Code Dx
Code Dx is a software vulnerability management and security analytics tool, now part of Black Duck's application security testing platform. It serves 4,000+ enterprises across government, defense, financial services, healthcare, and automotive with SAST, SCA, DAST, IAST, and AI-powered security analysis.
- Company typePrivate
- Founded2015
- HeadquartersNorthport, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Code Dx does
Code Dx is a software vulnerability management and security analytics tool founded in 2013 and headquartered in Northport, United States. The company originated as a vulnerability correlation and management platform and received early-stage funding from DataTribe, including a $2 million round in November 2019. Leadership comprises Anita D'Amico (CEO and Founder), Ken Prole (CTO), and Utsav Sanghani (Director, Product Management). Code Dx operates with 11-50 employees and was integrated into the broader Synopsys Software Integrity Group (SIG), which was subsequently divested in October 2024 by Synopsys to private equity firms Clearlake Capital Group and Francisco Partners and rebranded as Black Duck.
Within the Black Duck platform, Code Dx sits inside a comprehensive application security testing portfolio that unifies static analysis (SAST), software composition analysis (SCA), dynamic analysis (DAST), interactive analysis (IAST), and AI-powered analysis. The platform is delivered through the cloud-native Black Duck Polaris SaaS platform, on-premises deployments, and hybrid configurations, with enterprise field sales as the primary go-to-market and a developer-led adoption motion via the Code Sight IDE plug-in across Visual Studio, IntelliJ IDEA, and VS Code. Revenue is generated through subscription-based SaaS and on-premises licensing on annual and multi-year contracts, supplemented by professional services for implementation, deployment, and security program strategy, plus training and certification via Black Duck Academy. Customers include over 4,000 organizations across regulated verticals including government, defense, financial services, healthcare, automotive, telecommunications, and embedded systems.
The technical foundation rests on the proprietary Black Duck KnowledgeBase, which encodes 20+ years of human-validated security intelligence and feeds the ContextAI model and the agentic Black Duck Signal application security solution. The platform supports compliance with ISO 27001, GDPR, HIPAA, PCI DSS, NIST, FedRAMP, the EU Cyber Resilience Act, and supports SBOM generation and management across the software supply chain. Recent analyst recognition includes eight consecutive years as a Gartner Magic Quadrant Leader for Application Security Testing (highest for Ability to Execute in 2025) and Leader in the inaugural 2025 Gartner MQ for Software Supply Chain Security.
Code Dx firmographics
Firmographics- Name
- Code Dx
- Legal name
- Black Duck Software, Inc.
- Website
- https://codedx.com
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Code Dx is a software vulnerability management and security analytics tool, now part of Black Duck's application security testing platform. It serves 4,000+ enterprises across government, defense, financial services, healthcare, and automotive with SAST, SCA, DAST, IAST, and AI-powered security analysis.
- Ownership category
- akta.pro rank
Code Dx industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where Code Dx is headquartered
LocationHeadquarters
- HQ city
- Northport
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Code Dx business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Software Security Testing Solutions: Subscription-based SaaS and on-premises licensing for application security testing solutions including SAST, SCA, DAST, IAST, and AI-powered security tools. Revenue generated through annual or multi-year contracts with enterprise customers. Deployment flexibility (cloud, on-premises, hybrid) enables various pricing structures.
- Professional Services: Implementation and deployment services, security program strategy and planning, and customer success services. One-time and recurring service engagements complement the core software offerings.
- Training and Education: Black Duck Academy provides product education and certification programs for customers and users.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise pricing with deployment flexibility |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
Code Dx product offering
Product offeringCore offering
Code Dx is a software vulnerability management and security analytics tool. It operates within the application security testing domain, providing solutions that combine SAST, SCA, DAST, IAST, and AI-powered analysis to help organizations identify and remediate vulnerabilities across the software development lifecycle. The offering supports deployment via cloud-native SaaS, on-premises, and hybrid models, and is targeted at enterprise customers across regulated industries.
Product overview
Black Duck is a comprehensive application security testing company offering a platform-plus-modules architecture. The core offering is the Black Duck Polaris Platform, a unified SaaS solution integrating SAST, SCA, DAST, and AI-powered analysis. The product portfolio includes standalone offerings like Coverity Static Analysis (on-premises SAST), Black Duck SCA for open source management, and Seeker Interactive (IAST). Agentic AI capabilities are delivered through Black Duck Signal and ContextAI model. Developer-integrated tools include Code Sight IDE Plug-in with Black Duck Assist. The portfolio addresses the full software development lifecycle with deployment flexibility across cloud-native SaaS, on-premises, and hybrid environments.
Differentiator
Problem solved
Functional benefit
Brands
- Black Duck Polaris Platform: Cloud-native unified application security platform that consolidates SAST, SCA, and DAST into a single SaaS solution
- Black Duck Signal
- ContextAI
- Coverity Static Analysis
- Black Duck SCA
- Black Duck Code Sight
- Black Duck Assist
- Black Duck Detect
- Black Duck Bridge
Products and services
- Black Duck Polaris Platform Integrated SaaS Application Security and Risk Management platform that unifies SAST, SCA, DAST, and AI-powered analysis. Provides risk prioritization, policy control, and unified vulnerability management from a single cloud-native platform for enterprise security and development teams.
- Black Duck Signal Agentic AI Application Security for AI-powered software development. Eliminates noise and AI hallucinations with agentic AppSec backed by decades of security intelligence for enterprise security and development teams.
- Coverity Static Analysis SAST solution performing deep source code examination across more than 20 programming languages and 70+ frameworks. Detects critical quality defects impacting software reliability, maintainability, and performance for enterprise development teams.
- Black Duck SCA Software Composition Analysis solution providing visibility into open source and third-party components. Generates and manages Software Bills of Materials (SBOMs), tracks dependencies, and monitors for security vulnerabilities for enterprise development and compliance teams.
- Continuous Dynamic DAST solution that automatically scans new functionalities and runs deeper on-demand tests. Identifies vulnerabilities in APIs and web applications before and after deployment for enterprise security teams.
- Seeker Interactive Interactive Application Security Testing (IAST) providing unparalleled visibility into web application security posture and identifying vulnerability trends against compliance standards for enterprise security teams.
- Defensics Protocol Fuzzing Protocol fuzzing solution for identifying vulnerabilities in APIs and protocols before deployment, used by enterprise security teams to uncover hard-to-find defects through automated malformed-input testing.
- Software Risk Manager Application Security Posture Management (ASPM) solution for centralizing application security testing, policy enforcement, and vulnerability management for enterprise security programs.
Quantifiable outcome
- 65% of organizations reported experiencing a software supply chain attack in the past year - driving demand for comprehensive SCA solutions
- +2 more outcomes
Companies that use Code Dx
Customer profileNamed customers12 records
Segments6 records
Ideal customer profiles3 records
Code Dx technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
AI capability8 records
Feature10 records
Code Dx partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and strategic.
- JenkinscoreNative integration with Jenkins CI/CD platform for automated security scanning on code commits, pull requests, or scheduled builds.
- Azure DevOpscoreNative integration with Azure DevOps for automated security testing within Microsoft-centric development environments.
- GitHubcoreIntegration with GitHub SCM enabling event-driven automation, continuous discovery of new branches and repos, and pull request-based security scanning.
- GitLabcoreIntegration with GitLab SCM for security scanning and continuous security monitoring in GitLab CI/CD pipelines.
- BitbucketcoreIntegration with Bitbucket SCM for security scanning and automation within Atlassian-based development environments.
- GitHub ActionscoreNative CI/CD integration with GitHub Actions for automated security scanning in GitHub-hosted development workflows.
- Visual StudiocoreCode Sight IDE Plug-in integrates into Visual Studio for real-time security analysis directly in the development environment.
- IntelliJ IDEAcoreCode Sight IDE Plug-in integrates into IntelliJ IDEA for real-time security analysis in JetBrains-based development environments.
- VS CodecoreCode Sight IDE Plug-in integrates into Visual Studio Code for real-time security analysis in Microsoft's popular code editor.
- JiracoreAPI-first architecture enables custom integrations with issue-tracking systems like Jira for vulnerability management workflows.
- FPT SoftwarestrategicStrategic implementation partner providing application security services. FPT Software's Chief Delivery Officer publicly endorsed Black Duck AST tools for enterprises, especially those specializing in embedded systems.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Code Dx competitors and assessment
Company assessmentDirect peers
- Snyk: Developer-first security platform offering SAST, SCA, container security, and IaC scanning. Most direct competitor to Black Duck's Polaris platform with comparable enterprise reach but stronger developer mindshare and PLG motion.
- Veracode: Long-standing application security testing vendor (SAST, DAST, SCA) serving large enterprise customers in financial services and regulated industries. Direct competitor in the same Gartner Magic Quadrant and similar customer overlap.
- Checkmarx: Enterprise application security platform specializing in SAST and SCA with deep code analysis capabilities. Competes directly with Black Duck in the same enterprise AppSec deals and is named in the same Gartner MQ.
- Sonar (SonarQube): Code quality and security analysis platform with SonarQube (open source) and SonarCloud/SonarLint commercial offerings. Overlaps with Black Duck's SAST and developer-integrated security, particularly in shift-left and IDE-based detection.
- Mend (formerly WhiteSource): Software composition analysis and application security platform focused on open source security, license compliance, and SBOM. Direct peer in SCA, a category in which Black Duck's legacy brand originated.
- Contrast Security: Interactive application security testing (IAST) and runtime application self-protection (RASP) vendor. Direct peer to Black Duck's Seeker IAST offering with comparable deployment model in web application security.
Broad incumbents
- GitHub Advanced Security: Microsoft-owned integrated security features (CodeQL SAST, Dependabot SCA, secret scanning) bundled into GitHub Enterprise. A formidable broad incumbent that pressures standalone AST pricing by including security for free or low cost within the developer platform.
- OpenText Fortify: Enterprise application security suite (Fortify SAST, SCA) acquired from Micro Focus by OpenText. Broad incumbent in the same Gartner MQ with a strong on-premises installed base competing against Black Duck's Polaris SaaS in regulated industries.
Emerging players
- Semgrep: Fast-growing code security platform with strong open-source community positioning (Semgrep OSS) and an enterprise tier. Direct emerging competitor to Black Duck's SAST, especially attractive to developer-led security teams.
- Cycode: Software supply chain security and ASPM platform with a focus on code-to-cloud visibility, SBOM, and pipeline security. Emerging competitor in the same Gartner MQ for Software Supply Chain Security where Black Duck was named a Leader in 2025.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Code Dx social profiles
Digital presenceCode Dx compliance and trust
Trust signalCompliance9 records
Code Dx financial estimates
Financial estimateRevenue estimate
Valuation estimate
Code Dx leadership team
Management profileNumber of profiles
Profiles3 records
Code Dx funding detail
Funding detailFunding overview
Funding rounds2 records
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Code Dx M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Code Dx
What does Code Dx do?
Code Dx is a software vulnerability management and security analytics tool. It operates within the application security testing domain, providing solutions that combine SAST, SCA, DAST, IAST, and AI-powered analysis to help organizations identify and remediate vulnerabilities across the software development lifecycle. The offering supports deployment via cloud-native SaaS, on-premises, and hybrid models, and is targeted at enterprise customers across regulated industries.
Is Code Dx a public or private company?
Code Dx is a private company. It is classified as venture growth investor backed and is currently operating.
When was Code Dx founded?
Code Dx was founded in 2015. It employs 11 to 50 people.
Where is Code Dx based?
Code Dx is headquartered in Northport, United States, in the North America region.
How does Code Dx make money?
Three revenue lines are on record. Software Security Testing Solutions are the primary driver. The others are professional Services and training and Education.
Who are Code Dx's main competitors?
Direct peers on record are Snyk, Veracode, Checkmarx, Sonar (SonarQube), Mend (formerly WhiteSource) and Contrast Security. Broad incumbents are GitHub Advanced Security and OpenText Fortify. Emerging players are Semgrep and Cycode.
Does Code Dx have an API?
Yes. Black Duck's API-first architecture enables custom integrations with issue-tracking systems, container registries, and infrastructure-as-code platforms. Integration typically begins with Black Duck Detect or Black Duck Bridge CLI, which can be configured to automatically trigger comprehensive SAST, DAST, IAST, or SCA scans on code commits, pull requests, or scheduled builds. Developer documentation is at docs.blackduck.com.
What industry is Code Dx in?
Code Dx's product category is Application Security Testing. Its primary akta.pro industry code is BPAKAHAJ, Application Security & DevSecOps Services. Its NAICS code is 54151 and its SIC code is 7372.