The New Relic IAST homepage

New Relic IAST

Score7.0
Rank#3 of 14
PriceFree
Free planYes
Runs onWeb

Summary

New Relic IAST probes running application code to identify vulnerabilities that could be exploited, helping DevOps and security teams address risk across the software development lifecycle. Dynamic assessment simulates attacks and can show proof of exploit without code changes. New Relic APM agents deliver the capability; teams can enable it with a configuration change. Supported languages are Go, Java, Node.js, and Ruby. Findings receive CVSS version 3 severity ratings from Low through Critical, and guided remediation can point to code locations, stack and HTTP traces, URLs, exploit mechanisms, and parameters. IAST is integrated with New Relic Vulnerability Management for ongoing discovery, fixing, and verification of high-risk issues. It supports authenticated and API testing, as well as CI/CD and ticketing integrations. A free New Relic plan is available. IAST analysis is billed through an optional Compute Add On based on Compute Capacity Units used, and other pricing is available on request.

Who it is for

It suits DevOps and security teams seeking continuous application security testing. Teams using Go, Java, Node.js, or Ruby can run it through New Relic agents.

What is good

  • Attack simulation can provide proof of exploit without code changes.
  • Guided remediation includes code locations and traces.
  • Supports authenticated and API testing.
  • Connects with CI/CD pipelines and ticketing systems.

What to know first

  • Analysis billing depends on Compute Capacity Units consumed.
  • Supported languages are Go, Java, Node.js, and Ruby.

Verdict

New Relic IAST combines runtime vulnerability assessment with guided remediation and lifecycle management. Consider its listed language support and usage-based analysis billing when assessing fit.

New Relic IAST plans and pricing

All plans
Free Free 100 GB data ingest/month · 1 free full platform user · unlimited basic users · 50+ capabilities newrelic.com · 30 Sept 2026
Standard Not published Up to 5 full platform users · ticketed support · 2 business days support response SLA · SAML single sign-on newrelic.com · 30 Sept 2026
Enterprise Not published Unlimited full platform users · FedRAMP Moderate and HIPAA eligibility with Data Plus · priority ticket routing · 1-hour critical initial support response SLA newrelic.com · 30 Sept 2026
Pro Not published Unlimited full platform users · 2-hour critical initial support response SLA · Data Plus eligibility newrelic.com · 30 Sept 2026

Compared on interactive application security testing software

Free plan
Nonewrelic.com
Runtime targets
webnewrelic.com
Deployment
saasnewrelic.com
Authenticated testing
Yesnewrelic.com
API testing
Yesnewrelic.com
Instrumentation
agentnewrelic.com
CI/CD integration
Yesnewrelic.com
Language coverage
Go, Java, Node.js, Rubynewrelic.com

Facts

Purpose
New Relic IAST probes running code for exploitable vulnerabilities to help prevent cyberattacks and breaches.docs.newrelic.com · 30 Sept 2026
False positives
IAST is designed to provide fewer false-positive findings than traditional application security tools.docs.newrelic.com · 30 Sept 2026
Vulnerability management
IAST is fully integrated with New Relic Vulnerability Management for continuously finding, fixing, and verifying high-risk vulnerabilities across the software development lifecycle.docs.newrelic.com · 30 Sept 2026
Exploit validation
Dynamic assessment simulates real-world attacks and provides proof of exploit without requiring code changes.newrelic.com · 30 Sept 2026
Guided remediation
Guided remediation can identify code location, stack trace, HTTP trace, encountered URLs, exploit mechanism, and parameters.newrelic.com · 30 Sept 2026
Supported languages
IAST is available through New Relic agents for Go, Java, Node.js, and Ruby.docs.newrelic.com · 30 Sept 2026
Integrations
New Relic offers more than 780 integrations across applications, logs, and infrastructure data.newrelic.com · 30 Sept 2026
Billing
IAST is billed through an optional Compute Add On based on Compute Capacity Units consumed during analysis.docs.newrelic.com · 30 Sept 2026
Severity scoring
IAST assigns vulnerability severity using CVSS version 3, with Low, Medium, High, and Critical ranges.docs.newrelic.com · 30 Sept 2026
Compliance
New Relic currently lists FedRAMP, HIPAA-enabled capabilities, ISO 27001, ISO 42001, PCI DSS, SOC 1, SOC 2, and TISAX certifications or attestations.docs.newrelic.com · 30 Sept 2026
Data residency
Customers can choose between New Relic data centers in the United States and European Union.newrelic.com · 30 Sept 2026
CI/CD and ticketing
IAST supports seamless integration with CI/CD pipelines and ticketing systems.newrelic.com · 30 Sept 2026
Audience
IAST is intended for DevOps and security teams that need continuous application security testing across the software development lifecycle.newrelic.com · 30 Sept 2026

Company

Founded
2008newrelic.com · 28 Sept 2026
Headquarters
San Francisco, California, USAnewrelic.com · 28 Sept 2026

Best New Relic IAST alternatives

See all 12

Where it ranks on Everything Xiaomi

Is New Relic IAST yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources