Code Dx
Code Dx, a subsidiary of Synopsys since its acquisition in 2021, provides application security posture management (ASPM) tools designed to consolidate and prioritize vulnerabilities across the software development lifecycle.
Profile
Consolidates application security findings from multiple tools into prioritized risks for development teams.
Code Dx, a subsidiary of Synopsys since its acquisition in 2021, provides application security posture management (ASPM) tools designed to consolidate and prioritize vulnerabilities across the software development lifecycle. The company's flagship product, Software Risk Manager, integrates with over 150 third-party security tools to provide a unified view of risks in custom code, open source components, APIs, and containers. Originally founded as an independent vendor, Code Dx now operates within Synopsys' Software Integrity Group, leveraging its parent company's resources while maintaining its distinct product branding.
The platform is used by over 4,000 organizations, including notable clients like Broad Institute and the U.S. Department of Homeland Security. Recent focus areas include mapping findings to compliance standards like HIPAA and NIST, with particular emphasis on reducing alert fatigue for development teams. The 2023 Black Duck by Synopsys annual report indicated continued growth in enterprise ASPM adoption, though specific financials for Code Dx are no longer broken out separately post-acquisition.
Who buys this
- Enterprise DevOps teams managing complex application portfolios
- Financial services firms with strict compliance requirements
- Government agencies securing critical infrastructure
- Healthcare organizations managing PHI compliance
- Technology companies scaling secure development practices
Publicly disclosed clients
- Broad Institute
- U.S. Department of Homeland Security
Strengths and what to watch
Strengths
- Deep integration with 150+ security tools including SAST, DAST, and SCA solutions
- Policy engine for centralized security rule enforcement across development teams
- Compliance mapping for 20+ standards including NIST and HIPAA
Watch for
- Dependence on Synopsys' roadmap post-acquisition may limit product autonomy
- Increasing competition from standalone ASPM vendors like ArmorCode and Cycode
- Potential feature overlap with Synopsys' existing application security tools
Key Information
- Founded
- 2015
- Headquarters
- Northport
Frequently Asked Questions
What is Code Dx used for?
Code Dx consolidates security findings from multiple tools into prioritized risks for development teams. Its Software Risk Manager integrates with 150+ security tools, providing a unified view of vulnerabilities in custom code, open source components, and containers while reducing alert fatigue. Over 4,000 organizations use the platform.
How does Code Dx help with compliance?
Code Dx maps security findings to 20+ compliance standards including HIPAA and NIST. Its policy engine enables centralized security rule enforcement across development teams, particularly useful for financial services, healthcare, and government agencies with strict regulatory requirements for application security.
What companies use Code Dx?
Code Dx serves over 4,000 organizations including notable clients like Broad Institute and the U.S. Department of Homeland Security. Primary customer segments include enterprise DevOps teams, financial services firms, government agencies, healthcare organizations, and technology companies scaling secure development practices.
How many tools does Code Dx integrate with?
Code Dx integrates with more than 150 third-party security tools, including SAST, DAST, and SCA solutions. This extensive integration ecosystem allows teams to consolidate findings from multiple scanners into a single prioritized view of application security risks across the development lifecycle.
Who owns Code Dx now?
Synopsys acquired Code Dx in 2021, and it now operates within Synopsys' Software Integrity Group. While maintaining its product branding, Code Dx leverages Synopsys' resources. Financial details are no longer reported separately post-acquisition, per Synopsys' 2023 Black Duck report.
How does Code Dx compare to other ASPM tools?
Code Dx differentiates with its 150+ tool integrations and compliance mapping features. However, it faces competition from standalone ASPM vendors like ArmorCode and Cycode, and potential feature overlap with Synopsys' existing security tools may influence its roadmap post-acquisition.
Sources
- codedx.com — Product capabilities and integration claims
- www.blackduck.com — Customer count and compliance standard mappings
- www.blackduck.com — Notable client references
- techcrunch.com — Competitive landscape context