Our primary use case of this solution is to reduce our risks. I'm head of development and consulting.
What is our primary use case?
What is most valuable?
Insights is valuable at protecting a problematic library and enabling you to reduce the number of false positives.
What needs improvement?
As opposed to other solutions on the market, Insights doesn't know whether or not you're using effective methods, it's not very good at detecting intrusive methods. Support and training are lacking in the product.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
We've been using Kiuwan for three years, and haven't had any problems with stability.
What do I think about the scalability of the solution?
We are a small user, so scalability is not an issue.
How are customer service and support?
Kiuwan lacks decent support, it's very bad. A couple of years ago an American company bought Kiuwan and support became non-existent. It's a big part of why we're looking to move to another product. We have questions regarding false positives and nobody responds to our tickets. They don't have any answers. If you're looking for a cheaper solution and don't require support, it might be okay, but a large end company that has a lot of questions about how the developers are programming will have trouble.
How was the initial setup?
Deployment is not very complicated; you put the pipelines in Jenkins and configure. In this respect, it's similar to other solutions.
What's my experience with pricing, setup cost, and licensing?
Kiuwan uses a very good licensing model. We initially chose the solution because the price and quality matched. That's not the case anymore and the price is no longer any better than other solutions. The licensing model is based on a per-use payment model.
Which other solutions did I evaluate?
We've looked at other options. I think maybe the other solutions on the market show the attack vector, and it's easier to fix vulnerabilities. Kiuwan can't do this. Another issue is that other solutions have training included as part of the consultancy services but Kiuwan doesn't.
What other advice do I have?
I rate this solution six out of 10.
Which deployment model are you using for this solution?
Public Cloud
