Mission-critical, custom-built applications are becoming incredibly difficult to adapt to the ever-evolving needs of the business, to the point where it’s hardly possible for humans to keep up. CAST technology automatically ‘understands’ custom-built software systems and provides insights into their inner workings, with MRI-like precision. It augments the human capacity to help software owners maintain, enhance, modernize these applications with speed and confidence. Resulting from well over $200 million of R&D, CAST software is used and promoted by hundreds of companies, top management consultancies, the 10 largest system integrators, and all three major cloud vendors.
Do You Manage Peer Insights at CAST?
Access Vendor Portal to update and manage your profile.
1. provides valuable insights on software architecture 2. visibility on component dependency is good 3. easy integration with new applications
the dashboards and the possibility to see the problems in the code with suggestion on how to solve them
In recent versions, CAST has added Industry Standards including multiple recent versions CWE and OWASP. Grouping the Security Violations according to Industry Standards is a vast improvement to previous versions that tied only to their proprietary groupings.
1. integration with project management tool like Jira could be useful. 2. performance in browser is sometime slow, maybe when number of object is big. 3. Ui could be improved.
lack of plugin for integration in the pipeline
Out-of-the box CAST AIP excludes ALL 3rd party packages from the analysis. It provides analysis feedback ONLY on your organization's developed code. They do this through a file that states all file paths, internal comments, etc that would identify the code as a 3rd party package. While this is an OK practice to highlight only the issues within the developers direct control, it gives an incorrect representation of the Security Risks for the deployed application. The Security Profile of a deployed application MUST include ALL risks within ALL deployed code to be meaningful. CAST does not provide this out-of-the-box. Also of note - the analysis is Static Code Analysis Only. There is no Dynamic Analysis.