Checkmarx
Checkmarx provides an AI-powered application security platform — Checkmarx One — combining SAST, SCA, DAST, IaC, secrets, API, and ASPM capabilities with agentic AI agents, serving 1,800+ enterprise customers including 40% of the Fortune 100 as a Palo Alto Networks subsidiary.
- Company typePrivate
- Founded2006
- HeadquartersAtlanta, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingSoftware
What Checkmarx does
Checkmarx is an application security software vendor founded in 2006 in Israel and headquartered in Tel Aviv, operating today as a strategic subsidiary of Palo Alto Networks following its March 2024 acquisition. The company's flagship product is Checkmarx One, a unified AI-powered application security platform that combines hybrid static analysis (deterministic rules plus a purpose-tuned LLM), dynamic testing, software composition analysis, infrastructure-as-code scanning, secrets detection, API security, and container security, with all signals correlated through an Application Security Posture Management (ASPM) layer. Platform modules include NG SAST, DAST, SCA, API Security, Secrets Detection, IaC Security, Container Security, KICS (open-source IaC scanner), and Malicious Package Protection backed by a proprietary database of 420,000+ malicious packages continuously updated by the Checkmarx Zero research team. Newer agentic capabilities — Developer Assist, Triage Assist, Remediation Assist, AI-BOM, AI Supply Chain Security, and the Checkmarx MCP Server — extend the platform into AI-generated code governance and AI-native developer workflows across Cursor, Windsurf, AWS Kiro, and GitHub Copilot. The company holds FedRAMP High Impact Level authorization, ISO 27001, SOC 2 Type II, and ACN Level 2 certifications.
Checkmarx serves more than 1,800 enterprise customers across 70 countries, including 40% of the Fortune 100 and 860+ of the world's largest enterprises, with named customers spanning Best Buy, Software AG, Cebu Pacific, Citibank, Cisco, Accenture, and Wipro. Revenue is generated primarily through subscription-based enterprise agreements on Checkmarx One, supplemented by professional services, training (Codebashing), and managed offerings, with Checkmarx One surpassing $150M in annual recurring revenue within three years under CEO Sandeep Johri and posting more than 30% ARR growth year-to-date as of September 30, 2025. Distribution combines enterprise field sales, a global channel of resellers/VARs/GSIs/MSSPs, and Carahsoft as Master Government Aggregator for U.S. public-sector deals under NASA SEWP V, E&I Cooperative Services, and The Quilt contracts. The company has raised approximately $98.5M in venture funding from Insight Venture Partners, Salesforce Ventures, and Francisco Partners prior to the Palo Alto Networks acquisition, and continues to execute inorganic growth via acquisitions including Tromzo (December 2025, AI-native autonomous security agents), Dustico (August 2021, supply-chain attack detection), Custodela (2018), and Codebashing (2017).
Checkmarx firmographics
Firmographics- Name
- Checkmarx
- Legal name
- Checkmarx Ltd.
- Website
- https://checkmarx.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- Checkmarx provides an AI-powered application security platform — Checkmarx One — combining SAST, SCA, DAST, IaC, secrets, API, and ASPM capabilities with agentic AI agents, serving 1,800+ enterprise customers including 40% of the Fortune 100 as a Palo Alto Networks subsidiary.
- Ownership category
- akta.pro rank
Checkmarx industry classification
Industry- Product category
- Application Security Software
- NAICS
- Security Systems Services (except Locksmiths) (561621), Testing Laboratories and Services (541380), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where Checkmarx is headquartered
LocationHeadquarters
- HQ city
- Atlanta
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Checkmarx business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Checkmarx One Platform Subscription: Checkmarx operates on a subscription/SaaS model for its Checkmarx One platform, with enterprise agreements and per-seat or tiered organizational licensing. The platform has surpassed $150M ARR within three years under current leadership, indicating strong recurring revenue from enterprise subscriptions.
- Professional Services & Support: Premium services including expert-led security programs, training, certifications, managed services, and technical support plans complement the core platform subscription.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Checkmarx One Enterprise Edition with FedRAMP High authorization |
| Subscription | Annual | Platform add-ons and module expansion |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels7 records
Checkmarx product offering
Product offeringCore offering
Checkmarx sells the Checkmarx One platform, an agentic AI application security testing suite that combines hybrid static scanning (deterministic rules plus purpose-tuned LLM), dynamic analysis, software composition analysis, IaC scanning, secrets detection, API security, container security, and AI supply chain governance under a unified Application Security Posture Management (ASPM) risk view. The company also offers autonomous AI security agents (Developer Assist, Triage Assist, Remediation Assist), an MCP Server for AI-native access, and Codebashing developer secure-code training.
Product overview
Checkmarx offers Checkmarx One, a unified AI-powered application security platform combining hybrid scanning engines with autonomous AI agents. The platform includes core products for SAST (NG SAST), DAST, SCA, API Security, Secrets Detection, IaC Security, Container Security, and Repository Health. AI-powered add-ons include Developer Assist and Triage & Remediation Assist agents, ASPM for unified risk intelligence, AI-BOM for AI component governance, AI Supply Chain Security, Checkmarx MCP Server for AI-native access, and SBOM generation. The portfolio is available as cloud-native Checkmarx One or on-premises CxSAST, with Codebashing for developer training.
Differentiator
Problem solved
Functional benefit
Brands
- Checkmarx One: The unified AI-powered application security platform providing every surface with one correlated risk view.
- Checkmarx Assist
- Checkmarx Zero
- KICS
Products and services
- Checkmarx One Unified AI-powered application security platform providing hybrid scanning, AI-powered agents, and unified risk intelligence across code, supply chain, AI components, and runtime.
- NG SAST Next-generation static application security testing with hybrid scanning engine combining deterministic rules-based analysis with AI-powered analysis, covering 75+ languages with the highest F1 score in category.
- SCA (Software Composition Analysis) Software Composition Analysis identifying, prioritizing, and remediating open-source risk including vulnerabilities, malicious code, and license compliance issues with transitive dependency scanning.
- DAST for AI Dynamic Application Security Testing simulating real-world exploits against running applications and APIs, validating exploitability that static analysis alone cannot detect, including DAST for AI workloads.
- API Security API discovery and security solution that scans source code and documentation to identify shadow and zombie APIs, correlating SAST and DAST findings for comprehensive API risk visibility.
- Secrets Detection Secret detection scanner covering 170+ secret types, scanning source code, Git history, CI/CD pipelines, and IDE in real-time with pre-commit prevention and policy enforcement.
- IaC Security Infrastructure as Code security scanning for Terraform, Kubernetes, Helm, CloudFormation and other IaC frameworks, providing real-time misconfiguration detection and policy-as-code enforcement.
- Container Security Container image security scanning and configuration analysis for Docker and Kubernetes environments, validating build artifacts and detecting vulnerabilities in container layers.
- Malicious Package Protection Supply chain security protecting against malicious open-source packages using an industry-leading database of 420,000+ malicious packages with continuous registry monitoring and automated policy actions.
- Developer Assist IDE-native agentic AI security assistant that continuously scans, explains, and fixes vulnerabilities in human and AI-generated code before they reach the repository.
- Triage & Remediation Assist Autonomous AI agents that perform intelligent vulnerability triage using Attackability analysis and deliver merge-ready remediation fixes directly inside pull requests.
- ASPM (Application Security Posture Management) Application Security Posture Management providing unified risk intelligence and governance, correlating signals from all scanners into a prioritized risk view with exploitability-based scoring.
- AI Supply Chain Security Comprehensive AI component governance discovering LLMs, agents, MCP servers, and AI SDKs while assessing security risks and enforcing compliance across the AI-driven development lifecycle.
- AI-BOM (AI Bill of Materials) AI Bill of Materials providing deterministic, auditable visibility into every AI component across the SDLC, mapping AI assets against NIST AI RMF, EU AI Act, and ISO 42001 compliance requirements.
- Checkmarx MCP Server Model Context Protocol server providing AI-native access to Checkmarx One security capabilities, enabling AI assistants and agents to retrieve scan results, query findings, and act on results from any MCP-compatible environment.
- Repository Health Code repository security assessment ensuring repository configurations, access controls, and supply chain integrity meet enterprise security standards.
- SBOM (Software Bill of Materials) Software Bill of Materials generation, sharing, ingestion and management in industry-standard formats for component inventory and regulatory compliance.
- CxSAST (On-Premises) On-premises SAST solution for organizations requiring on-premise deployment, using the same scanning engine as Checkmarx One.
- Codebashing Developer secure code training platform providing interactive security education to build secure coding skills across development teams.
Quantifiable outcome
- F1 score of 0.64 — 3x the industry average of 0.20
- +7 more outcomes
Companies that use Checkmarx
Customer profileNamed customers7 records
Segments5 records
Ideal customer profiles5 records
Checkmarx technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration37 records
AI capability9 records
Feature10 records
Checkmarx partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and strategic.
- Palo Alto NetworkscorePalo Alto Networks acquired Checkmarx in March 2024 according to market research reports, integrating Checkmarx's application security capabilities into Palo Alto Networks' broader cybersecurity portfolio.
- Carahsoft Technology Corp.coreCarahsoft designated as Checkmarx's Master Government Aggregator to distribute Checkmarx's application security solutions to the U.S. public sector. Solutions distributed through Carahsoft's network of reseller partners via NASA SEWP V, E&I Cooperative Services Contract, and The Quilt contracts. Partnership aims to help government agencies integrate security throughout the software development lifecycle.
- EquixlystrategicEquixly partnership brings continuous API penetration testing and business logic validation to Checkmarx One customers. The integration combines Checkmarx's static code analysis with Equixly's agentic AI-powered offensive security platform, enabling autonomous testing of APIs and application workflows. Reflects broader industry shift toward proactive, continuous offensive security testing.
- ArchipelostrategicTechnical partnership correlating Checkmarx's application vulnerability findings with development-origin context within software delivery workflows. Integration combines Checkmarx's AppSec and ASPM capabilities with Archipelo's Developer Security Posture Management, enabling organizations to trace vulnerabilities back to developer identity, AI-assisted coding conditions, and workflow metadata.
- CredShieldsstrategicCredShields, a Web3 security firm, partnered with Checkmarx to integrate blockchain security tools and expertise into Checkmarx's enterprise platform. Collaboration aims to enhance security for tokenized assets, decentralized applications, and smart contracts. Focus on developing standards and integrating Web3 security into enterprise risk management.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Checkmarx competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first application security platform offering SAST, SCA, IaC, and container security. Most direct competitor to Checkmarx in the modern AppSec category, with overlapping target buyers (enterprise developers) and a comparable product breadth across code-to-cloud security.
- Veracode: Enterprise SAST/DAST/SCA platform serving large organizations with strong AppSec program management capabilities. Closest peer in the traditional enterprise AppSec segment, competing head-to-head for Fortune 500 deals.
- GitHub Advanced Security: Bundled code-scanning, secret-scanning, and dependency-review capabilities integrated into GitHub. Increasingly a direct competitor given native integration into the dominant enterprise source-control platform and bundled pricing economics.
- Synopsys Software Integrity (now Black Duck): Enterprise application security testing portfolio spanning SAST, SCA, fuzzing, and DAST. Long-standing direct competitor to Checkmarx across Fortune 500 AppSec deals, with comparable breadth of static and dynamic analysis capabilities.
- Sonar (SonarQube/SonarCloud): Code quality and security platform with SAST, secrets detection, and IaC scanning across 30+ languages. Competes directly in the developer-first AppSec segment with both open-source and enterprise editions, often displacing standalone SAST at the team level.
- JFrog: Software supply chain security platform with Xray SCA and runtime container security. Direct peer in the software supply chain and malicious-package protection categories where Checkmarx's Malicious Package Protection competes.
- Mend (formerly WhiteSource): SCA-focused application security vendor with growing SAST and supply-chain capabilities. Direct competitor in open-source dependency scanning and license-compliance use cases that overlap with Checkmarx's SCA portfolio.
Emerging players
- Semgrep: Open-source and managed SAST platform popular with developer teams; strong adoption in cloud-native engineering organizations and a credible lower-cost challenger that pressures Checkmarx at the mid-market and developer-led adoption layer.
- Contrast Security: IAST/RASP platform providing runtime-instrumented application security with code-level vulnerability visibility. Adjacent competitor in the AppSec segment, often considered alongside Checkmarx in modern enterprise AppSec stack evaluations.
Broad incumbents
- GitLab: DevSecOps platform bundling SAST, DAST, dependency, container, and IaC scanning into the CI/CD platform. Competes as a one-stop DevSecOps alternative for enterprises preferring single-vendor platform consolidation over best-of-breed AppSec point tools.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Checkmarx social profiles
Digital presenceCheckmarx compliance and trust
Trust signalCompliance4 records
Checkmarx financial estimates
Financial estimateRevenue estimate
Valuation estimate
Checkmarx leadership team
Management profileNumber of profiles
Profiles16 records
Checkmarx subsidiaries and ownership
Company hierarchySubsidiaries2 records
Checkmarx funding detail
Funding detailFunding overview
Funding rounds5 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Checkmarx M&A and investment
M&A and investmentM&A4 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Checkmarx
What does Checkmarx do?
Checkmarx sells the Checkmarx One platform, an agentic AI application security testing suite that combines hybrid static scanning (deterministic rules plus purpose-tuned LLM), dynamic analysis, software composition analysis, IaC scanning, secrets detection, API security, container security, and AI supply chain governance under a unified Application Security Posture Management (ASPM) risk view. The company also offers autonomous AI security agents (Developer Assist, Triage Assist, Remediation Assist), an MCP Server for AI-native access, and Codebashing developer secure-code training.
Is Checkmarx a public or private company?
Checkmarx is a private company. It is classified as corporate owned and is currently operating.
When was Checkmarx founded?
Checkmarx was founded in 2006. It employs 501 to 1,000 people.
Where is Checkmarx based?
Checkmarx is headquartered in Atlanta, United States, in the North America region.
How does Checkmarx make money?
Two revenue lines are on record. Checkmarx One Platform Subscription is the primary driver. The others are professional Services & Support.
Who are Checkmarx's main competitors?
Direct peers on record are Snyk, Veracode, GitHub Advanced Security, Synopsys Software Integrity (now Black Duck), Sonar (SonarQube/SonarCloud), JFrog and Mend (formerly WhiteSource). Emerging players are Semgrep and Contrast Security. GitLab is listed as a broad incumbent.
Does Checkmarx have an API?
Yes. Checkmarx provides comprehensive REST APIs and SARIF-based data exchange supporting any security tool in the ecosystem. The platform offers developer-friendly APIs for integrations, enabling organizations to build custom integrations. Additionally, Checkmarx MCP provides a standardized, AI-native interface for immediate, plug-and-play access across all environments without building or maintaining custom integrations. Developer documentation is at docs.checkmarx.com.
What industry is Checkmarx in?
Checkmarx's product category is Application Security Software. Its primary akta.pro industry code is BPAMADAJ, App Security, Compliance & Review Automation Platforms. Its NAICS code is 561621 and its SIC code is 7371.