+
+

Related Products

  • Aikido Security
    364 Ratings
    Visit Website
  • Parasoft
    152 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Rocket z/Assure VAP
    1 Rating
    Visit Website
  • Orca Security
    635 Ratings
    Visit Website
  • Feroot
    33 Ratings
    Visit Website
  • Astra Pentest
    296 Ratings
    Visit Website
  • RealCISO
    223 Ratings
    Visit Website
  • Criminal IP ASM
    21 Ratings
    Visit Website
  • Josys
    263 Ratings
    Visit Website

About

Kiuwan is an end-to-end application security platform that integrates seamlessly into your development process. Our toolset includes Static Application Security Testing (SAST), Software Composition Analysis (SCA), Software Governance and Code Quality, empowering your team to quickly identify and remediate vulnerabilities. Integrating into your CI/CD pipeline, Kiuwan enables early detection and remediation of security issues. Kiuwan supports strict compliance with industry standards including OWASP, CWE, MISRA, NIST, PCI DSS, and CERT, among others. ✅ Large language support: 30+ programming languages. ✅ Detailed action plans: Prioritize remediation with tailored action plans. ✅ Code Security: Seamless Static Application Security Testing (SAST) integration. ✅ Insights: On-demand or continuous scanning Software Composition Analysis (SCA) to help reduce third-party threats. ✅ One-click Software Bill of Materials (SBOM) generation Code Smarter. Secure Faster. Ship Sooner.

About

Oxeye is designed to expose vulnerable flows in distributed cloud native application code. We incorporate next-generation SAST, DAST, IAST, and SCA capabilities to ensure verification of risks in both Dev and Runtime environments. Built for developers and AppSec teams, Oxeye helps to shift-left security while accelerating development cycles, reducing friction, and eliminating vulnerabilities. We deliver reliable results with high accuracy. Oxeye analyzes code vulnerabilities across microservices delivering contextualized risk assessment enriched with infrastructure configuration data. With Oxeye developers can easily track and resolve vulnerabilities. We deliver the vulnerability visibility flow, steps to reproduce, and the exact line of code. Oxeye offers a seamless integration as Daemonset with a single deployment that doesn’t require performing changes in the code. We deliver frictionless security to your cloud-native apps.

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Financial institutions, Insurance Companies, Healthcare, Cyber Security, Investment Platforms, Transaction Services, ECommerce

Audience

Businesses searching for a cloud-native application security testing solution designed for architectures

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

API

Offers API Supported

API

Offers API Supported

Screenshots and Videos

Screenshots and Videos

Pricing

For both Code Security and Insights pricing is accessible on request, scans and continuous scanning is available.
Free Version Not Supported
Free Trial Not Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Not Supported

Reviews/Ratings

Overall 4.5 / 5
ease 4.7 / 5
features 4.2 / 5
design 4.3 / 5
support 3.7 / 5

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Pros & Cons from Real Users

Pros

  • The number of languages supported. The white-labeled branding capability. The relatively good ease of use. Customer interface, access to run analysis and review reports.
  • The product is very easy to use. I was asked to try this out with not much information and was able to get the first scan in with not much struggle at all.
  • We find very valuable to allow Kiuwan integrate with our development lifecycle (CI/CD) and we don't have to google or find fixes since it recommends fixes and tells you exactly where to find the issue within the code.
  • Very accurate analysis provided by Kiuwan on code risks. The best is that Kiuwan even provides the recommended fix which makes the remediation process easier and faster.
  • I've tried some products (even free like Snyk) and Kiuwan provides a full picture of static code risks and vulnerabilities. It allows team to improve code security and development practices.

Cons

  • Confusing administration with challenging setup. No ability to export mute, notes, and comments. No way to export and remove an application and re-import the results, mutes, notes back into the portal. There should be a setup timing of allowing an application to be reviewed for 15 or 30 days before data is stale and should be removed. Need a comparison to the previous quarter, month, or year's results. This will show maturity and improvement over time.
  • I think a bit more customization in how to select the source for scanning would be great (exclude/include pattern, different set of rules for different source types, etc).
  • False positives take time to turn off since its a manual process and the tools somehow lacks intelligence to detect whether the issue is real or not (e.g. hardcoded passwords are the most likely under this).
  • If they had to improve I'd suggest working on support. Sometimes support takes time to get back. Also, we've gone through platform upgrades and we weren't notified and broke our development cycles. Would be good to improve customer notifications somehow.
  • It's not a CON being honest but would be nice if they could offer something to scan infrastructure like Tenable.sc does.

Training

Documentation Supported
Webinars Supported
Live Online Not Supported
In Person Not Supported

Training

Documentation Not Supported
Webinars Not Supported
Live Online Supported
In Person Not Supported

Company Information

Kiuwan
Founded: 2012
Spain
www.kiuwan.com

Company Information

Oxeye
Israel
www.oxeye.io

Alternatives

Revenera SCA

Revenera SCA

Revenera

Alternatives

AppScan

AppScan

HCLSoftware
Xygeni

Xygeni

Xygeni Security
PT Application Inspector

PT Application Inspector

Positive Technologies
Contrast Assess

Contrast Assess

Contrast Security

Categories

Categories

IT Security Features

Anti Spam Not Supported
Anti Virus Not Supported
Email Attachment Protection Not Supported
Event Tracking Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
IP Protection Not Supported
Spyware Removal Not Supported
Two-Factor Authentication Not Supported
Vulnerability Scanning Supported
Web Threat Management Not Supported
Web Traffic Reporting Not Supported

Static Code Analysis Features

Analytics / Reporting Supported
Code Standardization / Validation Not Supported
Multiple Programming Language Support Supported
Provides Recommendations Supported
Standard Security/Industry Libraries Not Supported
Vulnerability Management Supported

Vulnerability Scanners Features

Asset Discovery Not Supported
Black Box Scanning Not Supported
Compliance Monitoring Not Supported
Continuous Monitoring Not Supported
Defect Tracking Not Supported
Interactive Scanning Not Supported
Logging and Reporting Not Supported
Network Mapping Not Supported
Perimeter Scanning Not Supported
Risk Analysis Supported
Threat Intelligence Supported
Web Inspection Not Supported

Integrations

Bitbucket Supported
GitLab Supported
Go Supported
Java Supported
Jira Supported
Amazon Web Services (AWS) Not Supported
C Supported
C++ Supported
CLion Supported
CloudBees Supported
Fortran Supported
HTML Supported
IBM Informix Supported
IBM Z Supported
IBM i Supported
Oracle Forms Supported
PyCharm Supported
Swift Supported
Trello Not Supported
Visual Studio Supported

Integrations

Bitbucket Supported
GitLab Supported
Go Supported
Java Supported
Jira Supported
Amazon Web Services (AWS) Supported
C Not Supported
C++ Not Supported
CLion Not Supported
CloudBees Not Supported
Fortran Not Supported
HTML Not Supported
IBM Informix Not Supported
IBM Z Not Supported
IBM i Not Supported
Oracle Forms Not Supported
PyCharm Not Supported
Swift Not Supported
Trello Supported
Visual Studio Not Supported
Claim Kiuwan Code Security and update features and information
Claim Kiuwan Code Security and update features and information
Claim Oxeye and update features and information
Claim Oxeye and update features and information