No more typing reviews! Try our Samantha, our new voice AI agent.

Aikido Security vs NGINX App Protect comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.3
Qualys TotalCloud effectively reduces costs and labor while enhancing asset visibility and risk management, boosting efficiency by up to 40%.
Sentiment score
7.5
Aikido Security improved efficiency by reducing vulnerabilities, review time, and costs while increasing productivity and profitability through streamlined processes.
Sentiment score
5.8
NGINX App Protect offers notable ROI, enhancing security, integrating with CICD pipelines, and providing compliance and time-saving benefits.
We are able to scan all our assets with less human intervention and achieve overall effective outcomes.
Dns architect at a outsourcing company with 5,001-10,000 employees
It has saved about 90% of our time.
Senior Consultant at a consultancy with 10,001+ employees
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
Security Manager at a consultancy with 10,001+ employees
Aikido Security caught a critical remote code execution vulnerability in my Python machine learning pipelines before it reached production.
GEN AI Engineer at a educational organization with 51-200 employees
Since we got rid of that, our productivity has increased, I believe, by thirty-two percent.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
We were expecting to complete the compliance in a month, but I figured out Aikido Security could do it within a week for all our 13 repositories.
Co-Founder & CTO at Mango Giraffe
 

Customer Service

Sentiment score
6.7
Qualys TotalCloud support is knowledgeable but inconsistent, with some delays and varying service quality affecting customer satisfaction.
Sentiment score
7.3
Aikido Security's efficient, responsive support and helpful resources lead to high satisfaction, though some desire 24/7 availability.
Sentiment score
5.8
NGINX App Protect's support is reliable and helpful, though costs and occasional delays affect accessibility for some users.
They are helpful, respond to my queries, and can answer any question.
Developer at a consultancy with 10,001+ employees
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Service Manager, Security Operations at CDA IT SOLUTIONS
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
Works at a consultancy with 10,001+ employees
Aikido Security was the easiest to use, the easiest to onboard, and the one with the most active customer support.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
Their team proactively reached out after signup to ensure we were set up correctly.
GEN AI Engineer at a educational organization with 51-200 employees
Customer support is good; if you raise a query, hardly within a day, your issues get resolved.
Security Researcher at a tech vendor with 10,001+ employees
They were quick and efficient when we had issues.
Project Manager at a comms service provider with 10,001+ employees
I would rate the customer support a 9 on a scale of 1 to 10.
Tech Lead at a tech vendor with 51-200 employees
 

Scalability Issues

Sentiment score
7.4
Qualys TotalCloud efficiently scales across multi-cloud environments, supporting diverse needs for small and large teams with minimal issues.
Sentiment score
7.7
Aikido Security efficiently scales with organizational growth, handling increased workloads and maintaining fast performance with minor adaptability challenges.
Sentiment score
6.1
NGINX App Protect offers strong scalability praised by users, despite challenges with policy limits and deployment delays.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
CIO at a venture capital & private equity firm with 11-50 employees
Our organization currently uses it to manage over 1200 web applications.
Analyst, Information Security at Infosys
It is absolutely scalable, and I would rate its scalability as nine out of ten.
retired at a consultancy with 10,001+ employees
That kind of reliability becomes invisible when it works well, which is exactly what you want from a security tool running in your CI/CD pipelines.
GEN AI Engineer at a educational organization with 51-200 employees
Aikido Security scales well by supporting multiple projects, repositories, and development teams on a single platform.
Full Stack Developer at Sri Krishna Arts and Science
You can deploy it on your team, and if you have a large team, it works very well.
Security Researcher at a tech vendor with 10,001+ employees
The scalability of NGINX App Protect is good and open source at its best.
Tech Lead at a tech vendor with 51-200 employees
 

Stability Issues

Sentiment score
8.4
Qualys TotalCloud is praised for its stability, 99.9% uptime, reliable performance, and responsive support for resolving issues.
Sentiment score
8.7
Aikido Security provides stable, reliable operation with seamless integration and efficient updates, consistently meeting user needs despite occasional delays.
Sentiment score
8.4
Users praise NGINX App Protect's stability and reliability, outperforming competitors, handling high traffic efficiently, and receiving high ratings.
Overall, the support provided has been excellent.
Analyst, Information Security at Infosys
It has a lot of scanning mechanisms, which are agentless APIs, eBPF, and cloud agents, that are highly reliable.
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
It is a stable solution, which is why we chose it.
CIO at a venture capital & private equity firm with 11-50 employees
The platform has been reliable and provides accurate security findings.
Full Stack Developer at Sri Krishna Arts and Science
It remains stable even when generating a large amount of code.
Senior Associate Infrastructure at Publicis Sapient
It is a quality solution, and I would rate its stability as eight out of ten.
IT Architect at a financial services firm with 10,001+ employees
 

Room For Improvement

Qualys TotalCloud needs UI/UX enhancements, better integrations, compliance reporting, Windows container security, AI threat prediction, and pricing clarity.
Aikido Security needs better tool integration, detailed guidance, interface simplification, customizable reporting, and improvements in speed and support.
NGINX App Protect needs enhancements in automation, UI, security, performance, and support, with complex setup and integration issues.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Analyst, Information Security at Infosys
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Project Lead at Persistent Systems
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
Senior Information Security Engineer at a consultancy with 10,001+ employees
I would love to see a Terraform module for Aikido Security.
SecOps Engineer at a real estate/law firm with 501-1,000 employees
I had a certain object with a UUID that was being considered as a private secret key or API key, which was not the case.
Co-Founder & CTO at Mango Giraffe
Aikido Security tells you what is vulnerable, but sometimes the fix suggestions are generic.
GEN AI Engineer at a educational organization with 51-200 employees
There was more information from F5 regarding hardware requirements and specifications to deploy the service.
IT Architect at a financial services firm with 10,001+ employees
For now, I think NGINX App Protect is good, but maybe I would like to see the logging feature added.
Dev Ops Engineer at BARQ Systems
The GUI and web GUI configuration could be improved to be easier to manage and use.
Dev Ops Engineer at adesso AG
 

Setup Cost

Qualys TotalCloud offers competitive pricing for large enterprises, providing flexible, cost-effective solutions with comprehensive features and benefits.
Aikido Security offers competitive pricing, minimal setup costs, and flexible plans, including a valuable free version and trial.
NGINX App Protect offers reasonable annual pricing, ranging from $25,000 to $400,000, aligning with industry-leading solutions.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Senior Manager at a financial services firm with 10,001+ employees
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
IT Manager at a consultancy with 10,001+ employees
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
Vice President at Inspira Enterprise
I used the free trial, which was sufficient for evaluating the platform and its core features.
Full Stack Developer at Sri Krishna Arts and Science
Aikido Security has a plan for $4,200 annually for up to 10 users.
Technical leader at a government with 5,001-10,000 employees
My experience with pricing, setup cost, and licensing is that the pricing is reasonable and based on the repository; they charge accordingly.
Senior Associate Infrastructure at Publicis Sapient
 

Valuable Features

Qualys TotalCloud enhances cloud security with risk prioritization, automation, and visibility, boosting efficiency in vulnerability management and remediation.
Aikido Security simplifies vulnerability scanning with a unified dashboard, strong automation, and integrations, enhancing security and compliance.
NGINX App Protect provides comprehensive security features including automation, real-time threat detection, DDoS protection, and flexible deployment options.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
Works at a consultancy with 10,001+ employees
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
Developer at a consultancy with 10,001+ employees
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
Senior Consultant at a consultancy with 10,001+ employees
We were able to get all codebase vulnerability fixes within a week for all our 13 or 14 repositories that we had.
Co-Founder & CTO at Mango Giraffe
Security shifted left, meaning issues were caught during development rather than after deployment.
GEN AI Engineer at a educational organization with 51-200 employees
My favorite feature is the dependency vulnerability scanning because it quickly identifies the risk in third-party packages, which saves me time in finding vulnerabilities.
Full Stack Developer at Sri Krishna Arts and Science
The most valuable feature is the ability to operate in a DevOps environment and to be configured through API and pipeline by the developers themselves.
IT Architect at a financial services firm with 10,001+ employees
Some threats like injection and running scripts, SQL injections, these all get stopped and rejected by the server.
Dev Ops Engineer at BARQ Systems
Detecting bots and blocking IPs have proven effective for securing applications.
Project Manager at a comms service provider with 10,001+ employees
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Container Security
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Cloud Workload Protection Platforms (CWPP) (9th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Aikido Security
Ranking in Container Security
16th
Average Rating
9.0
Reviews Sentiment
7.3
Number of Reviews
9
Ranking in other categories
Application Security Tools (7th), Static Application Security Testing (SAST) (4th), Web Application Firewall (WAF) (11th), Software Composition Analysis (SCA) (6th), Static Code Analysis (4th), Cloud Security Posture Management (CSPM) (12th), Dynamic Application Security Testing (DAST) (4th), DevSecOps (6th), Application Security Posture Management (ASPM) (5th)
NGINX App Protect
Ranking in Container Security
27th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
27
Ranking in other categories
Web Application Firewall (WAF) (20th), API Security (9th)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Tarunn Goswami - PeerSpot reviewer
GEN AI Engineer at a educational organization with 51-200 employees
Security has shifted left and now catches vulnerabilities early in our development workflow
There are a few areas for improvement. The first is scan speed. For large repositories, initial scans can be slow. Incremental scanning helps, but full scans still take considerable time. The second thing is the false positive rate. While Auto-Triage is good, it is not perfect. Occasionally, genuine issues get filtered out and real false positives slip through. The third one is remediation guidance. Aikido Security tells you what is vulnerable, but sometimes the fix suggestions are generic. More specific, actionable remediation steps would save developer time. The fourth one is IDE integrations. It currently works best in CI/CD pipelines. A proper VS Code or JetBrains plugin for real-time scanning while coding would be a significant improvement. From a customer point of view, the following things could change. The first thing is documentation for custom rules. Aikido Security allows you to create custom scanning rules, but the documentation for this feature is surprisingly thin. I spent considerable time in community forums and with trial and error just to configure basic custom rules. Step-by-step guides with real-world examples would make this feature much more accessible. The second thing is better Slack and communication integrations. Currently, security alerts come through email and dashboard notifications, but our team lives in Slack. A more configurable Slack integration that sends contextual alerts directly to the relevant developer, not just a generic channel notification, would dramatically improve response time. The third one is historical trend reporting. While Aikido Security shows current vulnerability status well, generating historical reports showing security posture improvement over time is limited. For presenting security progress to management or stakeholders, better exportable trend reports would be very valuable.
Valerio Guaglianone - PeerSpot reviewer
Dev Ops Engineer at adesso AG
Long-term web protection has supported reliable traffic management but needs a simpler interface
NGINX App Protect is a good product. I have used both versions from F5 -also the free version- (I mean the NGINX/NGINX One/App Protect free trial period), and I think it is a good product. It's stable, affordable, and easy to manage. NGINX App Protect is a comprehensive security solution that combines advanced WAF, DoS protection, API security, and DevSecOps automation in a lightweight, scalable package ideal for modern cloud-native architectures. The adaptive machine learning capabilities are truly commendable, as the solution can establish traffic baselines and detect anomalies in real time. It automatically adjusts security policies, minimizing the need for manual intervention and reducing false positives. Additionally, it supports scalable deployment across diverse environments, including on-premises, cloud, Kubernetes, and containers, offering both flexibility and scalability I have experience with the web server, F5 load balancer, and similar products provided by Ergon, for eg. the web application firewall and the Microgateway for K8S. I'm also familiar with F5 BIG-IP products.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Comms Service Provider
13%
Outsourcing Company
11%
Manufacturing Company
11%
Financial Services Firm
8%
Comms Service Provider
12%
Financial Services Firm
11%
Manufacturing Company
8%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise35
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise14
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What needs improvement with Aikido Security?
One area I think Aikido Security could improve is the depth of their reporting and remediation guidance; sometimes, t...
What is your primary use case for Aikido Security?
My main use case for Aikido Security is to consolidate all our application security scanning into one platform, prima...
What advice do you have for others considering Aikido Security?
My advice for anyone considering Aikido Security is to proceed and try it as the onboarding process is straightforwar...
What is your experience regarding pricing and costs for NGINX App Protect?
I will not be able to answer about my experience with pricing, setup cost, and licensing for NGINX App Protect, as so...
What needs improvement with NGINX App Protect?
I did not face any issues with NGINX App Protect. The only issue that we had is that someone was trying to install th...
What is your primary use case for NGINX App Protect?
I have been dealing with NGINX App Protect and the WAF policy. I usually recommend NGINX App Protect for banking and ...
 

Also Known As

Qualys TotalCloud with FlexScan
No data available
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Information Not Available
FinTech GoCardless ZIP CertifID HealthTech Dental Intelligence PE & Group Techstars Cronos Group Security Tech Human Security Tines HR Tech Simployer Recruitee Agency November Five Other Lighthouse (Hospitality Tech) Smokeball (LegalTech) Runna (B2C Tech) GEA Group (Manufacturing) Community fibre (Telecom) n8n (Software Development)
Information Not Available
Find out what your peers are saying about Aikido Security vs. NGINX App Protect and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.