Skip to content

Checkmarx One 검토

Checkmarx One은 SDLC 전반에 걸쳐 포괄적인 AppSec을 위한 AI 기반 에이전트를 갖춘 엔터프라이즈급 통합 애플리케이션 보안 플랫폼입니다.

shipped 2026년 7월 8일paid
Domain rating77Monthly visits54K/mo
Checkmarx One — product screenshot

핵심 포인트

1정부 애플리케이션 보안을 위해 2026년 7월 13일 FedRAMP Moderate 인증을 획득했습니다.
2F1 점수 0.64 및 오탐(false positives) 60% 감소를 특징으로 하는 새로운 하이브리드 SAST 스캐닝 엔진을 도입했습니다.
3SAST 엔진이 버전 9.7.2로 업그레이드되어 기능 및 업데이트가 향상되었습니다.
4클라우드 인사이트 적용 범위를 확장하기 위해 API 엔드포인트를 통해 CrowdStrike와 통합됩니다.

Stork Quadrant

Sleeping Giant· 46/100

Has a real moat but invisible to agents. Add an MCP and you'd climb.

Checkmarx One survives the agent shift because it owns three hard moats: regulatory (SOC2, HIPAA, PCI-DSS compliance as gating), trust (enterprises pay for liability and audit trails in security decisions), and coordination (it's embedded in CI/CD pipelines and orchestrates across dev, sec, and ops teams). An LLM alone can suggest fixes; Checkmarx owns the enforcement layer, the audit log, and the integration rails that make security decisions stick across an org. The brand moat (trusted by Fortune 500 AppSec teams) reinforces this.

Claude Haiku 4.5, scored 2026-07-14

Defensibility · 64/100

  • Physical-world coupling
  • Regulatory moat
  • Network liquidity
  • Proprietary refreshing data
  • High-trust catastrophic workflows
  • Multi-party coordination
  • Brand / community / taste

An LLM alone could replace

  • Generate security vulnerability reports from code analysis
  • Suggest remediation steps for common OWASP vulnerabilities
  • Classify and prioritize security findings by severity
  • Draft security policy documentation and compliance checklists

Agent-Readiness · 25/100

  • Verified MCP
  • Listed on agent surfaces
  • Usage-based pricing
  • Headless agent auth
  • Public OpenAPIhttps://docs.checkmarx.com/
  • Active changeloghttps://checkmarx.com/blog/ (2026-06-30)
  • llms.txthttps://checkmarx.com/llms.txt

How to defend

Double down on the coordination moat by making Checkmarx the orchestration layer that agents call, not the UI agents replace — own the API that enterprise security workflows depend on. Strengthen the data moat by building proprietary vulnerability intelligence (zero-days, supply-chain risk signals) that updates faster than public feeds and that competitors can't replicate.

  • Ship an MCP server and list it on Stork — biggest single point gain (+25).
  • Get listed in the Anthropic MCP registry, Cursor, or Claude Desktop (+20).
  • Add a usage-based or per-call tier; per-seat-only pricing dies when agents replace seats (+15).
  • Expose API-key auth with a self-serve sandbox tier; remove sales-call gates (+15).

Checkmarx One 소개

비즈니스 모델
Subscription SaaS
플랫폼
Web
대상 사용자
Enterprises and development teams focusing on application security.

요금제

Checkmarx One Packages
Not specified / Not specified
  • Comprehensive application security
  • AI-powered risk detection
  • Integration with DevOps
  • Customizable security policies

사양

API 제공 여부

예, 공개 API

Screenshots

overview

Checkmarx One이란 무엇인가요?

Checkmarx One은 Checkmarx가 개발한 애플리케이션 보안 플랫폼 도구로, 기업 및 개발 팀이 코드, 애플리케이션 및 AI 기반 개발을 대규모로 보호할 수 있도록 지원합니다. 이는 전체 소프트웨어 개발 수명 주기(SDLC)에 걸쳐 다양한 보안 테스트 기능을 통합합니다. 이 플랫폼은 소스 코드의 취약점을 식별하기 위한 Static Application Security Testing (SAST), 오픈 소스 구성 요소 위험을 위한 Software Composition Analysis (SCA), 런타임 취약점 평가를 위한 Dynamic Application Security Testing (DAST), 그리고 Infrastructure as Code (IaC) Security를 포함한 포괄적인 애플리케이션 보안 테스트(AST) 도구 모음을 제공합니다. 추가 기능으로는 통합된 위험 가시성을 위한 API Security, Container Security, Secrets Detection, Supply Chain Security 및 Application Security Posture Management (ASPM)가 있습니다. Checkmarx One은 CI/CD 파이프라인 및 개발자 워크플로에 통합하여 초기 취약점 탐지 및 수정 작업을 용이하게 하고, OWASP Top Ten과 같은 표준에 대한 규정 준수 보고를 지원하며, AI 소프트웨어 공급망 내에서 사람이 작성한 코드와 AI 생성 코드 모두를 보호하도록 설계되었습니다. 이는 대규모 엔터프라이즈 포트폴리오에 대한 취약점 관리를 중앙 집중화하고, 우선순위가 지정된 위험 관리 및 수정 추적을 위해 발견 사항을 집계합니다.

features

Checkmarx One의 주요 기능

Checkmarx One은 AI 기반 에이전트 및 하이브리드 스캐닝 기술을 활용하여 소프트웨어 개발 수명 주기 전반에 걸쳐 포괄적인 애플리케이션 보안을 제공하도록 설계된 강력한 기능 세트를 제공합니다.

  • 소스, 바이트 및 바이너리 코드 분석을 위한 Static Application Security Testing (SAST).
  • 오픈 소스 취약점 및 라이선스 문제를 식별하기 위한 Software Composition Analysis (SCA).
  • 실행 중인 애플리케이션에 대한 실제 공격 시뮬레이션을 위한 Dynamic Application Security Testing (DAST).
  • 템플릿의 안전하지 않은 구성을 탐지하기 위한 Infrastructure as Code (IaC) Security.
  • 새로운 위협 및 잘못된 구성으로부터 API를 보호하기 위한 API Security.
  • 취약점 검사를 위해 컨테이너 이미지를 스캔하는 Container Security.
  • 코드베이스 내에 하드코딩된 비밀을 식별하기 위한 Secrets Detection.
  • 더 넓은 소프트웨어 공급망 전반의 취약점을 다루는 Supply Chain Security.
  • 통합된 위험 및 신뢰 보기, 정책 시행 및 수정 추적을 위한 Application Security Posture Management (ASPM).
  • 결정론적 규칙과 AI 추론을 결합한 AI 기반 보안 에이전트 및 하이브리드 스캐닝 기술.

use cases

Checkmarx One은 누가 사용해야 하나요?

Checkmarx One은 주로 애플리케이션 보안을 위한 통합되고 확장 가능한 솔루션을 필요로 하는 기업 및 개발 팀, 특히 현대적인 AI 기반 개발 관행에 참여하는 기업 및 개발 팀에서 활용됩니다.

  • 중앙 집중식 취약점 관리, 위험 우선순위 지정 및 규정 준수 보고(예: PCI DSS, HIPAA, OWASP Top Ten)를 위한 AppSec 관리자 및 CISO.
  • 코드부터 클라우드까지 전체 SDLC에 걸쳐 포괄적인 보안 테스트를 추구하는 보안 전문가.
  • 통합 개발 환경(IDEs) 및 소스 코드 관리(SCM) 시스템 내에서 직접 초기 취약점 탐지 및 수정을 위한 소프트웨어 개발자.
  • AI 생성 코드 보호 및 AI 소프트웨어 공급망 전반의 신뢰 거버넌스에 중점을 둔 조직.
  • 자동화된 보안 테스트 및 통합 위험 인텔리전스를 필요로 하는 대규모 애플리케이션 포트폴리오를 가진 기업.

how to use

Checkmarx One 사용 방법

Checkmarx One은 기존 개발 및 보안 워크플로에 통합되어 애플리케이션 보안 테스트를 자동화하고 실행 가능한 통찰력을 제공합니다. 시작하려면 플랫폼을 구성하여 코드베이스 및 애플리케이션을 스캔해야 합니다.

  • 1자동화된 보안 스캔을 위해 Checkmarx One을 CI/CD 파이프라인(예: Jenkins, GitLab, GitHub Actions, Azure DevOps)에 통합합니다.
  • 2소스 코드 리포지토리, 애플리케이션 및 인프라 템플릿에 대한 SAST, SCA, DAST, IaC 및 기타 스캔을 구성합니다.
  • 3AI 기반 에이전트를 활용하여 취약점 탐지를 강화하고 개발자 워크플로 내에서 직접 AI 기반 수정 지침을 받습니다.
  • 4통합 플랫폼 내에서 다양한 스캐닝 엔진의 집계된 발견 사항을 모니터링하고 관리하여 우선순위가 지정된 위험 관리 및 수정 추적을 수행합니다.
  • 5보안 표준 및 규제 요구 사항 준수를 입증하기 위한 규정 준수 보고서를 생성합니다.

pricing

Checkmarx One 가격 및 요금제

Checkmarx One은 유료 구독 SaaS 모델로 운영됩니다. 특정 가격 등급 및 패키지 세부 정보는 공식 웹사이트에 공개되어 있지 않으므로, 조직의 필요와 규모에 따른 맞춤형 견적을 위해 Checkmarx에 직접 문의해야 합니다.

  • Checkmarx One 패키지: 가격은 공개되지 않았습니다. 자세한 내용은 공급업체에 문의하십시오.

Pros

  • +Ease of setup and integration with SCM systems and CI/CD pipelines, facilitating consistent scans.
  • +Comprehensive scanning capabilities, including SAST, SCA, DAST, IaC, API, and Secrets Detection, providing a 360-degree view of vulnerabilities.
  • +Actionable and developer-friendly remediation guidance, often including visual flowcharts, to accelerate vulnerability fixes.
  • +Promising AI capabilities designed to reduce remediation time by assisting with code changes and validation.
  • +Strong compliance reporting features, supporting adherence to standards like PCI DSS, HIPAA, and OWASP Top Ten.
  • +Exceptional customer support and account management, as noted by user reviews.

Cons

  • The enterprise-grade complexity of the platform may require significant initial setup and configuration efforts for optimal utilization.
  • While AI capabilities are promising, their full impact across all vulnerability types and complex remediation scenarios may still be evolving.
  • The default API rate limit of 100 requests per minute, though configurable, could necessitate adjustments for very large-scale or high-frequency automated deployments.
  • Specific pricing tiers and detailed cost structures are not publicly disclosed, which can complicate initial budgeting and cost estimation for potential clients.
  • Despite high F1 scores for its SAST engine, the inherent nature of static analysis means some level of false positives or negatives may still require manual review.

유사한 도구

Checkmarx One 대 경쟁사

Checkmarx One은 애플리케이션 보안 시장에서 여러 기존 및 신흥 플랫폼과 경쟁하며, SDLC 전반에 걸쳐 AI 기반 에이전트를 갖춘 통합된 클라우드 네이티브 접근 방식을 통해 차별화됩니다.

1

Veracode's platform focuses on safely harnessing AI's full potential by seamlessly embedding security into AI-augmented development workflows, with a strong emphasis on AI-driven remediation and trusted findings.

Similar to Checkmarx One, Veracode offers a unified platform for application security across the SDLC with AI-powered remediation. Veracode highlights its proprietary AI models and curated datasets for precise patch generation, aiming to reduce false positives and accelerate fixes.

2

Snyk positions itself as the 'AI Security Fabric,' providing an independent security layer that continuously validates AI-generated code, governs development agents, and secures AI-native applications.

Snyk, like Checkmarx One, offers comprehensive application security with AI-powered vulnerability scanning and fixes across the SDLC. Snyk emphasizes its DeepCode AI engine for unmatched scanning accuracy and its focus on securing AI-generated code and AI agents.

3
Contrast Security

Contrast Security's platform is built on runtime security, using real-time application behavior to detect and block attacks, and providing AI-powered remediation guidance, including for AI prompt injection vulnerabilities.

While Checkmarx One offers comprehensive AppSec across the SDLC, Contrast Security differentiates with its strong emphasis on runtime analysis (IAST/RASP) and its ability to unify static and runtime findings with AI for more accurate prioritization and remediation, reducing false positives.

4

Cycode offers a unified AppSec platform that provides complete coverage across the entire SDLC, from source code to runtime, with a 'Context Intelligence Graph' to correlate findings and prioritize risks.

Cycode, similar to Checkmarx One, aims to provide a unified platform for application security across the SDLC. Cycode emphasizes its ability to close gaps between tools and stages of development with end-to-end coverage and a unique Context Intelligence Graph for enhanced visibility and prioritization.

5
OpenText Fortify

OpenText Fortify provides enterprise-grade static application security testing (SAST) with AI-powered analysis and remediation, specifically designed to fortify code against vulnerabilities introduced by AI-assisted development ('vibe coding').

Fortify, like Checkmarx One, offers robust SAST capabilities with AI-driven insights and automated fixes. Fortify particularly highlights its focus on securing AI-generated code and integrating with AI coding assistants, providing contextual explanations and suggested code fixes directly in developer environments.

Stork에서 더 보기

관련 AI 도구

같은 카테고리의 다른 도구 — 공통 태그로 연결