FOR DEVELOPERS | Get a 1-month free trial of Developer Assist
Platform overview
Checkmarx One
Agentic AI
Checkmarx One Assist
AI-powered Agentic AppSec agents preventing and remediating threats autonomously.
Developer Assist
Developer-first AI agent for instant vulnerability prevention and fix.
Posture
ASPM
Unified visibility, control and prioritization across your entire AppSec posture.
PARTNERSHIPS & INTEGRATIONS
Partner Programs
Building stronger AppSec ecosystems through trusted partnerships.
Find a Partner
Discover certified partners to accelerate your AppSec journey.
SOLUTIONS FOR
Code
Supply Chain
Cloud
Services
Developer-first Al agent preventing and remediating vulnerabilities instantly in IDE.
SAST
Market-leading, developer-friendly static application security testing and analysis
DAST
Developer tailored dynamic application scanning for efficient security issues remediation.
API Security
Enterprise scale API security scanning for early detection of critical vulnerabilities.
SCA
Identify, prioritize, and remediate open-source vulnerabilities, malicious code, and license risks.
Malicious Package Protection
Reveal and eliminate malicious open-source packages using industry’s largest database.
Repository Health
Enhance security with full visibility into code repository health.
Software Supply Chain Security
Protect your entire software supply chain with industry-leading security across legacy, open source, and Al-generated code.
Container Security
Secure containerized applications across SDLC, from code to cloud runtime.
laC Security
Secure cloud infrastructure via advanced scanning and vulnerability detection.
Premium Support
Enhance security outcomes and ROl with proactive, expert technical support.
Premium Services
Accelerate AppSec program success while maintaining seamless developer experience.
Maturity Assessment
Assess your AppSec maturity and unlock actionable improvement steps.
Why Checkmarx
Customer Stories
Awards
Industry Recognition
Integrations
For the Public Sector
COMPARE CHECKMARX
vs. Snyk
vs. GitHub
vs. Veracode
vs. Fortify
vs. Black Duck
vs. Semgrep
RESEARCH
Checkmarx Zero
Research Blog
Disclosed Vulnerabilities
Open-Source Tools
Resources
Analyst Reports
Product Demos
Solution Briefs
Videos
Webinars
Whitepapers
LEARN
Blog
Documentation
Glossary
Knowledge Hub
Customer Enablement
The 2025 Gartner® Magic Quadrant™ for Application Security Testing
Read more
IDC MarketScape for ASPM 2025
The Forrester SAST Wave 2025
Checkmarx One Solution Brief
COMPANY
About Us
Leadership
Press Releases
Newsroom
Events
Careers
PARTNERS
Partner Directory
Become a Partner
GET IN TOUCH
Support Portal
Contact Us
Case Study Highlights
“Build” takes on a new meaning for the well-known construction company as it constructs a security-first culture and an end-to-end AppSec program
PCL Construction is a leading North American contractor relying heavily on 100+ apps developed in-house. PCL needed a unified AppSec solution to simplify security for business-critical applications.
Industry
Construction and Engineering
Location
Edmonton, Canada
Checkmarx Solutions & Services
4 hours
to onboard Checkmarx One
4.4 million
lines of code scanned weekly
21+ applications
scanned every week
The Need
With cloud-based applications, PCL needed application security solutions designed for modern development, delivered from the cloud. Ideally, PCL also wanted AppSec solutions that were easy to integrate and automate and could help it shift security into every phase of the software development life cycle (SDLC).
With more than 100 applications, the price was also a consideration. “I wanted a tool that would work well for the developers and had a licensing model that wasn’t going to break the bank,” explained Joel Godbout, Cybersecurity and Networking Manager, PCL Construction.
The Solution
After thoroughly evaluating several solutions, the team selected the Checkmarx One™ Application Security Platform, with Static Application Security Testing (SAST) and Software Composition Analysis (SCA).
Checkmarx One, a cloud-based solution, is the most comprehensive AppSec platform on the market. The platform was specifically designed for cloud development and today’s technology stack, processes, vulnerabilities, and risks. It’s easy to use and can be seamlessly integrated into the developer’s existing tools and processes.
Checkmarx’s pricing model, which licenses users for unlimited apps, was also appealing. PCL is a growing enterprise and having an AppSec solution that will scale as PCL adds more applications is invaluable.
The Results
PCL first deployed Checkmarx One several months ago, and the process was fast and seamless. The PCL development team had the first scan running from an automated build in about four hours and the platform has been up and running ever since.
The company’s onshore development team, which includes approximately 50 developers, uses the solution daily, and the company hopes to roll out the platform to its offshore developers soon. The platform is easy to learn and integrates well into existing developer workflows—optimizing adoption.
Checkmarx Codebashing is also helping to drive developer adoption. “It becomes part of everybody’s workday, identifying potential problems before they start — and how to avoid them,” said Blaine Stearns, Lead Solution Architect, PCL Construction.
Today, PCL uses Checkmarx SAST to rapidly detect and remediate security risks in its applications. It also enables the team to prioritize risks so it can focus on the most important issues first. PCL automates its SAST scans—spanning millions of lines of proprietary and open-source code—for nearly a dozen applications, and it continues to add applications to the platform.
PCL leverages significant open-source code in its applications, and Checkmarx SCA saves the team significant time as it reduces the risk associated with open source threats. “We’re in a stronger position today when it comes to open source supply chain or package threats because of Checkmarx One,” explained Godbout.
Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.
Joel Godbout
Cybersecurity and Networking Manager | PCL Construction