Try our new research platform with insights from 80,000+ expert users
Manh Duong - PeerSpot reviewer
General Manager at Groupe PROGEREAL- FINAREAL - PROMOREAL
Real User
Responsive support, simple implementation, and scalable
Pros and Cons
  • "The most valuable feature of HCL AppScan is scanning QR codes."
  • "The solution could improve by having a mobile version."

What is most valuable?

The most valuable feature of HCL AppScan is scanning QR codes.

What needs improvement?

The solution could improve by having a mobile version.

For how long have I used the solution?

I have been using HCL AppScan for approximately one year.

What do I think about the stability of the solution?

I have found HCL AppScan to be stable.

Buyer's Guide
HCL AppScan
June 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.

What do I think about the scalability of the solution?

HCL AppScan is a scalable solution. it can easily scale up and out.

How are customer service and support?

The support I have received has been good. I had an issue and I opened a ticket with the support, and everything went smooth. 

How was the initial setup?

The initial setup of HCL AppScan is easy.

What other advice do I have?

I rate HCL AppScan an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
David Mawazo - PeerSpot reviewer
Chief Information Officer at TeleTracking Technologies, Inc.
Real User
Straightforward setup, stable, and scalable
Pros and Cons
  • "The security and the dashboard are the most valuable features."
  • "The pricing has room for improvement."

What is our primary use case?

We use the solution to test our web applications and services.

What is most valuable?

The security and the dashboard are the most valuable features.

What needs improvement?

The pricing has room for improvement.

For how long have I used the solution?

I have been using the solution for eight years.

What do I think about the stability of the solution?

I give the stability a seven out of ten.

What do I think about the scalability of the solution?

I give the scalability an eight out of ten.

How are customer service and support?

The support is fine.

How would you rate customer service and support?

Neutral

How was the initial setup?

I give the initial setup a seven out of ten. The implementation took a few weeks.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

We have seen around a 50 percent return on investment.

What's my experience with pricing, setup cost, and licensing?

HCL AppScan is expensive.

What other advice do I have?

I give the solution an eight out of ten.

I recommend the solution to others.

We have around 4,000 end users.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
HCL AppScan
June 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
reviewer1676757 - PeerSpot reviewer
Innovation manager at a computer software company with 51-200 employees
Real User
Affordable and easy to expand but needs better performance
Pros and Cons
  • "It was easy to set up."
  • "Sometimes it doesn't work so well."

What is our primary use case?

I have a set project, and I'm writing an application for monitoring server status, and I tried several times to scan it with AppScan in order to understand if there are vulnerabilities in my code.

What is most valuable?

The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great.

It was easy to set up.

It's a stable solution.

The product is easy to scale. 

The solution is affordable and reasonably priced.

What needs improvement?

The performance could be better. Sometimes it doesn't work so well. There's a tool for connecting the cloud with the application server. Sometimes it doesn't work really well.

I have not come across any missing features. 

For how long have I used the solution?

I've been using the solution for six months. It's been less than a year so far. 

What do I think about the stability of the solution?

The solution has been stable. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

So far, we've found the solution can scale well.

How are customer service and support?

I've reached out to support in the past. They are pretty good, however, they are also working from India, and I'm in Italy. There is a delay of course when I open a ticket. We have to wait a bit due to the time shift.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. This was our first. 

How was the initial setup?

The initial setup is pretty simple and straightforward. It's not an overly complex or difficult process. 

It took about one day to deploy the solution.

What about the implementation team?

I handled the initial setup on my own. I did not ask for help from any consultants or integrators. 

What's my experience with pricing, setup cost, and licensing?

I actually pay for tokens. Any time that I want to perform scanning, I have to pay for another token. It's pretty good for me, this system, as it's really, really nice when I need it. I just need to pay for it, and that's it.

What other advice do I have?

We are end-users.

I'd rate the solution a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1467588 - PeerSpot reviewer
Owner/ Consultant at a tech services company with 1-10 employees
Consultant
Offers many support languages, scans in a decent amount of time and is easy to set up
Pros and Cons
  • "There's extensive functionality with custom rules and a custom knowledge base."
  • "The solution often has a high number of false positives. It's an aspect they really need to improve upon."

What is our primary use case?

We primarily use the solution for static analysis.

What is most valuable?

AppScan is within the top three or four static analyzers. Its features include support for many languages. 

The product has a relatively reasonable scan time.

There's extensive functionality with custom rules and a custom knowledge base.

What needs improvement?

The solution often has a high number of false positives. It's an aspect they really need to improve upon. 

The product has vulnerabilities, or findings, that are almost identical in nature. 

For how long have I used the solution?

I've used the solution for the last 12 months or so. It's been about a year at this point.

What do I think about the stability of the solution?

The stability is okay. it's good. It's not very good or excellent, it's just good. I would describe the stability as a bit better than acceptable.

What do I think about the scalability of the solution?

When I worked on it, it wasn't in the cloud. It didn't offer Federation. Now, it is my understanding that it has those, which would make it very scalable. That said, when I used it, I would not give it a very scalable grade - maybe a two out of ten for scalability if you are using it off of the cloud. That said, that's not the latest version. The latest is likely more scalable, I just don't have experience with it.

How are customer service and technical support?

The technical support is pretty good. They are knowledgeable and responsive. We were satisfied with the level of support we received.

Which solution did I use previously and why did I switch?

I also know a bit about Checkmarx, Fortify, Veracode, and AppScan.

How was the initial setup?

I didn't really do the actual setup once it got moved into the cloud. I don't know how easy the cloud set up was. However, it's my understanding that it is now potentially easier than it was before, which wasn't too bad. 

What's my experience with pricing, setup cost, and licensing?

I don't know the prices currently. I knew the prices when it was still in-house with IBM, however, I don't know what the cost is now.

What other advice do I have?

I worked with the solution at a previous company. Now I am a consultant and I no longer work with the product. I don't have a business relationship with HCL.

I wanted to do a POC with the current state of what was IBM AppScan and now is HCL. I contacted my contacts at IBM and then they started off the conversation and it went smoothly because a number of people from IBM had gone over to HCL when that product was acquired.

Various tools have their strengths, I would advise anyone who is interested in using a similar solution do a proof of concept first with a few options. Try Checkmarx, Fortify, Veracode, and AppScan, and see which one makes the most sense for your company's purposes. Those would be the top four in my opinion right now.

Overall, I would rate the solution eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
NamNguyen11 - PeerSpot reviewer
CTO at FPT Telecom
Reseller
Top 5Leaderboard
A cheap solution with a good technical support team
Pros and Cons
  • "The solution is cheap."
  • "Improvement can be done as per customer requirements."

What is our primary use case?

I use it for my customers. 

What needs improvement?

Improvement can be done as per customer requirements.

For how long have I used the solution?

I have been using HCL AppScan for some time. 

How are customer service and support?

The technical support is good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup took one to two days. 

What's my experience with pricing, setup cost, and licensing?

The solution is cheap. 

What other advice do I have?

I rate the overall solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
reviewer943074 - PeerSpot reviewer
Scientific Officer at a tech services company with 51-200 employees
Real User
Top 20
Efficiently scans through the website and identifies vulnerabilities

What is our primary use case?

HCL AppScan efficiently scans through the website and identifies vulnerabilities for AWS. It is reducing tools day by day, making it more efficient. 

What needs improvement?

HCL AppScan generates false results. Sometimes, it incorrectly identifies requests as vulnerable when they are not vulnerable. In the ADSL feature managed, the primary objective is to identify application security vulnerabilities. However, sometimes AppScan wrongly flags something as a vulnerability when it's not present, which we call a false positive.

For how long have I used the solution?

I have been using HCL AppScan for nine years.

What do I think about the stability of the solution?

I rate the solution’s stability an eight out of ten.

What do I think about the scalability of the solution?

The solution is scalable if required.

How are customer service and support?

Customer support is helpful. 

How would you rate customer service and support?

Positive

How was the initial setup?

There is a licensing partner. Sometimes, it is required to install a server. I must remove that license and then eject a new one on a different server. It becomes a bit harder for beginners if they do not have enough experience to install Zoho software.

Deployment takes around an hour, and one person can do it.

I rate the initial setup a six and a half out of ten, where one is difficult and ten is easy.

What's my experience with pricing, setup cost, and licensing?

The tool is not cost-efficient. Considering the type of service with encryption security scanning from HCL AppScan, it drives up the cost unnecessarily. It is fairly priced.

What other advice do I have?

There are some very cost-effective solutions out there. They are also very efficient for systems scanning.

Overall, I rate the solution an eight-point five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Mechanical maintenance technician at SAQ
Real User
Top 20
Helps with the scan of the web interface and supports special languages
Pros and Cons
  • "Compared to other tools only AppScan supports special language."
  • "The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed."

What is our primary use case?

I use the tool to scan the web interface.

What is most valuable?

Compared to other tools only AppScan supports special language.

What needs improvement?

The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed.

For how long have I used the solution?

I have been using the solution for two years.

How are customer service and support?

The solution has dedicated and good tech support. We can open a ticket and we get information within two hours. Once we open a ticket we get validation or confirmation of our problem. When we get to the specialist, we will get more information.

How would you rate customer service and support?

Positive

What other advice do I have?

I would rate the overall solution a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
VijayKumar16 - PeerSpot reviewer
Global Business Development Executive - Applications, Data & AI Practice at Kyndryl
Real User
Stable and scalable but not user-friendly
Pros and Cons
  • "AppScan is stable."
  • "AppScan is too complicated and should be made more user-friendly."

What is our primary use case?

I mainly use AppScan for vulnerability scanning and database bridging.

What needs improvement?

AppScan is too complicated and should be made more user-friendly.

For how long have I used the solution?

I've been using HCL AppScan for three to four years.

What do I think about the stability of the solution?

AppScan is stable.

What do I think about the scalability of the solution?

AppScan is scalable.

How are customer service and support?

HCL's technical support is ok, but it could be faster and more responsive.

How was the initial setup?

The initial setup was complex and took about a day and a half.

What other advice do I have?

I would rate AppScan four out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.