BlackDuck
Black Duck Software provides application security testing and software supply chain security software to over 4,000 enterprise organizations globally, offering SAST, SCA, DAST, and IAST through its Polaris Platform and standalone products, serving automotive, financial services, healthcare, and government sectors.
- Company typePrivate
- Founded2024
- HeadquartersBurlington, United States
- Headcount5,001–10,000
- GTM typeB2B
- OfferingSoftware
What BlackDuck does
Black Duck Software, Inc., headquartered in Burlington, Massachusetts, is an application security testing and software supply chain security company serving more than 4,000 enterprise organizations globally across automotive, financial services, healthcare, government, embedded software, and technology sectors. The company was carved out of Synopsys in October 2024 when Clearlake Capital and Francisco Partners acquired Synopsys' Software Integrity Group for up to $2.1 billion and re-established it as an independent, PE-backed entity operating under the Black Duck brand.
Its core product is the Black Duck Polaris Platform, a cloud-native SaaS application security platform that unifies SAST, SCA, and DAST under a single subscription. This platform is extended by standalone flagship products including Coverity Static Analysis (SAST across 20+ languages and 70+ frameworks), Black Duck SCA (open source and third-party component visibility with automated SBOM generation), Continuous Dynamic (DAST), Seeker Interactive (IAST), Defensics Protocol Fuzzing, and Software Risk Manager (ASPM). The portfolio is further extended by developer-facing add-ons including the Code Sight IDE Plug-in, Black Duck Assist (generative AI assistant), Black Duck Detect CLI and Bridge CLI, Polaris fAST Static and Dynamic, and AI Model Risk Insights. AI capabilities are anchored by ContextAI, a proprietary model trained on 20+ years of human-validated security intelligence, and by Black Duck Signal, an agentic AI application security product launched in March 2026 to secure AI-generated code in autonomous development workflows.
Black Duck generates revenue through four streams: SaaS subscriptions on the Polaris Platform (primary), on-premises licenses for customers with data-residency or regulatory requirements, professional services (implementation, customer success, audits, program strategy), and channel/reseller revenue through MSSPs and system integrators led by the Accenture agreement signed in February 2026. Pricing is quote-based and not publicly disclosed; deployment models span cloud SaaS, on-premises, and hybrid. The company sells through direct enterprise field sales for large accounts, self-serve SaaS for mid-market and developer-led adoption, and a global channel partner ecosystem, and it operates with 5,001-10,000 employees.
BlackDuck firmographics
Firmographics- Name
- BlackDuck
- Legal name
- Black Duck Software, Inc.
- Website
- https://blackducksoftware.com
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 5,001–10,000 employees
- Short description
- Black Duck Software provides application security testing and software supply chain security software to over 4,000 enterprise organizations globally, offering SAST, SCA, DAST, and IAST through its Polaris Platform and standalone products, serving automotive, financial services, healthcare, and government sectors.
- Ownership category
- akta.pro rank
BlackDuck industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Security Systems Services (56162)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), App Security, Compliance & Review Automation Platforms (BPAMADAJ)
Keywords
Where BlackDuck is headquartered
LocationHeadquarters
- HQ city
- Burlington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
BlackDuck business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Subscription (Polaris Platform): Cloud-native SaaS deployment providing immediate access, continuous updates, and elastic scalability with subscription-based pricing. The Polaris Platform is offered as a comprehensive application security testing solution unified under a single SaaS subscription.
- On-Premises Licenses: For customers with stringent data residency requirements, highly sensitive intellectual property, or specific regulatory mandates, Black Duck provides comprehensive on-premises deployment options including Coverity Static Analysis deployed on-premises.
- Professional Services: Implementation & Deployment services, Customer Success & Support, Open Source & Security Audits, Program Strategy & Planning. The Accenture MSSP agreement establishes Accenture will deliver enterprise-grade application security services worldwide using the Black Duck Polaris Platform.
- Channel/Reseller Revenue: Partners including Accenture gain rights to resell Black Duck solutions, creating channel revenue streams through the MSSP agreement and other reseller relationships.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise SaaS subscription with unified SAST, SCA, and DAST capabilities |
Go-to-market motion4 records
Distribution channels6 records
Marketing channels9 records
BlackDuck product offering
Product offeringCore offering
Black Duck provides application security testing solutions including Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) through its cloud-native Polaris SaaS Platform, alongside standalone products such as Coverity Static Analysis, Black Duck SCA, Continuous Dynamic, Seeker Interactive, and Defensics Protocol Fuzzing. The portfolio is extended by Black Duck Signal for AI-generated code security, the proprietary ContextAI model, and Code Sight IDE integration, enabling customers to identify vulnerabilities, manage open source license compliance, and secure software supply chains across the SDLC.
Product overview
Black Duck is an independent application security company that was formerly the Synopsys Software Integrity Group, acquired by Clearlake Capital and Francisco Partners in October 2024. The company offers True Scale Application Security through a unified platform-plus-modules architecture centered on the Black Duck Polaris Platform (a SaaS platform consolidating SAST, SCA, and DAST), alongside standalone flagship products including Coverity Static Analysis (SAST), Black Duck SCA (SCA), Continuous Dynamic (DAST), Seeker Interactive (IAST), and Defensics Protocol Fuzzing. The portfolio is extended by Black Duck Signal (agentic AI application security), Black Duck Assist (AI-powered IDE assistant), ContextAI (proprietary AI model), and Code Sight IDE Plug-in. This comprehensive suite enables organizations to secure proprietary code, open source components, third-party dependencies, and AI-generated code across the entire software development life cycle, integrating into DevSecOps pipelines through native CI/CD plugins, REST APIs, and IDE integrations.
Differentiator
Problem solved
Functional benefit
Products and services
- Black Duck Polaris Platform
Quantifiable outcome
- 65% of organizations experienced software supply chain attack in past year, underscoring need for Black Duck's supply chain security solutions
- +6 more outcomes
Companies that use BlackDuck
Customer profileNamed customers16 records
Segments7 records
Ideal customer profiles5 records
BlackDuck technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability8 records
Feature9 records
BlackDuck partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- AccenturecoreBlack Duck announced a managed security service provider (MSSP) agreement with Accenture, under which Accenture's Application Security Practice will standardize on the Black Duck Polaris Platform to deliver enterprise-grade application security services worldwide. Accenture gains rights to resell Black Duck solutions, combining the company's AI-powered security technology with Accenture's global consulting and security services expertise.
Scale indicators9 records
Recent moves7 records
Expansion highlights7 records
BlackDuck competitors and assessment
Company assessmentDirect peers
- Snyk: Snyk is a developer-first security platform offering SAST, SCA, container, and IaC scanning. It directly competes with Black Duck's Polaris Platform and Coverity/Coverage offerings, targeting the same developer and AppSec buyer across mid-market and enterprise.
- Veracode: Veracode is a long-standing AppSec testing vendor offering SAST, DAST, SCA, and manual penetration testing as a cloud-based platform. It competes head-to-head with Black Duck across enterprise AppSec programs and was historically a peer to Synopsys SIG.
- Checkmarx: Checkmarx provides enterprise application security testing (SAST, SCA, IAST, API security) and competes directly with Black Duck's Coverity SAST and Polaris Platform for large regulated organizations.
- Sonar (SonarQube): Sonar provides code quality and SAST (SonarQube, SonarCloud) targeting developer workflows. It overlaps with Black Duck's Coverity SAST and Code Sight IDE plugin on code-level quality and security scanning for developers.
- Mend (formerly WhiteSource): Mend is an SCA specialist focused on open source security and license compliance, directly comparable to Black Duck SCA's SBOM, vulnerability, and license-conflict capabilities.
- Contrast Security: Contrast Security pioneered IAST and runtime application security, directly comparable to Black Duck's Seeker Interactive product and ASPM offerings for enterprise AppSec teams.
Broad incumbents
- GitHub Advanced Security: GitHub Advanced Security bundles Code Scanning (SAST), Dependabot (SCA), and secret scanning natively into GitHub, competing as a broad incumbent platform with embedded distribution that pressures Black Duck's standalone developer integrations.
- JFrog: JFrog offers software supply chain security (JFrog Xray, JFrog Advanced Security) alongside its artifact repository platform. It competes with Black Duck in SCA, SBOM, and supply-chain security, with broader DevOps portfolio reach.
- Synopsys: Synopsys divested the Software Integrity Group to form Black Duck and continues to operate in adjacent EDA and IP businesses. As the former parent, Synopsys retains some customer overlap and competing product lines that may continue to bundle AppSec as part of broader design tool deals.
- Palo Alto Networks (Prisma Cloud): Palo Alto Networks Prisma Cloud delivers cloud-native application protection including SAST, SCA, and runtime security at platform scale. It competes as a broad incumbent in enterprise cloud security, increasingly overlapping with Black Duck's cloud and DevSecOps positioning.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
BlackDuck social profiles
Digital presenceBlackDuck compliance and trust
Trust signalCompliance12 records
BlackDuck financial estimates
Financial estimateRevenue estimate
Valuation estimate
BlackDuck leadership team
Management profileNumber of profiles
Profiles6 records
BlackDuck funding detail
Funding detailFunding overview
Funding rounds12 records
Investors15 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
BlackDuck M&A and investment
M&A and investmentM&A4 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about BlackDuck
What does BlackDuck do?
Black Duck provides application security testing solutions including Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) through its cloud-native Polaris SaaS Platform, alongside standalone products such as Coverity Static Analysis, Black Duck SCA, Continuous Dynamic, Seeker Interactive, and Defensics Protocol Fuzzing. The portfolio is extended by Black Duck Signal for AI-generated code security, the proprietary ContextAI model, and Code Sight IDE integration, enabling customers to identify vulnerabilities, manage open source license compliance, and secure software supply chains across the SDLC.
Is BlackDuck a public or private company?
BlackDuck is a private company. It is classified as private equity controlled and is currently operating.
When was BlackDuck founded?
BlackDuck was founded in 2024. It employs 5,001 to 10,000 people.
Where is BlackDuck based?
BlackDuck is headquartered in Burlington, United States, in the North America region.
How does BlackDuck make money?
Four revenue lines are on record. SaaS Subscription (Polaris Platform) is the primary driver. The others are on-Premises Licenses, professional Services and channel/Reseller Revenue.
Who are BlackDuck's main competitors?
Direct peers on record are Snyk, Veracode, Checkmarx, Sonar (SonarQube), Mend (formerly WhiteSource) and Contrast Security. Broad incumbents are GitHub Advanced Security, JFrog, Synopsys and Palo Alto Networks (Prisma Cloud).
Does BlackDuck have an API?
Yes. Black Duck provides an API-first architecture that facilitates custom integrations with issue-tracking systems like Jira, container registries, and infrastructure-as-code platforms. The API enables automated security across the software development life cycle, allowing customers to configure comprehensive SAST, DAST, IAST, or SCA scans on code commits, pull requests, or scheduled builds.
What industry is BlackDuck in?
BlackDuck's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 56162 and its SIC code is 7373.