

Find out in this report how the two Static Application Security Testing (SAST) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
By adopting templates and various different pipelines across our own IDP platform, we have saved upwards of 30 to 40% of development time.
Time is saved because we now save engineering time. Before, it required two to three engineers actively monitoring production during deployments, but after starting to use Harness, there is zero or minimal manual monitoring.
With Harness, the release process decreased from three or four hours to one or two hours, making deployments much quicker.
The main ROI factors include efficiency and how we meet compliance standards for various automotive requirements.
We have rarely faced issues with Harness tech support.
Harness customer support is really helpful anytime I try to reach out; they are available to assist with any issues I am facing.
We have been receiving incident reports whenever an incident occurs on Harness, and they are usually quick to respond.
The customer support team is very responsive, proactive, and engages in conversations to ensure our needs are met.
The issue is not about the knowledge of the support but about the prioritization of the tickets they handle.
During the initial phase, there was a need for follow-ups and clarifications.
Our entire organization uses it with hundreds of applications, and it supports this scale effectively.
It is able to work on our infrastructure side, which is EKS, and we are able to handle our organization growth effectively for an enterprise use case.
When I integrated Harness to more than 20 applications in one place, it becomes less stable.
Klocwork supports our scalability needs without issues, even as project volumes increase.
The program-to-program enablement is scalable.
We have rarely faced issues with Harness tech support.
Harness is decently stable.
Installation is easy, and the solution is stable.
There is not a lot of good support for pipeline as code, and I often find myself not using pipeline as code the way other platforms such as GitHub Actions or Jenkins integrate pipeline as code.
An improvement idea is better guided onboarding with more opinionated defaults and examples.
Previously, when deploying a version that had been deployed successfully before, it sometimes failed upon trying again, which seems to be an intermittent issue about stability.
There are too many warnings, and it requires expertise to determine the correct category for them.
Klocwork sometimes provides too many additional warnings which require expertise to manage.
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits.
From what I understand with respect to Harness, licensing and setup costs were relatively low for an enterprise, and the pricing was more catered toward enterprises who would invest in the technology.
It is less expensive than Coverity.
The solution is not very cheap, however, it is less expensive than Coverity.
Klocwork was competitively priced, making it a cost-effective solution for us.
Harness uses AI to suggest errors in case of deployment failures.
Meantime to recovery (MTTR) improved from 30 to 60 minutes before Harness to 5 to 10 minutes now.
The best features in Harness are its user-friendliness and setup configuration.
The most valuable feature of Klocwork is the static analysis tools, which help identify potential security threats and errors.
Its integration with the CI/CD pipeline has helped streamline the software development process.
It takes just half a day to set up.
| Product | Market Share (%) |
|---|---|
| Klocwork | 1.4% |
| Harness | 0.6% |
| Other | 98.0% |
| Company Size | Count |
|---|---|
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 2 |
| Large Enterprise | 12 |
Harness offers a comprehensive toolset for automating deployment processes and enhancing software update efficiency. It's lauded for its CI/CD capabilities, feature flagging, and real-time deployment monitoring. Key features include an intuitive UI, secret management, and robust rollback functionalities, all contributing to improved productivity and reduced errors in DevOps environments.
Klocwork detects security, safety, and reliability issues in real-time by using this static code analysis toolkit that works alongside developers, finding issues as early as possible, and integrates with teams, supporting continuous integration and actionable reporting.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.