No more typing reviews! Try our Samantha, our new voice AI agent.

Coverity Static vs TrendAI Vision One – Cloud Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coverity Static
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
43
Ranking in other categories
Static Application Security Testing (SAST) (8th)
TrendAI Vision One – Cloud ...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
23
Ranking in other categories
Vulnerability Management (28th), Container Security (22nd), Cloud Workload Protection Platforms (CWPP) (12th), Hybrid Cloud Computing Platforms (8th), Extended Detection and Response (XDR) (17th), Cloud Security Posture Management (CSPM) (14th), Cloud-Native Application Protection Platforms (CNAPP) (13th), Attack Surface Management (ASM) (9th), Cloud Infrastructure Entitlement Management (CIEM) (4th), Cloud Detection and Response (CDR) (7th), AI Security (12th)
 

Mindshare comparison

Coverity Static and TrendAI Vision One – Cloud Security aren’t in the same category and serve different purposes. Coverity Static is designed for Static Application Security Testing (SAST) and holds a mindshare of 2.8%, down 8.0% compared to last year.
TrendAI Vision One – Cloud Security, on the other hand, focuses on Extended Detection and Response (XDR), holds 1.7% mindshare, up 0.3% since last year.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Coverity Static2.8%
SonarQube14.5%
Checkmarx One9.2%
Other73.5%
Static Application Security Testing (SAST)
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
TrendAI Vision One – Cloud Security1.7%
CrowdStrike Falcon9.2%
SentinelOne Singularity Endpoint6.0%
Other83.1%
Extended Detection and Response (XDR)
 

Featured Reviews

BL
Software Quality Expert at Endress+Hauser AG
Useful for extra checks but not recommended for C++
We're currently facing a primary challenge with automation using Coverity. Each developer has a license and can perform manual checks, and we also have a nightly build that analyzes the entire software. The main issue is that the tool can't look behind submodules in our code base, so it doesn't see changes stored there. This limitation means it can't detect changes accurately, forcing us to analyze all files instead of just the modified ones. It struggles with repositories organized with different submodules. Although documentation suggests it's possible to configure Coverity to handle this, it requires effort. The solution's analysis tools are high-quality, but the web design could improve. For example, the data is organized into pages when there are many findings, such as ten thousand lines of information. Each page shows about a hundred items, and navigating through these pages (from items 100 to 200, 200 to 300, and so on) can be cumbersome. I've heard from a colleague about another Synopsys tool with a very good GUI. It might be a solution for us to include with Coverity. We invested in Coverity, but compared to SonarQube, it lacks a good interface. SonarQube has a responsive, intuitive GUI, but its analysis quality isn't as good as Coverity's. Coverity's interface isn't great, but its analysis is much better. We hope Synopsys will improve Coverity because it doesn't make a good impression when you first use it. We started with the command line and saw the results were very good. We moved from another tool with a slightly better GUI, but it crashed often, so Coverity was an improvement. When I used the solution earlier, I noticed some issues. It supports C++, which we use, but there's room for improvement. Coverity has two plug-ins. The newer one works well for languages like C# or Java and is very responsive. When we evaluated it with Synopsys, they presented it as easy to configure and install. However, C++ slows down significantly because it's analyzing in the background. It's not very responsive when typing, likely due to the many included files in C++ that need analysis. It's not as quick as with C# or other languages, where you get immediate feedback from Coverity. The classic plug-in is still supported but old-fashioned. It has a manual option, but I haven't checked it. The main problem for C++ users who prefer the old plug-in is responsiveness.
reviewer2793894 - PeerSpot reviewer
Platform Engineer Ii at a outsourcing company with 5,001-10,000 employees
Centralized cloud view has improved threat response and simplified compliance reporting
We are using Trend Vision One - Cloud Security for getting complete visibility of all the assets that exist within our cloud, and it helps us identify any sort of misconfigurations or fine-tuning that can be done to better our compliance. Trend Vision One - Cloud Security helps in onboarding all the cloud solutions or cloud providers that we have within our organization into a single dashboard, thereby providing greater visibility of all the assets. Earlier we used to have multiple dashboards to manage the same solution or capability, but with Trend Micro, we are able to get everything in a single pane of glass, benefiting our operations significantly. We are using the playbooks built into Trend Vision One - Cloud Security, which help us take a lot of response actions and bring automation capabilities into play. Trend Vision One - Cloud Security has positively impacted our organization by providing a single pane of glass visibility across all the cloud solutions that we have and reducing the number of threats we used to see earlier in the cloud. We are seeing that the number of cloud operations required earlier in terms of threat detection and response, and the time taken to detect a particular threat and take a response action, has considerably improved after onboarding Trend Micro.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Provides software security, and helps to find potential security bugs or defects."
"The most valuable feature is that there were not a whole lot of false positives, at least on the codebases that I looked at."
"The solution has improved our code quality and security very well."
"The security analysis features are the most valuable features of this solution."
"The solution was very simple to set up."
"The most valuable feature of Coverity is the wrapper. We use the wrapper to build the C++ component, then we use the other code analysis to analyze the code to the build object, and then send back the result to the SonarQube server. Additionally, it is a powerful capabilities solution."
"This solution is easy to use."
"The interface of Coverity is quite good, and it is also easy to use."
"Virtual patching is one of the key features, which is executed with their IPS."
"Detection response and cloud conformity are valuable features."
"The return on investment is very high because it is so flexible and you can actually cancel this service whenever you want."
"I use the tool for security solutions. It's a leader in Gartner and Forrester Wave reports. Customers rely on these reports."
"Trend Vision One - Cloud Security's best features are security analysis, remote access security, and driver security."
"You get to manage all these things from a single management console and point of view."
"Trend Vision One stands out for its stability and reliability compared to its competitors."
"The product helps us understand our environment better."
 

Cons

"We actually specified several checkers, but we found some checkers had a higher false positive rate. I think this is a problem. Because we have to waste some time is really the issue because the issue is not an issue. I mean, the tool pauses or an issue, but the same issue is the filter now.Some check checkers cannot find some issues, but sometimes they find issues that are not relevant, right, that are not really issues. Some customisation mechanism can be added in the next release so that we can define our Checker. The Modelling feature provided by Coverity helps in finding more information for potential issues but it is not mature enough, it should be mature. The fast testing feature for security testing campaign can be added as well. So if you correctly integrate it with the training team, maybe you can help us to find more potential issues."
"Ideally, it would have a user-based license that does not have a restriction in the number of lines of code."
"Right now, the Coverity executable is around 1.2GB to download. If they can reduce it to approximately 600 or 700MB, that would be great. If they decrease the executable, it will be much easier to work in an environment like Docker."
"The price is a concern, and there are a lot of false positives coming through."
"It should be easier to specify your own validation routines and sanitation routines."
"The quality of the code needs improvement."
"We use GitHub and Gitflow, and Coverity does not fit with Gitflow. I have to create a screen for our branches, and it's a pain for developers. It has been difficult to integrate Coverity with our system."
"It is an expensive solution. Their sales team is very arrogant."
"One area for improvement in Trend Vision One - Cloud Security is marketing; in particular, Trend Vision should update the marketing documentation. The information needs to be more comprehensive."
"Trend Vision One - Cloud Security could improve connections with different types of authentication and user groups concerning cloud services."
"Trend Vision One - Cloud Security should address threats automatically without having user input."
"The licensing model could be improved. To gain full coverage, you need to spend more to buy subscriptions for each kind of service they offer. It will start to be pricey if you want full coverage."
"I would like to see more third-party integrations being added into Trend Vision One - Cloud Security, as it currently has a good amount of integrations but does not allow ingestion from many third-party solutions."
"Documentation on cloud architecture and job architecture would be helpful."
"The licensing could be made easier to understand."
"The initial setup is easy for someone who operates container platforms on a daily basis. However, it could be difficult for those coming purely from informational security or another field of an IT."
 

Pricing and Cost Advice

"The solution is affordable."
"Offers varying prices for different companies"
"The licensing fees are based on the number of lines of code."
"I would rate the tool's pricing a one out of ten."
"The solution's pricing is comparable to other products."
"This is a pretty expensive solution. The overall value of the solution could be improved if the price was reduced. Licensing is done on an annual basis."
"The tool was fairly priced."
"Depending on the usage types, one has to opt for different types of licenses from Coverity, especially to be able to use areas like report viewing or report generation."
"It's a slightly expensive product."
"The pricing for Cloud One is reasonable because my costs scale up and down based on my infrastructure usage."
"I rate the solution's pricing a six out of ten."
"The Trend Vision One pricing is reasonable."
"While Trend Vision One - Cloud Security was a cost-effective solution for us in 2021, we've noticed a recent price increase that makes it less affordable."
"With everything I deal with, Trend Micro Cloud One's pricing is somewhere in the middle."
"Two years ago, it cost $200 for 20 credits, which was a high cost."
"Pricing for Trend Micro Cloud One Container Security in the corporate market is okay."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
902,417 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
29%
Computer Software Company
9%
Financial Services Firm
7%
Comms Service Provider
5%
Manufacturing Company
10%
Financial Services Firm
10%
Comms Service Provider
9%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise6
Large Enterprise10
 

Questions from the Community

How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What needs improvement with Coverity?
The price is a concern, and there are a lot of false positives coming through. Support with Coverity is adequate, but they take a longer time to respond. The core support is not straightforward, an...
What is your experience regarding pricing and costs for Trend Micro Cloud One Container Security?
The pricing for Trend Vision One - Cloud Security is very straightforward; we are using credits for calculating the solution that is required, and in terms of setup cost and licensing, it is very f...
What needs improvement with Trend Micro Cloud One Container Security?
I would like to see more third-party integrations being added into Trend Vision One - Cloud Security, as it currently has a good amount of integrations but does not allow ingestion from many third-...
What is your primary use case for Trend Micro Cloud One Container Security?
The main use case for Trend Vision One - Cloud Security is to secure our cloud environment from threats and we had to also abide by compliances, which is why we procured cloud security from Trend M...
 

Also Known As

Synopsys Static Analysis
Trend Micro Cloud One , Cloud One Workload Security, Trend Micro Cloud One Container Security, Trend Micro Cloud One Application Security, Cloud One File Storage Security, Cloud One Network Security, Cloud One Conformity
 

Overview

 

Sample Customers

SAP, Mega International, Thales Alenia Space
Information Not Available
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: May 2026.
902,417 professionals have used our research since 2012.