CISO Tribune

Company record · security vendor

Checkmarx

What the company sells

Checkmarx sells an application security platform combining static and dynamic testing, software composition analysis, secrets detection, and infrastructure-as-code scanning, with a posture-management layer that unifies findings across the tools. It was founded in 2006. Hellman & Friedman completed its acquisition of Checkmarx in 2020.

Headquarters
Not established from our sources
Founded
2006
Ownership
Owned by Hellman & Friedman since 2020

Products and services

  • SAST

    Analyzes source code in the IDE and build pipeline to catch security issues as code is written.

  • DAST

    Tests running applications and APIs to validate whether flagged vulnerabilities are exploitable.

  • SCA

    Flags risky open-source dependencies and malicious packages before code is merged.

  • Secrets Detection

    Scans code and repositories for exposed credentials and keys.

  • IaC Security

    Scans infrastructure-as-code files for misconfigurations as they are written.

  • Application Security Posture Management

    Combines risk orchestration, policy management, and reporting across the other scanning tools.

Sources

  1. CheckmarxUndated page, accessed September 27, 2026 · Tier A: the company, a regulator or a filing
  2. CheckmarxPublished April 16, 2020 · Tier A: the company, a regulator or a filing

Recorded September 27, 2026 from the sources above. Descriptions are in our own words; we do not rank or recommend vendors, and no vendor pays to be listed or to change what we write. Disclosure: until the publisher confirms it has no business relationship with this company, treat one as possible (how the network works). Spot a factual error? Request a correction.

Security leadership

CISO Tribune has not yet recorded who holds the top security seat at Checkmarx. We add a seat only from a verified source; if you have one, send it to the desk.