HCL AppScan and Fortify on Demand are prominent tools in the application security testing category. Fortify on Demand has the upper hand based on user reviews due to its comprehensive features, despite HCL AppScan's advantage in pricing and support.
Features: HCL AppScan is recognized for its strong scanning capabilities and effortless integration with diverse development environments. It effectively supports multiple platforms and languages. Its detailed scan results enhance issue identification. Fortify on Demand offers extensive scanning options with a cloud model appealing to large enterprises. Its in-depth vulnerability assessment and automatic remediation guidance are highly valued by users. The tool's ability to support a wide range of security standards makes it distinct.
Room for Improvement: Users suggest HCL AppScan enhance its reporting tools and scalability. Improved scan performance and real-time updates could benefit users. Opportunities for quicker integration with CI/CD pipelines are identified. Fortify on Demand users recommend enhancements in performance speed and user access controls. Its interface could be more intuitive for new users. Options for more customizable reporting tools are also sought.
Ease of Deployment and Customer Service: HCL AppScan users find deployment straightforward but note potential delays in customer service response times. The setup process is well-documented, though further streamlining could be beneficial. Fortify on Demand is appreciated for its simplified deployment process and responsive support, which provides enterprises with quick implementation and reliable assistance. This focus on customer service helps mitigate deployment challenges.
Pricing and ROI: HCL AppScan is perceived as cost-effective, offering favorable initial ROI with lower setup costs. It proves beneficial for organizations mindful of budget constraints while ensuring solid security assessments. Fortify on Demand, though demanding higher initial expenses, justifies its pricing with an advanced feature set offering satisfying long-term ROI. Reviews indicate that investment in Fortify's comprehensive capabilities reaps security dividends over time.
Fortify on Demand is a web application security testing tool that enables continuous monitoring. The solution is designed to help you with security testing, vulnerability management and tailored expertise, and is able to provide the support needed to easily create, supplement, and expand a software security assurance program without the need for additional infrastructure or resources.
Fortify on Demand Features
Fortify on Demand has many valuable key features. Some of the most useful ones include:
Fortify on Demand Benefits
There are several benefits to implementing Fortify on Demand. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the Fortify on Demand solution.
Dionisio V., Senior System Analyst at Azurian, says, "One of the top features is the source code review for vulnerabilities. When we look at source code, it's hard to see where areas may be weak in terms of security, and Fortify on Demand's source code review helps with that." He goes on to add, “Another reason I like Fortify on Demand is because our code often includes open source libraries, and it's important to know when the library is outdated or if it has any known vulnerabilities in it. This information is important to us when we're developing our solutions and Fortify on Demand informs us when it detects any vulnerable open source libraries.”
A Security Systems Analyst at a retailer mentions, “Being able to reduce risk overall is a very valuable feature for us.”
Jayashree A., Executive Manager at PepsiCo, comments, “Once we have our project created with our application pipeline connected to the test scanning, it only takes two minutes. The report explaining what needs to be modified related to security and vulnerabilities in our code is very helpful. We are able to do static and dynamic code scanning. When we are exploring some of the endpoints this solution identifies many loopholes that hackers could utilize for an attack. This has been very helpful and surprising how many vulnerabilities there can be.”
A Principal Solutions Architect at a security firm explains, “Its ability to perform different types of scans, keep everything in one place, and track the triage process in Fortify SSC stands out.”
PeerSpot user Mamta J., Co-Founder at TechScalable, states, "Almost all the features are good. This solution has simplified designing and architecting for our solutions. We were early adopters of microservices. Their documentation is good. You don't need to put in much effort in setting it up and learning stuff from scratch and start using it. The learning curve is not too much."
IBM Security AppScan enhances web application security and mobile application security, improves application security program management and strengthens regulatory compliance. By scanning your web and mobile applications prior to deployment, AppScan enables you to identify security vulnerabilities and generate reports and fix recommendations.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.