Black Duck Home Page
Black Duck Home Page
True Scale Application Security
  • Support
  • English
  • 日本語
  • 简体中文
close search bar

Sorry, not available in this language yet

close language selection
  • English
  • 日本語
  • 简体中文
  • Solutions
  • Products
  • Services
  • Partners
  • Resources
  • Blog
  • Company
  • Contact Sales

Company

go back

About Black Duck

  • Leadership
  • Newsroom
  • Blog
  • Partners
  • Careers
  • Contact Sales
Gartner Magic Quadrant

2023 Gartner® Magic Quadrant™ for AppSec Testing Read more

Forrester Wave Leader 2023 SAST Recognition

Forrester Wave Leader for SAST Read more

Forrester Wave Leader 2023 Software Analysis

Forrester Wave Leader for SCA Read more

close sub navigation

Products

go back

Integrated SaaS Platform

  • Polaris Platform
  • fAST Static
  • fAST SCA
  • fAST Dynamic

Tools

  • Coverity Static
  • Black Duck SCA
  • Continuous Dynamic
  • Seeker Interactive
  • Software Risk Manager ASPM
  • Defensics Protocol Fuzzing

Integrations

  • Code Sight IDE Plug-in
  • SCM Integrations
  • Build & CI Tool Integrations
  • Developer Workflow Integrations
  • 3rd-Party AST Tool Integrations
  • Cloud Deployment Integrations
Gartner Magic Quadrant 2023 Gartner® Magic Quadrant™ for AppSec Testing See why Black Duck is a Leader
close sub navigation

Solutions

go back

Use Cases

  • AI-generated code
  • API Security Testing
  • AppSec Program Consolidation
  • Application Security Testing
  • DevSecOps
  • Software Supply Chain Security
  • Manage Enterprise AppSec Risk
  • Container Security
  • Open Source License Compliance
  • M&A Due Diligence
  • Quality and Security Standards Compliance

By Technology

  • Static Analysis (SAST)
  • Software Composition Analysis (SCA)
  • Dynamic Analysis (DAST)
  • Interactive Analysis (IAST)
  • Penetration Testing
  • Mobile Application Security Testing (MAST)
  • Application Security Posture Management (ASPM)
  • Fuzz Testing Solutions

By Industry

  • Automotive
  • Financial Services
  • IoT & Embedded
  • Medical Devices
  • Public Sector

By Role

  • Dev and DevOps Teams
  • Security Teams
  • Legal Teams
close sub navigation

Services

go back

Security Testing Services

  • Overview
  • Penetration Testing

Security Program Services

  • Threat & Risk Assessments
  • Program Strategy & Planning
  • Security Training

Audit Services

  • Open Source & Security Audits

Customer Success

  • Overview
  • Implementation & Deployment
  • Premium and Designated Support
close sub navigation

Resources

go back

Latest Updates

  • Newsroom
  • Blog
  • Cybersecurity Research Center

Customer Resources

  • Support
  • Documentation
  • Black Duck Academy
  • Search Knowledge Base
  • Community Q&A

Other Resources

  • Datasheets
  • eBooks
  • Case Studies
  • Research & Reports
  • Webinars
  • White Papers
  • AppSec Glossary
  • Resource Library
Gartner Magic Quadrant 2023 Gartner® Magic Quadrant™ for AppSec Testing See why Black Duck is a Leader
close sub navigation

Introducing True Scale Application Security

Ensure Uncompromised Trust in Software for the Regulated, AI-Powered World

Learn more

2025 Open Source Security and Risk Analysis Report

Explore insights into open source security trends and recommendations for securing your software supply chain

Read the report

The All-in-One Application Security Platform Optimized for DevSecOps

Whether testing one application or thousands, automate any scan, any time, anywhere, all at once

Explore the Polaris platform

AppSec Leader for the Seventh Year in a Row

Discover why

Minimize business risk across the entire SDLC

Every business is a software business. Whether you’re selling it directly to your customers or relying on it to run your operations, Black Duck helps you protect your bottom line by building trust in your software—at the speed your business demands. 

<p>Your software is assembled as well as created. It includes more than open source and proprietary code. To build software users can trust, you must address the security of everything that goes into it.</p>

Secure your software supply chain

Building applications that users can trust requires securing everything that goes into them. Comply with supply chain requirements through comprehensive Software Bill of Materials (SBOM) management and eliminate risks throughout the application development life cycle.

Protect every aspect of your software

<p>Transforming your business through software requires speed and agility. Orchestrating and correlating your tests ensures that security doesn’t slow you down, even across multiple tools and vendors.</p>

Accelerate your AI transformation

Transform your DevSecOps program to keep up with the rapid pace of modern software development, driven by increasing adoption of AI-generated code. Improve developer productivity and automate security with developer-friendly solutions that integrate across the SDLC and in CI/CD pipelines without impeding software development.

Manage risks associated with AI-generated code

 

<p>Secure software requires more than just tools. You need to align your people, processes, and technology to address security risks based on your organization’s unique policies and business objectives.</p>

Manage AppSec risk at enterprise scale

Managing risk at scale requires you to streamline application security workflows and centralize risk visibility across your business. Reduce complexity and simplify the management of your AppSec program to improve your overall risk posture.

Simplify your AppSec program

When software powers safety-critical systems, you must be able to deliver software free of defects that is reliable and compliant.

Build secure, high-quality software faster

When your software powers safety-critical systems, ensuring it’s secure and free of defects isn’t just a requirement, it’s a necessity. Deliver secure, reliable, and compliant software quickly so you can ship products that your customers can trust.

Ensure your software is reliable and secure

The recognized leader in software security

See why our customers rely on Black Duck to help them build trust in their software

A Magic Quadrant™ Leader 7 Years Running

2023 Gartner® Magic Quadrant™ for Application Security Testing

See why
Gartner Magic Quadrant

Forrester Wave Leader for SCA

Black Duck is a Leader in the 2024 Forrester Wave™ for Software Composition Analysis

See why
Forrester Wave Leader for SCA

Forrester Wave Leader for SAST

Black Duck is a Leader in the Forrester Wave™ for Static Application Security Testing

See why
Forrester Wave Leader for SAST

Address risk based on your role

Security can’t be a solo act. From developers to CISOs and everyone in between, security is a team effort best achieved by clear roles and responsibilities, and defined outcomes.

Secure code as fast as you write it

Secure code as fast as you write it.

Build secure, high-quality, and compliant software faster and easier than ever before.

Learn more
Automate testing without compromising velocity

Automate testing without compromising velocity.

Maintain speed and innovation by building security into development pipelines.

Learn more
Manage Risk

Manage risk proactively and focus on what matters most.

Prioritize and act based on defined policies, automated workflows, and correlated risk insights.

Learn more

quotation mark

citi group logo

The format that Citi and Black Duck developed offers a great opportunity for team training—dynamic collaboration among the attendees to apply knowledge to common situations and problems faced by the team.

Peigi Maides
VP of AppSec awareness and training program manager of CISO office, Citi

Read the full story

Learn more how we help our customers
Learn more how we helped FPT Software

quotation mark

fpt software logo

We would strongly recommend the Black Duck AST tools to all enterprises, especially those specializing in embedded systems where code quality is of paramount importance.

Do Van Khav
Chief delivery officer and executive VP, FPT Software

Read the full story

Learn more how we help our customers
Learn more how we helped JDA Software

quotation mark

Blue Yonder Logo for SDLC Remediation

We’re now able to ensure that none of our products are released with open source license risks or security issues.

John Vrankovich
Principal architect, Blue Yonder

Read the full story

Learn more how we help our customers

Ready to get started?

The next frontier of application security is here to meet the exponential demands of modern software in a regulated, AI-powered world.

Contact sales
Learn more about our solutions
Black Duck Home Page

Follow

Manage Email Preferences Manage Cookie Settings 800 District Ave. Ste 201
Burlington, MA 01803

Contact Us

Solutions

  • AI-generated Code
  • API Security Testing
  • AppSec Consolidation
  • Application Security Testing
  • DevSecOps
  • Software Supply Chain Security
  • Manage AppSec Risk
  • Container Security
  • Open Source License Compliance
  • M&A Due Diligence
  • Quality & Security Standards Compliance

Products & Services

  • AppSec SaaS Platform
  • Static Analysis (SAST)
  • Software Composition Analysis (SCA)
  • Interactive Analysis (IAST)
  • Dynamic Analysis (DAST)
  • Penetration Testing
  • Protocol Fuzzing
  • AppSec Program Services
  • Threat & Risk Assessments

Support

  • Community
  • Documentation
  • Product Education
  • AppSec Training
  • Add-On Services

Resources

  • Datasheets
  • Webinars
  • Demos
  • Research & Reports
  • White Papers
  • Blog

Explore more

  • About us
  • Contact sales
  • Customer stories
  • Partners
  • Newsroom
  • Careers
  • Glossary
  • Sitemap

Legal

  • Agreements
  • Privacy
  • Security
©2025 Black Duck Software, Inc. All Rights Reserved