I develop use cases to enhance code quality, and in the event of code vulnerabilities, I guide the team on how to address and rectify them.
Cyber Security Engineer at a tech services company with 11-50 employees
A valuable code analysis and quality management platform, offering user-friendly features, and effective vulnerability identification to enhance software development processes
Pros and Cons
- "It provides value by offering options to enhance both code quality and the security of the company."
- "It could improve its scalability abilities."
What is our primary use case?
How has it helped my organization?
What is most valuable?
It provides value by offering options to enhance both code quality and the security of the company.
What needs improvement?
There are limited alternatives from other libraries or dependencies to enhance the application which posed a challenge for me as it necessitated modifications across different cases. It's problematic since you might need to alter or replace everything for potential improvements.
Buyer's Guide
Kiuwan
January 2025
Learn what your peers think about Kiuwan. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with it for approximately two years and six months.
What do I think about the stability of the solution?
It offers good stability capabilities.
What do I think about the scalability of the solution?
It could improve its scalability abilities.
Which solution did I use previously and why did I switch?
We've worked with Checkmarx, Veracode and Fortify. I find Kiuwan to be more user-friendly, you can easily locate and download data. However, in certain processes, it might not be the most cost-effective option.
How was the initial setup?
The initial setup was easy.
What other advice do I have?
Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Officer at Umniah
Scalable with good remediation capabilities and good stabilty
Pros and Cons
- "I've tried many open source applications and the remediation or correction actions that were provided by Kiuwan were very good in comparison."
- "The configuration hasn't been that good."
What is our primary use case?
We use the solution for in-house development. In one of the cases, we use it for some applications that we need to create something from scratch.
What we are considering more than anything else is maybe its quality of performance. We are looking for security vulnerabilities. I'm an Information Security Officer and that's why we are looking for vulnerabilities more than the quality of the code or the performance, however, it's great that it gives more detailed information about performance and the quality of the code. I'm actually looking to try another technology, to see if there's something we can do around static tests.
What is most valuable?
The solution is stable.
The solution is scalable.
I've tried many open source applications and the remediation or correction actions that were provided by Kiuwan were very good in comparison.
What needs improvement?
When you do the download test, there is some part that remains there from the static test. When it comes to the configuration of this library, I've not sure that Kiuwan gives a real vulnerability assessment for a configuration.
The configuration hasn't been that good. From a security perspective, we are looking into something in the middle between the static and the dynamic.
There are many open-source tools that can generate perfect results. It's not as good as the quality as the Kiuwan or maybe the SonarQube, however, I'm sure it's really close, and it's also free
We've had issues with technical support not being responsive enough.
We also have had issues with the initial setup.
For how long have I used the solution?
We've used the solution for around two years or so. It's been a while now.
What do I think about the stability of the solution?
We have found the solution to be stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution can scale if you need it to.
We're dealing with three customers that have this solution right now.
How are customer service and technical support?
We're working on some issues with some delays from the support team.
Which solution did I use previously and why did I switch?
We are also using Tenable.
How was the initial setup?
We faced a lot of problems with the initial setup and support gave us difficulties around the installation. That made us a little bit confused. When you lose your servers for the week, it's not a good thing.
With support, we had to troubleshoot the issues and that took about eight working days. It took us around 11 days to overcome the issues and to upgrade.
As an information security team, we were providing some services and were trying to make a vulnerability assessment. The security testing let us note a lot of vulnerabilities. We contacted support and it took us three months to overcome those particular issues.
In terms of maintenance, we have system admins that just look to see if the servers are running or not, however, for managing the servers, the servers implementation security team will handle that.
What's my experience with pricing, setup cost, and licensing?
We can likely find free open-source solutions that give us close to the quality we get with this solution. We'd rather not pay if we don't have to.
Customers must pay a yearly licensing fee.
What other advice do I have?
We got it from a partner. The partner is already connected to Kiuwan from Spain.
We are providing the Kiuwan solution for a small group of customers.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Kiuwan
January 2025
Learn what your peers think about Kiuwan. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Partner at a tech services company with 51-200 employees
Provides the ability to create specific action plans that determine the effort required by our teams to correct defects and ensure better code.
What is most valuable?
By far, the best feature we have found is the possibility of creating specific action plans that automatically determine the effort required by our teams in order to correct defects and ensure better code.
How has it helped my organization?
Code reviews have significantly improved, and it allows our teams to work together in a collaborative cloud environment.
What needs improvement?
More languages and frameworks would enhance this tool.
For how long have I used the solution?
I have used it for three years.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
Customer service is excellent. They have a very solid documentation site, as well as in-app support.
Technical Support:Technical support is 9/10.
Which solution did I use previously and why did I switch?
We previously used SonarQube. We have a portfolio of apps in different programming languages. With Sonar, our costs escalated too much, having to pay for plugins for each language.
How was the initial setup?
Initial setup is very straightforward; plug and play.
What about the implementation team?
We implemented it in-house with the aid of Kiuwan engineers.
What was our ROI?
We have had an improvement of 20% in our time to market and it significantly improved the quality of our code.
What's my experience with pricing, setup cost, and licensing?
I believe pricing varies according to the size of your apps.
Which other solutions did I evaluate?
We looked at Fortify and Checkmarx, but the costs were way too high
What other advice do I have?
We also use other features of the product. We scaled from security to the entire lifecycle and governance management of our stack, which has given us a full control over our application portfolio.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Manager and Business Continuity Manager at a legal firm with 51-200 employees
Helpful reporting features and is easy to understand
Pros and Cons
- "I've found the reporting features the most helpful."
- "The next release should include more flexibility in the reporting."
What is our primary use case?
I use the solution for daily software development in our company.
What is most valuable?
I've found the reporting features the most helpful.
What needs improvement?
I do not have a clear idea about what could be better. I feel like the general tool is pretty good.
The next release should include more flexibility in the reporting.
For how long have I used the solution?
I've been using the solution for three months.
What do I think about the stability of the solution?
The stability of the solution is all right.
What do I think about the scalability of the solution?
The solution offers complete scalability. I'm not looking to increase usage at the moment, however.
How are customer service and technical support?
We haven't used technical support. It's a very new tool for our company.
How was the initial setup?
I would rate the complexity of setup as a medium. It's not the easiest, but it's not the most complex. Deployment takes about six months. We have four staff members for deployment and maintenance.
What about the implementation team?
I am an information security manager and I collaborate with the software development team for implementation.
What was our ROI?
At this point, we do not see any ROI because at this moment we do not have any business that is completely dependant on this particular tool. I think in the next month we will have that.
Which other solutions did I evaluate?
We compared Kiuwan with other local solutions in Spain. We found Kiuwan had the best rates and price capabilities.
What other advice do I have?
I advise using Kiuwan because it's very straightforward and totally easy to understand. It's also easy to deploy.
I would rate this solution as 8 out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager
Supports continuous integration tools.
Our client requests our expertise to audit their business-critical applications. Before using Kiuwan, we were using other solutions. We switched to Kiuwan for 8 reasons:
- Ease of use and deployment: No hidden expenses, no complex deployment or complex administration. At last, we were able to help our clients to focus on improving quality without getting delayed by infrastructure issues. Upgrades are done automatically, no migration...
- Clear licensing model: Kiuwan has different licensing models, all easy to understand. We were able to select the model suitable to our client needs without paying extra money for unwanted features.
- Technology coverage: Kiuwan covers most of the known technologies including mobile applications.
- The quality model: We have the complete freedom to customise the quality model, per application, per technology or per client. On the ground, every application has its own context and should be monitored differently with a different quality model. Having the possibility to customise the quality model, to modify existing rules configuration or to remove some is a must and with Kiuwan, we can do it easily. Developing new rules was never that easy; Kiuwan have the best tools to develop new rules.
- Integration: Kiuwan supports continuous integration tools. Beside that, most of the features, like launching an analysis, or creating reports, can be automated. Once the analysis is industrialised, all we to have to do is focus on providing recommendations to improve quality, nothing else.
- Speed of analysis: Do you know any other tools that can analyse 2.5 millions line of code in 3 hours? The tools we used before took 15 hours for a single analysis on the same code. Real time saving.
- Support team: We can chat with the support team directly from the interface. This saves us lot of time, when we have a question or facing a critical issue. The support team is always here, reliable and fast. We had most of our questions answered in a couple of hours.
- Great features: Follow-up quality evolution, compare analysis versions to detect new or removed defects, define and prioritise action plans, security analysis, governance dashboard. We have all we need to help our clients set up SLAs, detect risks, repair critical issues...
With Kiwuan, we were able to help our clients get a better visibility of their development activities and to mitigate risks. We are using Kiuwan for 4 years now and we are getting good feedback from our clients.
What could be improved:
Kiuwan has two levels of KPIs, compared to ISO 9126-3 that defines 3 levels of KPIs. Adopting the ISO 9126-3 model definitively simplifies quality investigations. But the ISO 9126-3 makes the action plan management (or improvement plan) more tricky. Maybe a way of improving the quality model in Kiuwan would be adding the ISO 9126-3 model on top of the existing model to simplify investigations without complicating the action plan management.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partnership
Technical Team Lead at a tech services company with 10,001+ employees
Integration with Jenkins and JIRA, and the security support, are valuable.
What is most valuable?
- Very easy to use
- Integration with Jenkins and JIRA
- Security support
How has it helped my organization?
Code reviews are quicker and more reliable.
What needs improvement?
- Indicators regarding metrics
For how long have I used the solution?
I have used it for three years.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
Customer service is excellent.
Technical Support:Technical support is very good.
Which solution did I use previously and why did I switch?
We previously used a different solution. I switched because of the quotes and security rules.
How was the initial setup?
Initial setup is straightforward, no doubt.
What about the implementation team?
An in-house team implemented it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Software Architect at Digital Solution Foundry (Pty) Ltd
A usable and friendly interface, and is helping to improve the quality of our development process
Pros and Cons
- "The most valuable feature is the time to resolution, where it tells you how long it is going to take to get to a zero-base or a five-star security rating."
- "I would like to see better integration with Azure DevOps in the next release of this solution."
What is our primary use case?
We are a solution provider, and we are using this solution with one of our clients.
The primary use case for this solution is security and vulnerability testing. We are currently integrating this solution into our software development process.
We have a public cloud deployment.
How has it helped my organization?
This solution has improved the quality of the process, in general. This solution helps us to catch issues early on, and find problems that we never knew we had. This results in things being more secure.
What is most valuable?
The most valuable feature is the time to resolution, where it tells you how long it is going to take to get to a zero-base or a five-star security rating.
The interface is usable and friendly.
What needs improvement?
The rate of false positives, where it reports issues that are not really issues, can be improved.
Scanning of vulnerabilities on open-source projects is not particularly useful as it is.
I would like to see better integration with Azure DevOps in the next release of this solution.
For how long have I used the solution?
We have been using this solution for eight months.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
We haven't encountered any issues with the scalability of this solution. It is fine.
There are five or six users who are using this solution actively. There are software developers, a solution architect, and a lead developer. The solution is just being incorporated into our process.
How are customer service and technical support?
We haven't had any issues or need to engage with technical support.
Which solution did I use previously and why did I switch?
We are also using SonarQube in parallel with this solution. SonarQube is a good product, but I prefer Kiuwan from a functional perspective.
How was the initial setup?
The initial setup of this solution is very simple.
What about the implementation team?
We performed the implementation ourselves.
What other advice do I have?
This is a solution that I recommend.
The biggest lesson that I have learned from using this software is that we weren't as secure as we had thought. You think that you have pretty decent security until you get the tool and see where you are short.
I would rate this solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Account Manager at a wireless company with 51-200 employees
It is the most effective tool for IT procurement managers and directors
Pros and Cons
- "Lifecycle features, because they permit us to show non-technical people the risk and costs hidden into the code due to bad programming practices."
- "DIfferent languages, such Spanish, Portuguese, and so on."
What is most valuable?
Lifecycle features, because they permit us to show non-technical people the risk and costs hidden into the code due to bad programming practices.
It is the most effective tool for IT procurement managers and directors. Technical debt metrics and action plans oriented to rejected deliveries.
How has it helped my organization?
Kiuwan was used internally at Optimyth. We had no surprises derivated from security, performance, or maintainability issues.
What needs improvement?
DIfferent languages, such Spanish, Portuguese, and so on.
For how long have I used the solution?
I've used this solution for three years.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
An eight out of 10.
Which solution did I use previously and why did I switch?
In other companies I have worked for, we moved to Kiuwan/Optimyth because of the accuracy and easiness of use and setup.
Also, most of my partners and customers have moved to Kiuwan due to the metrics and programming languages supported.
How was the initial setup?
Not complex. I am a salesperson without tech training and I was able to use it
What's my experience with pricing, setup cost, and licensing?
Nothing special. It's a very fair model.
Which other solutions did I evaluate?
What other advice do I have?
If they need a tool to be used across your organization (technicians, managers, and directors), this is the tool.
Have highly qualified staff or consultancy provider (code quality and governance) to define the risk model to be used and measured with Kiuwan, this increases the ROI.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Kiuwan Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
GitLab
Veracode
Snyk
Checkmarx One
Mend.io
Fortify on Demand
HCL AppScan
Qualys Web Application Scanning
GitHub
Buyer's Guide
Download our free Kiuwan Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?