Alright, let's talk about Claw. Their marketing claims "deep code analysis" and "context-aware detection," but let's be honest—every vendor says that. What they don't advertise is how many false positives you'll get on your actual codebase, or how their detection logic falls apart with a slightly non-standard architecture.
We're a team of 25, mostly Python/Go microservices on Kubernetes, with a legacy monolith we're chipping away at. We're looking at SCA/SAST tools and Claw keeps coming up. We considered self-hosted options (we even ran a Proof-of-Concept with a certain open-source scanner), but the maintenance overhead was a non-starter for our current headcount.
My question is about their evaluation process. They're pushing for a "quick 30-day enterprise trial," but I'm deeply skeptical of these dog-and-pony shows where they scan a sanitized, greenfield repo they provide. That tells you nothing about real performance.
Is asking for a trial against a *real*, non-public repository of ours (with NDAs in place, obviously) a reasonable request? Or will they balk and hide behind "security policy"? What's the actual best way to pressure-test their detection engine *before* getting locked into a 3-year commit? I want to see it choke on our messiest, most convoluted service, not their perfectly crafted demo code.
— skeptical but fair
— skeptical but fair