By far, the best feature we have found is the possibility of creating specific action plans that automatically determine the effort required by our teams in order to correct defects and ensure better code.
Partner at a tech services company with 51-200 employees
Provides the ability to create specific action plans that determine the effort required by our teams to correct defects and ensure better code.
What is most valuable?
How has it helped my organization?
Code reviews have significantly improved, and it allows our teams to work together in a collaborative cloud environment.
What needs improvement?
More languages and frameworks would enhance this tool.
For how long have I used the solution?
I have used it for three years.
Buyer's Guide
Kiuwan
December 2024
Learn what your peers think about Kiuwan. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and support?
Customer Service:
Customer service is excellent. They have a very solid documentation site, as well as in-app support.
Technical Support:Technical support is 9/10.
Which solution did I use previously and why did I switch?
We previously used SonarQube. We have a portfolio of apps in different programming languages. With Sonar, our costs escalated too much, having to pay for plugins for each language.
How was the initial setup?
Initial setup is very straightforward; plug and play.
What about the implementation team?
We implemented it in-house with the aid of Kiuwan engineers.
What was our ROI?
We have had an improvement of 20% in our time to market and it significantly improved the quality of our code.
What's my experience with pricing, setup cost, and licensing?
I believe pricing varies according to the size of your apps.
Which other solutions did I evaluate?
We looked at Fortify and Checkmarx, but the costs were way too high
What other advice do I have?
We also use other features of the product. We scaled from security to the entire lifecycle and governance management of our stack, which has given us a full control over our application portfolio.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Officer at Umniah
Scalable with good remediation capabilities and good stabilty
Pros and Cons
- "I've tried many open source applications and the remediation or correction actions that were provided by Kiuwan were very good in comparison."
- "The configuration hasn't been that good."
What is our primary use case?
We use the solution for in-house development. In one of the cases, we use it for some applications that we need to create something from scratch.
What we are considering more than anything else is maybe its quality of performance. We are looking for security vulnerabilities. I'm an Information Security Officer and that's why we are looking for vulnerabilities more than the quality of the code or the performance, however, it's great that it gives more detailed information about performance and the quality of the code. I'm actually looking to try another technology, to see if there's something we can do around static tests.
What is most valuable?
The solution is stable.
The solution is scalable.
I've tried many open source applications and the remediation or correction actions that were provided by Kiuwan were very good in comparison.
What needs improvement?
When you do the download test, there is some part that remains there from the static test. When it comes to the configuration of this library, I've not sure that Kiuwan gives a real vulnerability assessment for a configuration.
The configuration hasn't been that good. From a security perspective, we are looking into something in the middle between the static and the dynamic.
There are many open-source tools that can generate perfect results. It's not as good as the quality as the Kiuwan or maybe the SonarQube, however, I'm sure it's really close, and it's also free
We've had issues with technical support not being responsive enough.
We also have had issues with the initial setup.
For how long have I used the solution?
We've used the solution for around two years or so. It's been a while now.
What do I think about the stability of the solution?
We have found the solution to be stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution can scale if you need it to.
We're dealing with three customers that have this solution right now.
How are customer service and technical support?
We're working on some issues with some delays from the support team.
Which solution did I use previously and why did I switch?
We are also using Tenable.
How was the initial setup?
We faced a lot of problems with the initial setup and support gave us difficulties around the installation. That made us a little bit confused. When you lose your servers for the week, it's not a good thing.
With support, we had to troubleshoot the issues and that took about eight working days. It took us around 11 days to overcome the issues and to upgrade.
As an information security team, we were providing some services and were trying to make a vulnerability assessment. The security testing let us note a lot of vulnerabilities. We contacted support and it took us three months to overcome those particular issues.
In terms of maintenance, we have system admins that just look to see if the servers are running or not, however, for managing the servers, the servers implementation security team will handle that.
What's my experience with pricing, setup cost, and licensing?
We can likely find free open-source solutions that give us close to the quality we get with this solution. We'd rather not pay if we don't have to.
Customers must pay a yearly licensing fee.
What other advice do I have?
We got it from a partner. The partner is already connected to Kiuwan from Spain.
We are providing the Kiuwan solution for a small group of customers.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Kiuwan
December 2024
Learn what your peers think about Kiuwan. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
Test Engineer at a tech company with 501-1,000 employees
A scalable tool with quality analysis and good technical support
Pros and Cons
- "The solution offers very good technical support."
- "The solution seems to give us a lot of false positives. This could be improved quite a bit."
What is our primary use case?
We analyze all the portfolio of applications from the customer. The customer is within the government of Spain. We analyze all their applications. On the portfolio of publications, we run analyses from all the applications.
What is most valuable?
From the tool itself, the developer can run an analysis with the same quality. With this tool, every developer has the opportunity to do an unlimited analysis.
The solution can scale well.
The solution offers very good technical support.
It's quite a stable product.
What needs improvement?
I'm still working on learning all the specifics of the tool; it's quite new to me.
The solution seems to give us a lot of false positives. This could be improved quite a bit.
The rules could be more clear. They need to have more clarity in that respect. It would help make the solution easier to use.
For how long have I used the solution?
I've been using the solution for about a year now.
What do I think about the stability of the solution?
The stability at this time is very good. It doesn't have bugs or glitches and it doesn't crash or freeze. It's very, very reliable.
What do I think about the scalability of the solution?
You can definitely scale the solution. However, if you want to analyze more, of course, you have to pay more. This might be limiting if you are an organization that has a specific budget.
In our organization, we have 1,000 users approximately on the solution.
How are customer service and technical support?
The technical support is very good. They are responsive and are very knowledgeable. We are satisfied with their level of service at this time.
How was the initial setup?
In terms of setting up the solution, you only have to download a client to make the analysis. In the local environment, you also only need Java 1.8 and an internet connection to make an analysis. You have to worry about working in the configuration and administration of the users of the quality models. It's pretty easy.
What's my experience with pricing, setup cost, and licensing?
I don't handle the payments or licensing aspects of the solution, therefore, I can't speak to the exact cost of the product. I only administer the tool.
That said, it's my understanding that, if you need to analyze more, you do need to pay more for the solution.
Which other solutions did I evaluate?
It was too difficult for us to evaluate different solutions. That said, I recall the other options being, for example, Veracode and SonarQube. There may have been more options that we considered evaluating as well, however, I don't recall the names of them.
What other advice do I have?
We're just a customer.
We are using the latest version of the solution.
Overall, I would rate the solution eight out of ten. It's worked quite well for us so far.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager
Supports continuous integration tools.
Our client requests our expertise to audit their business-critical applications. Before using Kiuwan, we were using other solutions. We switched to Kiuwan for 8 reasons:
- Ease of use and deployment: No hidden expenses, no complex deployment or complex administration. At last, we were able to help our clients to focus on improving quality without getting delayed by infrastructure issues. Upgrades are done automatically, no migration...
- Clear licensing model: Kiuwan has different licensing models, all easy to understand. We were able to select the model suitable to our client needs without paying extra money for unwanted features.
- Technology coverage: Kiuwan covers most of the known technologies including mobile applications.
- The quality model: We have the complete freedom to customise the quality model, per application, per technology or per client. On the ground, every application has its own context and should be monitored differently with a different quality model. Having the possibility to customise the quality model, to modify existing rules configuration or to remove some is a must and with Kiuwan, we can do it easily. Developing new rules was never that easy; Kiuwan have the best tools to develop new rules.
- Integration: Kiuwan supports continuous integration tools. Beside that, most of the features, like launching an analysis, or creating reports, can be automated. Once the analysis is industrialised, all we to have to do is focus on providing recommendations to improve quality, nothing else.
- Speed of analysis: Do you know any other tools that can analyse 2.5 millions line of code in 3 hours? The tools we used before took 15 hours for a single analysis on the same code. Real time saving.
- Support team: We can chat with the support team directly from the interface. This saves us lot of time, when we have a question or facing a critical issue. The support team is always here, reliable and fast. We had most of our questions answered in a couple of hours.
- Great features: Follow-up quality evolution, compare analysis versions to detect new or removed defects, define and prioritise action plans, security analysis, governance dashboard. We have all we need to help our clients set up SLAs, detect risks, repair critical issues...
With Kiwuan, we were able to help our clients get a better visibility of their development activities and to mitigate risks. We are using Kiuwan for 4 years now and we are getting good feedback from our clients.
What could be improved:
Kiuwan has two levels of KPIs, compared to ISO 9126-3 that defines 3 levels of KPIs. Adopting the ISO 9126-3 model definitively simplifies quality investigations. But the ISO 9126-3 makes the action plan management (or improvement plan) more tricky. Maybe a way of improving the quality model in Kiuwan would be adding the ISO 9126-3 model on top of the existing model to simplify investigations without complicating the action plan management.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partnership
Information Security Manager and Business Continuity Manager at a legal firm with 51-200 employees
Helpful reporting features and is easy to understand
Pros and Cons
- "I've found the reporting features the most helpful."
- "The next release should include more flexibility in the reporting."
What is our primary use case?
I use the solution for daily software development in our company.
What is most valuable?
I've found the reporting features the most helpful.
What needs improvement?
I do not have a clear idea about what could be better. I feel like the general tool is pretty good.
The next release should include more flexibility in the reporting.
For how long have I used the solution?
I've been using the solution for three months.
What do I think about the stability of the solution?
The stability of the solution is all right.
What do I think about the scalability of the solution?
The solution offers complete scalability. I'm not looking to increase usage at the moment, however.
How are customer service and technical support?
We haven't used technical support. It's a very new tool for our company.
How was the initial setup?
I would rate the complexity of setup as a medium. It's not the easiest, but it's not the most complex. Deployment takes about six months. We have four staff members for deployment and maintenance.
What about the implementation team?
I am an information security manager and I collaborate with the software development team for implementation.
What was our ROI?
At this point, we do not see any ROI because at this moment we do not have any business that is completely dependant on this particular tool. I think in the next month we will have that.
Which other solutions did I evaluate?
We compared Kiuwan with other local solutions in Spain. We found Kiuwan had the best rates and price capabilities.
What other advice do I have?
I advise using Kiuwan because it's very straightforward and totally easy to understand. It's also easy to deploy.
I would rate this solution as 8 out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Adds value to our customers to validate what they receive.
What is most valuable?
We only used these products to do some demos. The feedback was very positive.
How has it helped my organization?
Our organization is a product distributor. We don’t use the product internally. But for the customers/leads we presented it to, they see that it can add a lot of value to validate what they receive from their providers.
What needs improvement?
From a maketing perspective, I would suggest demonstrating that using these tools will make money for the customer. The customer should have a clear vision of what they purchsed and what they received. They should push more technical articles on LinkedIn. There is always space to make things better, but for now, it is making a difference.
These products have some dreams, as I heard from some Dev Managers, but I’m sure that with a closer relationship, we can upscale that.
For how long have I used the solution?
We are only showing the product to leads as demos.
How are customer service and technical support?
The technical support is very good. We have received valid answers to our questions.
Which solution did I use previously and why did I switch?
We had some experienced with Rational and Compuware, in addition to the APM tools that we distribute.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing models are poor. If it has a SaaS, the hybrid solution will be enough.
Which other solutions did I evaluate?
We did very careful research of solutions on the market and chose this one for our demos.
What other advice do I have?
“A fool with a tool is still a fool”. Chose somebody who can add the right processes, methods, and techniques to actually implement the customers' objectives. We try to build a eco-system to cross-sell our solutions.
There is a mix between maturity and money. That is the barrier to break before showing the customer that he is purchasing something without risks before he goes into production. They should focus on a product that adds value to the corporation.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Team Lead at a tech services company with 10,001+ employees
Integration with Jenkins and JIRA, and the security support, are valuable.
What is most valuable?
- Very easy to use
- Integration with Jenkins and JIRA
- Security support
How has it helped my organization?
Code reviews are quicker and more reliable.
What needs improvement?
- Indicators regarding metrics
For how long have I used the solution?
I have used it for three years.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
Customer service is excellent.
Technical Support:Technical support is very good.
Which solution did I use previously and why did I switch?
We previously used a different solution. I switched because of the quotes and security rules.
How was the initial setup?
Initial setup is straightforward, no doubt.
What about the implementation team?
An in-house team implemented it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Software Architect at Digital Solution Foundry (Pty) Ltd
A usable and friendly interface, and is helping to improve the quality of our development process
Pros and Cons
- "The most valuable feature is the time to resolution, where it tells you how long it is going to take to get to a zero-base or a five-star security rating."
- "I would like to see better integration with Azure DevOps in the next release of this solution."
What is our primary use case?
We are a solution provider, and we are using this solution with one of our clients.
The primary use case for this solution is security and vulnerability testing. We are currently integrating this solution into our software development process.
We have a public cloud deployment.
How has it helped my organization?
This solution has improved the quality of the process, in general. This solution helps us to catch issues early on, and find problems that we never knew we had. This results in things being more secure.
What is most valuable?
The most valuable feature is the time to resolution, where it tells you how long it is going to take to get to a zero-base or a five-star security rating.
The interface is usable and friendly.
What needs improvement?
The rate of false positives, where it reports issues that are not really issues, can be improved.
Scanning of vulnerabilities on open-source projects is not particularly useful as it is.
I would like to see better integration with Azure DevOps in the next release of this solution.
For how long have I used the solution?
We have been using this solution for eight months.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
We haven't encountered any issues with the scalability of this solution. It is fine.
There are five or six users who are using this solution actively. There are software developers, a solution architect, and a lead developer. The solution is just being incorporated into our process.
How are customer service and technical support?
We haven't had any issues or need to engage with technical support.
Which solution did I use previously and why did I switch?
We are also using SonarQube in parallel with this solution. SonarQube is a good product, but I prefer Kiuwan from a functional perspective.
How was the initial setup?
The initial setup of this solution is very simple.
What about the implementation team?
We performed the implementation ourselves.
What other advice do I have?
This is a solution that I recommend.
The biggest lesson that I have learned from using this software is that we weren't as secure as we had thought. You think that you have pretty decent security until you get the tool and see where you are short.
I would rate this solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Kiuwan Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Popular Comparisons
SonarQube Server (formerly SonarQube)
Veracode
GitLab
Snyk
Checkmarx One
Mend.io
Fortify on Demand
HCL AppScan
Qualys Web Application Scanning
GitHub
Buyer's Guide
Download our free Kiuwan Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- SAST vs. DAST: Which is better for application security testing?