Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Black Duck, a segment of the Synopsys Software Integrity Group, stands out as a prominent provider of application security testing (AST) solutions. Their extensive array of offerings encompasses tools for static analysis, software composition analysis (SCA), dynamic analysis, and interactive analysis, which assist organizations in detecting and addressing security vulnerabilities throughout the software development life cycle. By streamlining the identification and management of open-source software, Black Duck guarantees adherence to security and licensing regulations. Their solutions are meticulously crafted to enable organizations to foster trust in their software while effectively managing application security, quality, and compliance risks at a pace that aligns with business demands. With Black Duck, businesses are equipped to innovate with security in mind, delivering software solutions confidently and efficiently. Furthermore, their commitment to continuous improvement ensures that clients remain ahead of emerging security challenges in a rapidly evolving technological landscape.

Description

Recognized as the top-rated DAST solution by an independent research organization for three consecutive years, this tool automatically evaluates contemporary web applications and APIs while minimizing false positives and overlooked vulnerabilities. It accelerates remediation efforts through comprehensive reporting and seamless integrations, keeping compliance and development teams informed. Regardless of the scale of your application portfolio, it enables effective management of security assessments. The solution autonomously navigates and evaluates web applications to uncover vulnerabilities such as SQL Injection, XSS, and CSRF. With a modern interface and user-friendly workflows built on the Insight platform, InsightAppSec is straightforward to deploy, manage, and operate. Additionally, it can scan applications hosted on isolated networks with the optional on-premise engine. Furthermore, InsightAppSec provides assessments and reports on your web application's compliance with PCI-DSS, HIPAA, OWASP Top Ten, and various other regulatory standards, ensuring a comprehensive approach to application security. This multifaceted solution supports organizations in enhancing their security posture while streamlining assessment processes.

API Access

Has API No 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Apache Maven Yes 
BMC Helix ITSM No 
BlueFlag Security Yes 
C Yes 
C# Yes 
C++ Yes 
Coalfire No 
Do Status No 
Jenkins No 
Jira No 
Jira Work Management No 
Kondukto Yes 
Logilica Yes 
Longbow Yes 
OpenText Static Application Security Testing Yes 
Phoenix Security Yes 
Selenium No 
Selenium IDE No 
ThreadFix Yes 
Vulcan Cyber Yes 

Integrations

Apache Maven No 
BMC Helix ITSM Yes 
BlueFlag Security No 
C No 
C# No 
C++ No 
Coalfire Yes 
Do Status Yes 
Jenkins Yes 
Jira Yes 
Jira Work Management Yes 
Kondukto No 
Logilica No 
Longbow No 
OpenText Static Application Security Testing No 
Phoenix Security No 
Selenium Yes 
Selenium IDE Yes 
ThreadFix No 
Vulcan Cyber No 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Pricing Details

$2000 per app per year
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) Yes 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

Black Duck

Founded

2002

Country

United States

Website

www.blackduck.com

Vendor Details

Company Name

Rapid7

Founded

2000

Country

United States

Website

www.rapid7.com/products/insightappsec/

Product Features

IT Asset Management

Asset Tracking Yes 
Audit Management Yes 
Compliance Management Yes 
Configuration Management No 
Contract/License Management Yes 
Cost Tracking No 
Depreciation Management No 
IT Service Management No 
Inventory Management Yes 
Maintenance Management No 
Procurement Management No 
Requisition Management No 
Supplier Management Yes 

License Management

Automatic SKU Recognition No 
Central LM Server No 
Copy Protection No 
History Tracking Yes 
Node Management No 
Online Activation Yes 
Portable License No 
Sarbanes-Oxley Compliance Yes 
Timing Rights No 
Trial License Yes 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration No 
Training Resources No 
Vulnerability Detection No 
Vulnerability Remediation No 

Static Application Security Testing (SAST)

Application Security No 
Dashboard No 
Debugging No 
Deployment Management No 
IDE No 
Multi-Language Scanning No 
Real-Time Analytics No 
Source Code Scanning No 
Vulnerability Scanning No 

Alternatives

Revenera SCA Reviews

Revenera SCA

Revenera

Alternatives