Mend.io and Qualys CyberSecurity Asset Management compete in the cybersecurity space. Mend.io takes the lead in open-source governance due to its superior scanning and automation capabilities, whereas Qualys excels in asset visibility and integration.
Features: Mend.io provides strong capabilities in open-source dependency scanning, license management, and vulnerability prioritization. It is designed for comprehensive open-source governance and rapid security assessments. Users benefit from its automation and compatibility with various development environments. Qualys CyberSecurity Asset Management specializes in comprehensive asset visibility, security assessments, and risk management, especially for large IT infrastructures. Its integration with other Qualys tools provides detailed system vulnerability insights and lifecycle management.
Room for Improvement: Mend.io users suggest enhancements in role definitions, browser compatibility, and broader language support. Notifications and UI clarity could also be improved. For Qualys CyberSecurity Asset Management, areas for improvement include dynamic tagging, RBAC, scan frequency controls, and reporting flexibility. Enhanced integration with third-party tools and a more streamlined user interface are also areas for development.
Ease of Deployment and Customer Service: Mend.io supports multiple deployment models—Public, Private, and Hybrid Clouds—offering flexibility for diverse organizational needs. Its customer support is highly rated for responsiveness and technical expertise. Qualys CyberSecurity Asset Management operates primarily on Public and Hybrid clouds, with on-premises deployment options. Its support is praised for quick responses and effective issue resolution, though Mend.io slightly outshines it in technical support responsiveness.
Pricing and ROI: Mend.io offers a competitive pricing structure with fixed costs, regardless of language or scan limits, making it an attractive option for developers. Its ROI is highlighted by reduced vulnerability resolution times and an improved security culture. Qualys CyberSecurity Asset Management’s pricing is considered fair for its comprehensive offerings, which include detailed security assessments and bundled asset management services. Both tools show potential for strong ROI, with Mend.io focusing on reduced remediation times and Qualys emphasizing comprehensive asset coverage and custom pricing plans.
Mend.io has provided a good return on investment by significantly reducing vulnerabilities.
Improvements to our security infrastructure contributed to overall business growth of approximately 150 percent over the past year.
By automating tasks, it significantly reduces the human resources required, leading to increased efficiency and productivity.
It has reduced the number of development and scripting hours along with maintenance hours.
They prioritize providing the best experience to large organizations like ours, belonging to the Fortune 100.
The support team was knowledgeable and offered a variety of quick resolution options.
Their SMEs have sufficient knowledge, and if they are not the right contact, they quickly redirect us to someone who can help resolve issues.
I would rate their customer support a ten out of ten.
We have about 300,000 assets installed with agents worldwide.
Qualys Cybersecurity Asset Management has proven to be a highly scalable solution for us over the past couple of years.
Qualys CSAM is highly scalable.
AI integration in code security tools like Mend.io is still in its early stages and relatively immature.
I would rate the stability of Qualys CSAM a ten out of ten.
They are constantly adding capabilities.
This platform demonstrates excellent stability with consistent 100 percent uptime and no glitches observed.
The organization decided to consolidate tools and chose Snyk since it provides multiple functionalities in one solution.
Qualys is currently not able to identify assets lacking DNS information.
Features enhancing the interaction with IT or security teams should be added, such as a ticketing feature that, if an issue arises in the CSAM module, enables direct ticket creation in systems like ServiceNow.
We would prefer more options, such as 'approved only for pilot' or 'approved for this line of business,' allowing for better granularity in categorizing software.
The cost of Mend.io is competitive, being quite low compared to others.
A cost-effective solution.
A monthly subscription starting at approximately $72 per month, depending on the specific package and features included.
Though the solution is considered expensive, if bundled with other services such as VMDR or cloud agents, its value would significantly increase.
We find it 100% accurate in detecting vulnerabilities.
By correlating this with QDS scores, we can accurately assess the risk level of high or low QDS scores associated with each asset and monitor them accordingly.
The most valuable feature is the real-time visibility Qualys CyberSecurity Asset Management provides into all assets across our development and operational environments.
It also performs scans to identify any vulnerabilities, which helps to take proactive measures before those vulnerabilities are identified by any attacker.
Mend.io is a software composition analysis tool that secures what developers create. The solution provides an automated reduction of the software attack surface, reduces developer burdens, and accelerates app delivery. Mend.io provides open-source analysis with its in-house and other multiple sources of software vulnerabilities. In addition, the solution offers license and policy violation alerts, has great pipeline integration, and, since it is a SaaS (software as a service), it doesn’t require you to physically maintain servers or data centers for any implementation. Not only does Mend.io reduce enterprise application security risk, it also helps developers meet deadlines faster.
Mend.io Features
Mend.io has many valuable key features. Some of the most useful ones include:
Mend.io Benefits
There are many benefits to implementing Mend.io. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the Mend.io solution.
Jeffrey H., System Manager of Cloud Engineering at Common Spirit, says, “Finding vulnerabilities is pretty easy. Mend.io (formerly WhiteSource) does a great job of that and we had quite a few when we first put this in place. Mend.io does a very good job of finding the open-source, checking the versions, and making sure they're secure. They notify us of critical high, medium, and low impacts, and if anything is wrong. We find the product very easy to use and we use it as a core part of our strategy for scanning product code moving toward release.”
PeerSpot reviewer Ben D., Head of Software Engineering at a legal firm, mentions, “The way WhiteSource scans the code is great. It’s easy to identify and remediate open source vulnerabilities using this solution. WhiteSource helped reduce our mean time to resolution since we adopted the product. In terms of integration, it's pretty easy.”
An IT Service Manager at a wholesaler/distributor comments, “Mend.io provides threat detection and an excellent UI in a highly stable solution, with outstanding technical support.”
Another reviewer, Kevin D., Intramural OfficialIntramural at Northeastern University, states, "The vulnerability analysis is the best aspect of the solution."
Qualys CyberSecurity Asset Management provides advanced real-time asset visibility, dynamic tagging, and External Attack Surface Management. It streamlines asset discovery and management using cloud agents and IP-based scanning, enhancing risk management and software lifecycle tracking.
Qualys CyberSecurity Asset Management offers a comprehensive solution for managing asset inventories and tracking software lifecycle states. It facilitates network visibility and supports zero-day vulnerability solutions, enhancing security posture through efficient monitoring. Users benefit from its cloud-based interface, which provides in-depth asset configurations and insights. Key features include automated vulnerability scanning and unauthorized software management, reducing manual efforts. The platform also emphasizes the importance of timely remediation and ongoing risk mitigation across multiple environments. Despite its strengths, users note the need for enhanced integration with additional CMDBs beyond ServiceNow, as well as cost efficiency improvements. Requests also include better report customization, more scan control, and a simplified UI.
What are the key features of Qualys CyberSecurity Asset Management?In industries like finance, healthcare, and manufacturing, Qualys CyberSecurity Asset Management enhances asset control by offering visibility into hardware and software configurations. It aids in maintaining security compliance and identifying unauthorized software, crucial for sectors with strict regulatory requirements.
We monitor all Software Supply Chain Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.