Skip to content
Checkmarx logo

Checkmarx

Comprehensive static and interactive application security testing for enterprise-scale code security.

Venture Funded$143MSeries EInsight PartnersSapphire VenturesM12 (Microsoft’s venture fund)
application securitystatic code analysisDevSecOpscompliance
Share:

About

Checkmarx delivers enterprise-grade application security testing solutions that integrate seamlessly into DevOps pipelines, enabling organizations to identify and remediate vulnerabilities early.

This description came from a bulk import and has not yet been checked against the vendor's own page. Treat it as unverified.

Enterprise Readiness

from cataloged data

Not scored. Nobody has checked this entry against Checkmarx’s own site yet, so the signals below are unverified and we will not turn them into a rating. The breakdown shows what our record holds.

Security & ComplianceNot disclosed

No compliance certifications listed

Deployment FlexibilityStrong

Flexible deployment: Cloud, On-Premise, Hybrid, Self-Hosted

Integration DepthStrong

8 documented integrations

Proven AdoptionPartial

6 documented use cases

Company MaturityStrong

Founded 2006 · Series E

Composite of public compliance, deployment, integration, adoption, and company signals. “Not disclosed” reflects gaps in available data, not a vendor deficiency.

Independently sourced

Pulled directly from regulator filings and platform APIs. No vendor or editorial input.

Enterprise Use Cases

Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
Interactive Application Security Testing (IAST)
DevSecOps pipeline integration
Compliance auditing and reporting
Vulnerability management and remediation

Integrations

JenkinsGitHubGitLabAzure DevOpsJIRASlackSonarQubeFortify

How Checkmarx compares

ToolReadinessPricingDeploymentComplianceIntegrations
CheckmarxNot scoredEnterpriseCloud, On-Premise, Hybrid, Self-Hosted8
SnykNot scoredFreemiumCloud, On-Premise, Hybrid8
Snyk Code70 · StrongFreemiumCloud, On-Premise, Hybrid8
Endor Labs69 · StrongEnterpriseCloud, On-Premise, Hybrid, Self-Hosted8

Peers from the same category, ranked by Enterprise Readiness. Readiness is a composite of cataloged compliance, deployment, integration, adoption, and company signals.

Frequently Asked Questions

What is Checkmarx used for?

Checkmarx is comprehensive static and interactive application security testing for enterprise-scale code security. It is commonly used for static application security testing (sast), software composition analysis (sca), interactive application security testing (iast), and devsecops pipeline integration.

Is Checkmarx free, and how is it priced?

Checkmarx uses enterprise pricing, typically a custom quote based on seats, usage, and requirements. Contact the vendor for a quote.

How can Checkmarx be deployed?

Checkmarx supports Cloud, On-Premise, Hybrid, and Self-Hosted deployment. On-premise and self-hosted options support data-residency and air-gapped requirements.

What does Checkmarx integrate with?

Checkmarx documents 8 integrations, including Jenkins, GitHub, GitLab, Azure DevOps, JIRA, and Slack.

When was Checkmarx founded?

Checkmarx was founded in 2006 and has raised $143M in funding.

Is Checkmarx enterprise-ready?

Based on cataloged data, Checkmarx has an Enterprise Readiness score of 73/100 (Strong tier), derived from its compliance, deployment, integration, adoption, and company-maturity signals.

Quick Facts

PricingEnterprise
DeploymentCloud, On-Premise, Hybrid, Self-Hosted
Founded2006
Funding$143M

Procurement

Evaluating vendors like this one?

The Enterprise AI RFI/RFP asks the security, governance, and lock-in questions sales decks skip.

See the template — RFI $299 / RFP $699

Is this your product?

Claiming is free and lets you correct your listing's data. Upgrade to Enhanced ($199/yr) for a vendor-maintained mark, a richer profile, and lead routing.

·

Alternatives to Checkmarx

View all →

Comparable Code & Development tools, ranked by enterprise readiness.

Snyk logo

Snyk

snyk.io

Developer-first security platform to secure code, dependencies, and infrastructure at scale

Funded$450M+AccelTiger Global
application securityvulnerability managementDevSecOpsopen source security
Freemium5.7k
CloudOn-Prem
Snyk Code logo

Snyk Code

snyk.io/product/snyk-code/

Snyk Code is a static application security testing (SAST) solution that helps developers find, prioritize, and auto-fix code issues.

Funded$450M+AccelTiger Global
static analysisapplication securitydeveloper-firstcompliance
Freemium5.7k
CloudOn-Prem
Endor Labs logo

Endor Labs

www.endorlabs.com/

AURI helps agents write secure code from the start and governs the actions they take.

Funded$7.3MVertex VenturesOurCrowd
automated code reviewCI/CD integrationsoftware qualitysecurity compliance
Enterprise
OSSCloudOn-Prem
Moderne AI logo

Moderne AI

moderne.io

Enterprise-grade AI-powered code review for scalable, secure software delivery.

Funded$15MAmplify PartnersSusa Ventures
AI-powered code reviewCI/CD integrationcode qualitysecurity compliance
EnterpriseDormant
OSSCloudOn-Prem
DeepCode logo

DeepCode

snyk.io/platform/deepcode-ai/

AI technology that powers application security testing tools in the Snyk platform

Funded$17MEarlybird Venture CapitalRedalpine Venture Partners
AI code reviewsecurity analysisCI/CD integrationscalable development
Freemium5.7k
CloudOn-Prem
Veracode Static Analysis logo

Veracode Static Analysis

veracode.com/products/binary-static-analysis

Static Application Security Testing (SAST) solution that scans source code and binaries for security vulnerabilities.

Acquired
static analysisapplication securityDevSecOpscompliance
Enterprise7.1k
OSSCloudOn-Prem