AI Buyer Insights:

● Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

● Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

● Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

● Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

● Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

● Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

● Michelin, an e2open customer evaluated Oracle Transportation Management

● Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

● Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

● Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

● Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

● Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

● Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

● Michelin, an e2open customer evaluated Oracle Transportation Management

List of Checkmarx One Customers

loading spinner icon

Apply Filters For Customers

Logo Customer Industry Empl. Revenue Country Vendor Application Category When SI Insight
Cebu Air Transportation 6498 $387M Philippines Checkmarx Checkmarx One Application Security (AppSec) 2024 n/a
In 2024, Cebu Air implemented Checkmarx One to strengthen Application Security (AppSec) across its software development lifecycle. The initiative migrated on-premises CxSAST workloads to Checkmarx One and embedded automated scanning into CI/CD to support developer-centric security and compliance for customer booking and payments. The deployment emphasized Checkmarx One SAST capabilities, configured for pipeline-native scanning and developer feedback loops. Configuration included policy-driven scan profiles, centralized vulnerability triage, and integration points that push findings into developer workflows, enabling earlier remediation within SDLC and DevOps processes. Integrations focused explicitly on CI/CD pipeline integration to automate scanning during build and test phases, and on generating evidence artifacts for PCI DSS compliance tied to booking and payment applications. Operational coverage targeted application engineering, DevOps and security teams within Cebu Air in the Philippines, scaling AppSec access and day-to-day use beyond the initial security specialists. Governance was adjusted to support broader user access and role-based reporting, moving from a small specialist model to a wider AppSec program with more than 100 users. Outcomes reported in the vendor case study include scaling AppSec users from about 10 to over 100 and reducing vulnerability density by about 50 percent, while producing compliance evidence for PCI DSS on payment and booking systems.
HSBC USA Banking and Financial Services 2040 $3.9B United States Checkmarx Checkmarx One Application Security (AppSec) 2016 n/a
In 2016, HSBC USA integrated Checkmarx One into its Application Security (AppSec) toolset to formalize static application security testing and source code analysis across development pipelines. The implementation occurred under the HSBC Global Security Testing Team, targeting high risk business critical applications including web applications, thick clients, and REST APIs, and supporting quarterly PCI DSS ASV assessments for 11 Asia Pacific and European countries. Checkmarx One was configured to provide SAST and source code scanning capabilities, operating alongside DAST processes and manual testing to support a shift left strategy. The implementation emphasized automation and pipeline integration, with security testing automation fed into CI CD workflows to enable early detection of code level defects while preserving manual validation for false positive analysis and deep dive reviews. Integrations extended to developer and security toolchains that were explicitly in use at HSBC, with API testing workflows using Postman and Burp Suite, and defect and risk management linked to systems such as JIRA, Kenna, eGRC Archer, Confluence, and an internally developed Comet system. The program also incorporated SaaS based security testing for cloud hosted infrastructure and aligned static analysis results with network and infrastructure scans from tools like Tenable IO for consolidated risk triage. Governance changes included weekly application design reviews with project teams, formalized vulnerability likelihood analysis for risk rating, and collaborative remediation workflows with application development teams to align fixes to OWASP Top 10 guidance and internal security standards. The initiative supported ongoing Sec DevOps practices within HSBCs SDLC and contributed to achieving PCI compliance and quarterly attestation for networks in China, Canada, Hong Kong, and the United Kingdom.
Humana Insurance 95500 $83.1B United States Checkmarx Checkmarx One Application Security (AppSec) 2020 n/a
In 2020, Humana implemented Checkmarx One as its Application Security (AppSec) platform to centralize application vulnerability analysis and SAST capabilities across development and security functions. The Checkmarx One deployment was positioned to support DevSecOps practices and to automate security gating and code scanning within continuous integration pipelines. Configuration and functional scope emphasized static application security testing, source code analysis, and the design of security gates using automated testing in the software development lifecycle. Implementation work included integrating security checks into Azure DevOps based CI/CD pipelines, defining WAF policies, and extending coverage to container security patterns that referenced Docker and Kubernetes orchestration concepts. Operational integrations and toolchain interactions were explicit, with code scanning workflows at Humana covering more than 50 applications and using Rapid7 InsightAPP alongside Checkmarx One for vulnerability discovery. The program also referenced concurrent use and operational experiences with SonarCube, Qualys, Rapid7, and third-party library management tools such as JFrog, Nexus, and Artifactory, and it tracked remediation with ticketing and governance tools including Archer, Clarizen, and Nucleus. SIEM platform and DFIR tooling were part of the broader operational footprint for incident response and threat intelligence feeding application security efforts. Governance and process changes focused on developer training in secure design and coding practices, vulnerability remediation coordination with application teams, and compliance engagement with Legal, internal financial teams, and audit owners. The effort supported audit and assessment readiness including HIPPA and Hi trust related activities, coordination of pentest timelines for TSA critical and PCI audited applications, and embedding vulnerability management workflows into remedial lifecycle processes.
Ingersoll Rand Manufacturing 21000 $7.7B United States Checkmarx Checkmarx One Application Security (AppSec) 2020 n/a
In 2020, Ingersoll Rand implemented Checkmarx One as part of its Application Security (AppSec) toolset. The effort was led by the vulnerability management lead with a core team of three focused on maturing the vulnerability management program under NIST guidance, and the implementation scope emphasized vulnerability triage, remediation orchestration, patching documentation, and stakeholder training across development and security operations. Checkmarx One was configured to provide code analysis and static application security testing capabilities aligned with Application Security (AppSec) functional workflows, including role based administration, remediation workflow templates, and developer remediation guidance. The program integrated those code findings into documented remediation and patching processes, and the team administered complementary tooling to prioritize work. The AppSec deployment operated within a multi tool stack that included Kenna Security for risk based prioritization, NetSparker for dynamic scanning, and Qualys for asset and vulnerability discovery, with outputs used for vulnerability triage and ticketing. Triage processes consolidated Qualys and code analysis results into Kenna Security for risk scoring and remediation tracking, and operational coverage captured remediation efforts and consolidated monthly vulnerability, configuration, and platform coverage KPIs for leadership reporting. Governance and process changes included creation of vulnerability management workflows, remediation and patching documentation, training programs for stakeholders, and designation of escalation points for incident response and DLP issues. The program also incorporated compliance reviews and policy work to address GDPR, GLBA, and CCPA requirements, positioning Checkmarx One as the primary AppSec code analysis platform within the governed, risk based vulnerability management practice.
Mastercard Banking and Financial Services 35300 $28.2B United States Checkmarx Checkmarx One Application Security (AppSec) 2023 n/a
In 2023, Mastercard implemented Checkmarx One as its Application Security (AppSec) platform. The implementation is embedded within a global vulnerability management program run by a 60 plus person global team responsible for infrastructure scanning, SAST and DAST, red teaming, SBOM generation, and container vulnerability management operations. Configuration of Checkmarx One emphasized SAST pipeline integration, DAST orchestration, SBOM ingestion, and container image scanning while enforcing a shift left security model to embed scanning into continuous integration and delivery pipelines without impeding time to market. The deployment standardized scanning configurations and developer feedback loops to transform developer scanning workflows and support automated vulnerability triage. Mastercard consolidated security tooling leveraging Tenable, Checkmarx, and Nucleus platforms, aligning infrastructure scanning outputs from Tenable with application findings in Checkmarx One and centralizing vulnerability orchestration and reporting through Nucleus. Checkmarx One was configured to normalize vulnerability data feeds for enterprise consumption and to extend visibility into cloud environments and third party dependencies across global operations. Governance and operational oversight were formalized with direct reporting to the Deputy CSO, ongoing collaboration with enterprise risk, audit, and compliance functions, and regular executive engagement that includes presentations to audit committees and board subcommittees. The program explicitly targeted improved SLA compliance and expanded visibility into cloud and third party security risks as part of the end to end transformation of Mastercard's vulnerability management workflows.
Professional Services 5000 $7.0B Canada Checkmarx Checkmarx One Application Security (AppSec) 2025 n/a
Banking and Financial Services 56366 $23.1B United States Checkmarx Checkmarx One Application Security (AppSec) 2022 n/a
Insurance 3800 $8.3B United States Checkmarx Checkmarx One Application Security (AppSec) 2023 n/a
Banking and Financial Services 98000 $54.0B Canada Checkmarx Checkmarx One Application Security (AppSec) 2017 n/a
Banking and Financial Services 37086 $20.3B United States Checkmarx Checkmarx One Application Security (AppSec) 2022 n/a
Showing 1 to 10 of 10 entries

Buyer Intent: Companies Evaluating Checkmarx One

ARTW Buyer Intent uncovers actionable customer signals, identifying software buyers actively evaluating Checkmarx One. Gain ongoing access to real-time prospects and uncover hidden opportunities.

Discover Software Buyers actively Evaluating Enterprise Applications

Logo Company Industry Employees Revenue Country Evaluated
No data found
FAQ - APPS RUN THE WORLD Checkmarx One Coverage

Checkmarx One is a Application Security (AppSec) solution from Checkmarx.

Companies worldwide use Checkmarx One, from small firms to large enterprises across 21+ industries.

Organizations such as Humana, Royal Bank of Canada, Mastercard, PNC BANK and Truist Bank are recorded users of Checkmarx One for Application Security (AppSec).

Companies using Checkmarx One are most concentrated in Insurance and Banking and Financial Services, with adoption spanning over 21 industries.

Companies using Checkmarx One are most concentrated in United States and Canada, with adoption tracked across 195 countries worldwide. This global distribution highlights the popularity of Checkmarx One across Americas, EMEA, and APAC.

Companies using Checkmarx One range from small businesses with 0-100 employees - 0%, to mid-sized firms with 101-1,000 employees - 0%, large organizations with 1,001-10,000 employees - 40%, and global enterprises with 10,000+ employees - 60%.

Customers of Checkmarx One include firms across all revenue levels — from $0-100M, to $101M-$1B, $1B-$10B, and $10B+ global corporations.

Contact APPS RUN THE WORLD to access the full verified Checkmarx One customer database with detailed Firmographics such as industry, geography, revenue, and employee breakdowns as well as key decision makers in charge of Application Security (AppSec).