No more typing reviews! Try our Samantha, our new voice AI agent.

ACF2 vs Flow Security [EOL] comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ACF2
Average Rating
9.0
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Database Security (12th), Mainframe Security (4th)
Flow Security [EOL]
Average Rating
9.0
Reviews Sentiment
7.7
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Featured Reviews

reviewer1077621 - PeerSpot reviewer
IT Examiner at a financial services firm with 10,001+ employees
A reliable, scalable product for security and auditing of our mainframe environment
It is a good product. It has been used for years. As long as it is configured correctly, it is a very stable product. It depends on how an institution or a company configures it. It depends on an institution's risk appetite. You need to make sure it is configured as per the concept of least privilege, and the logging features, detection and control mechanism, and other things like that are enabled. If you configure it to give access to the public, then there could be compromises. You should also have someone who independently checks it to make sure that it is configured keeping security in mind. If it has been configured for a while, when there are enhancements to the product or when you enhance it, you need to make sure that security is also looked at, and it is configured according to an institution's security policies. I would rate it a nine out of 10.
reviewer2231631 - PeerSpot reviewer
Chief Information Security Officer at a computer software company with 51-200 employees
It gives us a risk report that helps us refine our process management by highlighting where we might be exposed
Flow's distinctive capability to analyze both data at rest and data in motion grants us the ability not only to get full visibility and classification of the data within our managed databases but also to visualize the data flows both within and beyond our environment. This enables us to achieve a comprehensive understanding of all our sensitive data, even as it traverses through applications, shadow databases, and external services such as third-party entities and SaaS applications. What we aspire to achieve with Flow is extended visibility into the external services themselves, which will allow us to see the data they contain.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I am deeply impressed with the quality and depth and breadth of security and functionality in CA’s ACF2 and Top Secret products."
"Excellent real-time reporting that saves time and resources."
"I love their support. The support is great. They are number one."
"The NOACCESS by default is another very good feature. Also, access rules are straightforward, and easy to understand."
"Without the product, extracting this information may take us as much as several days; instead, we can get it in real time."
"Know that this tool is a great tool, a good tool to use, because you can quickly automate, quickly provision, and deprovision new users, which is essential when you are bringing new people onboard."
"The most valuable feature is strict and reliable access control to CICS Resources."
"By providing a high level of access control to the z/OS systems, ACF2 allows us to maintain tight controls on dataset and system access and helps us keep unauthorized users from accessing PHI or PII data."
"Before implementing Flow Security, we had no mechanism to alert us when third-party contractors were accessing sensitive data or moving it to locations with lower security. Now we know precisely where the data is stored and can assess the risk when someone wants to develop something. Flow Security lowers our risk of a data breach."
 

Cons

"Initial setup could be complex if you rely on contractors to help with implementation."
"They can work on its ability to work in a distributed environment."
"Reporting can sometimes include false positives."
"The user access review could also be improved. It produces a lot of false positives."
"I would like my team and me to be able to use simple browsers, like Chrome, to be able to access mainframe data and provision users using the browser.​"
"They can work on its ability to work in a distributed environment. It's a mainframe product. As many companies move to the cloud, depending on what cloud models they choose, such as a public, hybrid, or private cloud, it should be deployable. I am not sure if it can be deployed on those platforms. It has been there since the '50s or '60s, and it's still scalable. It has survived all these years, and it's scalable to many platforms, but I don't know about the cloud."
"It needs longer rules. The max rule is 32K."
"It provides a good overview of our infrastructure, but I need more end-to-end visibility, and SaaS is one of the gaps."
report
Use our free recommendation engine to learn which Database Security solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Outsourcing Company
13%
Educational Organization
10%
Manufacturing Company
9%
Financial Services Firm
12%
Comms Service Provider
8%
Energy/Utilities Company
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise4
No data available
 

Also Known As

CA ACF2
No data available
 

Overview

 

Sample Customers

Sky, Rogers Communications
Information Not Available
Find out what your peers are saying about IBM, Imperva, Oracle and others in Database Security. Updated: September 2026.
913,683 professionals have used our research since 2012.