

HCL AppScan and Kiuwan compete in the security and code quality enhancement category. HCL AppScan seems to have the upper hand in scalability and stability, while Kiuwan offers a more cost-effective solution with a strong continuous integration process.
Features: HCL AppScan provides effective scanning during code construction with excellent scalability and stability, specializing in detecting reflected XSS vulnerabilities. Kiuwan offers impressive speed and modularity, enhancing both vulnerability scanning and code quality. It has a strong continuous integration process that ensures seamless security in software development.
Room for Improvement: HCL AppScan could improve its false positives rate, enhance usability, and expand service integration and language support. Users note a need for a better UI and database expansion. Kiuwan faces challenges with limited language support and issues like report downloading difficulties; improving dependency scanning and defining clearer rules are suggested enhancements.
Ease of Deployment and Customer Service: HCL AppScan offers high adaptability across various deployment environments with mixed reviews on technical support, especially after its transition from IBM. Kiuwan provides diverse deployment options including hybrid cloud environments, receiving slightly better feedback on support quality. Both are available in public cloud and on-premises formats.
Pricing and ROI: HCL AppScan is considered expensive with a challenging pricing model, but effective in reducing vulnerabilities, providing significant ROI over time. Kiuwan's more affordable subscription model based on code lines appeals to those prioritizing cost-effectiveness. Despite its higher cost, AppScan users highlight its better ROI through improved security efficiency.
| Product | Mindshare (%) |
|---|---|
| HCL AppScan | 2.3% |
| Kiuwan | 1.2% |
| Other | 96.5% |


| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 4 |
| Large Enterprise | 6 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
Kiuwan offers comprehensive security and vulnerability testing capabilities, focusing on code analysis, fast scanning, and detailed risk assessments. Supporting many technologies, it integrates well into development workflows to ensure code compliance and enhance code quality.
Known for its application portfolio governance, Kiuwan provides fast scanning and reporting features, alongside an intuitive interface. It supports languages from COBOL to JavaScript, offering modular capabilities and security integration for continuous deployment. Developers can perform efficient local or cloud-based scans, benefiting from action plans for better code correction. Integration with tools like Jenkins facilitates quick processing and detailed risk assessments, while challenges remain in language support expansion and smoother integration with Azure DevOps and popular IDEs. Enhanced frameworks and mobile development testing would amplify its utility, with users seeking improved navigation, report downloading, and technical support.
What are the most important features of Kiuwan?In industries focused on software development, Kiuwan is integral for security and vulnerability assessments. It's embedded into workflows to analyze, detect and correct vulnerabilities, addressing threats like SQL injection and adhering to OWASP Top 10. The tool supports secure coding practices and performance evaluation, aiding organizations in maintaining rigorous security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.