Try our new research platform with insights from 80,000+ expert users
it_user634890 - PeerSpot reviewer
Chief information with 5,001-10,000 employees
Real User
We use it to find breaches in apps while they are in development.
Pros and Cons
  • "It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply."
  • "We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices."

How has it helped my organization?

Before we had this solution, our security team was doing manual reviews with the scripts. This would take us a lot of work hours and a lot of people were involved in the process.

Now we just send it to AppScan and we can do other stuff like defining processes or dealing with management issues. We can focus on other aspects of our security.

It helps us avoid any downtime in the applications when they are already in production. It also prevents any vulnerability or security breaches.

What is most valuable?

We are currently using it in the integration of our agile process so we can find any breaches in the apps while they're in the development process. We can then fix breaches before they go into a production environment.

It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply.

That being said, we have to be very rigorous about what we are protecting, such as the type of data and the code itself. Having those features in the app is a huge must.

What needs improvement?

We are moving a lot into mobile. While the solution does have a lot of functionalities in mobile, we are trying to expand it more aggressively.

We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices.

We would like to see what type of exposure we have in those specific devices.

What do I think about the stability of the solution?

There have been no stability issues so far. It has handled anything that we have sent to it.

The number of events we receive per day depends on many factors. The events mostly occur when we charge a new code into AppScan to find the vulnerabilities.

For example, we found ten vulnerabilities with the solution. We can see what our mistakes were and we can try to avoid them the next time.

This solution makes our job a lot easier for continuous vulnerability assessments and development processes.

Buyer's Guide
HCL AppScan
June 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.

How are customer service and support?

We used technical support a couple months ago when we migrated from another version. We didn’t use them for an issue, but we got support to help us make the transition. They were very good.

The whole migration process was done in just a couple of weeks. It was fast and it went according to our expectations. After a couple of weeks, we were operational and it was up and running.

What other advice do I have?

At the beginning, you need to know the reach and what you are expecting. The solution is not going to be a silver bullet that will fix everything in your app.

You have to have a mature SDLC process for developers to follow. If they don't have that, AppScan could provide great insight in order to develop it. Once you have both things in motion, it runs automatically.

When looking for a vendor, we want to know if they will go beyond that what is out-of-the-box. We want to see if they will tell us what additional features we can exploit in the solution.

We want to know if they will provide us with knowledge about apps or code for a specific matter and if they can support our expectancy of growth in the near future.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Consultant at a tech vendor with 501-1,000 employees
Vendor
It detects cross-site scripting and SQL injection issues better than other tools.

What is most valuable?

The most valuable feature of this product is its capability to detect XSS and SQL injection.

How has it helped my organization?

Security issues reported by the tool help customers write secure code.

What needs improvement?

  • Better detection of DOM-based XSS
  • Better remediation guidance using code examples and contexts

For how long have I used the solution?

I have used it for four years.

What was my experience with deployment of the solution?

I did not encounter any deployment, stability or scalability issues.

Which solution did I use previously and why did I switch?

I previously used HP WebInspect and Qualys.

I prefer Appscan, as it much more user friendly, and it detects cross-site scripting and SQL injection issues much better than other tools in the market. Also, it has a lower false-positive count than others.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
HCL AppScan
June 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Yong Seok Kang - PeerSpot reviewer
Technical Consultant at MTRiver Consulting
Real User
Top 5Leaderboard
A security testing application that needs to improve security
Pros and Cons
  • "We use it as a security testing application."
  • "HCL AppScan needs to improve security."

What is our primary use case?

We use it as a security testing application. 

What needs improvement?

HCL AppScan needs to improve security. 

For how long have I used the solution?

I have been working with the product for ten years. 

What do I think about the stability of the solution?

HCL AppScan is pretty stable. 

How was the initial setup?

HCL AppScan is easy to deploy and can be done in one to two hours. 

What's my experience with pricing, setup cost, and licensing?

Our clients are willing to pay the extra money. It is expensive. 

What other advice do I have?

I rate HCL AppScan an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.