Thomas G.
TG
Senior DevSecOps Engineer
Enterprise (> 1000 emp.)
"Developer-friendly AppSec with a flexible policy engine"
5/5
What do you like best about Arnica?

I deployed Arnica to replace Checkmarx at a previous company, and I have brought it with me to several startups I support since then. I still use it in my current role, in a somewhat different capacity than the full enterprise program I originally ran.

The policy engine was the primary reason we selected it after evaluating multiple products, since none of the other vendors we tested could offer comparable granularity at the time. It deployed fast across GitHub and Azure DevOps through SCM integration, with no CI rework to start getting value, and our first blocking policy was live within 90 days.

We were able to create granular PR policies on severity, EPSS, finding type, direct versus transitive and prod versus dev dependencies, and package reputation, which let us stage enforcement from annotations into blocking and turn rollout into measurable maturity milestones.

It also strengthened our Security Champions program, since we could empower champions to review dismissals for their own teams. Developer experience improved because people handled findings in code they were already changing instead of years of historical debt.

Customer success has been a genuine strength, responsive and willing to help with rollout, and several requests we raised shipped faster than I expected.

The SBOM explorer experience is also something I personally appreciate, I use it regularly to check exposure across the organizations I support whenever another large supply chain attack hits the news.

My use of the AI review features is still early, more proof of concept than a rollout. I feel positive about the direction, since reviewing AI-generated code is a real challenge and having policy enforcement meet it at the source is the right place to solve it.

On cost, it was priced competitively against the other vendors we evaluated and the per-identity model scaled sensibly as the team grew. Review collected by and hosted on G2.com.

What do you dislike about Arnica?

Dashboard and reporting could be smoother, especially for executive or audit reporting, though I did not find it better in Checkmarx, Snyk, or GitHub Advanced Security. The API was accessible and well-documented enough that our vulnerability management aggregation platform built an integration to it, and we separately pulled findings into our own reporting.

We had some early challenges with SAST rule quality for older, non-web languages, C++ in particular, where SAST quality tends to be inconsistent industry-wide. We worked with Arnica on custom rules and coverage has improved since.

No DAST, which was a lower priority given our focus on pre-production risk, but runtime-heavy teams should weigh that.

The per-identity pricing model also made direct comparison against other vendors trickier, since most of them price differently, and it took some work to walk our finance stakeholders through it before a deal could move forward, though we concluded the pricing was fair once we normalized the comparison. Review collected by and hosted on G2.com.

Response from Anna Daugherty of Arnica

Thank you so much for your feedback, Thomas. We appreciate the detailed review, and are always looking to improve our features and capabilities. We can't wait to share exciting new updates at Arnica with you!

See what 9 reviewers think of Arnica

4.8 out of 5 · Verified reviews from real users

Read all reviews