Checkmarx Application Security Platform
October 19, 2021

Checkmarx announced the launch of the Checkmarx Application Security Platform to help CISOs, AppSec teams, and developers address the growing and dynamic security challenges they face.

With groundbreaking capabilities, the platform integrates into any workflow or tool, delivering security with the speed, scale, and flexibility to support the latest development requirements. It seamlessly works with all modern frameworks and development infrastructures through webhook integrations, a standard set of APIs, or command line interface.

Offering one-click scanning across many critical components of the application code, the platform provides the most complete, accurate, and actionable intelligence to remediate vulnerabilities early in the development life cycle. One click triggers a comprehensive scan to examine source code, third-party open-source libraries, API contracts, and infrastructure as code (IaC) templates. Results are aggregated, verified, and augmented with expert remediation advice to benefit security leaders, AppSec teams, and developers alike.

Through direct integration with Checkmarx Codebashing, the company’s developer education solution, the platform provides on-demand training to enable extensive code security, reduce human error, and enable organizations to build security into their processes and technologies as part of the application development life cycle.

Delivered as software as a service, the AppSec Platform tightly incorporates security into development while eliminating infrastructure management overhead as well as providing continuous updates and functional enhancements. Foundational services—such as metering, monitoring, access, and user experience—simplify administration of all applications, services, and deployment. In addition, the platform allows third parties to develop using platform services and APIs with a common experience and virtualized services that would otherwise vary across clouds.

“Software development drives business innovation, serving as an enabler and differentiator across all industries. However, software is becoming more complex, causing security and development teams to struggle with the fast pace and immense risk it can bring an organization,” said Razi Sharir, CPO at Checkmarx. “With the Checkmarx Application Security Platform, we are enabling secure software development across the business, giving security and AppSec teams visibility into all aspects of application code. This new integrated solution replaces multiple complex point products with a single platform that delivers actionable, accurate results, allowing developers to code boldly and quickly without sacrificing security.”

Committed to bringing security and development together through industry-leading products and services, Checkmarx has also pledged to continue contributing to these communities through education and open source projects like the IaC scanning project KICS.

“Checkmarx is a strong advocate for providing free tools and education to foster secure innovation across the community,” said Sharir. “KICS was just a starting point. We have some big announcements in the beginning of next year, as we work toward our goal of contributing back to the security and developer communities.”

Today’s CISOs face significant challenges, including managing a broad security scope, adhering to evolving global compliance requirements, effectively reporting security progress to the board, and mitigating the risk of internal and external threats. As the pace of application development increases, application security becomes a heightened priority as well.

Through the AppSec Platform, Checkmarx allows CISOs and their security teams to stay ahead of application security vulnerabilities, maintaining the deepest visibility across cloud-based components and architectures, such as containers, APIs, IaC, microservices, and more. The platform features a single dashboard that provides a unified view of all risk insights, including those from complex third-party code, reducing resolution time while increasing visibility and productivity. By integrating with all modern development infrastructure, it provides security professionals with flexibility while reducing their tool fatigue.

Nearly half (46%) of developers are expected to build and deploy software more quickly today than before the pandemic. This speed to market translates to business impact, with the McKinsey Developer Velocity Index finding that companies that achieved increased developer velocity in the top quartile saw revenue growth five times faster than organizations in the bottom quartile. To meet these increasing demands and deliver exceptional applications, development teams need a solution that seamlessly integrates with their existing workflows.

Checkmarx enables developers to easily build secure code from start to finish while accelerating development. Vulnerability detection occurs earlier in the development cycle, with the platform providing expert advice on how to quickly remediate risks. Whether through cloud native applications or on-premises deployment, it enables developers to integrate security in their coding environments from the start, allowing for full management of risks throughout development, even after the code is deployed. Teams can write code securely and confidently, providing significant market benefits for their organizations.

The Checkmarx Application Security Platform includes industry-leading SAST, SCA, Codebashing, and KICS application security services.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.