What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Exact current language list and which are fully versus partially supported: confirm with vendor
- Current module naming for the security and quality products: confirm
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Kiuwan parses source into a language-neutral model and applies rule sets that combine security checks with maintainability analysis. On the security side the rules cover the standard families, mapped to CWE, OWASP and to compliance frameworks such as PCI DSS and various national and sector standards, with data flow analysis used for the injection-class rules. On the quality side it computes technical debt indicators, complexity, duplication and a composite risk index, which is the product's distinguishing angle: one report that a manager can read as both a security posture and a maintainability posture.
Analysis is performed by a local analyzer component that runs on your infrastructure and uploads results to the platform, or runs entirely on-premises in self-hosted deployments. That split matters for organizations that will not send source code outside their boundary but still want a hosted console. Action plans group findings into prioritized remediation batches with effort estimates, and the platform maintains trend data across scans so you can show whether debt and risk are moving in the right direction.
Where it fits
Kiuwan runs in CI or on a schedule against application portfolios, owned by a security or engineering governance function. Its natural home is an organization managing many applications, including outsourced and legacy ones, where the question is which of these forty systems deserves attention rather than what is wrong with this pull request. It suits governance reporting more than fast developer feedback, though IDE plugins exist for per-developer scanning.
Strengths
- Coverage of legacy enterprise languages including COBOL, ABAP and RPG, which very few modern scanners attempt.
- Security and technical debt in one model, useful when arguing for remediation budget on the basis of total cost rather than risk alone.
- Local analyzer keeps source code on your infrastructure while still using a hosted console.
- Portfolio-level trend reporting is built for managing many applications rather than one.
Limitations
- Depth on modern web and cloud-native stacks is less impressive than its legacy coverage, and specialist scanners find more in those ecosystems.
- Effort and debt estimates are model-driven approximations that should be treated as relative signals, not as project plans.
- Feedback cycle is oriented to scheduled portfolio scans rather than fast per-commit gating.
Who it suits
A sensible choice for enterprises and public sector organizations with mixed legacy and modern portfolios, particularly where outsourced development needs to be measured against a contractual quality and security bar. A small product team shipping a single modern stack several times a day will find the governance orientation heavier than they need.
Used Kiuwan Code Security? Recommend it under your own name and title.
Recommend this tool