List of Checkmarx One Customers
Paramus, 7652, NJ,
United States
Since 2010, our global team of researchers has been studying Checkmarx One customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased Checkmarx One for Application Security (AppSec) from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using Checkmarx One for Application Security (AppSec) include: Humana, a United States based Insurance organisation with 95500 employees and revenues of $83.06 billion, Royal Bank of Canada, a Canada based Banking and Financial Services organisation with 98000 employees and revenues of $54.00 billion, Mastercard, a United States based Banking and Financial Services organisation with 35300 employees and revenues of $28.17 billion, PNC BANK, a United States based Banking and Financial Services organisation with 56366 employees and revenues of $23.08 billion, Truist Bank, a United States based Banking and Financial Services organisation with 37086 employees and revenues of $20.32 billion and many others.
Contact us if you need a completed and verified list of companies using Checkmarx One, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The Checkmarx One customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Cebu Air | Transportation | 6498 | $387M | Philippines | Checkmarx | Checkmarx One | Application Security (AppSec) | 2024 | n/a |
In 2024, Cebu Air implemented Checkmarx One to strengthen Application Security (AppSec) across its software development lifecycle. The initiative migrated on-premises CxSAST workloads to Checkmarx One and embedded automated scanning into CI/CD to support developer-centric security and compliance for customer booking and payments.
The deployment emphasized Checkmarx One SAST capabilities, configured for pipeline-native scanning and developer feedback loops. Configuration included policy-driven scan profiles, centralized vulnerability triage, and integration points that push findings into developer workflows, enabling earlier remediation within SDLC and DevOps processes.
Integrations focused explicitly on CI/CD pipeline integration to automate scanning during build and test phases, and on generating evidence artifacts for PCI DSS compliance tied to booking and payment applications. Operational coverage targeted application engineering, DevOps and security teams within Cebu Air in the Philippines, scaling AppSec access and day-to-day use beyond the initial security specialists.
Governance was adjusted to support broader user access and role-based reporting, moving from a small specialist model to a wider AppSec program with more than 100 users. Outcomes reported in the vendor case study include scaling AppSec users from about 10 to over 100 and reducing vulnerability density by about 50 percent, while producing compliance evidence for PCI DSS on payment and booking systems.
|
|
|
HSBC USA | Banking and Financial Services | 2040 | $3.9B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2016 | n/a |
In 2016, HSBC USA integrated Checkmarx One into its Application Security (AppSec) toolset to formalize static application security testing and source code analysis across development pipelines. The implementation occurred under the HSBC Global Security Testing Team, targeting high risk business critical applications including web applications, thick clients, and REST APIs, and supporting quarterly PCI DSS ASV assessments for 11 Asia Pacific and European countries.
Checkmarx One was configured to provide SAST and source code scanning capabilities, operating alongside DAST processes and manual testing to support a shift left strategy. The implementation emphasized automation and pipeline integration, with security testing automation fed into CI CD workflows to enable early detection of code level defects while preserving manual validation for false positive analysis and deep dive reviews.
Integrations extended to developer and security toolchains that were explicitly in use at HSBC, with API testing workflows using Postman and Burp Suite, and defect and risk management linked to systems such as JIRA, Kenna, eGRC Archer, Confluence, and an internally developed Comet system. The program also incorporated SaaS based security testing for cloud hosted infrastructure and aligned static analysis results with network and infrastructure scans from tools like Tenable IO for consolidated risk triage.
Governance changes included weekly application design reviews with project teams, formalized vulnerability likelihood analysis for risk rating, and collaborative remediation workflows with application development teams to align fixes to OWASP Top 10 guidance and internal security standards. The initiative supported ongoing Sec DevOps practices within HSBCs SDLC and contributed to achieving PCI compliance and quarterly attestation for networks in China, Canada, Hong Kong, and the United Kingdom.
|
|
|
Humana | Insurance | 95500 | $83.1B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2020 | n/a |
In 2020, Humana implemented Checkmarx One as its Application Security (AppSec) platform to centralize application vulnerability analysis and SAST capabilities across development and security functions. The Checkmarx One deployment was positioned to support DevSecOps practices and to automate security gating and code scanning within continuous integration pipelines.
Configuration and functional scope emphasized static application security testing, source code analysis, and the design of security gates using automated testing in the software development lifecycle. Implementation work included integrating security checks into Azure DevOps based CI/CD pipelines, defining WAF policies, and extending coverage to container security patterns that referenced Docker and Kubernetes orchestration concepts.
Operational integrations and toolchain interactions were explicit, with code scanning workflows at Humana covering more than 50 applications and using Rapid7 InsightAPP alongside Checkmarx One for vulnerability discovery. The program also referenced concurrent use and operational experiences with SonarCube, Qualys, Rapid7, and third-party library management tools such as JFrog, Nexus, and Artifactory, and it tracked remediation with ticketing and governance tools including Archer, Clarizen, and Nucleus. SIEM platform and DFIR tooling were part of the broader operational footprint for incident response and threat intelligence feeding application security efforts.
Governance and process changes focused on developer training in secure design and coding practices, vulnerability remediation coordination with application teams, and compliance engagement with Legal, internal financial teams, and audit owners. The effort supported audit and assessment readiness including HIPPA and Hi trust related activities, coordination of pentest timelines for TSA critical and PCI audited applications, and embedding vulnerability management workflows into remedial lifecycle processes.
|
|
|
Ingersoll Rand | Manufacturing | 21000 | $7.7B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2020 | n/a |
In 2020, Ingersoll Rand implemented Checkmarx One as part of its Application Security (AppSec) toolset. The effort was led by the vulnerability management lead with a core team of three focused on maturing the vulnerability management program under NIST guidance, and the implementation scope emphasized vulnerability triage, remediation orchestration, patching documentation, and stakeholder training across development and security operations.
Checkmarx One was configured to provide code analysis and static application security testing capabilities aligned with Application Security (AppSec) functional workflows, including role based administration, remediation workflow templates, and developer remediation guidance. The program integrated those code findings into documented remediation and patching processes, and the team administered complementary tooling to prioritize work.
The AppSec deployment operated within a multi tool stack that included Kenna Security for risk based prioritization, NetSparker for dynamic scanning, and Qualys for asset and vulnerability discovery, with outputs used for vulnerability triage and ticketing. Triage processes consolidated Qualys and code analysis results into Kenna Security for risk scoring and remediation tracking, and operational coverage captured remediation efforts and consolidated monthly vulnerability, configuration, and platform coverage KPIs for leadership reporting.
Governance and process changes included creation of vulnerability management workflows, remediation and patching documentation, training programs for stakeholders, and designation of escalation points for incident response and DLP issues. The program also incorporated compliance reviews and policy work to address GDPR, GLBA, and CCPA requirements, positioning Checkmarx One as the primary AppSec code analysis platform within the governed, risk based vulnerability management practice.
|
|
|
Mastercard | Banking and Financial Services | 35300 | $28.2B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2023 | n/a |
In 2023, Mastercard implemented Checkmarx One as its Application Security (AppSec) platform. The implementation is embedded within a global vulnerability management program run by a 60 plus person global team responsible for infrastructure scanning, SAST and DAST, red teaming, SBOM generation, and container vulnerability management operations.
Configuration of Checkmarx One emphasized SAST pipeline integration, DAST orchestration, SBOM ingestion, and container image scanning while enforcing a shift left security model to embed scanning into continuous integration and delivery pipelines without impeding time to market. The deployment standardized scanning configurations and developer feedback loops to transform developer scanning workflows and support automated vulnerability triage.
Mastercard consolidated security tooling leveraging Tenable, Checkmarx, and Nucleus platforms, aligning infrastructure scanning outputs from Tenable with application findings in Checkmarx One and centralizing vulnerability orchestration and reporting through Nucleus. Checkmarx One was configured to normalize vulnerability data feeds for enterprise consumption and to extend visibility into cloud environments and third party dependencies across global operations.
Governance and operational oversight were formalized with direct reporting to the Deputy CSO, ongoing collaboration with enterprise risk, audit, and compliance functions, and regular executive engagement that includes presentations to audit committees and board subcommittees. The program explicitly targeted improved SLA compliance and expanded visibility into cloud and third party security risks as part of the end to end transformation of Mastercard's vulnerability management workflows.
|
|
|
|
Professional Services | 5000 | $7.0B | Canada | Checkmarx | Checkmarx One | Application Security (AppSec) | 2025 | n/a |
|
|
|
|
Banking and Financial Services | 56366 | $23.1B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2022 | n/a |
|
|
|
|
Insurance | 3800 | $8.3B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2023 | n/a |
|
|
|
|
Banking and Financial Services | 98000 | $54.0B | Canada | Checkmarx | Checkmarx One | Application Security (AppSec) | 2017 | n/a |
|
|
|
|
Banking and Financial Services | 37086 | $20.3B | United States | Checkmarx | Checkmarx One | Application Security (AppSec) | 2022 | n/a |
|
Buyer Intent: Companies Evaluating Checkmarx One
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated | ||
|---|---|---|---|---|---|---|---|---|
| No data found | ||||||||