Company record · security vendor
Checkmarx
What the company sells
Checkmarx sells an application security platform combining static and dynamic testing, software composition analysis, secrets detection, and infrastructure-as-code scanning, with a posture-management layer that unifies findings across the tools. It was founded in 2006. Hellman & Friedman completed its acquisition of Checkmarx in 2020.
- Categories
- Headquarters
- Not established from our sources
- Founded
- 2006
- Ownership
- Owned by Hellman & Friedman since 2020
- Website
- checkmarx.com
Products and services
SAST
Analyzes source code in the IDE and build pipeline to catch security issues as code is written.
DAST
Tests running applications and APIs to validate whether flagged vulnerabilities are exploitable.
SCA
Flags risky open-source dependencies and malicious packages before code is merged.
Secrets Detection
Scans code and repositories for exposed credentials and keys.
IaC Security
Scans infrastructure-as-code files for misconfigurations as they are written.
Application Security Posture Management
Combines risk orchestration, policy management, and reporting across the other scanning tools.
Sources
- CheckmarxUndated page, accessed September 27, 2026 · Tier A: the company, a regulator or a filing
- CheckmarxPublished April 16, 2020 · Tier A: the company, a regulator or a filing
Recorded September 27, 2026 from the sources above. Descriptions are in our own words; we do not rank or recommend vendors, and no vendor pays to be listed or to change what we write. Disclosure: until the publisher confirms it has no business relationship with this company, treat one as possible (how the network works). Spot a factual error? Request a correction.
Security leadership
CISO Tribune has not yet recorded who holds the top security seat at Checkmarx. We add a seat only from a verified source; if you have one, send it to the desk.