

HCL AppScan and GitGuardian Platform both compete in the application security category, providing distinct solutions for different security needs. While AppScan is strong in vulnerability detection with good crawling capabilities, GitGuardian leads in real-time secret detection, making it crucial for securing code repositories.
Features: HCL AppScan offers comprehensive language support, static and dynamic testing, and effective vulnerability detection such as XSS in web applications. It integrates well into the SDLC. GitGuardian Platform excels in real-time secret detection across repositories, offering seamless CI/CD integration and supports a wide range of secret types, making it essential for early-stage data exposure prevention.
Room for Improvement: HCL AppScan could benefit from addressing false positives, improving scan speed, and enhancing integration in CI/CD environments. GitGuardian Platform needs better management of false positives, advanced customization options, and improved dashboards. Both should enhance third-party integration for a more connected experience.
Ease of Deployment and Customer Service: HCL AppScan predominantly offers on-premises deployment options and experiences mixed customer support feedback due to regional constraints. GitGuardian Platform operates efficiently in both public and hybrid cloud environments, generally receiving positive feedback on customer support and resource allocation.
Pricing and ROI: HCL AppScan faces criticism for high pricing, though it offers cost efficiencies over time, with users claiming a 50% return on investment by reducing vulnerabilities. GitGuardian Platform is considered expensive but justifies its price by preventing costly breaches, offering good value with its secrets management features, although rising prices may impact larger teams.
I can certainly say that we have saved significant time and resources in terms of people and automation.
Ninety percent of exposed secrets caught at the commit or PR stage, significantly reducing the risk of them reaching production.
The majority of our incidents for critical detectors and important secret types are remediated automatically or proactively by developers through GitGuardian's notification system, without security team involvement.
It effectively helps us with credentials security and has been performing satisfactorily.
I would rate their technical support a nine out of ten.
I would rate the technical support as excellent.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
Our experience shows that we were able to onboard multiple repositories and integrate it across different teams without performance degradation.
In terms of scalability, I would rate it around a ten out of ten, as it handles all the repositories and commit activity we have.
I would rate it a ten out of ten for scalability.
It is stable because when I push changes, it scans immediately, confirming fixes.
We did not face frequent downtime or disruptions in its core services, such as secret detection or CI/CD scanning.
We set up a lot of the repository, so GitGuardian is a required check.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
Better customization and control over detection rules would help, as real-world projects often require defining custom patterns or adjusting sensitivity levels based on specific use cases.
Another thing that would be good to see is some more metrics on the usage of the GitGuardian pre-push hooks.
The self-healing activity by developers isn't reflected in the analytics, requiring us to collect this data ourselves.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
Overall, the secret detection sector is expensive, but we are happy with the value we get.
It's fairly priced, as it performs a lot of analysis and is a valuable tool.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
One of the best features of the solution is the ability to use pre-push hooks.
A high number of our exposures are remediated by developers before security needs to step in, as the self-healing playbook process engages them automatically.
GitGuardian Platform performs the capability to detect secrets in real time exceptionally, as it activates from the commit and can detect it immediately.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
| Product | Mindshare (%) |
|---|---|
| GitGuardian Platform | 1.6% |
| HCL AppScan | 2.3% |
| Other | 96.1% |


| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 9 |
| Large Enterprise | 19 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
GitGuardian is a comprehensive platform focused on enhancing Non-Human Identity security by integrating Secrets Security and Secrets Observability to detect and manage secrets across development environments.
As cybersecurity threats increasingly target NHIs like service accounts and applications, GitGuardian offers a robust solution by supporting over 450 types of secrets and deploying honeytokens for additional defense. Trusted by leading organizations and developers, its monitoring and quick alert system enable effective detection and management of sensitive data, strengthening operational security across platforms.
What are the key features of GitGuardian?
What benefits and ROI should companies consider?
In the tech industry, GitGuardian is employed to safeguard APIs and sensitive credentials across code repositories like GitHub. Companies benefit from instant alerts and integrations with tools like Slack, effectively managing risks and enhancing security policies. While popular in sectors dependent on development agility, there is room for further improvement in customization and integration to meet specific industry needs.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.