Scanning the code and its parts
Static analysis, software composition analysis, the software bill of materials, container images
Back to your pull request from the start of this Market Segment. Two kinds of scanner read it before it merges:
Static application security testing (SAST)reads the source code for patterns that become vulnerabilities. Examples are unchecked user input, or a password written into the code, called a hard-coded secret.
Software composition analysis (SCA)reads the list of libraries the code depends on. It matches them against databases of known security flaws and of licences.
SCA became the faster-growing of the two after two events. In 2021, a serious flaw was found in Log4j, a logging library used in a huge number of Java programs, and companies scrambled to find where they used it. And regulators began to demand a software bill of materials (SBOM) for every piece of software: a list of every library inside it.
What is inside your software. An app is your own code plus many open-source libraries you did not write. Software composition analysis matches those libraries against databases of known flaws and licences, and the software bill of materials lists every library inside. The 2021 Log4j flaw sent companies looking for where they used it.
Black Duckis the largest company in this Market Segment, and the clearest example of this category's history. Synopsys, the chip-design company, built a software-security business by buying companies. In 2024 it spun that business out again as Black Duck. The new company took with it Coverity, the static analyser that a generation of C and Java teams ran, and the composition analysis Black Duck is named for. It has engineers in Bengaluru.
Checkmarxfrom Israel, is the other established name in static analysis. It has engineers in Pune.
Sonatyperuns the repository that most Java developers download their libraries from. It sells composition analysis built on the history of that repository. Its India centre is in Hyderabad.
Revenerain Bengaluru, looks at the same libraries from the licensing side. It checks whether the open-source code in a product is licensed for the way the product uses it. That is a legal risk before it is a security one.
Endor Labsis a newer company. It asks which of the flagged libraries the code actually reaches and uses, so teams fix ten things instead of a thousand. It now also governs the code that AI assistants write.
RapidFortlooks at the container image the software ships in: the packaged file that holds the app and everything it needs to run. It strips out the parts that are never used, which removes their vulnerabilities with them.
One company here comes from the place where finished software is stored:
JFrogsells an artifact repository, the store for the built software, called binaries, ready to deploy. More and more scanning happens there. Its Xray product is composition analysis built into the place the binaries live.
JFrog is covered mainly in Market Segment 6.1, DevOps and CI/CD tools (in Industry Vertical 6, Devtools companies). Black Duck, Checkmarx and Revenera also appear there, where security runs as a step in the developer's pipeline.
Testing the running application
Dynamic testing and penetration testing as a service, API security, and the posture layer above the scanners
Back to the food-delivery app from the start of this Market Segment. It is now live. The other way to find a flaw is to attack the running app the way an intruder would. This is called dynamic testing. When skilled people try to break in on purpose, with the owner's permission, it is called penetration testing.
The modern version is a service: automated scanning that runs all the time, with human testers behind it. It is sold as a subscription, rather than as a test once a year. (More on the attackers a company invites in, in Market Segment 4.11, Vulnerability management and penetration testing.)
Astra Securitywith engineers in Bengaluru, sells penetration testing as a service, with its own scanner.
Qodexstarted in Bengaluru and now has a US office in San Francisco. It is a young company doing the same for the API alone. The API is the interface most modern apps expose, and the one most attacks now target. Qodex's scanner writes and runs the tests itself.
Above all the scanners sits a problem of its own. A large company runs a dozen scanners and drowns in their findings.
ArmorCodewith engineers in Delhi NCR, sells the layer that collects every finding from every tool. It removes the duplicates, scores each finding by how much it matters to the business, and hands the developer a short list. The industry now calls this application security posture management (ASPM).
Too many findings, one short list. The code scanner, the library scanner, the container scanner and the API tests all send their findings to ArmorCode, which removes the duplicates, scores each finding by how much it matters to the business, and hands the developer a short list.
One company here does the same work on a different target, the phone app:
Zimperiumis here for its mobile app security. Its tools protect a company's own phone app against tampering and against reverse engineering, which means taking the app apart to see how it works. (More on it in Market Segment 4.4, Endpoint security and device management.)
Securing the code the model wrote.
A growing share of new code is written by AI assistants. They import libraries nobody chose, and repeat the flaws in the code they learned from. So the scanners are being rebuilt to read that code, and the assistant's suggestions, as they appear. Endor Labs sells this as AI code governance. Black Duck, Checkmarx and Sonatype are shipping the same. The same kind of AI can find a weak point in an API on its own, which is exactly what an attacker wants. Qodex and Astra are building it for the defence.
So your pull request from the start of this Market Segment is checked twice. It is scanned as code and libraries before it ships. Then it is attacked, on purpose, as a running app.