Cloud-Native Application Security
Our fast, accurate, agile application security testing is now deployable anywhere. Achieve continuous security and manage risk and compliance with the industry’s most comprehensive set of integrated testing and remediation solutions including static, dynamic, interactive, open source, container scanning, API testing and more. Born on the cloud, HCL AppScan 360˚, is a cloud-native application security platform built on modern unified architecture that you can deploy as self-managed on-prem, private cloud, public cloud, as-a-service, and more.
Benefits
Scalable Solutions
For every industry, geography, use case, and consumption model.
Centralized Dashboards
Customizable lenses and views of all testing results, testing status, and remediation progress, all in one place.
Actionable Reporting
Actionable fix recommendations for each vulnerability detected, simplifies and reduces the time for triage and remediation.
Customizable Policies
Security teams can manage priorities while still testing earlier in the development timeline with a rich set of customizable security, industry, and regulatory policies.
Regulatory Compliance
Achieve compliance with industry standards and benchmarks, such as PCI DSS, HIPAA, OWASP Top 10, SANS 25, and more.
Features
Easy integration and automation in the software development pipeline
Comprehensive Cloud-native Application Security Testing Suite
Comprehensive Cloud-native Application Security Testing Suite
Version 1.3 of HCL AppScan 360º is self-managed with both DAST and SAST technology. Future releases will expand the platform to include our entire set of integrated testing capabilities, all currently available as-a-service with HCL AppScan on Cloud.
Available Today
- Dynamic analysis (DAST): Test web applications and APIs against potential vulnerabilities while applications are running
- Static Analysis (SAST): Analyze source code in applications and APIs for potential vulnerabilities throughout the development life cycle
- Centralized application security management platform with customizable dashboards, policies and postures
- Self-managed on-premises and private cloud deployment options built on a fully Kubernetes cloud-native architecture
- Increased plug-ins for IDEs and CI/CD tools for SAST and DAST automation
- DTS integration and robust APIs for customized automation
Coming Soon
- Interactive Analysis (IAST): Monitor web applications and APIs to help find and fix vulnerabilities without slowing down development
- Software composition analysis (SCA): Identify vulnerabilities introduced by open-source software components
- Increased deployment options, including MSP and federal support