I used the solution to find vulnerabilities in our website and system. I did some regular checkups.
Software Quality Assurance Engineer at a tech services company with 11-50 employees
The UI was very intuitive and easy to understand, but the tool was expensive
Pros and Cons
- "The UI was very intuitive."
- "A desktop version should be added."
What is our primary use case?
What is most valuable?
The UI was very intuitive. It was very easy to understand. It was very easy to scan the websites, see the results, and deliver them to higher management.
What needs improvement?
It would have been better if we could use it on our desktop. A desktop version should be added.
For how long have I used the solution?
I had used the solution for one month.
Buyer's Guide
HCL AppScan
January 2026
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
What do I think about the stability of the solution?
The tool was very stable. I rate the tool’s stability a seven or eight out of ten. Very few people were using the tool in our organization. The stability could have been affected if there were more users.
What do I think about the scalability of the solution?
We had a few users.
Which solution did I use previously and why did I switch?
We have used solutions like Acunetix. HCL was better. The UI was pretty good. It was intuitive, easy to understand, and reliable.
How was the initial setup?
The installation was easy for me. It took a few hours. A senior employee helped me deploy the tool. The solution was deployed on the cloud.
What's my experience with pricing, setup cost, and licensing?
The tool was expensive. We paid a monthly license fee. There were no additional costs associated with the product.
What other advice do I have?
Someone who wants to use the solution must know why they need the solution. It is quite expensive. We must not spend much on something we do not need. If we have a need and can afford the solution, HCL is a good solution. It is very easy to understand. It has a lot of features. The reporting system is good. Overall, I rate the product a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Information Officer at a tech services company with 501-1,000 employees
Straightforward setup, stable, and scalable
Pros and Cons
- "The security and the dashboard are the most valuable features."
- "The pricing has room for improvement."
What is our primary use case?
We use the solution to test our web applications and services.
What is most valuable?
The security and the dashboard are the most valuable features.
What needs improvement?
The pricing has room for improvement.
For how long have I used the solution?
I have been using the solution for eight years.
What do I think about the stability of the solution?
I give the stability a seven out of ten.
What do I think about the scalability of the solution?
I give the scalability an eight out of ten.
How are customer service and support?
The support is fine.
How would you rate customer service and support?
Neutral
How was the initial setup?
I give the initial setup a seven out of ten. The implementation took a few weeks.
What about the implementation team?
The implementation was completed in-house.
What was our ROI?
We have seen around a 50 percent return on investment.
What's my experience with pricing, setup cost, and licensing?
HCL AppScan is expensive.
What other advice do I have?
I give the solution an eight out of ten.
I recommend the solution to others.
We have around 4,000 end users.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
HCL AppScan
January 2026
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
Innovation manager at a computer software company with 51-200 employees
Affordable and easy to expand but needs better performance
Pros and Cons
- "It was easy to set up."
- "Sometimes it doesn't work so well."
What is our primary use case?
I have a set project, and I'm writing an application for monitoring server status, and I tried several times to scan it with AppScan in order to understand if there are vulnerabilities in my code.
What is most valuable?
The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great.
It was easy to set up.
It's a stable solution.
The product is easy to scale.
The solution is affordable and reasonably priced.
What needs improvement?
The performance could be better. Sometimes it doesn't work so well. There's a tool for connecting the cloud with the application server. Sometimes it doesn't work really well.
I have not come across any missing features.
For how long have I used the solution?
I've been using the solution for six months. It's been less than a year so far.
What do I think about the stability of the solution?
The solution has been stable. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
So far, we've found the solution can scale well.
How are customer service and support?
I've reached out to support in the past. They are pretty good, however, they are also working from India, and I'm in Italy. There is a delay of course when I open a ticket. We have to wait a bit due to the time shift.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. This was our first.
How was the initial setup?
The initial setup is pretty simple and straightforward. It's not an overly complex or difficult process.
It took about one day to deploy the solution.
What about the implementation team?
I handled the initial setup on my own. I did not ask for help from any consultants or integrators.
What's my experience with pricing, setup cost, and licensing?
I actually pay for tokens. Any time that I want to perform scanning, I have to pay for another token. It's pretty good for me, this system, as it's really, really nice when I need it. I just need to pay for it, and that's it.
What other advice do I have?
We are end-users.
I'd rate the solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal Architect, Application Build Security. at a logistics company with 10,001+ employees
Improves application security, identifies gaps, and performs well
Pros and Cons
- "The HCL AppScan turnaround time for Burp Suite or any new feature request is pretty good, and that is why we are sticking with the HCL."
- "The dashboard, for AppScan or the Fortified fast tool, which we use needs to be improved."
What is our primary use case?
HCL AppScan is primarily used to improve application security. We are transitioning from DevOps to DevSecOps.
We are attempting to integrate these tools into our CICD pipeline in order to meet our business use cases. And if we notice that the tool is missing any business features or a feature, we will highlight them and work to have them fixed or implemented. That is how we go about it. We don't go for any generic features because that will be handled by the product team. We are here to identify our gaps and then have them implemented by the vendor team.
AppScan is only used for web scanning; we do not use it for anything else.
What is most valuable?
There are many features that are valuable. such as the APIs. API calls in AppScan, and similar to Burp Suite enterprise edition, which is also for API scans. I can trigger the scan ware API.
The HCL AppScan turnaround time for Burp Suite or any new feature request is pretty good, and that is why we are sticking with the HCL.
What needs improvement?
The dashboard, for AppScan or the Fortified fast tool, which we use needs to be improved. We always raise that as an announcement request because statistics gathering or management reports based on statistics are quite important. that is the only generic feature that we always request from the product team. The standard response is "Yes, it is in the pipeline, we will take a look."
We would like to see all of the results in the same product. However, specific products for a specific test are available on the market. For example, you cannot upload the task report to the DAST report dashboard and instead request that the product team or vendor team create a sophisticated dashboard for that. Definitely, they will say "No, it is not possible because you have a DAST tool on the market. Go and purchase that. It will have your dashboard. If you're a DevSecOps team, and you ask me I would like to see all of the reports uploaded and collaborated on the same dashboard of the particular product. This is the reason we are using an open-sourced vulnerable management tool.
For how long have I used the solution?
We have been using HCL AppScan for almost four years.
We are not working with the most recent update, but with two versions earlier.
What do I think about the stability of the solution?
The HCL AppScan performance is both stable and reliable.
Burp Suite and HCL AppScan are both stable and reliable when compared to other products.
What do I think about the scalability of the solution?
Scalability is a question that is determined by how you allocate your hardware. It is all about how you design your CICD program with HCL AppScan.
Scalability is quite simple to implement or achieve. Again, this is entirely dependent on your business requirements. Generally, or in short, scalability is not an issue with HCL AppScan.
This solution is used daily.
How are customer service and support?
We have contacted technical support when we need customization, and there are usually other bugs and day-to-day life hacks.
The support has improved since the transition from IBM to HCL AppScan.
Which solution did I use previously and why did I switch?
We are working with tools that are all related to application security, such as Qualys, SAST, DAST, open-sourced software scan, and penetration test tools.
Some of the penetration test tools we work with are Burp Suite, and OWASP Zap which is an open-source product.
How was the initial setup?
The initial setup with most of the products, particularly the Burp Suite and the HCL AppScan, is straightforward. The only difference is that when it is customized to your specific requirements, that is when the key part comes into play. We have to engage the professional services of the product team, or the vendor team, which is where the headache begins. That is a common challenge shared by the all vendor team.
Deployment and installation of AppScan take approximately three hours, or less than that if you have all of the necessary prerequisites, hardware, a database, and everything is in place, then three hours is all you need.
We put our application into maintenance mode during the version upgrade.
We require one person for the administration of this product.
What about the implementation team?
When customization is required, we have assistance from the vendor time.
Most of the HCL AppScan installations are customized. We use Pure Vanilla or a new malware product.
What's my experience with pricing, setup cost, and licensing?
With the features, that they offer, and the support, they offer, AppScan pricing is on a higher level.
They should reduce it slightly. But, in my opinion, it's not a big deal. If a tool is able to satisfy all your requirements, it doesn't matter, the cost is not a deciding factor.
There are no additional fees in addition to the licensing fee.
Which other solutions did I evaluate?
We looked into it and decided on two open-source vulnerable management products. We are currently conducting a proof-of-concept on those open source vulnerable management tools.
We are just looking into these open sources and experimenting with them. As a result, this is the first time we intend to incorporate this vulnerable management tool into our world.
We are looking for vulnerability management, purely for vulnerability management, that can collect reports from SAST, DAST, and other scan results and use them in the management dashboard.
What other advice do I have?
Before you choose a tool, whether it is Burp Suite, AppScan, or any other tool, you must first construct your business requirements, or the business use case. And you must detail out all of the product's features, as well as map the features to the business use cases. If the product meets or exceeds the majority of the business use cases, then you only need to choose that product. Otherwise, you will end up customizing the product after you buy it, which will create issues in terms of engaging with the professional services of that specific vendor. Then there's the matter of time and money.
Detail all of your business use cases, then map those use cases to the product feature list and choose the product.
We have a business relationship with AppScan, as customers, and some of our business partners have project outsourcing with IT companies, such as HCL, IBM, Dell, and Infosys.
I would rate HCL AppScan a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at a tech consulting company with 201-500 employees
A cheap solution with a good technical support team
Pros and Cons
- "The solution is cheap."
- "Improvement can be done as per customer requirements."
What is our primary use case?
I use it for my customers.
What needs improvement?
Improvement can be done as per customer requirements.
For how long have I used the solution?
I have been using HCL AppScan for some time.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup took one to two days.
What's my experience with pricing, setup cost, and licensing?
The solution is cheap.
What other advice do I have?
I rate the overall solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Scientific Officer at a tech services company with 51-200 employees
Efficiently scans through the website and identifies vulnerabilities
What is our primary use case?
HCL AppScan efficiently scans through the website and identifies vulnerabilities for AWS. It is reducing tools day by day, making it more efficient.
What needs improvement?
HCL AppScan generates false results. Sometimes, it incorrectly identifies requests as vulnerable when they are not vulnerable. In the ADSL feature managed, the primary objective is to identify application security vulnerabilities. However, sometimes AppScan wrongly flags something as a vulnerability when it's not present, which we call a false positive.
For how long have I used the solution?
I have been using HCL AppScan for nine years.
What do I think about the stability of the solution?
I rate the solution’s stability an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable if required.
How are customer service and support?
Customer support is helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
There is a licensing partner. Sometimes, it is required to install a server. I must remove that license and then eject a new one on a different server. It becomes a bit harder for beginners if they do not have enough experience to install Zoho software.
Deployment takes around an hour, and one person can do it.
I rate the initial setup a six and a half out of ten, where one is difficult and ten is easy.
What's my experience with pricing, setup cost, and licensing?
The tool is not cost-efficient. Considering the type of service with encryption security scanning from HCL AppScan, it drives up the cost unnecessarily. It is fairly priced.
What other advice do I have?
There are some very cost-effective solutions out there. They are also very efficient for systems scanning.
Overall, I rate the solution an eight-point five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Mechanical maintenance technician at a retailer with 5,001-10,000 employees
Helps with the scan of the web interface and supports special languages
Pros and Cons
- "Compared to other tools only AppScan supports special language."
- "The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed."
What is our primary use case?
I use the tool to scan the web interface.
What is most valuable?
Compared to other tools only AppScan supports special language.
What needs improvement?
The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed.
For how long have I used the solution?
I have been using the solution for two years.
How are customer service and support?
The solution has dedicated and good tech support. We can open a ticket and we get information within two hours. Once we open a ticket we get validation or confirmation of our problem. When we get to the specialist, we will get more information.
How would you rate customer service and support?
Positive
What other advice do I have?
I would rate the overall solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Global Business Development Executive - Applications, Data & AI Practice at a tech services company with 10,001+ employees
Stable and scalable but not user-friendly
Pros and Cons
- "AppScan is stable."
- "AppScan is too complicated and should be made more user-friendly."
What is our primary use case?
I mainly use AppScan for vulnerability scanning and database bridging.
What needs improvement?
AppScan is too complicated and should be made more user-friendly.
For how long have I used the solution?
I've been using HCL AppScan for three to four years.
What do I think about the stability of the solution?
AppScan is stable.
What do I think about the scalability of the solution?
AppScan is scalable.
How are customer service and support?
HCL's technical support is ok, but it could be faster and more responsive.
How was the initial setup?
The initial setup was complex and took about a day and a half.
What other advice do I have?
I would rate AppScan four out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST)Popular Comparisons
SonarQube
GitLab
Checkmarx One
Veracode
Coverity Static
GitHub Advanced Security
OpenText Core Application Security
Mend.io
OWASP Zap
Acunetix
Sonatype Lifecycle
PortSwigger Burp Suite Professional
Qualys Web Application Scanning
Klocwork
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Difference between IBM Appscan and HP fortify software
- Which solution do you prefer: Fortify WebInspect or HCL AppScan?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?




















