The ability for us as an organization is that we can quickly identify any security risks with our applications through their platform without having someone come in from another department or vendor just because they are more familiar/trained at it! It's not perfect but I don't think there really IS anything else out here like this so far anyway (at least nothing worth mentioning).
We have had no issues thusfar using them since implementing about 3 years ago - all of which were identified before implementation due primarily being PCI DSS requirements prioritizations etc..