

Contrast Security Assess and Check Point WAF are prominent solutions in the application security category. Contrast Security Assess appears to have an edge in reducing false positives and operational costs due to its efficient integration into the development environment, whereas Check Point WAF excels in leveraging AI for comprehensive threat detection and security management.
Features: Contrast Security Assess provides real-time monitoring, seamless integration with development tools like Azure DevOps, and an impressive reduction in false positives, enhancing security efficiency. Its flexible platform compatibility and detailed vulnerability insights are also notable. Check Point WAF offers advanced threat detection, AI-driven threat prevention, and effective zero-day attack protection with AI and ML capabilities that ensure robust threat mitigation.
Room for Improvement: Contrast Security Assess could benefit from AI-driven features and improved report customization for broader technology support. Enhanced API functionalities and client-side technology identification would advance its capabilities. Check Point WAF needs to simplify its UI, reduce false positives further, and streamline policy management to address initial setup complexity and enhance support documentation.
Ease of Deployment and Customer Service: Contrast Security Assess promotes quick deployment with excellent customer support, ensuring responsive assistance. Check Point WAF, while robust across environments, faces a more complex deployment process with generally helpful customer service that may struggle under high demand or complex multi-cloud queries.
Pricing and ROI: Contrast Security Assess is appreciated for improving development efficiency, reducing IT involvement, and offering a flexible licensing model, thereby enhancing ROI. Check Point WAF is considered cost-effective for its expansive features, though it may be more expensive than some competitors. Both products provide substantial ROI through cost savings and improved security, with Contrast Security Assess showing superior results in operational efficiency and personnel cost reduction.
When we are attacked, we can understand how important the solution is.
When you migrate to the cloud, it feels like saving 90% of your time.
Most of the operations happen in the background, so I do not spend much time on it.
Contrast has probably saved us a couple hundred hours over the past six years.
In the past, my company employed five security engineers, but with Contrast Security Assess, we only have two people.
The speed of fixing issues is significantly improved due to the vast amount of information provided by Contrast Security Assess, making it quite essential for finding the root cause of problems in the source code.
They need to increase the number of people for 24/7 support.
They were responsive even before we committed to buying their solution.
I also received full technical support, especially during the implementation.
They go out of their way to respond quickly and very knowledgeably.
Customer support is one of the strongest points of Contrast Security Assess, as they are really responsive and answer tickets in less than one hour.
Contrast Security's customer support is very active and overall incredible.
If I need to scale, I open a Whatsapp group with the director and the team, and we quickly proceed to do so.
They have sufficient resources, and there are no challenges from a scalability perspective.
Check Point CloudGuard WAF's scalability is very good.
It is fairly simple to install the agents for Contrast Security Assess and keep them updated.
Contrast Security Assess's scalability is not an issue at all.
It is very stable.
It is very stable, never crashing or giving me an error that I can see.
I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.
Contrast Security Assess is genuinely more accurate than most tools I have worked with because it uses instrumentation from inside the application.
We opened a ticket to customer support and experienced four weeks of disruption due to the extension malfunctioning in some of the .NET servers running Contrast Security Assess.
The provider could improve by providing better guidance and support during the configuration process.
Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
A machine learning-based adaptive mode could help the WAF learn over time and auto-tune policies.
Regarding Contrast Security Assess's AI capabilities, I think they are missing a huge opportunity because they could lead the way in automatic testing and AI security testing.
I would love to see more customizable, out-of-the-box reporting that speaks to both technical and non-technical people without extra configuration.
Contrast support has been great in fixing any issues or getting back to us with questions.
It is more expensive than f5, where we purchased everything as bundles, and Check Point costs more, but it is worth the money.
It is less costly than Cloudflare, Fortinet, and other vendors.
I know that its price is relatively expensive compared to other products but it gives benefits that are worth it.
The annual licensing for Contrast Security Assess costs about $20,000 to $100,000 per year, and per application, it costs about $5,000 to $15,000 per year.
Licensing costs are fairly high compared to other DAST and SAST tools, but it seems to be worth the money.
Upon implementation and evaluation with third-party penetration testing, it meets rigorous security standards required for dealing with financial institutions.
It can protect against zero-day attacks and hidden anomalies.
The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.
The real-time detection feature of Contrast Security Assess helps us very well compared to traditional SAST tools. Traditional tools scan from the outside and guess where problems might be. Contrast Security Assess works from the inside because it is embedded into the application.
The ability to see what is going on and what has been going on in a given application and basically get to see what is coming across it in real time is helpful in finding vulnerabilities to remediate before production deployments.
Instead of fixing each vulnerability reported independently, you can group them and fix them in a single point in the source code, resolving several vulnerabilities at once.
| Product | Mindshare (%) |
|---|---|
| Check Point WAF (formerly CloudGuard WAF) | 0.9% |
| Contrast Security Assess | 1.7% |
| Other | 97.4% |


| Company Size | Count |
|---|---|
| Small Business | 54 |
| Midsize Enterprise | 23 |
| Large Enterprise | 34 |
| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 3 |
| Large Enterprise | 10 |
Check Point WAF offers a robust security framework with AI-driven threat detection and seamless integration, protecting applications and APIs in multi-cloud environments.
Effective in preemptively blocking threats through AI and machine learning, Check Point WAF reduces false positives and operational workload. Its integration capabilities and threat intelligence provide comprehensive protection against zero-day attacks, while centralized management facilitates cost-effective and insightful threat reporting.
What are the main features of Check Point WAF?Check Point WAF is employed in industries securing web applications and APIs, especially in multi-cloud environments. It effectively protects backend services, prevents unauthorized access, and monitors traffic, making it suitable for businesses with diverse infrastructures. It ensures compliance with security standards and adapts to fluctuating traffic patterns.
Contrast Security Assess is an IAST platform known for accurate vulnerability detection. It integrates into development workflows, offering real-time insights into security issues with minimal false positives, supporting legacy applications and enhancing code security visibility.
Designed to integrate seamlessly into DevOps workflows, Contrast Security Assess automates real-time vulnerability detection and reduces false positives through its powerful IAST features. By continuously monitoring vulnerabilities, it provides a robust option for securing legacy applications and identifying vulnerabilities without lengthy scans. This cloud-hosted platform supports numerous programming languages, making it versatile for security testing across enterprise environments. Users benefit from detailed reports that pinpoint exact code locations requiring remediation, enhancing speed and efficiency in addressing security concerns.
What are the key features of Contrast Security Assess?Companies in industries requiring high levels of application security, such as finance and healthcare, implement Contrast Security Assess for its ability to enhance visibility and detect vulnerabilities early in the development lifecycle. Its seamless integration with DevOps processes makes it ideal for environments that prioritize agility while maintaining stringent security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.