New Relic IAST

  • Free to practise onyes
  • Free trialnot on record
  • Well documentedyes
  • Runs where you worknot on record

Runs on Web.

New Relic IAST probes running application code to identify vulnerabilities that could be exploited, helping DevOps and security teams address risk during software development. Dynamic assessment simulates attacks and can provide evidence of an exploit without code changes. New Relic APM agents deliver the feature, which can be enabled through a configuration setting. It supports Go, Java, Node.js, and Ruby, along with authenticated and API testing. Findings receive CVSS version 3 severity ratings from Low to Critical. Guided remediation can show the code location, stack and HTTP traces, URLs encountered, exploit mechanism, and parameters. Integration with New Relic Vulnerability Management supports ongoing discovery, fixing, and verification of high-risk issues; CI/CD pipelines and ticketing systems are also supported. The web-based service is designed to reduce false positives compared with traditional application security tools. A free plan is available. IAST analysis is billed through an optional Compute Add On according to Compute Capacity Units consumed, and other pricing is available on request.

Who it is for

New Relic IAST suits DevOps and security teams seeking continuous application security testing across the software development lifecycle. It supports teams working in Go, Java, Node.js, or Ruby.

What is good

  • Attack simulation can provide exploit evidence without code changes.
  • Guided remediation surfaces code locations, traces, URLs, and parameters.
  • Integrated with New Relic Vulnerability Management.
  • Supports CI/CD pipelines and ticketing systems.

What to know first

  • Supported languages are Go, Java, Node.js, and Ruby.
  • IAST analysis uses a billed optional Compute Add On.
  • Pricing beyond the free plan is available on request.

Verdict

New Relic IAST combines runtime vulnerability detection with exploit evidence and guided remediation. Teams should account for the supported language list and usage-based Compute Add On billing.

New Relic IAST plans and pricing

All plans
Free Free 100 GB data ingest/month · 1 free full platform user · unlimited basic users · 50+ capabilities newrelic.com · 30 Sept 2026
Standard Not published Up to 5 full platform users · ticketed support · 2 business days support response SLA · SAML single sign-on newrelic.com · 30 Sept 2026
Enterprise Not published Unlimited full platform users · FedRAMP Moderate and HIPAA eligibility with Data Plus · priority ticket routing · 1-hour critical initial support response SLA newrelic.com · 30 Sept 2026
Pro Not published Unlimited full platform users · 2-hour critical initial support response SLA · Data Plus eligibility newrelic.com · 30 Sept 2026

Compared on interactive application security testing software

Free plan
No
Runtime targets
web
Deployment
saas
Authenticated testing
Yes
API testing
Yes
Instrumentation
agent
CI/CD integration
Yes
Language coverage
Go, Java, Node.js, Ruby

Best New Relic IAST alternatives

See all 14