All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Black Duck enters AI-generated-code security as an established application-security vendor. The about page reports more than 4,000 customer organizations, and Polaris unifies its SAST, SCA, and DAST engines. Independent trade press confirms Leader standing in the Gartner Magic Quadrant for application security testing and in Gartner's new software supply chain ranking. Synopsys filings record the unit's 2024 sale to private equity as a privately held company. The part a rival cannot copy fast is the KnowledgeBase, the component database the Cybersecurity Research Center validates by hand. The catch a buyer should test is Signal, the agentic AI-code line, which reached general availability in March 2026 with no reference customer and no independent benchmark on the reviewed pages.
| Description | Application security company offering SAST, SCA, DAST, and IAST testing (the Polaris Platform unifies SAST, SCA, and DAST), backed by the human-validated KnowledgeBase, for proprietary, open-source, and AI-generated code. | [f1] |
|---|---|---|
| Founded | 2002 | [f2] |
| HQ | Boston, Massachusetts, United States | [f2] |
| Deployment | SaaS | [f3] |
| Product | What it does |
|---|---|
| Black Duck Polaris Platform | Cloud-native SaaS platform unifying SAST (fAST Static), SCA, and DAST engines with IaC analysis into one application security testing surface. |
| Black Duck SCA | Software composition analysis backed by the KnowledgeBase: detects open-source components, generates SBOMs, and supports regulatory compliance. |
| Coverity Static Analysis | Static application security testing (SAST) engine covering 22 languages and 200-plus frameworks for large-scale, complex software. |
| Seeker | Interactive application security testing (IAST) with active verification and sensitive-data tracking for web applications and services. |
| Black Duck DAST | Dynamic application security testing that identifies runtime vulnerabilities in web applications, APIs, and cloud-based services. |
| Black Duck Signal | Agentic application security that detects and fixes flaws in AI-generated code via MCP integrations with coding assistants and pipelines. |
| Defensics Protocol Fuzzing | Protocol fuzz testing that generates malformed inputs to find robustness and interoperability defects in software and connected devices. |
| Software Risk Manager ASPM | Application security posture management that consolidates findings from multiple testing tools with integrations, correlation, and central policy. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Black Duck Signal is an agentic application security solution that detects and fixes flaws in AI-generated code via MCP integrations with coding assistants and pipelines. It is mapped to the AI Defense Matrix. [f4]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Black Duck provides application security testing and software composition analysis. This conventional security is mapped to the Cyber Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Black Duck names the enterprise application security buyer responsible for software the business ships and ties the pain to proprietary code, open-source components, and AI-generated code across the development life cycle. SC Media's coverage of the Black Duck research finding that 86% of analyzed codebases contained vulnerable open source quantifies the problem independently of the vendor. [s5, s2, s9, s12] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Proprietary engines run under Polaris, with Coverity static analysis across 22 languages and 200-plus frameworks, software composition analysis, dynamic testing, and Seeker interactive testing, and Signal adds agentic AI-code analysis. The documented portfolio breadth and mature engine coverage put the depth at a high level, though the newer Signal line carries no independent performance validation. [s2, s4, s12] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Enterprise adoption of AI coding assistants created the AI-generated-code review demand Signal sells against, and the underlying application security testing market carries sustained analyst-tracked demand plus regulatory drivers such as the EU Cyber Resilience Act. SC Media and IT Security Guru cover the rising open-source and supply-chain risk independently. [s9, s11, s12] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Black Duck earns its team credibility through a sustained, independently recognized research record rather than founder pedigree: the Cybersecurity Research Center publishes the annual Open Source Security and Risk Analysis report, which SC Media covered in 2025, and the company has held a Gartner-recognized position in application security testing for eight years per SecurityBrief. CEO Greg Hughes brings enterprise software exits at Veritas and Serena rather than an application security track record. [s9, s10, s6] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Black Duck reports more than 4,000 organizations and vendor-displayed reference customers including FPT Software and Austrian Post Group, and SecurityBrief and IT Security Guru independently confirm repeat Gartner Leader placements in two analyst categories. The scale figure stays own-voice and the company is private with no third-party revenue reporting, so traction reads as strong rather than confirmed at the exceptional level a 5 requires. [s5, s14, s10, s11] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Synopsys filings record the 2024 sale of the Software Integrity business to Clearlake Capital and Francisco Partners in a deal valued at up to 2.1 billion dollars, and the public record shows a current Polaris platform and a 2026 Signal launch without disclosing post-carve-out output history. Private margins keep output per dollar unconfirmable at scale. [s7, s8] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Application security testing is an established Gartner category, and SecurityBrief and IT Security Guru independently report Black Duck as a Leader in the application security testing Magic Quadrant for an eighth year and in Gartner's new software supply chain security ranking, so buyers slot the portfolio without coaching. As a Leader among several rather than the category definer. [s10, s11, s1] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 | Black Duck is the embedded enterprise testing platform that startups in this cluster fear being bundled away by, with CI/CD and IDE workflow embedding, a reported base of more than 4,000 organizations, an independently confirmed Gartner Leader procurement position, and the hand-curated KnowledgeBase. Synopsys filings independently record the 2024 carve-out establishing the standalone application security provider. [s7, s10, s3] |
Black Duck sells application security testing to enterprises and frames its remit as securing both proprietary code and third-party components, including AI-generated code, across the development life cycle. The about page positions the company for a world ruled by AI and regulation, and the homepage names a comprehensive portfolio across static, dynamic, software-composition, and interactive testing, so the buyer is the security team responsible for software the business ships.
The breadth of the problem is older than the AI framing and independently quantified. Black Duck's core market is the testing of source code, open-source dependencies, and running applications for known and exploitable flaws, and SC Media's coverage of Black Duck research reports that 86% of analyzed codebases contained vulnerable open source, evidence the pain exists at the scale the company claims rather than only on its own pages.
The newer pain is AI-generated code arriving faster than conventional tools can review it. Signal addresses that narrower segment inside coding assistants, but it ships into the same enterprise security buyer the rest of the portfolio already serves, rather than a separately cultivated market. [s5, s9, s2]
Black Duck runs a wide testing portfolio under one platform rather than a single tool. The Polaris Platform unifies SAST through Polaris fAST Static, SCA through Polaris fAST SCA, and DAST through Polaris fAST Dynamic into a single cloud-native SaaS offering, with Coverity static analysis covering 22 languages and more than 200 frameworks and Seeker interactive testing extending coverage into running web applications.
The software composition analysis line rests on a curated data asset. Black Duck SCA combines dependency, binary, and snippet analysis to build a software bill of materials, and the company says a vast component database, human-validated by its Cybersecurity Research Center, tells a customer exactly what to fix and supports regulatory compliance such as the EU Cyber Resilience Act.
Signal is the agentic AI-code layer the company added on top. Black Duck Signal connects with coding assistants including Claude Code, Google Gemini, and GitHub Copilot through the Model Context Protocol, and Help Net Security describes ContextAI as a purpose-built model containing petabytes of human-validated security intelligence. That architecture is described on official and trade-press pages but is not yet backed by a public benchmark a buyer could check. [s2, s3, s12]
Black Duck enters AI-code security from the incumbent's seat rather than as a challenger. SecurityBrief and IT Security Guru independently report it as a Leader in the Gartner Magic Quadrant for application security testing for an eighth year and as a Leader in Gartner's new software supply chain security ranking, and the company reports more than 4,000 organizations as customers, so the bundling risk that pushes startups in this market toward acquisition runs the other direction for Black Duck.
The closest rivals are the other established testing platforms, not the AI-native startups. Checkmarx, Snyk, and Semgrep each run a broad application security platform that contests the same enterprise buyer deciding which platform reviews its code. Black Duck competes against them on portfolio breadth across SAST, SCA, DAST, and IAST and a long scanning heritage.
The differentiator Black Duck claims is its accumulated security data. The company positions the KnowledgeBase and ContextAI as the advantage an AI-native entrant cannot copy quickly, and while its analyst standing is now independently confirmed, it offers the data-quality claim as its own description rather than an independent evaluation of whether the data improves detection. [s10, s11, s3]
Black Duck carries strong commercial proof at the company level. The about page reports more than 4,000 organizations worldwide as customers, SecurityBrief and IT Security Guru independently confirm repeat Gartner Leader placements, and the customer-value and SCA pages carry named references including FPT Software, Austrian Post Group, and Datametica crediting the testing and software composition lines.
The proof for Signal specifically is thin. The AI-code product reached general availability in March 2026, and the reviewed sources carry no named Signal reference customer, no disclosed deployment count, and no independent benchmark of its detection or remediation against rival tools.
Distribution leans on the existing enterprise motion. Signal ships through Black Duck's established sales and platform relationships and integrates with the coding assistants developers already use, rather than through a separate marketplace or partner channel visible in the public record. [s5, s10, s14, s3]
Black Duck's leadership pairs an operator CEO with a recruited executive bench. Greg Hughes leads the company after serving as CEO of Veritas and, earlier, turning around Serena Software and selling it to Micro Focus. He joined from the Francisco Partners operating team, one of the firms that now owns Black Duck, so his exits sit in enterprise software rather than application security.
The product and go-to-market roster is publicly identifiable. The leadership page lists Dipto Chakravarty as Chief Product and Technology Officer alongside other recruited leaders, set beside the Software Integrity Group management team that Synopsys filings said was expected to lead the standalone company after the carve-out.
A sustained, independently recognized research and category record is the strongest team signal. The Cybersecurity Research Center publishes the annual Open Source Security and Risk Analysis report, which SC Media covered in 2025, and the organization has held a Gartner-recognized position in application security testing for eight consecutive years through the Synopsys era and into independence, a publication and standing record that outweighs the absence of a founder application security exit. [s9, s10, s6, s7]
Black Duck serves more than 4,000 organizations and sells into security teams that already vet their software supply chain, so its testing tools run inside customers' own compliance and audit workflows. The SCA line generates software bills of materials customers fold into their own audits and supports regulatory compliance such as the EU Cyber Resilience Act.
Ownership and structure are a matter of independent public record. Synopsys filings with the SEC record the 2024 sale of the Software Integrity business to Clearlake Capital and Francisco Partners and describe the result as a newly independent, privately held company, completed on September 30, 2024, so a buyer has a clear picture of who controls the business and that it is not publicly traded.
The open readiness item is product-level assurance for Signal, which inspects source code and applies fixes inside developer workflows without a documented data-handling commitment for the new product. The established products carry the routine disclosure history a buyer can review, with the NVD recording vulnerabilities such as an unauthenticated cross-site scripting flaw in Coverity Connect, distinct from the unproven assurance picture around Signal. [s7, s3, s13]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Checkmarx | competes with | Established enterprise application security platform contesting the same buyer deciding which platform reviews proprietary and AI-written code. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Snyk | competes with | Developer-first application security platform with SCA, SAST, and AI-code guidance, overlapping Black Duck's SCA and AI-code coverage. | |
| Semgrep | competes with | Code-security platform with SAST, SCA, and AI-code review features contesting the same enterprise application security demand. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Cycode | competes with | Application security posture management vendor covering the software supply chain and AI-generated code Black Duck also secures. | |
| GitHub | adjacent | Owns code scanning and the Copilot coding assistant, positioned to fold AI-code security into tools developers already use. |
Add analyzed competitors to compare them side by side with Black Duck.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Black Duck's buyers create more switching friction than its technology does. Named references are large enterprises from a base of over 4,000 organizations spanning startups to the Fortune 100, and buyers that size route a replacement through security and legal review. The engineering is hard, and Black Duck is not alone in it. Its static, software-composition, dynamic, and interactive testing rests on years of program-analysis expertise, yet a funded rival has the same skills, and its SOC 2 and ISO 27001 are attestations a rival could earn. The asset a rival could match only over years is the KnowledgeBase, the component database the Cybersecurity Research Center validates by hand. The edge is that buyer review and that curated data, while the product class stays open to competition.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 2/3 | Black Duck sells software the customer configures and operates, but layers human-validated expertise on top, a hand-curated component database, the verified Continuous Dynamic findings that filter DAST results to true positives, and ContextAI security intelligence that tells a customer what to fix, so the output is interpreted risk judgment delivered as a platform. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Polaris embeds in CI/CD with configured policy gates, a unified risk score, and accumulated bill-of-materials history, so replacing it means re-integrating and re-tuning across the development estate, meaningful friction in effort short of network effects or mandated data residency. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Black Duck publishes a SOC 2 Type 2, ISO 27001, and ISO 27017 on its Security Commitments page, and its SCA line lists product features supporting regulatory compliance such as the EU Cyber Resilience Act and generating software bills of materials customers fold into their own audit workflows. Those are commercial attestations plus procurement-easing product features, not a mandate for this product class and with no federal authorization, so a determined rival could match them. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | SAST across 22 languages, SCA with binary and snippet matching, dynamic testing, interactive testing with active verification, and agentic multi-agent exploitability analysis sit in program-analysis and machine-learning territory that takes years of specialized expertise to build. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The named references are large enterprises including FPT Software and Austrian Post Group, drawn from a base of more than 4,000 organizations the customer page describes as spanning startups through the Fortune 100, and every product page routes the buyer to sales rather than a public rate card. The reviewed record documents the sales-led motion but not the overall customer mix, so procurement gating is a reasonable read of a buyer that size rather than a documented fact. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Polaris is a SaaS platform with application features that scans, scores, and gates code in the development pipeline rather than infrastructure customer traffic is forced through inline. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The KnowledgeBase is a named component database the Cybersecurity Research Center curates by hand, and ContextAI carries security intelligence collected over two decades, an accumulating content asset. It is replicable by a funded rival over time rather than an irreplaceable dataset with a line-specific mandate. |
Black Duck sells application security testing to the enterprise security team that owns software the business ships, and frames its remit as securing proprietary code, open-source components, and AI-generated code across the development life cycle. The about page positions the company for a world ruled by AI and regulation, and the homepage names a comprehensive portfolio across static, dynamic, software-composition, and interactive testing, so the segmentation rides the established application security buyer rather than a separately cultivated AI-code market.
The base is broad and named. The about page reports more than 4,000 organizations worldwide as customers, the customer-value page carries case-study references including FPT Software and Austrian Post Group, and SC Media reported Black Duck's own finding that 86% of analyzed codebases contained vulnerable open-source components, the scale of open-source risk this segment buys against. The reviewed pages do not describe the customer mix, so the sales motion rather than the buyer population is what the record shows.
Signal narrows that segment to the team adopting AI coding assistants. Help Net Security's general-availability coverage says Signal is designed to complement existing application security testing activities, and the reviewed pages document no Polaris cross-sell motion and no shared commercial packaging, so the addressable set for the AI-code line reads as adjacent to the application security buyer the company already serves rather than a documented route to market. That adjacency is an inference from the portfolio rather than a fact the record establishes.
Black Duck runs a wide testing portfolio under one platform rather than a single tool. The Polaris Platform unifies SAST through Polaris fAST Static, SCA through Polaris fAST SCA, and DAST through Polaris fAST Dynamic into one cloud-native SaaS offering, Coverity static analysis covers 22 languages and more than 200 frameworks for large-scale software, and Seeker adds interactive testing with active verification for running web applications.
The differentiated input is the curated data. Black Duck SCA combines dependency, binary, and snippet analysis to build a software bill of materials, and rests on a component database the Cybersecurity Research Center validates by hand and that the company says tells a customer exactly what to fix. Black Duck publishes the annual Open Source Security and Risk Analysis report that SC Media covers, and the dynamic line adds Continuous Dynamic expert validation that filters scan results to true positives, layering human judgment on top of the engines.
Signal is the agentic AI-code layer added on top. The product connects with coding assistants including Claude Code, Google Gemini, and GitHub Copilot through the Model Context Protocol, and Black Duck attributes its accuracy to ContextAI, which Help Net Security describes as a purpose-built model containing petabytes of human-validated security intelligence. The agentic and ContextAI claims are described on official and trade-press pages but carry no public benchmark a buyer could check.
Go-to-market leans on an established enterprise motion and outside validation. SecurityBrief and IT Security Guru independently confirm that Black Duck holds a Leader position in the Gartner Magic Quadrant for application security testing and in Gartner's new software supply chain security ranking, and the about page reports more than 4,000 organizations as customers, the outside validation and scale that anchor its go-to-market.
Named demand depends on the established lines. The customer-value page carries case-study references including FPT Software and Austrian Post Group, and the SCA page carries a customer testimonial crediting supply-chain risk reduction inside CI/CD pipelines, without naming the organization in the fetched text. That proof attaches to the testing portfolio rather than to Signal.
For Signal specifically the record is thin. The AI-code product reached general availability in March 2026, and the fetched pages name no Signal reference customer, no disclosed deployment count, and no independent benchmark of its detection against rival tools, so the channel reach is the indirect signal rather than proof of independent AI-code traction.
Black Duck does not publish a public rate card for its testing portfolio. The SCA, Coverity, Seeker, and platform pages route the buyer to a get-pricing request and a sales contact rather than a self-serve price, consistent with a vendor selling negotiated enterprise agreements rather than to self-service developers.
The buying unit follows the established application security motion. Polaris is sold as a SaaS platform that consolidates SAST, SCA, and DAST, and the fetched pages disclose no metered dimension at all, so what a customer is actually charged for is a question for sales rather than a fact on the public record.
The fetched record does not document Signal pricing. The AI-code product reached general availability in March 2026, and the public pages route the buyer to a demo request without a published price or packaging detail, so the cost basis for the AI-code line is not visible to a buyer comparing it against rival assistant integrations.
Polaris is delivered as a cloud-native SaaS platform, so the customer configures policy and scans rather than running testing infrastructure on premises. The platform onboards code from repositories such as GitHub and GitLab and unifies scan results into a single risk view, concentrating the customer's application security operations on one managed surface.
Operations target developer-speed feedback. The platform applies policy-driven gates and filters findings to the issues that drive most risk, the SCA line generates a persistent bill of materials and monitors components for emergent risk, and the dynamic line adds verified findings that remove false positives, the continuous operation an enterprise application security program runs day to day.
Signal delivers inside developer tooling rather than as a separate console. The product runs scans through coding assistants and IDEs over the Model Context Protocol and analyzes new code incrementally so fixes apply before check-in, which places the AI-code operation in the same workflow developers already use rather than a standalone scanning step.
Trust rests on attestations, scale, analyst standing, and ownership of public record. Black Duck publishes a Security Commitments page listing a SOC 2 Type 2 covering security, availability, and confidentiality, an ISO 27001 certification, an ISO 27017 certification, and an ISO 26262 functional-safety mark, with a downloadable SOC 3 report, and it serves more than 4,000 organizations while holding a Gartner Magic Quadrant Leader placement in application security testing for the eighth consecutive time, and a Leader spot in Gartner's new software supply chain security ranking.
Ownership is a matter of public record. Synopsys filings with the SEC record the 2024 sale of the Software Integrity business to Clearlake Capital and Francisco Partners and describe the result as a newly independent, privately held company, so a buyer has a clear picture of who controls the business and that it is not publicly traded.
The curated data is part of the trust pitch. The SCA line rests on a component database the Cybersecurity Research Center validates by hand, and the company describes the KnowledgeBase as the basis for telling a customer exactly what to fix and supporting regulatory compliance such as the EU Cyber Resilience Act, which supplies the accumulated security content a regulated application security buyer weighs.
The open readiness item is product-level assurance for Signal specifically. The established products carry a public disclosure record a buyer can review, with the NVD documenting an unauthenticated cross-site scripting flaw in Coverity Connect versions before 2022.12.0, while the company-wide attestations are not documented on the fetched pages as covering the AI-code line, which reached general availability in March 2026 without a public benchmark, so a security review will likely ask how Signal handles proprietary code and what leaves the environment.
Polaris is built to be the single application security platform for a development organization. The platform consolidates SAST, SCA, DAST, infrastructure-as-code analysis, and secrets detection into one SaaS surface, so a buyer can replace fragmented point tools with one vendor, the consolidation Black Duck sells.
Outward, the line integrates into the developer ecosystem rather than binding to one vendor stack. Polaris onboards from common code repositories and Signal connects to coding assistants from multiple providers through the Model Context Protocol, so the platform reaches developers wherever they write code rather than only inside a single assistant.
Inward, adoption deepens reliance on Black Duck. Standardizing on Polaris concentrates a customer's scanning, bill-of-materials history, and risk scoring with one platform, and the curated KnowledgeBase is a Black Duck-controlled input the customer cannot reproduce, which is both the value a buyer consolidates onto and the concentration a buyer wary of single-vendor dependence weighs against it.
Black Duck pairs an owner-linked operator chief executive with a refreshed executive roster that mixes recruited leaders and some continuity from the Synopsys Software Integrity Group. The leadership page names Greg Hughes as Chief Executive Officer, who was previously CEO of Veritas and before that a Senior Operating Partner on the Francisco Partners operating team, one of the firms that co-owns Black Duck, so the seat is held by an owner-linked enterprise-software operator rather than the leader who ran the carve-out.
The product and go-to-market roster is publicly identifiable and recently recruited. The leadership page lists Dipto Chakravarty as Chief Product and Technology Officer alongside a Chief Revenue Officer, a Chief Financial Officer, and a Chief Information Security Officer, while Synopsys filings said the existing Software Integrity Group management team was expected to lead the standalone company after closing, so the bench is part inherited and part rebuilt rather than the division carried over intact.
A sustained, independently recognized research and category record is the strongest team signal. Black Duck publishes the annual Open Source Security and Risk Analysis report, which SC Media covered in 2025 as based on Black Duck Audit analyses of commercial codebases, and the organization has held a Gartner-recognized position in application security testing for eight consecutive years through the Synopsys era and into independence, a publication and standing record that outweighs the absence of a founder application security exit.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Black Duck about page (True Scale Application Security) | official | 2026-06-23 |
| f2 | Wikipedia on Black Duck Software history | research | 2026-06-14 |
| f3 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f4 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f5 | Black Duck platform | official | 2026-06-14 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Black Duck homepage (Polaris Platform, Gartner Magic Quadrant Leader for the eighth consecutive time) “A Magic Quadrant Leader for the Eighth Consecutive Time. 2025 Gartner Magic Quadrant for Application Security Testing, Black Duck placed highest for Ability to Execute.” | official | 2026-06-28 |
| s2 | Black Duck Polaris platform page (unified SAST, SCA, DAST engines) “It integrates the industry's most powerful security analysis engines, including SAST with Polaris fAST Static, SCA with Polaris fAST SCA, and DAST with Polaris fAST Dynamic, into a single, fully integrated platform.” | official | 2026-06-28 |
| s3 | Black Duck SCA product page (KnowledgeBase, Cybersecurity Research Center, SBOM, EU CRA, Datametica customer testimonial) “A vast component database, human-validated by the Cybersecurity Research Center, tells you exactly what to fix. ... support regulatory compliance (e.g., EU CRA).” | official | 2026-06-28 |
| s4 | Coverity SAST product page (22 languages, 200-plus frameworks) “Coverity provides in-depth support for 22 programming languages, more than 200 frameworks, and many popular infrastructure-as-code platforms.” | official | 2026-06-28 |
| s5 | Black Duck about page (True Scale Application Security, over 4,000 organizations) “Over 4,000 organizations worldwide trust Black Duck” | official | 2026-06-28 |
| s6 | Black Duck leadership page (Greg Hughes CEO, Dipto Chakravarty CPTO) “Greg is the CEO of Black Duck Software. Previously, Greg was a Senior Operating Partner of the Francisco Partners Operating team ... Greg served as CEO of Veritas ... Prior to Veritas, Greg was the CEO of Serena Software, where he led the successful turnaround and sale to Micro Focus” | official | 2026-06-28 |
| s7 | Synopsys 8-K exhibit 99.1, sale of Software Integrity Group to Clearlake and Francisco Partners (May 6, 2024, up to $2.1 billion) “The existing Software Integrity Group management team is expected to lead the newly independent, privately held company after the transaction closes.” | regulatory | 2026-06-28 |
| s8 | Synopsys 10-K fiscal 2024 (sale of Software Integrity business completed September 30, 2024) “On September 30, 2024, we completed the previously announced sale of our Software Integrity business to entities controlled by funds affiliated with the Sponsors” | regulatory | 2026-06-28 |
| s9 | SC Media: Report, 86% of codebases contain vulnerable open source components (Laura French, Feb 25 2025) “86% of analyzed codebases contained vulnerable open source components” | press | 2026-06-28 |
| s10 | SecurityBrief UK: Black Duck named leader in Gartner Magic Quadrant for eighth year (Jed Nykolle Harme, Oct 15 2025) “Black Duck has been recognised as a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing for the eighth year running.” | press | 2026-06-28 |
| s11 | IT Security Guru: Black Duck lands Leader spot in Gartner's brand-new Software Supply Chain Security Magic Quadrant (June 22, 2026) “Gartner's move to carve out this category signals that analysts now regard SSCS as a mature, standalone discipline rather than a subset of application security testing or DevSecOps tooling.” | press | 2026-06-28 |
| s12 | Help Net Security: Black Duck Signal secures AI-generated code with agentic application security “Signal analysis is differentiated by its use of ContextAI, Black Duck's purpose-built application security model containing petabytes of human validated security intelligence.” | press | 2026-06-28 |
| s13 | NVD CVE-2023-23849, unauthenticated cross-site scripting in Coverity Connect prior to 2022.12.0 “Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability.” | research | 2026-06-28 |
| s14 | Black Duck customer value page (named case-study customers: FPT Software, Austrian Post Group, TAS Group) “Austrian Post Group secures software at scale Gains full visibility and control across open source risk and compliance” | official | 2026-06-28 |
| s15 | Black Duck Signal product page (agentic AI application security) “Signal connects with popular AI coding assistants including Claude Code, Google Gemini, and GitHub Copilot via Model Context Protocol (MCP)” | official | 2026-06-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Black Duck Polaris platform page (unified SAST, SCA, DAST engines) “It integrates the industry's most powerful security analysis engines, including SAST with Polaris fAST Static, SCA with Polaris fAST SCA, and DAST with Polaris fAST Dynamic, into a single, fully integrated platform.” | official | 2026-06-28 |
| s2 | Black Duck Signal product page (agentic application security) “Signal connects with popular AI coding assistants including Claude Code, Google Gemini, and GitHub Copilot via Model Context Protocol (MCP)” | official | 2026-06-28 |
| s3 | Black Duck leadership page (Greg Hughes CEO, Dipto Chakravarty CPTO) “Greg is the CEO of Black Duck Software. Previously, Greg was a Senior Operating Partner of the Francisco Partners Operating team. Prior to Francisco Partners, Greg served as CEO of Veritas” | official | 2026-06-28 |
| s4 | Help Net Security: Black Duck Signal secures AI-generated code with agentic application security “Signal analysis is differentiated by its use of ContextAI, Black Duck's purpose-built application security model containing petabytes of human validated security intelligence.” | press | 2026-06-28 |
| s5 | Black Duck about page (True Scale Application Security, over 4,000 organizations) “Over 4,000 organizations worldwide trust Black Duck” | official | 2026-06-28 |
| s6 | Black Duck homepage (Gartner Magic Quadrant Leader for the eighth consecutive time, FPT Software reference) “A Magic Quadrant Leader for the Eighth Consecutive Time. 2025 Gartner Magic Quadrant for Application Security Testing, Black Duck placed highest for Ability to Execute.” | official | 2026-06-28 |
| s7 | Synopsys 8-K exhibit 99.1, sale of Software Integrity Group to Clearlake and Francisco Partners (May 6, 2024, up to $2.1 billion) “The existing Software Integrity Group management team is expected to lead the newly independent, privately held company after the transaction closes.” | regulatory | 2026-06-28 |
| s8 | Black Duck customer value page (named case-study customers: FPT Software, Austrian Post Group, TAS Group) “Austrian Post Group secures software at scale Gains full visibility and control across open source risk and compliance” | official | 2026-06-28 |
| s9 | Coverity SAST product page (22 languages, 200-plus frameworks) “Coverity provides in-depth support for 22 programming languages, more than 200 frameworks, and many popular infrastructure-as-code platforms.” | official | 2026-06-28 |
| s10 | Black Duck Security Commitments page (SOC 2 Type 2, ISO 27001, ISO 27017, ISO 26262) “SOC 2 Type 2 Covering security, availability, and confidentiality ... ISO 27001 Certification ... ISO 27017 Certification” | official | 2026-06-28 |
| s11 | Black Duck SCA product page (KnowledgeBase, Cybersecurity Research Center, SBOM, EU CRA, Datametica customer testimonial) “A vast component database, human-validated by the Cybersecurity Research Center, tells you exactly what to fix. ... support regulatory compliance (e.g., EU CRA).” | official | 2026-06-28 |
| s12 | Black Duck Seeker IAST product page (active verification, sensitive-data tracking) “The industry's first interactive application security testing (IAST) software solution with active verification and sensitive-data tracking for web-based applications.” | official | 2026-06-28 |
| s13 | Black Duck DAST product page (Continuous Dynamic expert validation) “above all, that ALL of the findings are verified. And we are 99% false positives-free.” | official | 2026-06-28 |
| s14 | SC Media: Report, 86% of codebases contain vulnerable open source components (Laura French, Feb 25 2025) “86% of analyzed codebases contained vulnerable open source components” | press | 2026-06-28 |
| s15 | SecurityBrief UK: Black Duck named leader in Gartner Magic Quadrant for eighth year (Jed Nykolle Harme, Oct 15 2025) “Black Duck achieved the highest position for Ability to Execute for the sixth year in succession.” | press | 2026-06-28 |
| s16 | IT Security Guru: Black Duck lands Leader spot in Gartner's brand-new Software Supply Chain Security Magic Quadrant (June 22, 2026) “Gartner's move to carve out this category signals that analysts now regard SSCS as a mature, standalone discipline rather than a subset of application security testing or DevSecOps tooling.” | press | 2026-06-28 |
| s17 | NVD CVE-2023-23849, unauthenticated cross-site scripting in Coverity Connect prior to 2022.12.0 “Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability.” | research | 2026-06-28 |
| s18 | Synopsys 10-K fiscal 2024 (sale of Software Integrity business completed September 30, 2024) “On September 30, 2024, we completed the previously announced sale of our Software Integrity business to entities controlled by funds affiliated with the Sponsors” | regulatory | 2026-06-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.