

HCL AppScan and Contrast Security Assess compete in the application security domain. Contrast Security Assess seems to have the upper hand due to its advanced feature set and perceived value, making it an attractive choice for those prioritizing feature richness.
Features: HCL AppScan provides comprehensive vulnerability scanning with automated security testing and detailed reporting, facilitating integration into various development environments. Contrast Security Assess offers real-time vulnerability detection and improved visibility for developers, emphasizing actionable insights that are integrated into the coding process.
Room for Improvement: HCL AppScan could enhance its feature set for real-time analysis and developer interaction. It might also benefit from a more modern approach to ease deployment. Contrast Security Assess might improve by offering more competitive pricing and adjusting its setup process to appeal to budget-conscious customers. Both could enhance their customer service models to provide additional value.
Ease of Deployment and Customer Service: HCL AppScan allows for a straightforward deployment with robust customer support that aids in its integration into existing systems. Contrast Security Assess stands out with quick-to-implement options and a responsive support team, easing integration with modern methodologies.
Pricing and ROI: HCL AppScan offers cost-effective setups with proven ROI, appealing to budget-conscious customers. In contrast, Contrast Security Assess justifies its higher initial cost through enhanced features and advanced integration, offering a compelling ROI for those who prioritize comprehensive security insights.
Contrast has probably saved us a couple hundred hours over the past six years.
In the past, my company employed five security engineers, but with Contrast Security Assess, we only have two people.
The speed of fixing issues is significantly improved due to the vast amount of information provided by Contrast Security Assess, making it quite essential for finding the root cause of problems in the source code.
They go out of their way to respond quickly and very knowledgeably.
Customer support is one of the strongest points of Contrast Security Assess, as they are really responsive and answer tickets in less than one hour.
Contrast Security's customer support is very active and overall incredible.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
It is fairly simple to install the agents for Contrast Security Assess and keep them updated.
Contrast Security Assess's scalability is not an issue at all.
Contrast Security Assess is genuinely more accurate than most tools I have worked with because it uses instrumentation from inside the application.
We opened a ticket to customer support and experienced four weeks of disruption due to the extension malfunctioning in some of the .NET servers running Contrast Security Assess.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
Regarding Contrast Security Assess's AI capabilities, I think they are missing a huge opportunity because they could lead the way in automatic testing and AI security testing.
I would love to see more customizable, out-of-the-box reporting that speaks to both technical and non-technical people without extra configuration.
Contrast support has been great in fixing any issues or getting back to us with questions.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
The annual licensing for Contrast Security Assess costs about $20,000 to $100,000 per year, and per application, it costs about $5,000 to $15,000 per year.
Licensing costs are fairly high compared to other DAST and SAST tools, but it seems to be worth the money.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
The real-time detection feature of Contrast Security Assess helps us very well compared to traditional SAST tools. Traditional tools scan from the outside and guess where problems might be. Contrast Security Assess works from the inside because it is embedded into the application.
The ability to see what is going on and what has been going on in a given application and basically get to see what is coming across it in real time is helpful in finding vulnerabilities to remediate before production deployments.
Instead of fixing each vulnerability reported independently, you can group them and fix them in a single point in the source code, resolving several vulnerabilities at once.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
| Product | Mindshare (%) |
|---|---|
| HCL AppScan | 2.3% |
| Contrast Security Assess | 1.7% |
| Other | 96.0% |


| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 3 |
| Large Enterprise | 10 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
Contrast Security Assess is an IAST platform known for accurate vulnerability detection. It integrates into development workflows, offering real-time insights into security issues with minimal false positives, supporting legacy applications and enhancing code security visibility.
Designed to integrate seamlessly into DevOps workflows, Contrast Security Assess automates real-time vulnerability detection and reduces false positives through its powerful IAST features. By continuously monitoring vulnerabilities, it provides a robust option for securing legacy applications and identifying vulnerabilities without lengthy scans. This cloud-hosted platform supports numerous programming languages, making it versatile for security testing across enterprise environments. Users benefit from detailed reports that pinpoint exact code locations requiring remediation, enhancing speed and efficiency in addressing security concerns.
What are the key features of Contrast Security Assess?Companies in industries requiring high levels of application security, such as finance and healthcare, implement Contrast Security Assess for its ability to enhance visibility and detect vulnerabilities early in the development lifecycle. Its seamless integration with DevOps processes makes it ideal for environments that prioritize agility while maintaining stringent security standards.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.