackhawk.com/security

StackHawk alternatives

Other devsecops tools we track, ranked by the same independent score.

All StackHawk alternatives, ranked →

Compare StackHawk

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for StackHawk, not the verdict.

Balanced composite 51 / 100
medium · 73%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture450.219.4
Reliability500.094.7
Capabilities750.053.8
Price level800.043.4
Pricing transparency450.052.3
Integrations310.051.6

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Content

AttributeValueEvidence
Faq6 itemsmediumsource · 2026-09-10 · 62%

Features

AttributeValueEvidence
CapabilitiesDast: Yes · Hosting: cloud · Ci native: Yes · Ide plugin: Yes · Auto fix pr: Yes · Open source: Yesmediumsource · 2026-08-14 · 60%

Integrations

AttributeValueEvidence
Count11mediumsource · 2026-08-14 · 60%

Market

AttributeValueEvidence
AvailabilityPrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-08-14 · 75%

Pricing

AttributeValueEvidence
Price levellowmediumsource · 2026-08-14 · 60%
TransparentNomediumsource · 2026-08-14 · 60%
Free tierYesmediumsource · 2026-08-14 · 60%
Modelfreemiummediumsource · 2026-08-14 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-03 · 60%

Security

AttributeValueEvidence
Disclosure policyYesmediumsource · 2026-08-03 · 60%
Soc2Yeshighsource · 2026-08-03 · 75%
Still deciding?

Is StackHawk the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank StackHawk against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of StackHawk

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves StackHawk up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows StackHawk's independent score and links back to this profile.

StackHawk, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/stackhawk" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/stackhawk.svg" alt="StackHawk, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![StackHawk, verified on vioscaleAI](https://www.vioscale.ai/badge/software/stackhawk.svg)](https://www.vioscale.ai/software/stackhawk)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing StackHawk. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim StackHawk

Not the owner? How vendor profiles work