

HCL AppScan and Rapid7 InsightAppSec compete in the security solutions category. HCL AppScan has a slight advantage due to its comprehensive security setup and development process integration.
Features: HCL AppScan integrates security into the development process, providing effective vulnerability detection features like XSS and SQL injection detection, and offers extensive language support. Rapid7 InsightAppSec is noted for its ease of use, dynamic scanning capabilities, and flexibility in scan scheduling.
Room for Improvement: HCL AppScan users report issues with false positives, usability complexity, and integration challenges with other tools. Rapid7 InsightAppSec users express concerns about report complexity, false positives, limited integrations, and high pricing.
Ease of Deployment and Customer Service: HCL AppScan offers on-premises deployment, with mixed experiences in technical support, particularly after the IBM transition. Rapid7 InsightAppSec supports both Hybrid and Public Cloud deployments, with a satisfactory support experience needing better regional resources.
Pricing and ROI: HCL AppScan is considered expensive but provides significant ROI by reducing vulnerabilities. Rapid7 InsightAppSec is cheaper, with flexible licensing. While Fair, customers see room for cost improvements.
| Product | Mindshare (%) |
|---|---|
| Rapid7 InsightAppSec | 5.7% |
| HCL AppScan | 9.1% |
| Other | 85.2% |


| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 2 |
| Large Enterprise | 5 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
Rapid7 InsightAppSec is a cloud-based security tool offering robust web scanning capabilities with a user-friendly interface and seamless integration. It enhances dynamic application security testing through customizable modules, providing comprehensive reports and remediation guidance.
InsightAppSec delivers dynamic application security testing with features like Attack Replay and a centralized dashboard for vulnerability insights. It supports flexible deployment options and simplifies scheduling frequent scans. The tool's intuitive graphical interface and extensive scanning coverage make it valuable for identifying vulnerabilities in web applications, APIs, and e-commerce sites, ensuring compliance. However, improvements are needed in detection accuracy, reporting options, and integrations with external tools like WAF and ticketing systems. There is a need for better scan management, support for mobile applications, customized reporting options, pricing flexibility, improved support, and AI integration.
What are the key features of InsightAppSec?Industries rely on InsightAppSec for vulnerability scanning to secure web applications, APIs, and e-commerce platforms. Its integration within the SDLC aids in automating scans during development. While limitations exist with certain tool integrations, its cloud-based engine and effective reporting make it essential for internal and external application security assurance.
We monitor all Dynamic Application Security Testing (DAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.