Contrast Assess is an Interactive Application Security Testing tool that analyzes running applications for security risks. An agent instruments application code with sensors, examining execution, data flow, configuration, HTTP requests and responses, and back-end connections. Assess combines static, dynamic, and interactive testing approaches, and can identify vulnerabilities in custom code, open-source libraries, frameworks, and application configurations, including SQL injection, cross-site scripting, and insecure configurations. It continuously monitors applications and APIs for real-time assessments. Results include vulnerability lists with remediation guidance, application scores, route coverage, flow maps, and compliance and policy reporting. The tool is designed for developers and AppSec teams, with feedback in IDE, test, and QA environments. Integration with Contrast SCA can identify third-party library issues and show whether vulnerable methods are called by the running application. Supported languages include Java, Kotlin, Scala, .NET Framework, .NET Core, C#, VB.NET, Node.js, Python, Go, and PHP. Contrast says source code and binaries remain on customer servers. Pricing is on request; hosted and on-premises customers require application licenses.
Who it is for
Assess is designed for developers and AppSec teams seeking security feedback in IDE, test, and QA workflows. It supports applications built with the listed languages and can monitor APIs as well as applications.
What is good
- Combines static, dynamic, and interactive testing approaches.
- Continuously monitors applications and APIs.
- Provides remediation guidance, route coverage, and flow maps.
- Source code and binaries remain on customer servers.
What to know first
- Pricing is available on request.
- Hosted and on-premises customers require application licenses.
- Analysis relies on an agent instrumenting running applications.
Verdict
Assess pairs runtime instrumentation with continuous application and API analysis, plus reporting for development and AppSec workflows. Pricing is on request, and hosted and on-premises customers need application licenses.
Compared on interactive application security testing software
- Deployment
- hybrid
- API testing
- Yes
- Instrumentation
- agent
- CI/CD integration
- Yes
- Language coverage
- Java, Kotlin, Scala, .NET Framework, .NET Core, C#, VB.NET, Node.js, Python, Go, PHP




