Black Duck
Black Duck is an AI-powered application security company providing SAST, SCA, DAST, IAST, and agentic AI security tools through its Polaris Platform. The company serves 4,000+ organizations across financial services, automotive, healthcare, government, and embedded software verticals globally.
- Company typePrivate
- Founded2002
- HeadquartersBurlington, United States
- Headcount1,001–5,000
- GTM typeB2B
- OfferingSoftware
What Black Duck does
Black Duck is an AI-powered application security company that provides a comprehensive portfolio of testing tools for proprietary code, open source components, and AI-generated code. The company's core offering is the Polaris Platform, a cloud-native SaaS solution that unifies static analysis (Coverity), software composition analysis (Black Duck SCA), dynamic analysis (Continuous Dynamic), and interactive analysis (Seeker), supplemented by protocol fuzzing (Defensics), application security posture management (Software Risk Manager), and an IDE plug-in (Code Sight). Underpinning the portfolio is ContextAI, a proprietary security-specific model trained on 20+ years of human-validated intelligence from the Black Duck KnowledgeBase, and Black Duck Signal, an agentic AI solution for autonomous vulnerability detection and remediation that integrates with GitHub Copilot, Claude Code, Cursor, and Google Gemini.
The company serves 4,000+ organizations across verticals including financial services, automotive, healthcare, medical devices, public sector, and embedded software, with named customers such as Finra, DHS, Honeywell, Ceva, Trend Micro, Broad Institute, CGI, FPT Software, and Genetec. Black Duck has been recognized as a Gartner Magic Quadrant Leader for Application Security Testing for eight consecutive years and as a Leader in the inaugural 2026 Magic Quadrant for Software Supply Chain Security. The product portfolio supports compliance with SOC 2, FedRAMP, GDPR, HIPAA, PCI DSS, ISO 27001/27002, NIST SP 800-53, NIST CSF, the EU Cyber Resilience Act, ISO/SAE 21434, and frameworks such as OWASP, MISRA, CERT, CWE, and OpenChain.
Black Duck was founded in 2002 and acquired by Synopsys in 2017, becoming the Synopsys Software Integrity Group. In October 2024, Synopsys sold the business unit to private equity firms Clearlake Capital Group and Francisco Partners, establishing Black Duck as an independent company headquartered in Burlington, Massachusetts. Revenue is generated through annual and multi-year subscription licensing for SaaS, on-premises, and hybrid deployments, supplemented by professional services including BSIMM assessments, open source audits, and program strategy consulting. Distribution is global, spanning direct enterprise field sales, VARs, system integrators, and MSSPs, with government procurement supported through the GSA MAS IT schedule.
Black Duck firmographics
Firmographics- Name
- Black Duck
- Legal name
- Black Duck Software, Inc.
- Website
- https://blackduck.com
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 1,001–5,000 employees
- Short description
- Black Duck is an AI-powered application security company providing SAST, SCA, DAST, IAST, and agentic AI security tools through its Polaris Platform. The company serves 4,000+ organizations across financial services, automotive, healthcare, government, and embedded software verticals globally.
- Ownership category
- akta.pro rank
Black Duck industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Software Publishers (5132), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- App Security, Compliance & Review Automation Platforms (BPAMADAJ)
- akta.pro secondary industries
- AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage) (HDAAAKAG), Model Testing, Validation & Quality Assurance (HDAAABAH), Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE)
Keywords
Where Black Duck is headquartered
LocationHeadquarters
- HQ city
- Burlington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Black Duck business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Subscription/SaaS Licensing: Annual and multi-year subscription licensing for cloud-native SaaS platform (Polaris), on-premises deployments (Coverity, Black Duck SCA), and hybrid environments. Subscription model provides continuous updates, support, and access to security intelligence.
- Professional Services: Implementation, deployment, training, and advisory services including BSIMM assessments, Maturity Action Planning, open source software audits, and program strategy consulting.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription licensing |
Go-to-market motion1 record
Distribution channels8 records
Marketing channels7 records
Black Duck product offering
Product offeringCore offering
Black Duck sells an AI-powered application security testing portfolio, delivered primarily through its cloud-native Polaris Platform, that unifies SAST, SCA, DAST, IAST, protocol fuzzing, and ASPM capabilities. Its proprietary ContextAI model and 20+ year KnowledgeBase power agentic AI analysis (Black Duck Signal) to detect, validate, and remediate vulnerabilities in proprietary code, open source components, and AI-generated code. The portfolio is sold via subscription SaaS, on-premises, and hybrid licensing to enterprise customers, supplemented by professional services for audits, BSIMM assessments, implementation, and program strategy.
Product overview
Black Duck is an AI-powered application security company offering a comprehensive portfolio of application security testing solutions. The portfolio centers on the Black Duck Polaris Platform, a unified SaaS solution that integrates SAST, SCA, DAST, and AI-powered analysis capabilities. Key products include Black Duck Signal for agentic AI application security, Coverity Static Analysis for SAST, Black Duck SCA for software composition analysis, and the Code Sight IDE Plug-in with Black Duck Assist AI assistant. ContextAI serves as the proprietary model powering all AI capabilities. Additional products cover Dynamic Analysis (Continuous Dynamic), Interactive Analysis (Seeker), Protocol Fuzzing (Defensics), and Application Security Posture Management (Software Risk Manager). The company also provides CLI tools (Detect, Bridge) and the KnowledgeBase for vulnerability intelligence. Together, these tools enable organizations to secure proprietary code, open source components, and AI-generated code across the entire software development lifecycle.
Differentiator
Problem solved
Functional benefit
Brands
- Polaris: Integrated SaaS Application Security and Risk Management platform.
- Black Duck Signal
- Coverity
- Black Duck SCA
- Continuous Dynamic
- Seeker
- Defensics
- Software Risk Manager
- Code Sight
- Black Duck Assist
- ContextAI
Products and services
- Black Duck Polaris Platform Integrated SaaS Application Security and Risk Management platform that unifies SAST, SCA, and DAST capabilities into a single cloud-native solution with AI-driven DevSecOps features, risk prioritization, and policy control.
- Black Duck Signal Agentic AI application security solution that uses ContextAI to analyze code, assess risk, validate findings, and automate remediation at AI speed in autonomous development workflows.
- Coverity Static Analysis Market-leading SAST solution performing deep source code examination across 20+ programming languages and 70+ frameworks to detect critical quality defects affecting reliability, maintainability, and performance.
- Black Duck SCA Software Composition Analysis solution providing complete visibility into open source and third-party components, SBOM generation and management, and continuous monitoring against the Black Duck KnowledgeBase.
- Continuous Dynamic Dynamic Application Security Testing (DAST) solution that automatically scans new functionalities and runs deeper on-demand tests to identify vulnerabilities in web applications before and after deployment.
- Seeker Interactive Interactive Application Security Testing (IAST) solution providing visibility into web application security posture and identifying vulnerability trends against compliance standards.
- Defensics Protocol Fuzzing Protocol fuzzing solution that generates automated tests to discover vulnerabilities in software by testing with malformed or random inputs.
- Software Risk Manager Application Security Posture Management (ASPM) solution that standardizes security risk management across the enterprise with unified policies and compliance reporting.
- Code Sight IDE Plug-in IDE-integrated security analysis plug-in for Visual Studio, IntelliJ IDEA, and VS Code that brings real-time security feedback directly into developer workflows.
- Open Source and Security Audits Professional services offering comprehensive open source software audits for license compliance, security assessment, and IP risk evaluation, often used for M&A due diligence.
- Program Strategy and Planning Professional services for software security program strategy and planning, including BSIMM assessments, Maturity Action Planning, and program consulting.
- Implementation and Deployment Professional services for implementation and deployment of Black Duck solutions across customer environments.
- Customer Success and Support Customer success and support services for Black Duck customers using the Polaris Platform and other products.
Quantifiable outcome
- Mean vulnerabilities per codebase doubled 107% year-over-year (2026 OSSRA)
- +5 more outcomes
Companies that use Black Duck
Customer profileNamed customers10 records
Segments8 records
Ideal customer profiles4 records
Black Duck technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration18 records
AI capability8 records
Feature7 records
Black Duck partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core.
- AccenturecoreManaged Security Service Provider (MSSP) agreement where Accenture's Application Security Practice standardized on Black Duck Polaris Platform. Accenture delivers comprehensive security solutions to clients worldwide combining Black Duck technology with Accenture's global reach. Accenture gains ability to resell Black Duck solutions and provide on-premises deployments backed by advisory services.
- NowSecurecorePartnership offering continuous automated mobile app security testing software bridging gap between manual and pen testing. Provides rapid automated static, dynamic, interactive, and API security analysis of Android (.apk/.aab) and iOS (.ipa) binaries on real devices, enabling full-coverage assessments completed in minutes.
- Secure Code WarriorcoreSecure Code Warrior delivers impactful security training for DevSecOps with interactive eLearning and hands-on labs. Enhances developers' secure coding capabilities to fix issues detected by Black Duck's portfolio and preclude new issues directly at developer desktop.
- AWS (Amazon Web Services)coreTechnology alliance enabling customers to use secure, cloud-native applications developed with AWS CI/CD tools and deployed on AWS infrastructure.
- GitHubcoreIntegration partnership securing code stored in GitHub and built/tested using GitHub Actions. Black Duck Security GitHub App enables automated security scanning.
- MicrosoftcoreIntegration partnership using Black Duck AppSec tools with Microsoft application development solutions from Visual Studio to Azure DevOps.
- Google CloudcorePartnership bringing security to Google serverless CI/CD platform and applications deployed on Google Cloud infrastructure.
Scale indicators9 records
Recent moves7 records
Expansion highlights5 records
Black Duck competitors and assessment
Company assessmentDirect peers
- Sonar (SonarQube/SonarCloud): Sonar provides code quality and SAST tools used by developers and enterprises for static analysis and security detection. It competes with Black Duck's Coverity SAST and Code Sight IDE plug-in offerings.
- Veracode: Veracode provides SAST, DAST, SCA, and application security posture management to large enterprises. It competes head-to-head with Black Duck's Polaris suite and Coverity SAST in regulated and Fortune 500 accounts.
- Mend (formerly WhiteSource): Mend provides software composition analysis, SAST, and supply chain security for open source and AI-generated code. It overlaps directly with Black Duck SCA, Black Duck Signal, and supply chain offerings.
- Snyk: Snyk is a developer security platform offering SAST, SCA, container, and IaC scanning aimed at the same enterprise and developer-base customers as Black Duck. It is the most-cited direct competitor in the AppSec testing category.
- Contrast Security: Contrast Security offers IAST, RASP, and SAST solutions targeting modern application and API security. It is a direct competitor to Black Duck's Seeker IAST and broader AppSec portfolio.
- Checkmarx: Checkmarx offers SAST, SCA, IaC security, and application security posture management for enterprise development teams. It is a long-standing direct competitor to Black Duck/Coverity across application security testing.
Broad incumbents
- GitLab: GitLab is a broad DevSecOps platform that bundles SAST, SCA, DAST, and container security natively into its CI/CD and source code management product. It is a broad incumbent competing for the same AppSec budget, especially among platform-led buyers.
- Palo Alto Networks (Prisma Cloud / Code to Cloud): Palo Alto Networks bundles SAST, SCA, IaC, and runtime security into its broader Prisma Cloud and code-to-cloud platform. It is a large incumbent competing for enterprise AppSec and supply chain security spend alongside Black Duck.
- JFrog: JFrog provides artifact management and software supply chain security (including SCA via JFrog Xray) as part of its broader binary/DevOps platform. It overlaps with Black Duck's supply chain, SCA, and SBOM offerings.
Emerging players
- Cycode: Cycode provides application security posture management (ASPM), SAST, SCA, and secrets detection with a focus on pipeline-native security. It competes with Black Duck Software Risk Manager and broader Polaris capabilities.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Black Duck social profiles
Digital presenceBlack Duck compliance and trust
Trust signalCompliance16 records
Black Duck financial estimates
Financial estimateRevenue estimate
Valuation estimate
Black Duck leadership team
Management profileNumber of profiles
Profiles4 records
Black Duck funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Black Duck M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Black Duck
What does Black Duck do?
Black Duck sells an AI-powered application security testing portfolio, delivered primarily through its cloud-native Polaris Platform, that unifies SAST, SCA, DAST, IAST, protocol fuzzing, and ASPM capabilities. Its proprietary ContextAI model and 20+ year KnowledgeBase power agentic AI analysis (Black Duck Signal) to detect, validate, and remediate vulnerabilities in proprietary code, open source components, and AI-generated code. The portfolio is sold via subscription SaaS, on-premises, and hybrid licensing to enterprise customers, supplemented by professional services for audits, BSIMM assessments, implementation, and program strategy.
Is Black Duck a public or private company?
Black Duck is a private company. It is classified as private equity controlled and is currently operating.
When was Black Duck founded?
Black Duck was founded in 2002. It employs 1,001 to 5,000 people.
Where is Black Duck based?
Black Duck is headquartered in Burlington, United States, in the North America region.
How does Black Duck make money?
Two revenue lines are on record. Subscription/SaaS Licensing is the primary driver. The others are professional Services.
Who are Black Duck's main competitors?
Direct peers on record are Sonar (SonarQube/SonarCloud), Veracode, Mend (formerly WhiteSource), Snyk, Contrast Security and Checkmarx. Broad incumbents are GitLab, Palo Alto Networks (Prisma Cloud / Code to Cloud) and JFrog. Cycode is listed as an emerging player.
Does Black Duck have an API?
Yes. Black Duck provides an API-first architecture enabling custom integrations with issue-tracking systems, CI/CD platforms, and other tools. The company offers CLI tools including Black Duck Detect CLI and Black Duck Bridge CLI for triggering scans. The platform integrates via REST APIs and webhooks. Developer documentation is at docs.blackduck.com.
What industry is Black Duck in?
Black Duck's product category is Application Security Testing. Its primary akta.pro industry code is BPAMADAJ, App Security, Compliance & Review Automation Platforms, with a secondary code of HDAAAKAG, AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage). Its NAICS code is 5132 and its SIC code is 8734.