start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

The AI boom is fundamentally changing how we build software, while also introducing a whole new frontier of vulnerabilities.

For security teams already drowning in backlogs, the last thing they need is a tool that just generates more "findings"—they need a way to prioritize and patch with actual velocity. HCL AppScan 360° v2.1 meets this challenge head-on by operationalizing AI across the full security stack.

From smarter discovery to automated fix suggestions, we’re helping you cut through the noise, discover issues, understand and secure them quickly, all with an on-premise platform designed for full data sovereignty. 

Talk to Your Security Data

The new AppScan MCP (Model Context Protocol) server changes how developers and security teams interact with their findings. Instead of the usual context-switching between dashboards, spreadsheets, and your editor, you can now connect HCL AppScan 360° directly into your AI-powered IDE.

If you are a developer, you get a unified, natural-language interface to ask about SAST, DAST, SCA, and IAST findings right where you write code.

And because the MCP server runs on your infrastructure, your vulnerability data stays exactly where it should, under your control. You maintain sovereignty over all your data by connecting to and harnessing the power of your own LLM, not one we choose for you.

Fix Vulnerabilities Automatically

When AppScan was created 27 years ago, before the application security tool market existed, finding vulnerabilities was the hard part. Modern application security testing tools (SAST, DAST, SCA, IAST) shipped with the HCL AppScan 360° v2.1 platform solve the problem. Fixing these issues is where teams lose time. 

Our cloud-native application security platform, HCL AppScan 360° 2.1, has dramatically closed this gap by integrating HCL AppScan RapidFix (an automated triage and remediation platform) directly into the platform interface and into the SAST remediation workflow. Powerful Agentic AI looks at your findings alongside your actual source code, recommends how to triage them, and, where it can, generates code fixes that plug straight into your Git workflow.

The result: Developers spend less time interpreting security reports, and security teams watch remediation timelines shrink.

Secure Your AI-powered Applications

If your applications use large language models (LLMs), you need comprehensive testing for a whole new category of risk. HCL AppScan 360° 2.1 is one of the first platforms to offer multiple solutions to secure your AI ecosystem.

DAST for LLM-augmented applications tests your AI-powered web apps dynamically, probing for prompt injection, sensitive data disclosure and other threats from the OWASP Top 10 for LLM Applications before they ever reach production. 

On the runtime side, IAST generative AI monitoring watches how your application handles LLM output, flagging cases where AI-generated responses flow into security-sensitive prompts and responses without proper validation. It works across Java, .NET, and Node.js, with support for OpenAI and LangChain integrations.

Software Composition Analysis (SCA) for Supply Chain Security 

Vulnerability databases are essential, but they're no longer enough on their own. The Software Composition Analysis (SCA) engine now includes integrated malware detection, automatically scanning your open-source dependencies for known malicious or compromised packages and flagging them in your license report so nothing slips through unnoticed.

To help with prioritization, EPSS (Exploit Prediction Scoring System) scores are now available for SCA findings.

Additional Security Enhancements in HCL AppScan 360° v2.1 

Beyond the big-ticket items, HCL AppScan 360° 2.1 brings a set of practical improvements that add up quickly:

  • AppScan Presence opens the door to DAST scanning for internal or firewalled applications, creating a secure tunnel to your private network without any public exposure.
  • New integrations with Slack, Splunk and Cursor AI meet your teams where they already work, putting security alerts, scan analytics and AI-assisted coding remediation within arm's reach.
  • Centralized email notifications replace the old per-scan setup with organization-wide preferences, delivering clean HTML scan summaries straight to the right inboxes.
  • On the compliance side, this release adds reports for the OWASP Top 10 for LLM Applications 2025 and Canada's ITSG-33, along with refreshed versions of ISO 27001/27002, PCI DSS v4.0.1, NIST 800-53, GDPR and HIPAA.

The Bottom Line 

Security shouldn’t be a bottleneck to innovation. With version 2.1, HCL AppScan 360° moves beyond just "finding" bugs to actually solving them.

By bridging the gap between security data and the developer’s IDE—while maintaining total data sovereignty—we’re helping teams eliminate remediation debt without compromising on privacy. 

From malware detection in your software supply chain to dynamic probing of your LLM integrations, this release ensures your security posture evolves alongside the modern stack.

Transform your application security with AI. Contact us to know more about HCL AppScan 360°2.1.

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.

Training Developers to Build in Security from the Start
  |  May 18, 2026
Training Developers to Build in Security from the Start
Train developers to code securely from the start. Reduce vulnerabilities, rework, and risk with in-context security training and real-time guidance.
HCLTech (HCLSoftware) Named Only Customer’s Choice in Application Security Testing
  |  April 21, 2026
HCLTech (HCLSoftware) Named Only Customer’s Choice in Application Security Testing
HCLSoftware receives Gartner® Peer Insights™ Customers’ Choice in Application Security Testing, explore verified feedback from real users.