start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

Enterprise security teams have faced a persistent constraint: adopting best-in-class application security tooling often means accommodating vendor-specific architecture. Database choices can be narrowed. Cloud options can become limited. Observability workflows can get fragmented. Security tools shouldn't impose that unnecessary infrastructure constraint.

HCL AppScan 360° is a cloud-native application security platform built to deploy where you need it - on-premises or in a private/sovereign cloud. With version 2.2, we've extended that flexibility by adding support for database options, cloud deployment, observability stack and security testing for modern application development. This gives enterprises more options in how they deploy, and manage their application security.

More Database Flexibility with PostgreSQL

Many organizations standardize on PostgreSQL for cost optimization, compliance requirements, or open-source alignment. HCL AppScan 360° version 2.2 now fully supports PostgreSQL for new installations with full production support.

Configuration works the same way as SQL Server through standard deployment procedures, with identical performance and scalability. 

Organizations that are using PostgreSQL can now deploy HCL AppScan 360° within the database infrastructure. This gives enterprises greater flexibility to align application security deployment with their existing database strategy. 

Expanded Cloud Deployment Support 

Applications run on diverse infrastructure. Some organizations standardize on GCP, others on Azure, many remain on-premises. Version 2.2 expands deployment flexibility to support more of these existing infrastructure choices. 

HCL AppScan 360° now supports Google Kubernetes Engine (GKE) and Azure Kubernetes Service (AKS) via Helm-based installation. Deploy HCL AppScan 360° on the cloud infrastructure you have already selected. Scan applications where they actually run. Keep security analysis in the same region as your workloads, reducing data transfer costs and meeting data residency requirements. Your infrastructure strategy stays intact; security simply integrates within it.

See Everything in One Dashboard 

Most large enterprises have invested significantly in observability infrastructure. These platforms are core to how ops teams see what's happening in production.

HCL AppScan 360° version 2.2 integrates native OpenTelemetry support, streaming system-wide logs and performance metrics directly to your existing observability platform of choice. Security operations teams can bring AppScan 360° system-wide logs and performance metrics into their existing observability dashboards. This creates more unified visibility across the environment.

With unified visibility across your infrastructure, the next step is ensuring every application, API, and dependency is thoroughly tested. Modern development moves fast. You need security testing that keeps pace. 

Comprehensive Testing for Modern Development

Applications built today use diverse languages, frameworks, and APIs. Version 2.2 delivers security testing that matches this reality. It helps prioritize what actually matters, test modern API standards, and support the languages developers use.

SCA: Know Which Vulnerabilities Actually Matter

Open-source dependencies are foundational, but not all vulnerabilities pose equal risk. Version 2.2 introduces function-level reachability: using Dynamic agent, you can now report whether a vulnerable function is invoked during runtime. This helps teams prioritize SCA findings based on actual application behavior to eliminate noise and focus on exploitable risk.

Additional software composition analysis (SCA) capabilities include proactive CVE monitoring to automatically track newly published vulnerabilities against packages you've already scanned, custom SCA policies, CycloneDX support for SBOM generation, and expanded language support including F# and the UV Python package manager.

DAST: Modern Coverage 

The Dynamic Application Security Testing (DAST) engine now detects post-quantum security risks by flagging legacy encryption protocols. It supports OpenAPI 3.1 and 3.2 definitions with API key authentication for modern APIs. For web applications, automatic login improvements extend coverage to Vue.js, Microsoft Entra, and Okta. These enhancements extend DAST coverage across modern APIs and web applications. 

IAST: Python Runtime Support

Python has become foundational for backend services, machine learning, and data science. A new Interactive Application Security Testing (IAST) agent supports Python 3.9+ and Flask applications, with validation showing 100% coverage of the Python OWASP Benchmark. In addition to Python, IAST also supports Node.js (with LangChain framework for LLM applications), PHP, Java, and .NET.

With comprehensive testing capabilities across modern application environments, security teams need operational capabilities that scale, including deployment flexibility, governance controls, and automation that reduce manual work.

Simplifying Deployment and Management at Scale

Version 2.2 simplifies platform deployment and day-to-day operations, reducing friction for security teams managing enterprise-scale deployments.

Deployment & Infrastructure:

  • Modular installation lets you install specific services or target only failed components during an installation retry, eliminating the need to restart the entire configuration process. 
  • Enhanced Setup Assistant now validates infrastructure readiness before installation, catching environment and network constraints upfront.

Governance & Operations:

  • Custom issue fields let you tag findings according to your risk framework and filter scans by organizational context.
  • Redesigned Roles page groups permissions logically, making it faster to set up role-based access controls for large teams.
  • Bulk scan deletion allows administrators to clean up multiple scans at once instead of one-by-one.

These changes reflect a consistent philosophy: get security tooling out of the way and let teams operate according to their existing processes.

What This Release Means

HCL AppScan 360° version 2.2 gives organizations greater flexibility to integrate application security into their existing environments, while expanding testing capabilities across SAST, DAST, SCA, and IAST. 

Existing users can review upgrade paths from version 2.1 to version 2.2

Organizations evaluating enterprise SAST, DAST, SCA, and IAST solutions can now explore how version 2.2 extends capabilities that support modern enterprise application security requirements.

Explore HCL AppScan 360° version 2.2. Schedule a demo

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.