Modern software delivery moves at accelerating speed, increasing pressure to ship applications quickly while the “deperimeterization” of corporate networks and pervasive internet exposure expand the attack surface. In this context, software security becomes critical, and the most proactive stance is to reduce vulnerabilities at development time rather than relying solely on downstream defenses. Because manual source code review is tedious and error-prone, organizations need automated tools that detect and help remediate issues across the entire software development life cycle.
Checkmarx is a privately held application security vendor founded in 2006 and headquartered in Ramat Gan, Israel, focused on automated code review that identifies technical and logical vulnerabilities. The company has expanded from its original static analysis roots into a broader “Software Exposure” discipline that aims to cover the full attack surface across software types (applications, APIs, firmware, services) and development phases. The Checkmarx Software Exposure Platform combines tools, integrations, managed services, and training to help organizations detect, prioritize, and mitigate software risk, including risks arising from third-party open source components, process weaknesses, and developer skill gaps. Deployment can be on-premises or in public cloud, with access via web console and IDE integrations (Visual Studio, Eclipse, IntelliJ IDEA).
Core components include CxSAST for scanning uncompiled source directly (supporting 25+ languages) with incremental scanning that can cut analysis time up to 80%, rich metadata, remediation guidance, and suppression of recurring false positives. CxAudit and CxQL enable custom queries for advanced and business-logic detections. CxOSA extends analysis to open source vulnerabilities and licensing compliance, partnering with WhiteSource and enabling policies to block risky libraries. CxIAST detects runtime issues during testing via an agent, supporting Java, .NET, and Node.js, and covering 40+ vulnerability types with minimal test-cycle impact. Unified orchestration correlates results to reduce false positives, while CxCodebashing and AppSec Accelerator support skills and DevSecOps transformation.
See All Locations
See All Locations