I am representing Checkmarx as a reseller. I work with both the cloud and on-premises versions. I have been working with Checkmarx for more than twelve years.
We have integrated Checkmarx into all the company's development pipelines. We use it to scan more than 4,000 repositories and around 25,000 pipelines. The integration is particularly useful as it works directly with several common SCM solutions in the market, such as GitHub and Bitbucket, and with CI/CD tools like Jenkins and GoCD. This allows us to register repositories quickly and scan code efficiently in our development process.
Whenever a web application needs to be moved into production, a static code analysis or source code review must be done. The analyst runs several tools on the web application and collects details. Completing a source code review for a particular application will take around five working days. Since we moved to Checkmarx, it has reduced the time significantly. Usually, we get the report within a day. It lists all the critical vulnerabilities and provides remediation. We provide suggestions to the customers and the project owners to fix the loopholes immediately so that we can move to production. Sometimes, the life cycle is reduced from five days to one day.
Technical Lead at a computer software company with 10,001+ employees
Real User
Top 20
2023-02-22T11:11:01Z
Feb 22, 2023
Our company uses the solution to check the vulnerabilities in our products at the build level. We capture, identify potential issues and fixes, and publish reports on a weekly basis. We work in the banking industry and have a license for 100 users.
Senior Cybersecurity Solution Architect at Dimension Data
Real User
2021-10-13T14:14:00Z
Oct 13, 2021
Checkmarx is used only for static application security testing (SAST), and it can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security.
Director at a tech services company with 11-50 employees
Reseller
2021-03-09T22:51:35Z
Mar 9, 2021
We're selling their licenses and their technologies. We have on-premises and cloud deployments. Its deployment depends on the customer requirements. It is used for a range of requirements for DevSecOps. It has been deployed to ensure that the development cycle delivers clean and secure code that is vulnerability-free. It is there as a part of the whole compliance and security process.
Information Security Architect at a tech services company with 1,001-5,000 employees
Real User
2021-03-02T14:51:49Z
Mar 2, 2021
We are using multiple solutions for application security, and Checkmarx is one of them. We are a client-centric organization, and we are also providing support to clients for application security. Sometimes, we have our own production, and then we scan the customer information and provide application security. For a few clients, it is deployed on the cloud, and for a few customers, it is on-premises.
Senior Manager at a manufacturing company with 10,001+ employees
Real User
2021-01-04T18:28:47Z
Jan 4, 2021
We use Checkmarx for security vulnerability identification. We are using its latest version. We have a license to upgrade to the latest version. Whenever there is a new version, we update it to the latest version.
Director of consultory at a non-tech company with 1,001-5,000 employees
Real User
2020-12-24T12:43:00Z
Dec 24, 2020
We onboard clients with the solution. We install the product and do the first scan with them. We help developers with security and the best practices with their applications with this solution.
Sr. Application Security Manager at a tech services company with 201-500 employees
Real User
2020-09-21T06:33:17Z
Sep 21, 2020
I am in charge of application security and Checkmarx is one of the products that I use in this capacity. We use this product for code scanning and static code analysis.
General Manager at a consultancy with 51-200 employees
Real User
2020-09-13T07:02:21Z
Sep 13, 2020
We use Checkmarx for static analysis as part of our software development lifecycle. It is very important because it helps us identify the security flaws in the code at a very early stage. Ultimately, this helps in reducing costs.
I am the founder and the chairman of an internationally certified cybersecurity research lab. I have a Ph.D. in cryptology and network security. We are a strategic partner of Checkmarx. Our job is to help them develop solutions. Currently, we are developing some algorithms and strategic solutions for them. Checkmarx informs us about what is happening, in advance, before they launch a product. We are also one of their testers.
Senior Security Engineer at a pharma/biotech company with 501-1,000 employees
Real User
2020-08-19T07:57:33Z
Aug 19, 2020
When I had an issue that was causing trouble in my code, I would upload it to Checkmarx to perform static code analysis. I would then study the reports.
Technical Lead at a tech services company with 1,001-5,000 employees
Real User
2020-07-05T09:38:13Z
Jul 5, 2020
We use this solution to check our systems for any vulnerabilities in our applications. Currently, I'm working on a banking tool, which is aligned with the menu. Our system was created 30 years ago and still is running in the market and doing well. However, currently, there are so many changes happening. Any solution coming into the technology needs to have a security check to ensure everything is safe.
The primary use case is for a white-box penetration testing security. When we work with source code, it's a tool to help us conduct a deep analysis on a source code level. We push the zip file with source code to our own stent with the solution and receive a report. Also, we work with the interface to find the vulnerabilities we may have. The most popular projects for us are the mobile application security assessment. We propose this option to our customers to check source code for iOS and Android mobile applications.
We are using it for static security scanning and static security testing. We also use it for code dependency analysis. We use two of the solution's tools for each variable.
Software Configuration Manager at a tech vendor with 501-1,000 employees
Real User
2019-06-19T05:02:00Z
Jun 19, 2019
The primary use that we have for Checkmarx is the evaluation of source code vulnerabilities. We use Git to connect to Checkmarx. We don't use GitHub. We use our own self-hosted Git. We're just using generic Git. One of the biggest thorns in our side is managing that aspect of it. It wouldn't matter if it was GitHub or Bitbucket or any of the other tools that you can use to connect Git to Checkmarx. The issue is the same. The tool is good at telling us what repository we're connected to, but it is horrible in telling us what branch we're connected to.
Practice Head - IT Risk & Security Management Services at Suma Soft Private Limited
Real User
2019-05-16T16:17:00Z
May 16, 2019
My team uses this product extensively for application vulnerability assessment. This solution is for static application security testing and is used within our software development process. As the software developers are creating solutions, they are able to identify vulnerabilities while the application is being written, rather than after the entire development is over. We were interested in having the raw source code scanned, so that was the primary requirement and that is where Checkmarx comes in. We do not need any precompiled libraries, or compiled source code, to be checked by the source code analysis solution. We have a security team that uses this product to scan source code, rather than have the developers handle it. We do not have any developer licenses (i.e. the SDLC Edition). Instead, the security team identifies the vulnerabilities and shares the report with the development team.
Checkmarx One is an enterprise cloud-native application security platform focused on providing cross-tool, correlated results to help AppSec and developer teams prioritize where to focus time and resources.
Checkmarx One offers comprehensive application scanning across the SDLC:
Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
API security
Dynamic Application Security Testing (DAST)
Container security
IaC security
Correlation,...
I am representing Checkmarx as a reseller. I work with both the cloud and on-premises versions. I have been working with Checkmarx for more than twelve years.
We have integrated Checkmarx into all the company's development pipelines. We use it to scan more than 4,000 repositories and around 25,000 pipelines. The integration is particularly useful as it works directly with several common SCM solutions in the market, such as GitHub and Bitbucket, and with CI/CD tools like Jenkins and GoCD. This allows us to register repositories quickly and scan code efficiently in our development process.
I use the tool for testing purposes.
Whenever a web application needs to be moved into production, a static code analysis or source code review must be done. The analyst runs several tools on the web application and collects details. Completing a source code review for a particular application will take around five working days. Since we moved to Checkmarx, it has reduced the time significantly. Usually, we get the report within a day. It lists all the critical vulnerabilities and provides remediation. We provide suggestions to the customers and the project owners to fix the loopholes immediately so that we can move to production. Sometimes, the life cycle is reduced from five days to one day.
We use the product for static code analysis, supply chain, and container security.
We use the solution for dynamic application testing.
We use the solution on a developing project. Before we bring the code to production, we have to ensure its quality, and we use this solution.
We use the solution for our international customers.
Our company uses the solution to check the vulnerabilities in our products at the build level. We capture, identify potential issues and fixes, and publish reports on a weekly basis. We work in the banking industry and have a license for 100 users.
We primarily use Checkmarx for assessing vulnerabilities in applications.
We mainly use this solution for static comprehension testing.
We are currently using the solution for scanning vulnerabilities.
Our main uses of this solution are to ensure our required compliance policies are met, and that we are applying best practice.
We use Checkmarx as a code analysis tool.
Checkmarx is used for application security, we can detect the stability and other details on how to fix issues.
I am using it for software assurance focused on security. I am using its latest version.
We use it for code scanning and security testing for our in-house application development. We are using its latest version.
We are using Checkmarx for application code scanning, such as scanning for different leverages in the application code.
Checkmarx is used only for static application security testing (SAST), and it can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security.
We use the solution for scanning the code for security.
We're selling their licenses and their technologies. We have on-premises and cloud deployments. Its deployment depends on the customer requirements. It is used for a range of requirements for DevSecOps. It has been deployed to ensure that the development cycle delivers clean and secure code that is vulnerability-free. It is there as a part of the whole compliance and security process.
We are using multiple solutions for application security, and Checkmarx is one of them. We are a client-centric organization, and we are also providing support to clients for application security. Sometimes, we have our own production, and then we scan the customer information and provide application security. For a few clients, it is deployed on the cloud, and for a few customers, it is on-premises.
We're more evaluating the solution rather than using it right now. We're resellers and it's something we'd like to offer to our clients.
We use Checkmarx for security vulnerability identification. We are using its latest version. We have a license to upgrade to the latest version. Whenever there is a new version, we update it to the latest version.
We onboard clients with the solution. We install the product and do the first scan with them. We help developers with security and the best practices with their applications with this solution.
We primarily use the solution for static analysis.
We primarily use Checkmarx for application security and tracking.
I am in charge of application security and Checkmarx is one of the products that I use in this capacity. We use this product for code scanning and static code analysis.
We use Checkmarx for static analysis as part of our software development lifecycle. It is very important because it helps us identify the security flaws in the code at a very early stage. Ultimately, this helps in reducing costs.
I am the founder and the chairman of an internationally certified cybersecurity research lab. I have a Ph.D. in cryptology and network security. We are a strategic partner of Checkmarx. Our job is to help them develop solutions. Currently, we are developing some algorithms and strategic solutions for them. Checkmarx informs us about what is happening, in advance, before they launch a product. We are also one of their testers.
When I had an issue that was causing trouble in my code, I would upload it to Checkmarx to perform static code analysis. I would then study the reports.
We use Checkmarx for scanning our source code.
We use this solution to check our systems for any vulnerabilities in our applications. Currently, I'm working on a banking tool, which is aligned with the menu. Our system was created 30 years ago and still is running in the market and doing well. However, currently, there are so many changes happening. Any solution coming into the technology needs to have a security check to ensure everything is safe.
The primary use case is for a white-box penetration testing security. When we work with source code, it's a tool to help us conduct a deep analysis on a source code level. We push the zip file with source code to our own stent with the solution and receive a report. Also, we work with the interface to find the vulnerabilities we may have. The most popular projects for us are the mobile application security assessment. We propose this option to our customers to check source code for iOS and Android mobile applications.
We are using it for static security scanning and static security testing. We also use it for code dependency analysis. We use two of the solution's tools for each variable.
The primary use that we have for Checkmarx is the evaluation of source code vulnerabilities. We use Git to connect to Checkmarx. We don't use GitHub. We use our own self-hosted Git. We're just using generic Git. One of the biggest thorns in our side is managing that aspect of it. It wouldn't matter if it was GitHub or Bitbucket or any of the other tools that you can use to connect Git to Checkmarx. The issue is the same. The tool is good at telling us what repository we're connected to, but it is horrible in telling us what branch we're connected to.
Our primary use case for this solution is SAST, Static Application Security Testing.
My team uses this product extensively for application vulnerability assessment. This solution is for static application security testing and is used within our software development process. As the software developers are creating solutions, they are able to identify vulnerabilities while the application is being written, rather than after the entire development is over. We were interested in having the raw source code scanned, so that was the primary requirement and that is where Checkmarx comes in. We do not need any precompiled libraries, or compiled source code, to be checked by the source code analysis solution. We have a security team that uses this product to scan source code, rather than have the developers handle it. We do not have any developer licenses (i.e. the SDLC Edition). Instead, the security team identifies the vulnerabilities and shares the report with the development team.
We use Checkmarx to review the source code for the external applications that we expose to the cloud or other servers on the internet.
Code scan. We performed periodic static code scans on copies of our Git repository to identify possible vulnerabilities.
Our primary use case solution is for code scanning.