Black Duck
Black Duck (formerly Synopsys Software Integrity Group) provides a comprehensive application security platform focusing on Software Composition Analysis (SCA) and static/dynamic testing. It enables organizations to manage open-source risks, identify vulnerabilities in proprietary code, and ensure license compliance across the SDLC. The platform complements DevSecOps workflows by integrating security gates into CI/CD pipelines and providing deep visibility into software supply chain risks.
Visit websiteAsk about pricing, alternatives, or if Black Duck is right for you.
The Picari read
Black Duck provides DAST and SAST for teams that need both source-code analysis and runtime testing in one platform. Its main differentiator in this category is the combination of Polaris fAST Static, Polaris fAST Dynamic, and Continuous Dynamic for scanning web apps and APIs before and after deployment. It fits enterprises that want vendor-managed application security testing with low-false-positive validation.
- Organizations seeking a comprehensive application security platform that integrates SCA, SAST, and DAST across the SDLC.
- Managing open-source software risks and license compliance.
- Identifying security vulnerabilities in proprietary and third-party code.
- Integrating security testing into CI/CD pipelines.
- Automating security gates within the SDLC.
Product catalogue
Black Duck pricing and integrations
For Black Duck integration and pricing details, ask Picari. Start a briefing with your question, such as whether it connects to your SIEM, identity provider and ticketing stack, or how it is priced at your seat count and data volume.
Unverified profile
This profile hasn't been verified by Black Duck yet. Information may be incomplete.
Are you from Black Duck? Verify this profileProfile last updated on 7 September 2026 by Picari.