Klocwork and GitGuardian compete in the software security and code analysis sector. GitGuardian appears to have the upper hand due to its broader range of integrations and secrets detection capabilities, which are highly valued by users.
Features: Klocwork offers static code analysis with integration into CI environments, allowing for customized checkers and low false-positive rates. Its incremental and on-the-fly analysis improves code quality by identifying defects early. GitGuardian excels in detecting secrets with low false-positive rates and provides real-time alerts. It offers a Dev in the loop feature, enabling swift remediation and collaboration between developers and security teams. GitGuardian supports diverse integrations, including API keys and secrets management.
Room for Improvement: Klocwork struggles with managing global variables, false positives, and static analysis rule complexity. It has limited language support and needs better dashboard tools and Agile DevOps integration. GitGuardian requires an improved user interface, support for more data environments, and enhanced analytics and customization options. Users also seek better team management features and smoother integration across broader security contexts.
Ease of Deployment and Customer Service: Klocwork deploys primarily on-premises or in private clouds with responsive technical support, although initial setup may take time. GitGuardian offers flexible public and private cloud deployments, as well as on-premises options. Both companies are praised for their responsive customer service, but GitGuardian provides a broader deployment scope with more cloud compatibility.
Pricing and ROI: Klocwork is competitively priced with flexible license models but is not cheap. Its ROI is demonstrated through improved compliance and reduced defect resolution time. GitGuardian is also considered reasonably priced, offering a free tier and straightforward pricing, which is advantageous for managing security risks and detection capabilities. GitGuardian's pricing could be a concern for larger user bases.
I can certainly say that we have saved significant time and resources in terms of people and automation.
The majority of our incidents for critical detectors and important secret types are remediated automatically or proactively by developers through GitGuardian's notification system, without security team involvement.
The main ROI factors include efficiency and how we meet compliance standards for various automotive requirements.
It effectively helps us with credentials security and has been performing satisfactorily.
I would rate their technical support a nine out of ten.
I would rate the technical support as excellent.
The customer support team is very responsive, proactive, and engages in conversations to ensure our needs are met.
The issue is not about the knowledge of the support but about the prioritization of the tickets they handle.
During the initial phase, there was a need for follow-ups and clarifications.
In terms of scalability, I would rate it around a ten out of ten, as it handles all the repositories and commit activity we have.
I would rate it a ten out of ten for scalability.
Currently, what GitGuardian Platform is doing works effectively.
Klocwork supports our scalability needs without issues, even as project volumes increase.
The program-to-program enablement is scalable.
We set up a lot of the repository, so GitGuardian is a required check.
The SaaS platform has experienced two significant moments of downtime or instability in the last six months, requiring notices and retrospectives.
I would rate the stability of the GitGuardian Platform as excellent with no downtimes.
Installation is easy, and the solution is stable.
Another thing that would be good to see is some more metrics on the usage of the GitGuardian pre-push hooks.
The self-healing activity by developers isn't reflected in the analytics, requiring us to collect this data ourselves.
We are looking for better metrics and audit data, wanting more features such as knowing which users are creating the most secrets or committing the most secrets, what repository, what directory, and who is not checking in secrets.
There are too many warnings, and it requires expertise to determine the correct category for them.
Klocwork sometimes provides too many additional warnings which require expertise to manage.
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits.
Overall, the secret detection sector is expensive, but we are happy with the value we get.
It's fairly priced, as it performs a lot of analysis and is a valuable tool.
It is less expensive than Coverity.
The solution is not very cheap, however, it is less expensive than Coverity.
Klocwork was competitively priced, making it a cost-effective solution for us.
One of the best features of the solution is the ability to use pre-push hooks.
A high number of our exposures are remediated by developers before security needs to step in, as the self-healing playbook process engages them automatically.
GitGuardian Platform performs the capability to detect secrets in real time exceptionally, as it activates from the commit and can detect it immediately.
The most valuable feature of Klocwork is the static analysis tools, which help identify potential security threats and errors.
Its integration with the CI/CD pipeline has helped streamline the software development process.
It takes just half a day to set up.
GitGuardian is an advanced secrets security platform that strengthens Non-Human Identity security and ensures compliance with industry standards by detecting and managing secrets in development environments.
GitGuardian integrates Secrets Security and Secrets Observability, facilitating the detection of compromised secrets and managing legitimate secrets' lifecycle. Supporting over 450 types of secrets, the platform offers public monitoring for leaked data and employs honeytokens as an added defense. Trusted by over 600,000 developers, organizations such as Snowflake and ING rely on GitGuardian for robust secrets protection.
What features define GitGuardian?In sectors like healthcare and telecommunications, GitGuardian is implemented for detecting and managing the exposure of sensitive information in code repositories. Teams benefit from its ability to integrate with platforms such as GitHub, allowing for immediate alerts and efficient remediation of security risks, enhancing application security by safeguarding operational environments.
Klocwork detects security, safety, and reliability issues in real-time by using this static code analysis toolkit that works alongside developers, finding issues as early as possible, and integrates with teams, supporting continuous integration and actionable reporting.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.