Check Point CloudGuard WAF vs Mend.io comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Check Point CloudGuard WAF
Ranking in Application Security Tools
11th
Average Rating
9.0
Number of Reviews
30
Ranking in other categories
Web Application Firewall (WAF) (14th)
Mend.io
Ranking in Application Security Tools
13th
Average Rating
8.4
Number of Reviews
29
Ranking in other categories
Software Composition Analysis (SCA) (4th), Static Code Analysis (4th), Software Supply Chain Security (1st)
 

Featured Reviews

RL
Mar 7, 2024
Easy deployment, good reporting, and excellent support
The service was available for the client on time. They had a go-to-market or a due date to start sending the app to various students to apply. We were there 24/7 hoping and waiting for everything to be fine, and it worked perfectly and smoothly. The client was very happy with the performance of Check Point on this project. When comparing it with Imperva, we strongly feel that the formula that Check Point delivers on WAF was what the client needed. Check Point CloudGuard works perfectly for preemptively blocking Zero Day attacks and detecting hidden anomalies. Check Point is all about prevention. We strongly believe that if you want to prevent threats, Check Point is the one. There is no one else.
GP
Jul 17, 2022
Provides threat detection and an excellent UI in a highly stable solution, with outstanding technical support
We have been looking at how we could improve the automation to human involvement ratio from 60:40 to 70:30, or even potentially 80:20, as there is room for improvement here. We are discussing this internally and with Mend; they are very accommodating to us. We think they openly receive our feedback and do their best to implement our thoughts into the roadmap. I consider scan reports to be another area for improvement, but this is also an area of improvement for user management on our end. We need to train end users on how to deal with alerts and the best approach to take for new projects. We have weekly meetings with Mend and encourage all users who integrate the solution into their product life cycle to attend. This has been very useful, as these technical meetings assist our staff in the best use practices and improving their interpretation of reports, which allows us to leverage the product to our greatest advantage. We are also able to ask for solutions adaptations to suit our requirements, as we produce hardware as a company, not virtual products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"After integrating AppSec with other applications, team members can easily work without fear of confidential information exposure."
"I find the configuration and real-time monitoring features valuable."
"Its ability to adapt to our applications and ensure our security policies are followed is a big plus."
"The tool's most valuable feature is AI, which makes operations easier. Moreover, it is easy to deploy."
"We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and it was amazing to see the results."
"The tool performs device health checkups and updates us. It helps us to be compliant with regulatory policies."
"By using a cloud application security solution, our company can save costs by reducing the need for additional security hardware and software and improving operational efficiency."
"With the solution, we managed to obtain complete comprehensive visibility of the entire environment in the cloud, thus having better control of each of the resources."
"The reporting capability gives us the option to generate an open-source license report in a single click, which gets all copyright and license information, including dependencies."
"The most valuable feature is the inventory, where it compiles a list of all of the third-party libraries that we have on our estate."
"The solution boasts a broad range of features and covers much of what an ideal SCA tool should."
"The most valuable features are the reporting, customizing libraries "In-house, White list, license selection", comparing the products/projects, and License & Copyright resolution."
"The overall support that we receive is pretty good. ​"
"The results and the dashboard they provide are good."
"It gives us full visibility into what we're using, what needs to be updated, and what's vulnerable, which helps us make better decisions."
"We set the solution up and enabled it and we had everything running pretty quickly."
 

Cons

"The coding configurations can be simplified to save time for IT teams and developers."
"I advise proactive threat detection intelligence offline, which can also help monitor and ensure system checks and compliances are in place."
"I have faced issues with the tool's blocking aspects. It is hard to open or block web services due to the multitude of cloud centers. I have to do the process manually at times. We have a bug which is hard to solve."
"Deeper and more transparent integration between Cloud Application Security and analysis monitoring tools could be very valuable - although the solution currently offers integrations with third-party security tools."
"I do not know if it is already there, but I would like to have complete visibility between the posture management and firewall as a service."
"It was costlier than other solutions."
"I have encountered issues with Check Point CloudGuard Application Security's technical support. It also has missing configuration features."
"The documentation needs to be updated, more improved, and simplified... so that even a beginner can start with this application. It can make things more beginner-friendly."
"We specifically use this solution within our CICD pipelines in Azure DevOps, and we would like to have a gate so that if the score falls below a certain value then we can block the pipeline from running."
"It would be good if it can do dynamic code analysis. It is not necessarily in that space, but it can do more because we have too many tools. Their partner relationship support is a little bit confusing. They haven't really streamlined the support process when we buy through a reseller. They should improve their process."
"Mend lets you create custom policies. They're not too complicated to set up, but it would be helpful if they had some preconfigured policies to match what we have in Azure DevOps. That would save us a lot of time. It's tedious to configure the policies manually, and I lack the capacity to do it right now. Other products have preconfigured packs and templates, and Mend doesn't."
"WhiteSource needs improvement in the scanning of the containers and images with distinguishing the layers."
"The solution lacks the code snippet part."
"WhiteSource Prioritize should be expanded to cover more than Java and JavaScript."
"Mend supports most of the common package managers, but it doesn't support some that we use. I would appreciate it if they can quickly make these changes to add new package managers when necessary."
"Some detected libraries do not specify a location of where in the source they were matched from, which is something that should be enhanced to enable quicker troubleshooting."
 

Pricing and Cost Advice

"It is reasonable as compared to the other solutions."
"Check Point CloudGuard Application Security's pricing is comparable to other products in the market."
"The tool's licensing costs are yearly and competitive."
"It is not cheap, but it is worth it."
"Considering all the benefits we've observed, we find the price to be satisfactory."
"I work for an Indian banking client. In India, companies are on a budget. The company liked Check Point very much, but it was a little bit costly compared to FortiWeb. However, it had more features compared to FortiWeb."
"The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
"I find the pricing to be reasonable."
"Pricing and licensing are comparable to other tools. When we started, it was less than our existing solution. I can't go into specifics, but it isn't cheap."
"We always negotiate for the best price possible, and as far as I know, Mend has done an excellent job with their pricing. Our management is happy with the pricing, which has led to renewals."
"The version that we are using, WhiteSource Bolt, is a free integration with Azure DevOps."
"This is an expensive solution."
"We are paying a lot of money to use WhiteSource. In our company, it is not easy to argue that it is worth the price. ​"
"As we were using an SaaS-based service, the solution must be scalable, although my understanding is that this is based on the licensing model one is using."
"When comparing the price of WhiteSource to the competition it is priced well. The cost for 50 users is approximately $18,000 annually."
"The solution involves a yearly licensing fee."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Security Firm
26%
Financial Services Firm
24%
Computer Software Company
7%
Healthcare Company
7%
Financial Services Firm
18%
Computer Software Company
17%
Manufacturing Company
11%
Insurance Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about CloudGuard for Application Security?
The app control is very sensitive, and the threat detection and prevention is better than other Check Point solutions. There is a centralized management console for threat protection and self-inspe...
What is your experience regarding pricing and costs for CloudGuard for Application Security?
It is reasonable compared to other solutions. Check Point is a medium-sized business in the market, whereas F5, Juniper, SonicWall, and IBM are big players. Compared to them, its pricing is quite r...
What needs improvement with CloudGuard for Application Security?
We have many users or employees who are using the VPN to access our network. More configuration for VPN users is required. More scalability is also required because, as compared to other Check Poin...
How does WhiteSource compare with SonarQube?
Red Hat Ceph does well in simplifying storage integration by replacing the need for numerous storage solutions. This solution allows for multiple copies of replicated and coded pools to be kept, ea...
How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What do you like most about Mend.io?
The best feature is that the Mend R&D team does their due diligence for all the vulnerabilities. In case they observe any important or critical vulnerabilities, such as the Log4j-related vulner...
 

Comparisons

 

Also Known As

Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
WhiteSource, Mend SCA, Mend.io Supply Chain Defender, Mend SAST
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
Microsoft, Autodesk, NCR, Target, IBM, vodafone, Siemens, GE digital, KPMG, LivePerson, Jack Henry and Associates
Find out what your peers are saying about Check Point CloudGuard WAF vs. Mend.io and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.