

HCL AppScan and Klocwork compete in the security and code analysis software category. HCL AppScan seems to have an edge in security integration within the development process, while Klocwork excels in static code analysis for quick feedback.
Features: HCL AppScan is valued for identifying vulnerabilities like XSS and SQL injection and supports seamless integration with SDLC processes. It offers Postman integration and agile security process support. Klocwork is known for on-the-fly analysis and static code analysis, providing custom checkers to meet coding requirements and efficiently detect issues during code development.
Room for Improvement: HCL AppScan needs enhanced usability and support for more programming languages. Other areas include integration improvements with CI/CD pipelines and reducing false positives. Klocwork could benefit from improved user interface for quicker insights and better language support, alongside addressing false warnings and enhancing integration capabilities.
Ease of Deployment and Customer Service: HCL AppScan offers flexible deployment across public, private, and hybrid clouds but presents mixed reviews on customer support. Klocwork focuses on on-premises deployment; its customer service is generally seen as responsive and knowledgeable.
Pricing and ROI: HCL AppScan is seen as expensive but offers substantial ROI in reducing vulnerabilities. In contrast, Klocwork's competitive pricing with a per-user license model appeals to varied organizational sizes, delivering good ROI, particularly for software-centric organizations.
The main ROI factors include efficiency and how we meet compliance standards for various automotive requirements.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
The issue is not about the knowledge of the support but about the prioritization of the tickets they handle.
The customer support team is very responsive, proactive, and engages in conversations to ensure our needs are met.
During the initial phase, there was a need for follow-ups and clarifications.
Klocwork supports our scalability needs without issues, even as project volumes increase.
The program-to-program enablement is scalable.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
Installation is easy, and the solution is stable.
Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities.
We would like Klocwork to connect to Git and notify developers of issues tied to specific commits.
Klocwork sometimes provides too many additional warnings which require expertise to manage.
Klocwork should be able to analyze large codebases efficiently, supporting a desktop version for periodic small delta changes before pushing to the server.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
It is less expensive than Coverity.
The solution is not very cheap, however, it is less expensive than Coverity.
Klocwork's pricing seems attractive, as it uses a per-user license model that does not have a lot of overhead.
We were able to identify security issues such as certificate-related issues, authentication-related issues, and weak encryption-related issues.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
Its integration with the CI/CD pipeline has helped streamline the software development process.
The most valuable feature of Klocwork is the static analysis tools, which help identify potential security threats and errors.
It takes just half a day to set up.
| Product | Mindshare (%) |
|---|---|
| Klocwork | 1.5% |
| HCL AppScan | 2.3% |
| Other | 96.2% |

| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 2 |
| Large Enterprise | 13 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
Klocwork offers advanced static code analysis with integration capabilities for enhanced development efficiency, supporting various development environments and providing clear defect reports. It streamlines software development by reducing defects and improving code quality.
Klocwork integrates seamlessly into CI/CD pipelines, providing real-time and incremental analysis to identify and rectify code defects quickly. It supports multiple integrated development environments (IDEs) and minimizes false positives in its analysis. While primarily supporting C/C++, Java, and C#, there is a need to expand language support and enhance its static analysis engine. The tool assists in adhering to industry standards with features like automated code parsing and MISRA compliance checks. Ease of setup and collaboration capabilities further promotes efficiency, although the dashboard could benefit from user-friendly updates and better integration with Agile tools.
What are the primary features of Klocwork?Klocwork is extensively implemented in industries that prioritize software quality and security standards, particularly in environments focused on C/C++ development on Linux systems. Its capabilities in automated code parsing, traffic analysis, and support for DevOps integration make it invaluable for industries requiring strict MISRA compliance and internal standards adherence. By aiding refactoring and detecting memory-related vulnerabilities, Klocwork contributes to the maintainability and security standards in these sectors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.