

HCL AppScan and Check Point WAF are leading products in application security, with HCL AppScan appearing to have an upper hand in code analysis, while Check Point WAF focuses on AI-driven threat prevention.
Features: HCL AppScan provides detecting reflected XSS vulnerabilities, Postman integration for API scanning, and integration with the SDLC. Check Point WAF offers AI-driven threat prevention, zero-day protection without relying on signatures, and reducing false positives significantly.
Room for Improvement: HCL AppScan needs enhancement in support speed, usability, and database size along with centralized management for scans. Check Point WAF requires improvements in UI simplicity, false positive reduction, and policy management, with setup and documentation complexities noted.
Ease of Deployment and Customer Service: HCL AppScan provides adaptable deployment options across environments but struggles with slow support. Check Point WAF offers flexible deployment but can face initial setup complexity and insufficient documentation.
Pricing and ROI: HCL AppScan, though expensive, offers significant cost savings and ROI, particularly valued for code analysis. Check Point WAF, also costly, provides competitive pricing with value in its security features, although higher compared to other market options.
When we are attacked, we can understand how important the solution is.
When you migrate to the cloud, it feels like saving 90% of your time.
Most of the operations happen in the background, so I do not spend much time on it.
They need to increase the number of people for 24/7 support.
They were responsive even before we committed to buying their solution.
I also received full technical support, especially during the implementation.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
If I need to scale, I open a Whatsapp group with the director and the team, and we quickly proceed to do so.
They have sufficient resources, and there are no challenges from a scalability perspective.
Check Point CloudGuard WAF's scalability is very good.
It is very stable.
It is very stable, never crashing or giving me an error that I can see.
I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
The provider could improve by providing better guidance and support during the configuration process.
Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
A machine learning-based adaptive mode could help the WAF learn over time and auto-tune policies.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
It is more expensive than f5, where we purchased everything as bundles, and Check Point costs more, but it is worth the money.
It is less costly than Cloudflare, Fortinet, and other vendors.
I know that its price is relatively expensive compared to other products but it gives benefits that are worth it.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
Upon implementation and evaluation with third-party penetration testing, it meets rigorous security standards required for dealing with financial institutions.
It can protect against zero-day attacks and hidden anomalies.
The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
| Product | Mindshare (%) |
|---|---|
| Check Point WAF (formerly CloudGuard WAF) | 0.9% |
| HCL AppScan | 2.3% |
| Other | 96.8% |


| Company Size | Count |
|---|---|
| Small Business | 56 |
| Midsize Enterprise | 23 |
| Large Enterprise | 36 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
Check Point WAF offers a robust security framework with AI-driven threat detection and seamless integration, protecting applications and APIs in multi-cloud environments.
Effective in preemptively blocking threats through AI and machine learning, Check Point WAF reduces false positives and operational workload. Its integration capabilities and threat intelligence provide comprehensive protection against zero-day attacks, while centralized management facilitates cost-effective and insightful threat reporting.
What are the main features of Check Point WAF?Check Point WAF is employed in industries securing web applications and APIs, especially in multi-cloud environments. It effectively protects backend services, prevents unauthorized access, and monitors traffic, making it suitable for businesses with diverse infrastructures. It ensures compliance with security standards and adapts to fluctuating traffic patterns.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.