What is our primary use case?
We have just recently adopted this solution to use for our code security. We are still new to using these kinds of tools.
How has it helped my organization?
We are using this solution to increase the quality of our software and to test the vulnerabilities in our tools before the customers find them. Customers look for problems in code, so it is better to perform tests and prove that our code is free from vulnerabilities beforehand.
This is standard here in Spain, where the customers use the same tools to check for vulnerabilities. If we are using the same tools then it is not possible for the customers to find different problems. If we are using different tools then maybe the results would be different. We want the customer's report to list the same issues.
So far, the tool has shown us four issues, and we are starting to clean the vulnerabilities.
What is most valuable?
This program is very easy to use. I can use this tool, and I am new to these kinds of tools.
What needs improvement?
Better integration with code repositories is something that we will need.
I would like to see better integration with the Visual Studio and Eclipse IDEs.
It would be helpful to have better testing for vulnerabilities in mobile development.
For how long have I used the solution?
We have been using this solution for about two months.
What do I think about the stability of the solution?
We have had no issues with stability since we started working with this solution.
Currently, we are using this tool about once a week. However, we want to extend this to using the tool on a daily basis. At the moment we are only using a single test, but we want it to be used by all of the developers on their normal day.
What do I think about the scalability of the solution?
Our solution is in the cloud, so I don't think that we'll have any problem with scalability.
We have approximately twenty developers using this solution
How are customer service and technical support?
We did have a support case with a customer, but I was on holiday and did not interact with technical support myself. I think that the support was quick and fine.
Which solution did I use previously and why did I switch?
This is our first solution for code security.
How was the initial setup?
The installation of this solution is easy.
What's my experience with pricing, setup cost, and licensing?
This solution is cheaper than other tools.
Which other solutions did I evaluate?
We ran a project to evaluate solutions and we finally chose Kiuwan. For the evaluation, we weighed both price and technical aspects of the tool, equally. We found that this is a cheaper tool for the level of quality.
We tried putting the same piece of code into different tools. For example, in Java, the tools have similar results. So for Java, there's a low cost, and the preference is for the content of the coders. For mobile development, we are not too experienced, and it is not the perfect tool because the integration with certain products is very manual. The price, however, justifies adopting this product.
What other advice do I have?
For the moment, this is a solution that I could recommend. It is a cheaper way for us to enter into working on code security.
The biggest lesson that I have learned to make sure that we do not have any big security issues during development. We are confident about the vulnerabilities that are being found in our Java code, but we are not sure about other languages such as Angular. This solution may not be able to detect all of the problems that are in the code.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.