AppScan

AppScan

HCLSoftware
+
+

Related Products

  • Aikido Security
    239 Ratings
    Visit Website
  • Parasoft
    148 Ratings
    Visit Website
  • Feroot
    32 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Jscrambler
    40 Ratings
    Visit Website
  • BranditScan
    68 Ratings
    Visit Website
  • Criminal IP
    457 Ratings
    Visit Website
  • Criminal IP ASM
    20 Ratings
    Visit Website
  • PostScan Mail
    137 Ratings
    Visit Website
  • ESET PROTECT Advanced
    2,303 Ratings
    Visit Website

About

HCL AppScan is a suite of application security testing platforms, technologies, and services that help organizations detect and remediate vulnerabilities throughout the software development lifecycle (SDLC). Powerful static, dynamic, interactive, and open-source scanning engines (DAST, SAST, IAST, SCA, API) quickly and accurately test code, web applications, APIs, mobile applications, containers, and open-source components with the help of AI and machine learning capabilities. Centralized dashboards provide visibility, oversight, compliance policies, and reporting. HCL AppScan’s scanning engines are maintained by expert security researchers and are continuously updated to remain current with recent technologies, vulnerabilities, and attack vectors. With HCL AppScan, organizations can manage their application security posture and reduce risk across their entire software supply chain.

About

Kiuwan is an end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. Integrating into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. ✅ Large language support: 30+ programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation Code Smarter. Secure Faster. Ship Sooner.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Application developers, Penetration testing

Audience

Financial institutions, Insurance Companies, Healthcare, Cyber Security, Investment Platforms, Transaction Services, ECommerce

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

$296
Pay per scan for $296
Free Version
Free Trial

Pricing

For both Code Security and Insights pricing is accessible on request, scans and continuous scanning is available.
Free Version
Free Trial

Reviews/Ratings

Overall 4.0 / 5
ease 4.0 / 5
features 4.0 / 5
design 4.0 / 5
support 5.0 / 5

Reviews/Ratings

Overall 4.5 / 5
ease 4.7 / 5
features 4.2 / 5
design 4.3 / 5
support 3.7 / 5

Pros & Cons from Real Users

Pros

  • It is very easy to use. Good UI easy to understand and provide a multiple verity of security scan. It is available in both cloud and on prem.

Cons

  • It generate extra false positive. It uses one more utility with it which is AppScan Go.

Pros & Cons from Real Users

Pros

  • The number of languages supported. The white-labeled branding capability. The relatively good ease of use. Customer interface, access to run analysis and review reports.
  • The product is very easy to use. I was asked to try this out with not much information and was able to get the first scan in with not much struggle at all.
  • We find very valuable to allow Kiuwan integrate with our development lifecycle (CI/CD) and we don't have to google or find fixes since it recommends fixes and tells you exactly where to find the issue within the code.
  • Very accurate analysis provided by Kiuwan on code risks. The best is that Kiuwan even provides the recommended fix which makes the remediation process easier and faster.
  • I've tried some products (even free like Snyk) and Kiuwan provides a full picture of static code risks and vulnerabilities. It allows team to improve code security and development practices.

Cons

  • Confusing administration with challenging setup. No ability to export mute, notes, and comments. No way to export and remove an application and re-import the results, mutes, notes back into the portal. There should be a setup timing of allowing an application to be reviewed for 15 or 30 days before data is stale and should be removed. Need a comparison to the previous quarter, month, or year's results. This will show maturity and improvement over time.
  • I think a bit more customization in how to select the source for scanning would be great (exclude/include pattern, different set of rules for different source types, etc).
  • False positives take time to turn off since its a manual process and the tools somehow lacks intelligence to detect whether the issue is real or not (e.g. hardcoded passwords are the most likely under this).
  • If they had to improve I'd suggest working on support. Sometimes support takes time to get back. Also, we've gone through platform upgrades and we weren't notified and broke our development cycles. Would be good to improve customer notifications somehow.
  • It's not a CON being honest but would be nice if they could offer something to scan infrastructure like Tenable.sc does.

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

HCLSoftware
Founded: 2019
India
www.hcl-software.com/appscan

Company Information

Kiuwan
Founded: 2012
Spain
www.kiuwan.com

Alternatives

Alternatives

Revenera SCA

Revenera SCA

Revenera
Xygeni

Xygeni

Xygeni Security
Flawnter

Flawnter

CyberTest
PT Application Inspector

PT Application Inspector

Positive Technologies

Categories

Categories

Static Application Security Testing (SAST) Features

Application Security
Dashboard
Debugging
Deployment Management
IDE
Multi-Language Scanning
Real-Time Analytics
Source Code Scanning
Vulnerability Scanning

Application Security Features

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

IT Security Features

Anti Spam
Anti Virus
Email Attachment Protection
Event Tracking
Internet Usage Monitoring
Intrusion Detection System
IP Protection
Spyware Removal
Two-Factor Authentication
Vulnerability Scanning
Web Threat Management
Web Traffic Reporting

Static Code Analysis Features

Analytics / Reporting
Code Standardization / Validation
Multiple Programming Language Support
Provides Recommendations
Standard Security/Industry Libraries
Vulnerability Management

Vulnerability Scanners Features

Asset Discovery
Black Box Scanning
Compliance Monitoring
Continuous Monitoring
Defect Tracking
Interactive Scanning
Logging and Reporting
Network Mapping
Perimeter Scanning
Risk Analysis
Threat Intelligence
Web Inspection

Integrations

ThreadFix
Bitbucket
Bitrise
C
C#
C++
CloudBees
Fortran
GitLab
IBM Informix
IBM i
Jira
NorthStar Navigator
Perl
PhpStorm
PyCharm
Ruby
SENTRIO
TypeScript
WordPress

Integrations

ThreadFix
Bitbucket
Bitrise
C
C#
C++
CloudBees
Fortran
GitLab
IBM Informix
IBM i
Jira
NorthStar Navigator
Perl
PhpStorm
PyCharm
Ruby
SENTRIO
TypeScript
WordPress
Claim AppScan and update features and information
Claim AppScan and update features and information
Claim Kiuwan Code Security and update features and information
Claim Kiuwan Code Security and update features and information