TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    FortiCNAPP

    Score6 out of 10
    N/AFortiCNAPP is an enterprise Cloud-Native Application Protection Platforms solution that unifies security posture management, developer code scanning, cloud identity governance, and runtime threat detection into a single management console. FortiCNAPP represents the evolution of Fortinet's cloud security portfolio following its acquisition of Lacework in August 2024. Formerly marketed as Lacework FortiCNAPP, the platform incorporates Lacework's foundational polygraph behavioral analysis engine…N/A

    HackerOne

    Score9 out of 10
    N/AHackerOne is a hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be exploited, from the company of the same name in San Francisco. The service is used for vulnerability location, pen testing, bug bounty, and vulnerability triage services.N/A
    Pricing
    FortiCNAPPHackerOne
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    FortiCNAPPHackerOne
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details—For more information please email www.hackerone.com/contact or find us on the AWS Marketplace: https://aws.amazon.com/marketplace/seller-profile?id=10857e7c-011b-476d-b938-b587deba31cf
    More Pricing Information
    Community Pulse
    FortiCNAPPHackerOne
    Considered Both Products
    Fortinet
    No answer on this topic
    HackerOne
    No answer on this topic
    Key User Insights
    Would buy again
    100%
    Would buy again
    7 Answers
    No answers on this topic
    Delivers good value for the price
    No answers on this topic
    No answers on this topic
    Happy with the feature set
    100%
    Happy with the feature set
    7 Answers
    No answers on this topic
    Lived up to sales and marketing promises
    No answers on this topic
    No answers on this topic
    Implementation went as expected
    100%
    Implementation went as expected
    5 Answers
    No answers on this topic
    Best Alternatives
    FortiCNAPPHackerOne
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    Palo Alto Networks Prisma Cloud
    Score8.9 out of 10
    No answers on this topic
    Enterprises
    Microsoft Defender for Cloud
    Score8.7 out of 10
    No answers on this topic
    All AlternativesView all alternativesView all alternatives
    User Ratings
    FortiCNAPPHackerOne
    Likelihood to Recommend
    7.1
    (7 ratings)
    7.0
    (2 ratings)
    User Testimonials
    FortiCNAPPHackerOne
    Likelihood to Recommend
    Fortinet
    Lacework is well suited for behavioral analysis. One thing to consider thought is in the early stages there will be quite a bit of noise generated by Lacework. There will be a higher volume alerts generated initially - until a good baseline is generated. Overall Lacework is good with alert handling - integration with Slack is good.
    Incentivized
    Read full review
    HackerOne
    It is one of the good platforms for security researchers to submit bugs and other vulnerabilities, it however, has some challenges, in terms of un-verified and duplicate submissions.
    Incentivized
    Read full review
    Pros
    Fortinet
    • Easy to set-up the agent in cloud workloads.
    • Easy integration with ticketing and messaging tools.
    • Detailed visibility of all our container workloads across multiple accounts.
    Incentivized
    Read full review
    HackerOne
    • Filter for spammy bug reports
    • Nice central interface
    • Payment/reward system is nice
    Incentivized
    Read full review
    Cons
    Fortinet
    • UI can be complicated and hard to know where to click to find information.
    • Ability to create and manage cases or tickets from events that trigger.
    Read full review
    HackerOne
    • A lot of duplicate bugs get reported, although it does offer automatic suggestion of previously reported bugs that may be duplicates, it is far from perfect.
    • Anyone can report bugs, a lot of them are not verified before submission. This sometimes leads to a lot of time spent in verifying if the bug is really actionable.
    • Each submission has to be treated with equal potential, a lot of time, some time gets invested in vulnerabilities that aren't as important as some others.
    Incentivized
    Read full review
    Alternatives Considered
    Fortinet
    Compared to Sysdig Falco (the free open-source IDS), Lacework helps security teams by providing actionable alerts and a user-friendly interface that gives you an overview of all workloads being monitored, and detailed insights into these workloads if needed. Falco requires you to build your own integration and interface around it, including a mechanism to whitelist certain alerts. This made it harder for the security team to focus their time on potential intrusions.
    Incentivized
    Read full review
    HackerOne
    These were very close and we liked HackerOne better. For a time we did have both and we felt the need to consolidate the information into one platform and end of life our internal offering. Overall we've been fairly happy with HackerOne.
    Incentivized
    Read full review
    Return on Investment
    Fortinet
    • Being a FinTech company, financial institutions who partner with us want to know that we are appropriately maintaining a Security, Risk and Compliance program that maintains a level of comfort for their vendor management. Lacework gives us the ability to monitor and maintain a level of security for our infrastructure that puts our partners at ease, reduces the revenue cycle for new partners and opens doors to the future.
    Read full review
    HackerOne
    • Bugs that can't be tracked internally are submitted by external researchers, which is an important factor for security vulnerabilities.
    • Even if the bugs reported are duplicates, there still is provision to award reputation points, that keep the researchers engaged.
    • It also requires a lot of verification and validation, as a lot of the submissions are unverified to begin with.
    Incentivized
    Read full review
    ScreenShots