No article in the knowledge graph for PortSwigger yet.
Who is PortSwigger?
PortSwigger is a private cybersecurity software company focused on application security testing, particularly for finding and validating web application and API vulnerabilities in enterprise development and security workflows.
- Burp Suite (application security and DAST) for web and API testing
- Web vulnerability scanning, manual testing, and penetration testing workflows
- Support for HTTP, HTTPS, web sessions, authentication flows, and modern web application traffic analysis
- Security research, training, and methodology for web application attack and defense techniques
- Enterprise use across DevSecOps, security assurance, and internal red team or AppSec programs
Show more
More About PortSwigger
PortSwigger operates as a software company in cybersecurity, with products and research centered on application security. In enterprise environments, its offerings are commonly used by application security teams, penetration testers, internal red teams, and developers who need to assess the security of web applications and APIs before release and during production change cycles. Its tools fit into security validation workflows for custom applications, customer-facing web platforms, and internal business systems.
The company is closely associated with Burp Suite (application security and DAST), which combines automated scanning with manual testing capabilities. That positioning differs from security categories focused mainly on endpoint, network perimeter, or identity controls. Its tools are used to inspect and manipulate web traffic, test session handling and authentication logic, examine request and response behavior, and identify issues such as injection flaws, cross-site scripting, access control weaknesses, and other web application vulnerabilities. These workflows align with HTTP and HTTPS analysis, proxy-based interception, crawling, scanning, and testing of API endpoints and application logic.
PortSwigger is also associated with web security education and research that enterprises use to support training and skills development in secure testing practices. In organizations with DevSecOps programs, its tooling can complement static analysis, software composition analysis, and broader vulnerability management processes by focusing on runtime behavior and exploitability in deployed applications. That places the company within the application security and offensive security segments of cybersecurity software, with active product emphasis on web and API testing rather than general-purpose security operations tooling.
As a company, PortSwigger is positioned around enterprise and practitioner use cases for application security testing software and related training content. Its current solution areas map most directly to application security, dynamic testing, manual web assessment, and security research for modern web architectures.
Our description of PortSwigger. Updated September 2026.