

HCL AppScan and Fortify Software Security Center are leading software security tools. Fortify Software Security Center has the advantage with a comprehensive feature set offering superior interoperability and governance.
Features: HCL AppScan is noted for its integration into development processes and ease of use with fast web scan capabilities. However, it is criticized for false positives. Fortify Software Security Center centralizes static and dynamic analysis, enables comprehensive vulnerability management, and offers extensive customization options.
Room for Improvement: HCL AppScan users cite false positives and CI/CD integration challenges, with desires for better language support. Fortify Software Security Center needs improvements in dataset aggregation and better documentation.
Ease of Deployment and Customer Service: HCL AppScan offers flexible deployment options, though its customer service has mixed reviews post-IBM transition. Fortify Software Security Center is primarily on-premises with reliable support, despite a slow setup process.
Pricing and ROI: HCL AppScan is generally more affordable, offering significant cost savings and faster ROI. Fortify Software Security Center, while more expensive, justifies its cost through robust features and scalability, leading to improved ROI for many users.
| Product | Mindshare (%) |
|---|---|
| HCL AppScan | 2.6% |
| Fortify Software Security Center | 1.5% |
| Other | 95.9% |


| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 1 |
| Large Enterprise | 3 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
Fortify Software Security Center offers comprehensive application security through a centralized console that integrates static and dynamic analysis, making it essential for organizations focused on robust security operations.
Fortify Software Security Center delivers extensive capabilities that facilitate application security testing, code audits, and bug fixes. Its centralized console enhances governance and control, while its interoperability with tools like Kiuwan and Azure strengthens its functionality. The dashboard's intuitive data customization, along with the ability to store and report data on-premises, further complements its integration capabilities. Although improvements in dataset aggregation, integration with tools like Jira, and resolution of false positives are required, its ability to scan and analyze source code to identify security violations is acknowledged.
What are the key features of Fortify Software Security Center?Fortify Software Security Center is adopted in software-driven industries for its robust application security capabilities. Users in technology sectors rely on its static code analysis for auditing and security testing. Its on-premises deployment model and integration with platforms like Azure make it ideal for storing and reporting data, providing customization that aligns with industry standards.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.