Security Stack Logo

Catalog

Domains and Categories

TL;DRThe catalog is a two-level map of our own design.

Domains are broad areas of security, the level you browse. Categories are the specific markets inside them, the level where products actually compete and where listings are compared.

Everything on this page is live, so it always reflects the map as it stands.

How Categories are defined

This taxonomy is our own work. We do not claim it is an industry standard, because none exists: every vendor, analyst firm, and buyer draws the map a little differently. Ours is drawn for one purpose, which is helping you find and compare the products behind the outcomes you are responsible for.

It is informed by the industry, not invented in a vacuum. Where an established market vocabulary exists, Categories keep those names, so what you see here matches what you will meet in vendor material and analyst coverage. Where products cluster ahead of any established definition, we draw the line ourselves.

Our team researches the map continuously to keep it current as the industry moves. A Category is added when a market genuinely exists, not when a vendor invents a label, and the map stays biased to precision: a product is tagged only with the Categories its documentation shows it competes in.

The Domains

There are currently 23 Domains. They are an editorial layer: broad enough that every security product has a home, few enough to browse. Each collects the Categories of one problem area, and evaluation packs are built at this level.

Governance, Risk & Compliance
Risk management, compliance tracking, policy management, and audit automation
Privacy & Data Governance
Privacy management, data governance, consent management, and regulatory compliance
Identity & Access Management
Authentication, authorization, and user access management
Security Awareness & Training
Security training, phishing simulation, and workforce awareness programs
Security Operations
SIEM, SOAR, incident response, threat detection, and security monitoring
Threat Intelligence
Threat hunting, intelligence feeds, and adversary analysis
Vulnerability Management
Assessing, prioritizing, and remediating vulnerabilities across infrastructure and systems
Penetration Testing & Attack Simulation
Automated penetration testing, breach and attack simulation (BAS), and red-team tooling
Application Security
Securing applications across the software development lifecycle and at runtime
Container Security
Container image scanning, runtime protection, and Kubernetes security
Supply Chain Security
Software supply chain security, dependency risk, and third-party management
AI Security
Securing AI/ML systems, LLM protection, and AI pipeline security
Endpoint Protection
Endpoint protection, detection, and response for securing devices against modern threats
Mobile Security
Mobile device management, mobile app protection, and mobile threat defense
Browser Security
Secure enterprise browsers, browser isolation, and web threat protection
Email Security
Protecting email communications through phishing defense, malware filtering, encryption, and DMARC/SPF/DKIM enforcement
Network & Infrastructure Security
Network security, firewalls, intrusion prevention, and infrastructure protection
Cloud Security
Cloud workload protection, identity-driven cloud controls, and secure cloud configurations
Data Protection
Data loss prevention, data security, encryption, access controls, backup & recovery
Blockchain Security
Blockchain infrastructure protection, smart contract security, and crypto asset safeguarding
Hardware Security
Hardware security, firmware protection, and embedded device security
Robotics & Autonomous Systems Security
Security solutions specifically designed for robotic systems, autonomous vehicles, and intelligent automation.
Cyber-Physical Systems (CPS) Security
Security for cyber-physical and operational environments where compromise has physical consequences: operational technology (OT/ICS), enterprise and industrial IoT, connected medical devices (IoMT), and building automation. Vendors typically discover assets passively, monitor industrial and device protocols, and protect environments where patching and downtime are constrained.

Look up a Category

103 Categories are defined, and 94 of them currently hold listed products. Pick one to see where it sits and what it covers.