Contrast Security makes application security simple
What do you like best about the product?
Contrast makes understanding vulnerabilities easy. For every vulnerability found in custom code, there is an answer to what the vulnerability is, why it is a risk, and how to fix the vulnerability. It is also great at identifying libraries used within the application and the potential vulnerabilites for each library.
What do you dislike about the product?
Although Contrast is great at identitfying libraries, the default scoring for the libraries can be very particular. It can make developers feel discouraged seeing an F score because the library is a version behind. There is a way to change the scoring to only look at associated vulnerabilities, but there is still a benefit to seeing libraries that are behind on updates.
What problems is the product solving and how is that benefiting you?
With Contrast's IAST product we are able to see vulnerabilities at runtime and it reduces the amount of false positives that we see with other tools. Communication with development teams has improved because the breakdown of vulnerabilities is so clear.
There are no comments to display