Catalog
Domains and Categories
TL;DRThe catalog is a two-level map of our own design.
Domains are broad areas of security, the level you browse. Categories are the specific markets inside them, the level where products actually compete and where listings are compared.
Everything on this page is live, so it always reflects the map as it stands.
How Categories are defined
This taxonomy is our own work. We do not claim it is an industry standard, because none exists: every vendor, analyst firm, and buyer draws the map a little differently. Ours is drawn for one purpose, which is helping you find and compare the products behind the outcomes you are responsible for.
It is informed by the industry, not invented in a vacuum. Where an established market vocabulary exists, Categories keep those names, so what you see here matches what you will meet in vendor material and analyst coverage. Where products cluster ahead of any established definition, we draw the line ourselves.
Our team researches the map continuously to keep it current as the industry moves. A Category is added when a market genuinely exists, not when a vendor invents a label, and the map stays biased to precision: a product is tagged only with the Categories its documentation shows it competes in.
The Domains
There are currently 23 Domains. They are an editorial layer: broad enough that every security product has a home, few enough to browse. Each collects the Categories of one problem area, and evaluation packs are built at this level.
- Governance, Risk & Compliance
- Risk management, compliance tracking, policy management, and audit automation
- Privacy & Data Governance
- Privacy management, data governance, consent management, and regulatory compliance
- Identity & Access Management
- Authentication, authorization, and user access management
- Security Awareness & Training
- Security training, phishing simulation, and workforce awareness programs
- Security Operations
- SIEM, SOAR, incident response, threat detection, and security monitoring
- Threat Intelligence
- Threat hunting, intelligence feeds, and adversary analysis
- Vulnerability Management
- Assessing, prioritizing, and remediating vulnerabilities across infrastructure and systems
- Penetration Testing & Attack Simulation
- Automated penetration testing, breach and attack simulation (BAS), and red-team tooling
- Application Security
- Securing applications across the software development lifecycle and at runtime
- Container Security
- Container image scanning, runtime protection, and Kubernetes security
- Supply Chain Security
- Software supply chain security, dependency risk, and third-party management
- AI Security
- Securing AI/ML systems, LLM protection, and AI pipeline security
- Endpoint Protection
- Endpoint protection, detection, and response for securing devices against modern threats
- Mobile Security
- Mobile device management, mobile app protection, and mobile threat defense
- Browser Security
- Secure enterprise browsers, browser isolation, and web threat protection
- Email Security
- Protecting email communications through phishing defense, malware filtering, encryption, and DMARC/SPF/DKIM enforcement
- Network & Infrastructure Security
- Network security, firewalls, intrusion prevention, and infrastructure protection
- Cloud Security
- Cloud workload protection, identity-driven cloud controls, and secure cloud configurations
- Data Protection
- Data loss prevention, data security, encryption, access controls, backup & recovery
- Blockchain Security
- Blockchain infrastructure protection, smart contract security, and crypto asset safeguarding
- Hardware Security
- Hardware security, firmware protection, and embedded device security
- Robotics & Autonomous Systems Security
- Security solutions specifically designed for robotic systems, autonomous vehicles, and intelligent automation.
- Cyber-Physical Systems (CPS) Security
- Security for cyber-physical and operational environments where compromise has physical consequences: operational technology (OT/ICS), enterprise and industrial IoT, connected medical devices (IoMT), and building automation. Vendors typically discover assets passively, monitor industrial and device protocols, and protect environments where patching and downtime are constrained.
Look up a Category
103 Categories are defined, and 94 of them currently hold listed products. Pick one to see where it sits and what it covers.