CodeSecure
CodeSecure, now part of the AdaCore group following a 2025 merger, provides CodeSonar static analysis tools for C/C++ application security testing. It serves safety-critical and security-critical software developers across avionics, defense, medical, automotive, and other regulated industries through enterprise subscription licensing.
- Company typePrivate
- Founded1988
- HeadquartersBethesda, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What CodeSecure does
CodeSecure was an application security testing company that merged with AdaCore in 2025 and now operates as a subsidiary brand within the AdaCore group. Its primary product, CodeSonar, is a static analysis tool that identifies defects, security vulnerabilities, and code quality issues in C/C++ and other enterprise languages. The combined entity serves safety-critical and security-critical software development customers across regulated verticals including avionics, automotive, defense, medical devices, rail, security, and space, where certifications such as DO-178C, ISO 26262, IEC 62304, and EN 50128 govern development tool qualification.
CodeSecure firmographics
Firmographics- Name
- CodeSecure
- Legal name
- AdaCore
- Website
- https://codesecure.com
- Company type
- Private
- Founded year
- 1988
- Operating status
- Acquired
- Headcount range
- 51–100 employees
- Short description
- CodeSecure, now part of the AdaCore group following a 2025 merger, provides CodeSonar static analysis tools for C/C++ application security testing. It serves safety-critical and security-critical software developers across avionics, defense, medical, automotive, and other regulated industries through enterprise subscription licensing.
- Ownership category
- akta.pro rank
CodeSecure industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where CodeSecure is headquartered
LocationHeadquarters
- HQ city
- Bethesda
- HQ country
- United States
- HQ region
- North America
Markets served
CodeSecure business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Software Licensing and Support: CodeSecure/AdaCore generates revenue through software licensing of CodeSonar, GNAT Pro, and SPARK Pro tools, along with associated support contracts. The unified GNAT Tracker support portal provides software releases, case management, and documentation access.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise licensing with custom pricing |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
CodeSecure product offering
Product offeringCore offering
CodeSecure develops and sells application security testing and static analysis tools, with CodeSonar as its primary product providing comprehensive static analysis for C/C++ and other enterprise languages. Following the 2025 merger with AdaCore, these capabilities are integrated with AdaCore's broader portfolio of high-integrity software development tools including GNAT Pro compilation toolchain, SPARK Pro formal verification, GNAT Static Analysis for Ada, and the GNAT Dynamic Analysis Suite.
Product overview
CodeSecure was an application security testing company that merged with AdaCore in 2025. It is now part of AdaCore's unified toolchain portfolio. CodeSecure's primary product was CodeSonar, a static analysis tool for C/C++ and enterprise languages, which is now offered as part of AdaCore's static analysis portfolio alongside GNAT Static Analysis for Ada. Together with AdaCore's other offerings—GNAT Pro (compilation toolchain for Ada, C/C++, and Rust), SPARK Pro (formal proof), and GNAT Dynamic Analysis Suite—CodeSecure/CodeSonar extends AdaCore's coverage into application security testing for C/C++ codebases, complementing the existing language-specific analysis tools in the portfolio.
Differentiator
Problem solved
Functional benefit
Brands
- CodeSonar: Application security testing tool for C/C++ and other enterprise languages, now offered as part of AdaCore's static analysis portfolio.
Products and services
- CodeSonar CodeSonar is a static analysis tool for C/C++ and other enterprise languages, used by safety-critical and security-critical industries (avionics, defense, medical, automotive, rail, security, space) to identify defects, security vulnerabilities, and code quality issues through comprehensive static code analysis. It is targeted at enterprise software development teams building safety-critical applications.
Companies that use CodeSecure
Customer profileNamed customers1 record
Segments7 records
Ideal customer profiles1 record
CodeSecure technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
CodeSecure partnerships and signals
Strategic signalScale indicators1 record
Recent moves4 records
Expansion highlights4 records
CodeSecure competitors and assessment
Company assessmentBroad incumbents
- Checkmarx: Checkmarx provides enterprise SAST and application security platforms. While not focused on safety-critical embedded like CodeSecure, it competes for the same application-security budget at large enterprise customers.
- Veracode: Veracode is an enterprise application security platform offering SAST, DAST, SCA, and software composition analysis. It competes with CodeSonar in the broader SAST market, though less specialized in safety-critical embedded.
- Synopsys (Coverity / Black Duck): Synopsys offers Coverity SAST and the Black Duck portfolio as broad-market application security testing platforms. They compete with CodeSecure in static analysis for embedded and safety-critical code while serving a much wider customer base across all software industries.
- GitHub Advanced Security: GitHub Advanced Security (CodeQL, Dependabot, secret scanning) provides SAST tightly integrated with the GitHub developer workflow. It is a major competitive force in enterprise application security and an alternative path for C/C++ security scanning that may displace tools like CodeSonar.
Emerging players
- Sonar (SonarSource): Sonar's SonarQube/SonarCloud platform provides code quality and security analysis for many languages including C/C++. It is a broader-market SAST competitor with growing presence in enterprise DevSecOps pipelines, increasingly overlapping with CodeSonar for general-purpose codebases.
- Snyk: Snyk offers developer-first security testing (SAST, SCA, container, IaC). It targets modern DevSecOps pipelines and competes with CodeSonar on application security scanning, although it does not address safety-critical formal verification.
Regional players
- Vector Informatik: Vector Informatik provides embedded software tools and AUTOSAR solutions for automotive OEMs and suppliers. It overlaps with CodeSecure's automotive (ISO 26262) and embedded safety-critical toolchain offerings, particularly in the European OEM market.
Direct peers
- LDRA: LDRA provides static analysis, dynamic analysis, and unit testing tools specifically for safety-critical embedded software in avionics, automotive, medical, and industrial — overlapping directly with CodeSecure/AdaCore's target verticals and certification-focused value proposition.
- Parasoft: Parasoft offers static analysis, unit testing, and compliance tools (C/C++test, dotTEST) for embedded and safety-critical industries including automotive (ISO 26262), aerospace (DO-178C), and medical (IEC 62304), directly comparable to CodeSecure's certification-mapped offerings.
- GrammaTech (Perforce): GrammaTech's CodeSonar competitor (now under Perforce) provides static analysis for C/C++ focused on safety- and security-critical embedded software, directly overlapping CodeSecure's flagship CodeSonar product in avionics, defense, and automotive.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
CodeSecure social profiles
Digital presenceCodeSecure financial estimates
Financial estimateRevenue estimate
Valuation estimate
CodeSecure leadership team
Management profileNumber of profiles
CodeSecure funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CodeSecure M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CodeSecure
What does CodeSecure do?
CodeSecure develops and sells application security testing and static analysis tools, with CodeSonar as its primary product providing comprehensive static analysis for C/C++ and other enterprise languages. Following the 2025 merger with AdaCore, these capabilities are integrated with AdaCore's broader portfolio of high-integrity software development tools including GNAT Pro compilation toolchain, SPARK Pro formal verification, GNAT Static Analysis for Ada, and the GNAT Dynamic Analysis Suite.
Is CodeSecure a public or private company?
CodeSecure is a private company. It is classified as corporate owned and is currently acquired.
When was CodeSecure founded?
CodeSecure was founded in 1988. It employs 51 to 100 people.
Where is CodeSecure based?
CodeSecure is headquartered in Bethesda, United States, in the North America region.
How does CodeSecure make money?
One revenue line is on record: software Licensing and Support.
Who are CodeSecure's main competitors?
Broad incumbents on record are Checkmarx, Veracode, Synopsys (Coverity / Black Duck) and GitHub Advanced Security. Emerging players are Sonar (SonarSource) and Snyk. Vector Informatik is listed as a regional player. Direct peers are LDRA, Parasoft and GrammaTech (Perforce).
Does CodeSecure have an API?
No public API is recorded for CodeSecure.
What industry is CodeSecure in?
CodeSecure's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA). Its NAICS code is 54151 and its SIC code is 7372.