Try our new research platform with insights from 80,000+ expert users

HCL AppScan vs SentinelOne Singularity Cloud Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
1.7
HCL AppScan enhances architecture with fewer errors and improved security, achieving 50% return and 20% cost savings.
Sentiment score
7.2
SentinelOne Singularity Cloud Security automates operations, improving compliance, reducing costs, and boosting productivity by up to 40%.
The detailed information PingSafe gives about how to fix vulnerabilities reduces the time spent on remediation by about 70 to 80 percent.
Security and Compliance Manager at Bidgely
After implementing SentinelOne, it takes about five to seven minutes.
Cloud engineer at a construction company with 5,001-10,000 employees
Our ability to get in and review our vulnerability stance, whether daily, monthly, weekly, or whatever it might be, has drastically improved over our prior provider.
IT Support Specialist at a non-tech company with 201-500 employees
 

Customer Service

Sentiment score
5.6
HCL AppScan's support is responsive with mixed reviews, facing regional challenges and lagging behind competitors like Veracode.
Sentiment score
7.8
SentinelOne's Cloud Security users praise fast, effective support with proactive assistance and efficient issue resolution across multiple channels.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
There is still room for improvement when it comes to the speed of response.
Founder Director at Techsa Services
When we send an email, they respond quickly and proactively provide solutions.
Security and Compliance Manager at Bidgely
They took direct responsibility for the system and could solve queries quickly.
Senior DevOps Engineer at a tech services company with 501-1,000 employees
Having a reliable team ready and willing to assist with any issues is essential.
Director, DevOps at Relay Network
 

Scalability Issues

Sentiment score
3.9
HCL AppScan is scalable yet varies by license, integration issues, infrastructure compatibility, and CI/CD pipeline design effectiveness.
Sentiment score
8.1
Users praise SentinelOne Singularity Cloud Security's scalable integration, adaptability, and high ratings, ideal for diverse organization sizes.
I would rate it a 10 out of 10 for scalability.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
Scalability is no longer a concern because Cloud Native Security is a fully cloud-based resource.
CISO at a computer software company with 201-500 employees
I would rate the scalability of PingSafe 10 out of 10.
Sr DevOps Engineer at a media company with 51-200 employees
 

Stability Issues

Sentiment score
7.2
HCL AppScan is stable and reliable, with minor hardware issues, improved by recent upgrades enhancing performance and stability.
Sentiment score
8.2
SentinelOne Singularity Cloud Security offers high stability, rare glitches, and 100% uptime, outperforming previous tools in reliability and performance.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
Founder Director at Techsa Services
SentinelOne Singularity Cloud is incredibly reliable.
Security Analyst at Intersistemi Italia s.p.a.
We contacted Cloud Native Security, and they addressed it in a day.
DevSecOps Engineer at a tech company with 1,001-5,000 employees
The only downtime we had was when switching from V1 to V2 but it was smooth.
Cloud Security Specialist at a insurance company with 10,001+ employees
 

Room For Improvement

HCL AppScan requires improvements in vulnerability detection, usability, integration, performance, support, pricing, and language/codebase compatibility to stay competitive.
SentinelOne Singularity needs better container security, integrations, and usability enhancements, addressing reporting, costs, and documentation issues.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
Founder Director at Techsa Services
If they can merge Kubernetes Security with other modules related to Kubernetes, that would help us to get more modules in the current subscription.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
As organizations move to the cloud, a cloud posture management tool that offers complete cloud visibility becomes crucial for maintaining compliance.
CISO at a computer software company with 201-500 employees
I would also like to see Cloud Native Security offer APIs that allow us to directly build dashboards within the platform.
Senior Cybersecurity Engineer at a computer software company with 11-50 employees
 

Setup Cost

HCL AppScan is considered expensive but cost-effective, with varied pricing opinions influenced by its premium features and discounts.
SentinelOne Singularity Cloud is valued for its adaptable pricing and cost-effectiveness, notably through AWS partnerships, against competitors.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
With very little negotiation involved, we just let them know what we could pay and they were willing to meet us at slightly above what we paid with Sophos, which was still very fair for what we were looking at.
IT Support Specialist at a non-tech company with 201-500 employees
There are some tools that are double the cost of Cloud Native Security.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
I recall Cloud Native Security charging a slightly higher premium previously.
Senior Cybersecurity Engineer at a computer software company with 11-50 employees
 

Valuable Features

HCL AppScan detects vulnerabilities, integrates with agile processes, offers scalability, user-friendly features, and AI-enhanced rapid scanning for security.
SentinelOne Singularity Cloud Security offers real-time threat detection, automated remediation, and seamless cloud integration with advanced security features.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
Founder Director at Techsa Services
This helps visualize potential attack paths and even suggests attack paths a malicious actor might take.
Security Engineer-DevSecOps at a computer software company with 51-200 employees
The infrastructure-as-code feature is helpful for discovering open ports in some of the modules.
DevSecOps Engineer at a tech company with 1,001-5,000 employees
This tool has been helpful for us. It allows us to search for vulnerabilities and provides evidence directly on the screen.
Cloud Security Specialist at a insurance company with 10,001+ employees
 

Categories and Ranking

HCL AppScan
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
44
Ranking in other categories
Application Security Tools (20th), Static Application Security Testing (SAST) (17th), Dynamic Application Security Testing (DAST) (4th)
SentinelOne Singularity Clo...
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
116
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (3rd), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (3rd), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (2nd), AI Software Development (1st), AI Observability (2nd)
 

Mindshare comparison

HCL AppScan and SentinelOne Singularity Cloud Security aren’t in the same category and serve different purposes. HCL AppScan is designed for Application Security Tools and holds a mindshare of 2.3%, down 2.6% compared to last year.
SentinelOne Singularity Cloud Security, on the other hand, focuses on Cloud-Native Application Protection Platforms (CNAPP), holds 5.3% mindshare, up 2.7% since last year.
Application Security Tools Market Share Distribution
ProductMarket Share (%)
HCL AppScan2.3%
SonarQube17.9%
Checkmarx One10.2%
Other69.6%
Application Security Tools
Cloud-Native Application Protection Platforms (CNAPP) Market Share Distribution
ProductMarket Share (%)
SentinelOne Singularity Cloud Security5.3%
Wiz20.2%
Prisma Cloud by Palo Alto Networks12.8%
Other61.7%
Cloud-Native Application Protection Platforms (CNAPP)
 

Featured Reviews

Ravi Khanchandani - PeerSpot reviewer
Founder Director at Techsa Services
Has improved identification of encryption and authentication issues across cloud and on-prem applications
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interface. However, there is one feature called SCA, which stands for Software Composition Analysis, that could be improved. When I'm doing an application scan, HCL AppScan has the ability to generate information about what components are in use. For example, if I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present. I would like to see more detailed reports from the tool. Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities. For instance, I could identify that I had the Log4j vulnerability and know that I need to fix my application accordingly. If they add the features I'm describing, I would consider giving them a higher rating. However, I've only been experienced with the product for three months.
SC
Information Security Engineer at DataVigilant Infotech
Enables us to prioritize and effectively address critical security issues
Evidence-based reporting helps us to prioritize and solve critical security issues. The new visualization feature demonstrates how an attacker can enter the system, highlighting the potential path that can be exploited and outlining all the steps the attacker could take. With that visibility, we can ensure the perimeter is strong and attackers cannot enter, thus reducing the risk. It has helped us prioritize issues. The visibility into how an attack could happen is valuable. For example, it highlights the system vulnerability and outlines where an attack could propagate. The visualization helps me to prioritize remediation, and if I don't know where to start, I can check to see the score that enables me to prioritize issues. I am using infrastructure-as-code scanning, and it's one of the useful features. In pre-production, it identifies embedded secrets and misconfigurations, including issues with Kubernetes or some privileged containers. This feature allows us to pass the audit and secure IaC code so that it isn't easily exploitable by attackers. We can more proactively work to identify and resolve vulnerabilities by using the dashboard and the alerting system that SentinelOne provides. It helps us with audits and compliance. We can show the compliance in percentage. We can confidently say that our company or infrastructure is very secure. It has improved our security posture by 30% to 35%. It has reduced our false positives by 30%. It has helped teams collaborate better. The security team manages SentinelOne Singularity Cloud Security, and when it flags vulnerabilities, they are forwarded to DevOps for remediation. Previously, we needed to identify and report the issues, but there would be lapses in communication. Now, there is a centralized dashboard that anyone can look at and see the open issues and work on them.
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
881,078 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
12%
Government
11%
Manufacturing Company
10%
Financial Services Firm
14%
Computer Software Company
12%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business48
Midsize Enterprise20
Large Enterprise54
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interf...
What is your primary use case for HCL AppScan?
I'm currently working with BigFix and HCL AppScan. At least three people in my company are using HCL AppScan. Since we are a reseller, we run it in both lab environments and live production applica...
What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best features.
What is your experience regarding pricing and costs for PingSafe?
I think the pricing of SentinelOne Singularity Cloud Security is a bit high.
What needs improvement with PingSafe?
We did not try to use the threat investigations feature from SentinelOne Singularity Cloud Security.Drift detection with respect to infrastructure code is important. When somebody makes changes to ...
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
PingSafe
 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Information Not Available
Find out what your peers are saying about SonarSource Sàrl, Veracode, Checkmarx and others in Application Security Tools. Updated: January 2026.
881,078 professionals have used our research since 2012.