Try our new research platform with insights from 80,000+ expert users
SeniorCl3552 - PeerSpot reviewer
Senior Cloud Architect at a tech company with 1,001-5,000 employees
Real User
Provides a better integration for our ecosystem, but we are still waiting to see the roadmap
Pros and Cons
  • "It provides a better integration for our ecosystem."
  • "You can easily find particular features and functions through the UI."
  • "Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
  • "I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources."

What is our primary use case?

We integrate AppSense with Fortinet FortiGate Next-Generation Firewall products. This integration is new for us, but so far, we have had good results. However, it is a new integration. 

Fortinet has a lot of potential and integrations going on with IBM: QRadar, AppSense, and IBM Cloud.

How has it helped my organization?

It provides a better integration for our ecosystem. From a Fortinet perspective, this can lead to integration of selling our own products.

What is most valuable?

Its integration from a UI perspective. You can easily find particular features and functions through the UI. 

For its first initial release, the integration was pretty good.

What needs improvement?

More seamless integration with Fortinet's technologies as this would make our customers happy. At the moment, it is a good integration, but it is the first time that we have done it. Therefore, there needs to be more integration within our fabric, so it is less obvious.

Visibility is an issue for us. Our partners were not even aware that we had an integration with AppSense. They do not know we have integrations with some of IBM products. Part of this is our marketing budget is small compared to IBM's.

I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources. We are not like IBM, which is huge. We need to prioritize which engineer will work on which technology. 

With QRadar, it has better integration because we have been working with it for awhile and there is a roadmap. There are always new things coming out.

Buyer's Guide
HCL AppScan
May 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

Unknown. We are too new to the product.

What do I think about the scalability of the solution?

Unknown. We are too new to the product.

How are customer service and support?

The IBM technical support staff are good.

What other advice do I have?

Have a look at the competitors as well. There is more than one vendor in the market. I would definitely do your due diligence.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
David Mawazo - PeerSpot reviewer
Chief Information Officer at TeleTracking Technologies, Inc.
Real User
Straightforward setup, stable, and scalable
Pros and Cons
  • "The security and the dashboard are the most valuable features."
  • "The pricing has room for improvement."

What is our primary use case?

We use the solution to test our web applications and services.

What is most valuable?

The security and the dashboard are the most valuable features.

What needs improvement?

The pricing has room for improvement.

For how long have I used the solution?

I have been using the solution for eight years.

What do I think about the stability of the solution?

I give the stability a seven out of ten.

What do I think about the scalability of the solution?

I give the scalability an eight out of ten.

How are customer service and support?

The support is fine.

How would you rate customer service and support?

Neutral

How was the initial setup?

I give the initial setup a seven out of ten. The implementation took a few weeks.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

We have seen around a 50 percent return on investment.

What's my experience with pricing, setup cost, and licensing?

HCL AppScan is expensive.

What other advice do I have?

I give the solution an eight out of ten.

I recommend the solution to others.

We have around 4,000 end users.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
HCL AppScan
May 2025
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Yong Seok Kang - PeerSpot reviewer
Technical Consultant at MTRiver Consulting
Real User
Top 5Leaderboard
A security testing application that needs to improve security
Pros and Cons
  • "We use it as a security testing application."
  • "HCL AppScan needs to improve security."

What is our primary use case?

We use it as a security testing application. 

What needs improvement?

HCL AppScan needs to improve security. 

For how long have I used the solution?

I have been working with the product for ten years. 

What do I think about the stability of the solution?

HCL AppScan is pretty stable. 

How was the initial setup?

HCL AppScan is easy to deploy and can be done in one to two hours. 

What's my experience with pricing, setup cost, and licensing?

Our clients are willing to pay the extra money. It is expensive. 

What other advice do I have?

I rate HCL AppScan an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Mechanical maintenance technician at SAQ
Real User
Top 20
Helps with the scan of the web interface and supports special languages
Pros and Cons
  • "Compared to other tools only AppScan supports special language."
  • "The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed."

What is our primary use case?

I use the tool to scan the web interface.

What is most valuable?

Compared to other tools only AppScan supports special language.

What needs improvement?

The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed.

For how long have I used the solution?

I have been using the solution for two years.

How are customer service and support?

The solution has dedicated and good tech support. We can open a ticket and we get information within two hours. Once we open a ticket we get validation or confirmation of our problem. When we get to the specialist, we will get more information.

How would you rate customer service and support?

Positive

What other advice do I have?

I would rate the overall solution a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
VijayKumar16 - PeerSpot reviewer
Global Business Development Executive - Applications, Data & AI Practice at Kyndryl
Real User
Stable and scalable but not user-friendly
Pros and Cons
  • "AppScan is stable."
  • "AppScan is too complicated and should be made more user-friendly."

What is our primary use case?

I mainly use AppScan for vulnerability scanning and database bridging.

What needs improvement?

AppScan is too complicated and should be made more user-friendly.

For how long have I used the solution?

I've been using HCL AppScan for three to four years.

What do I think about the stability of the solution?

AppScan is stable.

What do I think about the scalability of the solution?

AppScan is scalable.

How are customer service and support?

HCL's technical support is ok, but it could be faster and more responsive.

How was the initial setup?

The initial setup was complex and took about a day and a half.

What other advice do I have?

I would rate AppScan four out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1495479 - PeerSpot reviewer
Senior Manager, IT Test Automation Engineering at a outsourcing company with 10,001+ employees
Real User
Offers a few specific development languages but needs more languages and lacks good technical support services
Pros and Cons
  • "The solution offers services in a few specific development languages."
  • "They have to improve support."

What is most valuable?

The solution offers services in a few specific development languages.

What needs improvement?

They have to improve support. Their support before, when it was IBM, was very good technical support. However, now, it's very bad.

They could add more language coverage. They don't cover so many development languages. They really should be covering more. If they did, it would be a huge improvement.

How are customer service and technical support?

The technical support is no longer any good. It's gone downhill since they were under IBM. Now, we are no longer satisfied with their level of service and we hope they will improve their services in the future.

Which other solutions did I evaluate?

I'm currently looking into Checkmarx. I'm evaluating their offering to see how it compares. This product lacks in many areas, and so we are looking at other options.

What other advice do I have?

I don't have information on the relationship HCL has with my company. My understanding is they are just a vendor for us.

In general, I would rate them at a six out of ten. There are many areas in which they could improve, including by adding more languages and re-vamping their technical support. They are lacking in a lot of areas.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user634890 - PeerSpot reviewer
Chief information with 5,001-10,000 employees
Real User
We use it to find breaches in apps while they are in development.
Pros and Cons
  • "It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply."
  • "We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices."

How has it helped my organization?

Before we had this solution, our security team was doing manual reviews with the scripts. This would take us a lot of work hours and a lot of people were involved in the process.

Now we just send it to AppScan and we can do other stuff like defining processes or dealing with management issues. We can focus on other aspects of our security.

It helps us avoid any downtime in the applications when they are already in production. It also prevents any vulnerability or security breaches.

What is most valuable?

We are currently using it in the integration of our agile process so we can find any breaches in the apps while they're in the development process. We can then fix breaches before they go into a production environment.

It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply.

That being said, we have to be very rigorous about what we are protecting, such as the type of data and the code itself. Having those features in the app is a huge must.

What needs improvement?

We are moving a lot into mobile. While the solution does have a lot of functionalities in mobile, we are trying to expand it more aggressively.

We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices.

We would like to see what type of exposure we have in those specific devices.

What do I think about the stability of the solution?

There have been no stability issues so far. It has handled anything that we have sent to it.

The number of events we receive per day depends on many factors. The events mostly occur when we charge a new code into AppScan to find the vulnerabilities.

For example, we found ten vulnerabilities with the solution. We can see what our mistakes were and we can try to avoid them the next time.

This solution makes our job a lot easier for continuous vulnerability assessments and development processes.

How is customer service and technical support?

We used technical support a couple months ago when we migrated from another version. We didn’t use them for an issue, but we got support to help us make the transition. They were very good.

The whole migration process was done in just a couple of weeks. It was fast and it went according to our expectations. After a couple of weeks, we were operational and it was up and running.

What other advice do I have?

At the beginning, you need to know the reach and what you are expecting. The solution is not going to be a silver bullet that will fix everything in your app.

You have to have a mature SDLC process for developers to follow. If they don't have that, AppScan could provide great insight in order to develop it. Once you have both things in motion, it runs automatically.

When looking for a vendor, we want to know if they will go beyond that what is out-of-the-box. We want to see if they will tell us what additional features we can exploit in the solution.

We want to know if they will provide us with knowledge about apps or code for a specific matter and if they can support our expectancy of growth in the near future.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1676757 - PeerSpot reviewer
Innovation manager at a computer software company with 51-200 employees
Real User
Affordable and easy to expand but needs better performance
Pros and Cons
  • "It was easy to set up."
  • "Sometimes it doesn't work so well."

What is our primary use case?

I have a set project, and I'm writing an application for monitoring server status, and I tried several times to scan it with AppScan in order to understand if there are vulnerabilities in my code.

What is most valuable?

The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great.

It was easy to set up.

It's a stable solution.

The product is easy to scale. 

The solution is affordable and reasonably priced.

What needs improvement?

The performance could be better. Sometimes it doesn't work so well. There's a tool for connecting the cloud with the application server. Sometimes it doesn't work really well.

I have not come across any missing features. 

For how long have I used the solution?

I've been using the solution for six months. It's been less than a year so far. 

What do I think about the stability of the solution?

The solution has been stable. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

So far, we've found the solution can scale well.

How are customer service and support?

I've reached out to support in the past. They are pretty good, however, they are also working from India, and I'm in Italy. There is a delay of course when I open a ticket. We have to wait a bit due to the time shift.

Which solution did I use previously and why did I switch?

We did not previously use a different solution. This was our first. 

How was the initial setup?

The initial setup is pretty simple and straightforward. It's not an overly complex or difficult process. 

It took about one day to deploy the solution.

What about the implementation team?

I handled the initial setup on my own. I did not ask for help from any consultants or integrators. 

What's my experience with pricing, setup cost, and licensing?

I actually pay for tokens. Any time that I want to perform scanning, I have to pay for another token. It's pretty good for me, this system, as it's really, really nice when I need it. I just need to pay for it, and that's it.

What other advice do I have?

We are end-users.

I'd rate the solution a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros sharing their opinions.