

Contrast Security Assess and Mend.io are competing solutions in software security, each offering unique strengths. Contrast Security Assess has an edge with specialized detection capabilities, while Mend.io stands out for its comprehensive features and user-friendly integration.
Features: Contrast Security Assess delivers in-depth security insights with real-time vulnerability detection, offers notable support options, and excels in niche detection capabilities. Mend.io integrates seamlessly with various development tools, handles complex workflows efficiently, and provides a robust feature set catering to specific user needs.
Room for Improvement: Contrast Security Assess could enhance its reporting functionalities, refine intuitive reporting, and expand its feature set beyond niche applications. Mend.io users seek faster software updates, improved integration capabilities, and enhanced detail in support documentation.
Ease of Deployment and Customer Service: Contrast Security Assess is valued for a straightforward deployment process and attentive customer service, offering personalized support during transitions. Mend.io provides a quick setup with ample support, though it may occasionally lack the desired level of detail.
Pricing and ROI: Contrast Security Assess clients view it as cost-effective with substantial long-term ROI, appreciating favorable setup costs. Mend.io, though noted for higher initial costs, is recognized for delivering significant ROI through its comprehensive features, affirming its value over time.
Contrast has probably saved us a couple hundred hours over the past six years.
In the past, my company employed five security engineers, but with Contrast Security Assess, we only have two people.
The speed of fixing issues is significantly improved due to the vast amount of information provided by Contrast Security Assess, making it quite essential for finding the root cause of problems in the source code.
Mend.io has provided a good return on investment by significantly reducing vulnerabilities.
They go out of their way to respond quickly and very knowledgeably.
Customer support is one of the strongest points of Contrast Security Assess, as they are really responsive and answer tickets in less than one hour.
Contrast Security's customer support is very active and overall incredible.
Critical tickets are responded to within an hour.
They prioritize providing the best experience to large organizations like ours, belonging to the Fortune 100.
I have noticed that the speed to respond has decreased over time.
It is fairly simple to install the agents for Contrast Security Assess and keep them updated.
Contrast Security Assess's scalability is not an issue at all.
Regarding scalability, I would also rate it a ten because in some cases, I have 500 projects inside a single product, so I think it is quite scalable.
Contrast Security Assess is genuinely more accurate than most tools I have worked with because it uses instrumentation from inside the application.
We opened a ticket to customer support and experienced four weeks of disruption due to the extension malfunctioning in some of the .NET servers running Contrast Security Assess.
Mend.io is very stable; we did not have any issues.
AI integration in code security tools like Mend.io is still in its early stages and relatively immature.
Regarding Contrast Security Assess's AI capabilities, I think they are missing a huge opportunity because they could lead the way in automatic testing and AI security testing.
I would love to see more customizable, out-of-the-box reporting that speaks to both technical and non-technical people without extra configuration.
Contrast support has been great in fixing any issues or getting back to us with questions.
That's not a limitation of Mend.io; I think that's a general problem with any tool in the market because no tool in the market will actually know what portion of the code I'm actually using from that particular library if it is vulnerable or not.
The actual challenge is how easy it is to integrate it in the early phase of the software development life cycle.
I strongly recommend that they start working with AI for the reporting part.
The annual licensing for Contrast Security Assess costs about $20,000 to $100,000 per year, and per application, it costs about $5,000 to $15,000 per year.
Licensing costs are fairly high compared to other DAST and SAST tools, but it seems to be worth the money.
The cost of Mend.io is competitive, being quite low compared to others.
The real-time detection feature of Contrast Security Assess helps us very well compared to traditional SAST tools. Traditional tools scan from the outside and guess where problems might be. Contrast Security Assess works from the inside because it is embedded into the application.
The ability to see what is going on and what has been going on in a given application and basically get to see what is coming across it in real time is helpful in finding vulnerabilities to remediate before production deployments.
Instead of fixing each vulnerability reported independently, you can group them and fix them in a single point in the source code, resolving several vulnerabilities at once.
We find it 100% accurate in detecting vulnerabilities.
It handles Application Security, performing SCA SAST and container scanning.
The features I find most valuable in Mend.io are the ease of use; it is very easy to access and integrate.
| Product | Mindshare (%) |
|---|---|
| Mend.io | 2.5% |
| Contrast Security Assess | 1.7% |
| Other | 95.8% |


| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 3 |
| Large Enterprise | 10 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 3 |
| Large Enterprise | 22 |
Contrast Security Assess is an IAST platform known for accurate vulnerability detection. It integrates into development workflows, offering real-time insights into security issues with minimal false positives, supporting legacy applications and enhancing code security visibility.
Designed to integrate seamlessly into DevOps workflows, Contrast Security Assess automates real-time vulnerability detection and reduces false positives through its powerful IAST features. By continuously monitoring vulnerabilities, it provides a robust option for securing legacy applications and identifying vulnerabilities without lengthy scans. This cloud-hosted platform supports numerous programming languages, making it versatile for security testing across enterprise environments. Users benefit from detailed reports that pinpoint exact code locations requiring remediation, enhancing speed and efficiency in addressing security concerns.
What are the key features of Contrast Security Assess?Companies in industries requiring high levels of application security, such as finance and healthcare, implement Contrast Security Assess for its ability to enhance visibility and detect vulnerabilities early in the development lifecycle. Its seamless integration with DevOps processes makes it ideal for environments that prioritize agility while maintaining stringent security standards.
Mend.io integrates seamlessly into development environments, providing open-source dependency scanning, CVE detection, and license management to enhance security and efficiency during code development.
Mend.io delivers comprehensive open-source vulnerability detection and remediation, seamlessly integrating with CI/CD workflows. It equips organizations with tools for software composition analysis and license risk detection, efficiently identifying vulnerabilities and managing policies. Mend.io supports a wide array of programming languages and deployment environments while integrating with developer tools like GitHub, Jenkins, and Azure DevOps to enhance security feedback and decision-making. Its ease of use and rapid setup boost efficiency in managing open-source dependencies and reducing vulnerabilities.
What are Mend.io's Key Features?Mend.io empowers industries such as finance, healthcare, and e-commerce by integrating robust open-source security measures within their development cycles, enhancing their ability to address vulnerabilities swiftly and maintain compliance amidst rigorous regulatory standards.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.