TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    HCL AppScan

    Score7.2 out of 10
    N/AAppScan (formerly Rational AppScan) is an application security testing solution acquired by HCL Technologies from IBM in late 2018. Appscan supports both dynamic (DAST) and static (SAST) application security testing.N/A

    Veracode

    Score8.5 out of 10
    Mid-Size Companies (51-1,000 employees)
    Veracode provides advanced application security solutions, trusted by enterprises to develop and maintain secure software. Its platform identifies exploitable risks, speeds up vulnerability remediation, and reduces security debt at scale using a proprietary AI-assisted remediation engine.N/A
    Pricing
    HCL AppScanVeracode
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    HCL AppScanVeracode
    Free Trial
    YesYes
    Free/Freemium Version
    NoYes
    Premium Consulting/Integration Services
    NoYes
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details—Developer pricing options available
    More Pricing Information
    Community Pulse
    HCL AppScanVeracode
    Considered Both Products
    HCLSoftware
    Chose HCL AppScan
    When we used Veracode, it takes a-lot of time to run a source code analysis. It's user interface is also bit clumsy. So we switched to HCL AppScan. It enables enterprises to scan internal and external applications for vulnerabilities. It provides quick and easy access to the …
    Incentivized
    Chose HCL AppScan
    We have been using AppScan for about 14 years (Before it was acquired by IBM). A few years ago we did an upgrade from the standard edition to the enterprise edition (to allow several users at once) in order to accommodate the growth of our team. Prior to this upgrade we looked …
    Incentivized
    Veracode
    Chose Veracode
    Veracode stands out as the best of breed for all types of AppSec scanners.
    Incentivized
    Chose Veracode
    None
    Incentivized
    Chose Veracode
    Veracode is a solution easy to set up and integrate with virtually any pipeline--a single product for three solutions.
    Incentivized
    Chose Veracode
    I used AppScan for dynamic scanning when it was IBM, but it was too clunky and hard to use. Developers and testers needed to spend quite a bit of time configuring scans. I also used Checkmarx for static scanning and it was faster, but it requires you to install on your own …
    Incentivized
    Chose Veracode
    Software as a service is a key factor. Programs are easy to establish and quick to ramp up. Low false positive rates means lower engineer fatigue and frustration. Data path exposure makes resolution obvious and easier. Other providers tend to sell technology and many times …
    Incentivized
    Key User Insights
    Would buy again
    100%
    Would buy again
    5 Answers
    92%
    Would buy again
    128 Answers
    Delivers good value for the price
    No answers on this topic
    96%
    Delivers good value for the price
    90 Answers
    Happy with the feature set
    100%
    Happy with the feature set
    5 Answers
    95%
    Happy with the feature set
    132 Answers
    Lived up to sales and marketing promises
    No answers on this topic
    95%
    Lived up to sales and marketing promises
    76 Answers
    Implementation went as expected
    No answers on this topic
    86%
    Implementation went as expected
    101 Answers
    Best Alternatives
    HCL AppScanVeracode
    Small Businesses
    No answers on this topic
    Rencore Code (SPCAF)
    Score8.8 out of 10
    Medium-sized Companies
    No answers on this topic
    Trend Vision One Email and Collaboration Security
    Score9.9 out of 10
    Enterprises
    No answers on this topic
    Checkmarx
    Score7.6 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    HCL AppScanVeracode
    Likelihood to Recommend
    8.3
    (6 ratings)
    8.3
    (144 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    6.3
    (9 ratings)
    Usability
    -
    (0 ratings)
    5.5
    (29 ratings)
    Availability
    -
    (0 ratings)
    7.3
    (2 ratings)
    Performance
    -
    (0 ratings)
    2.7
    (2 ratings)
    Support Rating
    -
    (0 ratings)
    7.6
    (67 ratings)
    Implementation Rating
    -
    (0 ratings)
    5.5
    (4 ratings)
    Configurability
    -
    (0 ratings)
    6.4
    (2 ratings)
    Contract Terms and Pricing Model
    -
    (0 ratings)
    4.5
    (1 ratings)
    Ease of integration
    -
    (0 ratings)
    6.4
    (2 ratings)
    Product Scalability
    -
    (0 ratings)
    6.4
    (2 ratings)
    Vendor post-sale
    -
    (0 ratings)
    6.4
    (3 ratings)
    Vendor pre-sale
    -
    (0 ratings)
    8.2
    (2 ratings)
    User Testimonials
    HCL AppScanVeracode
    Likelihood to Recommend
    HCLSoftware
    In HCL AppScan automation maintain a reasonable pace of review and remediation of flaws for our apps. HCL AppScan is a cloud-based enterprise mobile application security testing solution for Android and iOS applications developed using Java, .Net or Objective-C. So it covers all our area and It consists of three components: AppScan Source Edition for developing and testing apps internally, AppScan Standard Edition for testing internally or externally, and AppScan Enterprise Edition for large enterprises who need to secure their entire mobile application portfolio across the organization with multiple device types.
    Incentivized
    Read full review
    Veracode
    Veracode helped us our team's developers in saving time significantly. For instance, if I take a library and assume it's going to work until it reaches QA or UAT, where we find out there's a vulnerability, that can require extensive effort for code refactoring or redesigning; Veracode helps prevent that before the pull request is merged.
    Incentivized
    Read full review
    Pros
    HCLSoftware
    • AppScan works well in finding application vulnerabilities such as SQL injection, cross-site scripting and all of the OWASP top 10.
    • Flexible reporting allows us to generate executive reports for application owners as well as separate technical reports for developers and system engineers.
    • Technical reports include remediation information and cross reference CVSS scores
    • Because it maintains data on all repeated assessments it helps us to do trending and metrics on compliance
    Incentivized
    Read full review
    Veracode
    • It is good at recommending fixing issues with third-party dependencies used in application code with detailed version information and knowing which version fixes what.
    • It has a very nice interface for triaging flaws. One can sort the vulnerabilities found in code from Very Likely to be exploited to least likely to be exploited.
    • There is a collections feature that allows us to group together groups of application profiles belonging to the same suite of applications.
    Incentivized
    Read full review
    Cons
    HCLSoftware
    • It can have a FAQ session in the Application itself.
    • It can recommend the fix for the error that occurred during the scan.
    • Like its storing multiple manuals explore, It should have the capability of storing multiple logins.
    Incentivized
    Read full review
    Veracode
    • Scan results stability: from one scan to another, additional flaws appear whereas code did not change.
    • Entry points selection: hard to be sure selection is optimal, should be automatized or hidden.
    • Branches management: we currently use sandboxes to scan different branches of our software. Would be good to have real branches management.
    Incentivized
    Read full review
    Likelihood to Renew
    HCLSoftware
    No answers on this topic
    Veracode
    At this time, and we just renewed a month ago, I dont see any products out there overall that can offer what Veracode does. Yes, its not cheap by any means, but for the money its the best application security scanning tool out there.
    Incentivized
    Read full review
    Usability
    HCLSoftware
    No answers on this topic
    Veracode
    - Almost no setup required and easy to configure - Very easy to use, intuitive UI with integrated analytics and learning portals. - Seamless to review the results, triage them, generate reports. - Security progression of the product/application is tracked via successive scans. - Privileges/Roles nicely fine grained and tightly controlled to let teams "view" only their products.
    Incentivized
    Read full review
    Reliability and Availability
    HCLSoftware
    No answers on this topic
    Veracode
    Veracode has always been up and available to us.
    Incentivized
    Read full review
    Performance
    HCLSoftware
    No answers on this topic
    Veracode
    At this point, it runs well and mostly in a timely fashion. Dynamic scans take days but this may be a config issue still to be resolved.
    Incentivized
    Read full review
    Support Rating
    HCLSoftware
    No answers on this topic
    Veracode
    Overall, Veracode support is helpful, community support is great, and documentation is available for self-service. Our Customer Success Manager is very helpful and reaches out regularly to see if we need assistance. We have not utilized many of the other resources offered by Veracode, however, in the future we would like to leverage secure coding training for our Development teams.
    Incentivized
    Read full review
    Implementation Rating
    HCLSoftware
    No answers on this topic
    Veracode
    We use it as a SAS service, so really just getting our teams to mold the use of Veracode into their SDLC has been a process of years in the making. It comes down to what your teams are ready and willing to accept and change. Management is key in getting their groups on board with using it regularly. If it doesnt have management backing, your security teams have little to no influence in getting this process off the ground fully.
    Incentivized
    Read full review
    Alternatives Considered
    HCLSoftware
    Both solutions are decent, however, I had team members who had the experience working with HCL AppScan. Also, the product was priced nominally which suited our budget. Further, HCL AppScan's user community was bigger and many learning resources were freely available which helped junior peers learn quickly and eliminate any issues
    Incentivized
    Read full review
    Veracode
    Veracode is slower with scan results however the flaws discovered and sites crawled are almost the same. Rapid7 InsightAppSec only does dynamic scans. Veracode did find more links on a site crawl. Rapid7 InsightAppSec has more out of the box reports than Veracode. Both integration to DevOps tools were striaghtforward.
    Incentivized
    Read full review
    Contract Terms and Pricing Model
    HCLSoftware
    No answers on this topic
    Veracode
    No idea
    Incentivized
    Read full review
    Scalability
    HCLSoftware
    No answers on this topic
    Veracode
    It meets our needs.
    Incentivized
    Read full review
    Return on Investment
    HCLSoftware
    • There are countless implementations to accomplish the same thing, and so many configurations are required.
    • Even if you test it finished and find no vulnerabilities, there is no point if you just get the error screen.
    • Until now, I was worried about vulnerabilities and security in software development, but I think it was good to find the vulnerability problem quickly with HCL AppScan.
    Incentivized
    Read full review
    Veracode
    • Positive: Scanning all our applications on Veracode provides us an overview of our cyber security posture for the organization as a whole.
    • Positive: Performing the SAST, SCA and DAST scanning for all the applications at the early stages of the SDLC helps us identify and mitigate security vulnerabilities early, reducing the risk of data breaches and cyber-attacks.
    • Negative: Sometimes Veracode SAST scanner closed and reopens some findings, leading to reliability issues on the scanner itself.
    Incentivized
    Read full review
    ScreenShots

    HCL AppScan Screenshots

    Screenshot of Cloud Security: AppScan will scan Docker containers and container images to ensure that third party components have not introduced vulnerabilities to an application. Software composition analysis (SCA) tools help organizations inventory third-party commercial and open source components used within their software to understand which components and versions are being used and to identify security vulnerabilities affecting those components.Screenshot of API Testing: This dangerous attack vector can be secured by identifying vulnerable third-party components, automating and integrating API testing and detecting issues in the IDE.Screenshot of Auto Issue Correlation: AppScan leverages three technologies (DAST, SAST, IAST) to enrich results, validate fixes and reduce the number remediation tasks by grouping issues together.Screenshot of 30+ Code Languages Supported: HCL AppScan offers an extensive list of supported code languages.

    Veracode Screenshots

    Screenshot of a fixScreenshot of the Veracode PlatformScreenshot of SCAScreenshot of SCA Github