Checkmarx is an enterprise
application security company headquartered in Atlanta, Georgia in the United States.
Founded in 2006, the company provides application security testing (AST) solutions that embed security into every phase of the
software development lifecycle
In software engineering, a software development process is a process of dividing software development work into smaller, parallel, or sequential steps or sub-processes to improve design, product management. It is also known as a software deve ...
(SDLC), an approach to
software testing
Software testing is the act of examining the artifacts and the behavior of the software under test by validation and verification. Software testing can also provide an objective, independent view of the software to allow the business to apprecia ...
known as "shift everywhere."
History
Checkmarx was founded in 2006 by Maty Siman, the company's CTO, and Emmanuel Benzaquen, former CEO (2006 – 2023), and has over 900 employees.
Sandeep Johri has been serving as the CEO since February of 2023. The application security platform was designed for CISOs, AppSec managers, security advisors, and software developers.
On July 17, 2017, Checkmarx acquired Codebashing and started offering it as a service to help developers learn secure coding practices with gamified modules in their chosen programming language. In 2018, it also acquired Custodela, a company that provides software security program development as well as consulting services.
Checkmarx was acquired in April 2020 by Hellman & Friedman, a private equity firm with headquarters in San Francisco.
In August 2021, Checkmarx acquired Dustico, a software that detects backdoors and malicious attacks in the software supply chain.
In 2021, the company launched Checkmarx One, a cloud-native Enterprise Application Security platform, which became its most known product. It offers enterprises a full suite of application security testing tools to enable DevSecOps, including
static application security testing (SAST),
dynamic application security testing (DAST),
Software Composition Analysis (SCA),
supply chain security
__NOTOC__
Supply chain security (also "supply-chain security") activities aim to enhance the security of the supply chain or value chain, the transport and logistics systems for the world's cargo and to "facilitate legitimate trade".Government o ...
(SCS),
API security, container security, infrastructure as code security (KICS),
as well as CheckMarx Codebashing.
Checkmarx One also offers Checkmarx Fusion, a scan correlation engine (83% of scans are currently cross-correlated in Checkmarx One deployments) and CheckAI.
In January 2022, the company launched AppSec Program Maturity Assessment (APMA), a service that helps users determine the exact phase of the AppSec program and the required steps to complete it. In the same month, Checkmarx Optimizer was also launched, which helps reduce application security testing alert fatigue.
On May 31, 2023, Checkmarx introduced CheckAI, the first set of GenAI solutions to help accelerate AppSec. It includes the AI Query Builder for SAST and IaC Security. In addition, in July 13, 2023, Checkmarx launched a plugin that helps users secure their code generated by GenAI, such as ChatGPT.
Application Security Research
Checkmarx's research department is known for uncovering technical vulnerabilities in popular technologies, software, applications, and
IoT
The Internet of things (IoT) describes physical objects (or groups of such objects) with sensors, processing ability, software and other technologies that connect and exchange data with other devices and systems over the Internet or other com ...
devices.
In November 2019, the company's security research team uncovered a number of vulnerabilities affecting Google and Samsung smartphones. The vulnerabilities allowed an attacker to take remote control of smartphone apps, giving them the ability to take photos, record video and conversations, and identify the phone's location. The research team submitted a report to the Android security team at Google and continued to provide feedback as the vulnerabilities were addressed.
In January 2020, Checkmarx detailed multiple security vulnerabilities with the Trifo Ironpie robot vacuum. The company has also uncovered issues with Amazon Alexa,
Meetup,
and Tinder,
among others.
In August 2022, Checkmarx researchers found vulnerabilities in the Ring Android app, which could have allowed malicious applications to be installed on the user's phone to expose personal data, geolocation, and camera recordings. The same year, Checkmarx uncovered malicious activity from the LofyGang and RED-LILI.
In the first half of 2023, Checkmarx supply chain research team detected several open-source software supply chain attacks that specifically targeted the banking sector. These attacks showcased advanced techniques, including targeting specific components in web assets of the victim bank by attaching malicious functionalities.
Reception
Gartner
Gartner, Inc is a technological research and consulting firm based in Stamford, Connecticut that conducts research on technology and shares this research both through private consulting as well as executive programs and conferences. Its clients ...
named Checkmarx as a Leader for six consecutive years (2018 to 2023) in Gartner
Magic Quadrant
Magic Quadrant (MQ) is a series of market research reports published by IT consulting firm Gartner that rely on proprietary qualitative data analysis methods to demonstrate market trends, such as direction, maturity and participants.
Their analys ...
for Application Security Testing. It was also recognized by customers on Gartner® Peer Insights™ as a Customers' Choice for Application Security Testing for the fourth consecutive year.
In 2021, Checkmarx won three gold Cybersecurity Global Excellence Awards for 'Software,' 'Application Security,' and 'Best Cybersecurity Company (500-999 employees).' Checkmarx was also named a Strong Performer in The Forrester Wave™: Software Composition Analysis, Q3 2021.
In 2022, Checkmarx earned a Fortress Cyber Security Award.
In 2023, Checkmarx was recognized as market leader in The Forrester Wave™: Static Application Security Testing, Q3 2023 and a Strong Performer in The Forrester Wave™: Software Composition Analysis, Q2 2023. The same year, the Checkmarx One™ Platform received a 2023 DEVIES Award in the DevSecOps category.
Funding
Checkmarx's early investors include
Salesforce
Salesforce, Inc. is an American Cloud computing, cloud-based software company headquartered in San Francisco, California. It provides customer relationship management (CRM) software and applications focused on sales, customer service, marketi ...
, which remains a partner as Checkmarx provides security reviews for the Salesforce AppExchange.
In 2015, U.S. private equity and venture capital firm
Insight Partners
Insight Partners (previously Insight Venture Partners) is an American venture capital and private equity firm based in New York City. The firm invests in growth-stage technology, software and Internet businesses.
History
Insight Partners was ...
acquired Checkmarx for $84 million.
In April 2020, private equity firm
Hellman & Friedman
Hellman & Friedman LLC (H&F) is an American private equity firm, founded in 1984 by Warren Hellman and Tully Friedman, that makes investments primarily through leveraged buyouts as well as growth capital investments. H&F has focused its effort ...
, alongside private investment firm TPG, acquired Checkmarx for $1.15 billion.
After the acquisition, Insight Partners retained a minority interest in the company.
[{{Cite web, last=Novinson, first=Michael, date=2020-06-24, title=The Biggest 10 Cybersecurity Acquisitions Of 2020 (So Far), url=https://www.crn.com/slide-shows/security/the-biggest-10-cybersecurity-acquisitions-of-2020-so-far-/8, access-date=2020-09-04, website=CRN]
See also
*
Security testing
References
Software companies established in 2006
Software companies of Israel
Computer security software
Computer security software companies
Static program analysis tools
Software testing tools