Checkmarx / checkmarx.com
AI-powered application security testing platform providing SAST, SCA, DAST, IaC security scanning, and AI-powered code vulnerability detection for DevSecOps teams.
Pricing
Free
Free plan
No
Category
Developer Tools
Platforms
4
Free plan
No
API access
No
Open source
No
Platforms
4
Checkmarx is an enterprise application security testing (AST) platform providing static application security testing (SAST), software composition analysis (SCA), dynamic application security testing (DAST), infrastructure-as-code (IaC) security scanning, and API security — covering the full application security testing spectrum for DevSecOps programmes. AI Guided Remediation is Checkmarx's AI capability — providing AI-generated fix recommendations for identified vulnerabilities, explaining in plain language why a code pattern is vulnerable and what the developer should change. The AI guidance reduces the friction of acting on SAST findings — developers understand what to fix and how rather than receiving opaque vulnerability reports. SAST scans source code for security vulnerabilities — SQL injection, cross-site scripting, path traversal, and hundreds of other vulnerability patterns across 30+ programming languages. SCA identifies open-source components with known CVEs, outdated dependencies, and licence compliance issues. DAST dynamically tests running applications for vulnerabilities that static analysis cannot detect. Checkmarx One is the unified cloud-native platform combining all testing capabilities with developer-centric workflow integration. With customers including Airbnb, Samsung, and Salesforce, Checkmarx validates at internet-scale and enterprise software companies for DevSecOps.
Checkmarx AI runs as llm assistant software built around code and text workflows. Users typically start with a prompt, upload, or connected data source, and the underlying model handles the heavy lifting before returning a result you can refine or export. It's available on web, ide plugins, and ci/cd.
The capabilities that matter most for teams evaluating Checkmarx AI.
AI-generated vulnerability fix recommendations explaining what to change and why — reducing developer friction from opaque SAST reports to actionable fix guidance with code suggestions.
SAST, SCA, DAST, IaC, and API security in one platform — covering all application security testing domains for comprehensive DevSecOps without separate tool management.
Static analysis coverage across polyglot development environments — identifying security vulnerabilities in Java, Python, JavaScript, Go, C#, and 25+ other programming languages.
Enterprise licensing. No public pricing. Annual contracts. Private company (Hellman & Friedman). Demo available.
Model
Enterprise
Starting price
Free
Free trial
Yes
Snyk (covered) provides developer-first SCA and SAST. Veracode (rank 813) provides AST with binary scanning. Semgrep provides lightweight SAST. GitHub Advanced Security provides security scanning within GitHub.
A side-by-side look at the closest alternative in this category.
Key facts about model providers, platforms, and team support.
Model Provider
OpenAI, Checkmarx
Platforms
Web, IDE plugins, CI/CD, API
Deployment
SaaS, On-premise
Integrations
GitHub, GitLab, Jenkins, Azure DevOps, Jira, API
Team Collaboration
Yes
Launch Year
2023
Compliance signals and data-handling notes as reported by the vendor.
SOC 2 Type II. ISO 27001. GDPR compliant. FedRAMP eligible. Enterprise data handling agreements.
Source code and vulnerability scan data processed on Checkmarx cloud or customer on-premise. Code scanning occurs locally in CI/CD pipelines — code transmitted to cloud for reporting and management.
Editorial Verdict
Checkmarx is a leading AI application security platform for DevSecOps teams wanting full-spectrum SAST, SCA, DAST, and IaC scanning with AI-guided vulnerability remediation in one enterprise platform.
Last verified July 24, 2026.
Enterprise licensing. No public pricing. Annual contracts. Private company (Hellman & Friedman). Demo available.
Enterprise licensing. No public pricing. Annual contracts. Privately held (Broadcom subsidiary). Demo available.
SOC 2 Type II. ISO 27001. GDPR compliant. FedRAMP eligible. Enterprise data handling agreements.
SOC 2 Type II. ISO 27001. GDPR compliant. FedRAMP authorised. Enterprise data handling agreements.
Source code and vulnerability scan data processed on Checkmarx cloud or customer on-premise. Code scanning occurs locally in CI/CD pipelines — code transmitted to cloud for reporting and management.
Source code and binary application data transmitted to Veracode cloud for analysis. FedRAMP for US government application security scanning.
Verified reviews from signed-in users, stored in the backend and averaged into this tool's rating.
Sign in to rate Checkmarx AI and leave a review.
No other reviews yet — be the first to share how this tool performs in practice.