About Salt Security
Salt Security is the only AI-infused API Security Solution for the entire API lifecycle — from API discovery to posture management to threat protection.

AI-powered API security platform providing runtime protection, API discovery, and behavioral analytics to stop API-based attacks.
Salt Security is the only AI-infused API Security Solution for the entire API lifecycle — from API discovery to posture management to threat protection.
Our take on Salt Security
Salt Security is a well-established player in the application security testing space, headquartered in Palo Alto, CA. Founded in 2016, the company has built a mid-sized organization with strong depth that serves a diverse range of clients across multiple industries including financial services, healthcare, technology, and government sectors.
Their core service offerings span API Security, Runtime Protection, Behavioral Analytics, AI Security, among other specialized capabilities. Salt Security has positioned itself as a reliable partner for organizations seeking to identify and remediate vulnerabilities in their software applications before they can be exploited by malicious actors. The company's approach emphasizes both automated scanning technologies and expert-driven assessment methodologies.
One of the notable strengths of Salt Security is its commitment to staying current with evolving threat landscapes and emerging attack vectors. Their security professionals bring deep technical expertise and industry certifications that add credibility to their assessments. Clients frequently cite the quality of reporting and actionable remediation guidance as key differentiators.
From a service delivery standpoint, Salt Security demonstrates professionalism in project management, clear communication throughout engagements, and thorough documentation of findings. Their solutions are designed to integrate into modern development workflows, supporting organizations in their shift-left security initiatives and DevSecOps transformations.
For organizations evaluating application security testing providers, Salt Security represents a solid option worth considering. Their combination of technical capabilities, industry experience, and commitment to client success makes them a competitive choice in the Palo Alto market and beyond. Prospective clients should evaluate specific service offerings against their unique requirements to ensure the best fit for their security program needs.
Verified credentials and recognition earned by Salt Security
Verified
This agency has a verified website presence.
LinkedIn Verified
This agency has a verified LinkedIn company page.
Top Rated
This agency has an exceptional AgencyCluster score of 80+.
10+ Years
Established in 2016. Over 10 years of experience.
Mid-Size
Medium (51-200)
Rankings earned on AgencyCluster
Common questions about Salt Security.
Salt Security has earned rankings on 4 AgencyCluster lists: Top 25 Application Security Testing in California, Top 10 Application Security Testing in California, Top 50 Application Security Testing, Top 25 Application Security Testing. Their highest AgencyCluster Score is 86/100. Rankings are merit-based and determined by evidence across six evaluation pillars — agencies cannot pay for higher positions.
In our evaluation for Application Security Testing, Salt Security scores 86/100 overall. Their strongest areas are Credibility, Freshness, Proof of Work & Outcomes, Reputation, Category Fit, Delivery Maturity. A high Outcomes score means they have verifiable case studies with measurable results — the most heavily weighted factor in our methodology.
Salt Security was founded in 2016, giving them over a decade of experience in application security testing. In an industry where many agencies are less than 5 years old, 10+ years of sustained operations signals stability, client retention, and the ability to adapt through multiple technology cycles. Today, the team is mid-size.
Yes. Salt Security has been vetted and verified by AgencyCluster's editorial team through a rigorous, multi-factor review process. Unlike self-serve directories, AgencyCluster does not accept automated submissions — every agency is evaluated manually before being published. Our vetting covers identity verification (website, LinkedIn, domain age), business legitimacy (years of operation, team size, registered presence), evidence of work (case studies, portfolio, client outcomes), reputation checks across third-party platforms, activeness and freshness of their online presence, and screening for red flags including misconduct, fraud, or misleading claims. Agencies that fail any critical check are not listed. For Salt Security, verified signals include a functioning website, LinkedIn company profile, 10+ years of operating history (founded 2016), 4 earned rankings on curated top lists.