Black Duck static application security testing (SAST) tools provide fast, scalable, and comprehensive static code analysis in the cloud, on premises, and at the developer desktop.

Find issues earlier

Run code scans early in the SDLC to prevent issues from delaying releases.

Streamline workflows

Integrate static analysis results into your existing tools to resolve issues quickly.

Eliminate the noise

Focus on what matters by reducing false positives and prioritizing critical issues.

Code smarter, not harder

Don’t let code defects derail your release. Integrate Black Duck SAST tools throughout the SDLC to catch issues earlier.

Notify developers of security and quality issues as they code, so problems get resolved before they’re committed.

Integrate static analysis when and where you need it

No matter what your development stack looks like, code scans integrate seamlessly into your development and DevOps workflows and toolchains.

Static Code Analysis Tools Image

Scan in the cloud

Polaris fAST Static is an easy-to-use SaaS solution that quickly scans your code for vulnerabilities, secrets, and misconfigured IaC templates. And it offers prebuilt integrations into leading SCM and CI/CD solutions.

Static Code Analysis Tools Image

Scan on premises

Coverity® Static Analysis helps teams deliver highly reliable software that complies with functional safety, security, and industry standards such as MISRA, CERT C/C++, and OWASP Top 10.

Static Code Analysis Tools Image

Scan in the IDE

Code Sight™ IDE Plug-in scans code as it’s written to find security and quality issues in real time, without slowing you down.

Ensure comprehensive analysis of diverse applications

Our static analysis tools are built on a universal scan engine that delivers the same fast, accurate, and scalable results in the cloud, on premises, and in the IDE.

Provide complete language and framework support

We support over 20 languages and 250 frameworks to provide highly accurate results.

Run fast scans at just the right time

Scan on your terms with fast scans early in the SDLC or in-depth full-project scans.

Configure checkers to fit your needs

Reduce false positives with configurable checkers to fit your risk profile.

The Black Duck advantage

Since 2016, Black Duck has been a Leader in the Gartner® Magic Quadrant for Application Security Testing. See why our customers rely on Black Duck to help them build trust in their software.

Customer testimonials

“Using Coverity has helped enhance our mandate to ensure code quality and security, as well as to enforce our compliance with SEI-CERT coding standards for C, C++, and Java, and MISRA standards for C.”
Thales Alenia Space
“Coverity gave us a code quality approach that was very efficient, especially given the multimillion lines of code that needed to be scanned”
Mega International

Customer success stories: 4,000+ organizations trust Black Duck

BroadInstitute-Logo-color
DHS-Logo-color
TrendMicro-Logo-color
Honeywell-Logo-color
Ceva-Logo-color
CGI-Logo-color
Commence(formerly DOMA)-Logo-color
Exterro(formerly-AccessData)-Logo-color
Finra-Logo-color
Leonardo-Logo-color
Linx-Logo-color
magnet-marelli-logo-color
Nuance-Logo-color
Olympus-Logo-color
Oppo-Logo-color
ScienceLogic-Logo-color
ZPE-Logo-color
nasa-logo-color
BAM-Technologies-Logo-color
0 %
of the Fortune 100
0 %
of the top 10 financial services companies
0 %
of the top 10 technology companies
0 %
of the top 10 Fortune Global 500 automotive companies

Static application security testing resources

Report

Gartner® Magic Quadrant

See why Black Duck is a Leader in application security testing
Case Study

Thales Alenia Space

Ensuring software reliability and security from design through development
White paper

Build reliability and security into your SDLC

Deliver robust software quickly with Coverity
Datasheet

Coverity Static Analysis

Scalable static analysis for secure, high-quality code delivery