IRM Consulting & Advisory
Marketplace
Cybersecurity Marketplace

Welcome to our Cybersecurity Marketplace

The IRM Cybersecurity Marketplace is a free catalog of cybersecurity tools and solutions across 24 categories, curated for startups, SaaS companies, and SMBs.

  • 24 categories
  • Free for startups & SMBs
  • Curated by certified experts

Contact Us

All Products

224Products
floating circle
CloudQuery Logo

CloudQuery

Cloud Security

CloudQuery transforms multi-cloud sprawl into a unified asset inventory: extensible, queryable cloud config and security data.

Free
Visit
Logo for Cira Canada

CIRA Canadian Shield

Threat Modeling

Free online protection built for Canadians Block access to malicious websites that can steal your data, install harmful software or trick you into scams. Built with your privacy in mind, Canadian Shield helps reduce online tracking while keeping your data in Canada. Detects and Blocks emerging online threats before they reach you.

Free
Visit
Cloudflare Logo

Cloudflare Zero Trust (Free Plan)

Access Management

Replace your VPN with identity-based access. Cloudflare Zero Trust's free plan, best for teams under 50 users, verifies user identity and device health on every request to your internal and SaaS applications, enforcing least-privilege access for employees and contractors.

Free
Visit
Semgrep Logo

Semgrep Community Edition

Application Security

Semgrep Community Edition is a free, open-source (LGPL 2.1) static analysis engine for finding and fixing security vulnerabilities in your source code. It supports 30+ programming languages, ships with 3,000+ customizable open-source rules, and runs locally on macOS, Windows and Linux with no login required.

Free
Visit
Velociraptor Logo

Velociraptor

Forensics Investigation

Velociraptor is an advanced, open-source (AGPL) digital forensics and incident response (DFIR) tool. Using the Velociraptor Query Language (VQL), responders can collect evidence and hunt for threats across Windows, macOS and Linux endpoints, helping small teams investigate incidents quickly without costly tooling.

Free
Visit
Nuclei Logo

Nuclei

Vulnerability Assessment

Nuclei is a fast, open-source (MIT) vulnerability scanner from ProjectDiscovery. It draws on a community library of more than 12,000 detection templates to find security issues across web applications, cloud infrastructure and networks, and lets you write your own templates to check for the risks that matter to your business.

Free
Visit
Trivy Logo

Trivy

Vulnerability Assessment

Trivy is an all-in-one, open-source (Apache 2.0) security scanner that finds known vulnerabilities (CVEs), infrastructure-as-code misconfigurations, exposed secrets and license issues across code repositories, container images and Kubernetes clusters. It is an easy first scanner for lean DevOps and engineering teams.

Free
Visit
CISA Cyber Security Evaluation Tool (CSET) Logo

CISA Cyber Security Evaluation Tool (CSET)

Governance Risk & Compliance (GRC)

CSET is a free software tool from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) that gives you a systematic, repeatable way to evaluate your security posture. It guides you step by step through your IT and operational technology environment, compares your answers to recognized government and industry standards, and provides recommendations to improve your cybersecurity.

Free
Visit
Arize Phoenix Logo

Arize Phoenix

AI Governance & Risk

You cannot govern AI you cannot see. Arize Phoenix is an open-source platform for tracing and evaluating AI applications and agents, so you can observe how they behave, annotate issues and measure quality over time. It is free to self-host on a laptop, in Docker or on Kubernetes.

Free
Visit
Guardrails AI Logo

Guardrails AI

AI Governance & Risk

Put policy controls around what goes into and comes out of your LLMs. Guardrails AI is an open-source (Apache 2.0) Python framework that adds input and output guards to AI applications, using pre-built validators from Guardrails Hub to detect and reduce specific types of risk and to extract structured, reliable data from language models.

Free
Visit
Promptfoo Logo

Promptfoo

AI Governance & Risk

Stop the trial-and-error approach to AI quality and security. Promptfoo is an open-source (MIT) CLI and library for evaluating and red-teaming LLM applications, letting you run automated tests against your prompts, models and agents before they reach production. Now part of OpenAI, the open-source project continues to be developed.

Free
Visit
PyRIT Logo

PyRIT

AI Governance & Risk

Before you ship a generative AI feature, find out how it can be misused. PyRIT (Python Risk Identification Tool) is Microsoft's open-source framework that helps security teams and engineers red-team generative AI systems and proactively identify risks, so issues are found and fixed before your customers find them.

Free
Visit
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.