

HCL AppScan and Contrast Security Assess compete in the application security domain. Contrast Security Assess seems to have the upper hand due to its advanced feature set and perceived value, making it an attractive choice for those prioritizing feature richness.
Features: HCL AppScan provides comprehensive vulnerability scanning with automated security testing and detailed reporting, facilitating integration into various development environments. Contrast Security Assess offers real-time vulnerability detection and improved visibility for developers, emphasizing actionable insights that are integrated into the coding process.
Room for Improvement: HCL AppScan could enhance its feature set for real-time analysis and developer interaction. It might also benefit from a more modern approach to ease deployment. Contrast Security Assess might improve by offering more competitive pricing and adjusting its setup process to appeal to budget-conscious customers. Both could enhance their customer service models to provide additional value.
Ease of Deployment and Customer Service: HCL AppScan allows for a straightforward deployment with robust customer support that aids in its integration into existing systems. Contrast Security Assess stands out with quick-to-implement options and a responsive support team, easing integration with modern methodologies.
Pricing and ROI: HCL AppScan offers cost-effective setups with proven ROI, appealing to budget-conscious customers. In contrast, Contrast Security Assess justifies its higher initial cost through enhanced features and advanced integration, offering a compelling ROI for those who prioritize comprehensive security insights.
In the past, my company employed five security engineers, but with Contrast Security Assess, we only have two people.
Contrast Security's customer support is very active and overall incredible.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
Contrast Security Assess is genuinely more accurate than most tools I have worked with because it uses instrumentation from inside the application.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
I would love to see more customizable, out-of-the-box reporting that speaks to both technical and non-technical people without extra configuration.
Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities.
The annual licensing for Contrast Security Assess costs about $20,000 to $100,000 per year, and per application, it costs about $5,000 to $15,000 per year.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
The agent lives inside the running application, allowing it to see exactly what is happening in real-time. This means we are getting accurate alerts instead of a long list of potential issues that require manual investigation.
We were able to identify security issues such as certificate-related issues, authentication-related issues, and weak encryption-related issues.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
| Product | Mindshare (%) |
|---|---|
| HCL AppScan | 2.3% |
| Contrast Security Assess | 1.6% |
| Other | 96.1% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 3 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
Contrast Security Assess is an IAST platform known for accurate vulnerability detection. It integrates into development workflows, offering real-time insights into security issues with minimal false positives, supporting legacy applications and enhancing code security visibility.
Designed to integrate seamlessly into DevOps workflows, Contrast Security Assess automates real-time vulnerability detection and reduces false positives through its powerful IAST features. By continuously monitoring vulnerabilities, it provides a robust option for securing legacy applications and identifying vulnerabilities without lengthy scans. This cloud-hosted platform supports numerous programming languages, making it versatile for security testing across enterprise environments. Users benefit from detailed reports that pinpoint exact code locations requiring remediation, enhancing speed and efficiency in addressing security concerns.
What are the key features of Contrast Security Assess?Companies in industries requiring high levels of application security, such as finance and healthcare, implement Contrast Security Assess for its ability to enhance visibility and detect vulnerabilities early in the development lifecycle. Its seamless integration with DevOps processes makes it ideal for environments that prioritize agility while maintaining stringent security standards.
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.