Attackers Got Faster.
Here’s How You Stay Ahead.
Your Checkmarx One protection gets stronger release by release.
See what’s live, what’s in early access, and what’s next, and get notified the moment each one ships.
HYBRID SCANNING
Checkmarx Fusion: Deterministic Precision Meets Frontier AI.
Most scanners force a choice: catch more and drown in noise, or cut the noise and miss what matters. Checkmarx Fusion does both. A rules-based or AI-based engine runs first depending on the language, then several curated frontier models reason over the code in parallel. The Findings Analysis Engine reconciles everything into one verified result set.
-
Trusted and complete
0.74 F1 in SAST, and the same answer every scan. 60–70% fewer false positives than standalone AI scanning.
-
Efficient at scale
Incremental scanning gets faster over time. Choose high- or low-cost models. Predictable spend, not a compounding token bill.
-
Works within Checkmarx One
Findings flow to Risk Orchestration, Triage Assist and Remediation Assist. One platform, not a silo.
Now Generally Available
Live in Checkmarx One today.
-
Explore LLM Scanner
AI Supply Chain Security
LLM Scanner: See the Risky Code Hiding Inside Your AI Models.
Checkmarx’s LLM Scanner exposes hidden code and security risks inside your AI model packages before they ever run in production. A new capability inside Checkmarx One (part of AI Supply Chain Security) that scans the hidden Python source code bundled inside AI model packages, before any model runs in production.
-
Explore NG SAST
HYBRID SCANNING ENGINES
NG SAST: Three Engines, One Clean Result Set.
Static analysis rebuilt on three layers: A deterministic rules-based foundation refined over two decades of enterprise AppSec. A purpose-tuned LLM engine that extends it to any language, including AI-generated code and emerging stacks. And the Findings Analysis Engine, which confirms true positives and suppresses false ones before a single finding reaches a developer. The result: 0.64 F1 and 60% fewer false positives, across every language in your stack.
-
Explore MCP Server
CHECKMARX ASSIST
Checkmarx MCP Server: AI Agents With Real Security Context.
The Checkmarx MCP Server gives AI coding assistants secure, governed access to Checkmarx One through a single MCP connection. Developers and agents can retrieve scan results, investigate vulnerabilities and act on remediation guidance with the same enterprise security context, across MCP-compatible IDEs, terminals and assistants, without building a custom integration for every tool.
-
Explore AI-BOM
AI SUPPLY CHAIN SECURITY
AI-BOM: Know Exactly What AI Is in Your Software.
LLMs introduce a class of dependency risk no traditional SBOM tracks: models, agents, MCP servers and fine-tuning datasets. The Checkmarx AI Bill of Materials gives security teams deterministic, auditable visibility into every AI component across the SDLC, mapped against NIST AI RMF, EU AI Act and ISO 42001 requirements. Know what AI is in your software before your auditors ask.
-
Explore the Agents
CHECKMARX ASSIST 2.0
Triage & Remediation Assist: Resolve Risk as Fast as AI Ships It.
Two autonomous agents that take the manual work out of vulnerability management. Triage Assist tells you what requires action and what can be safely ignored, using provable attackability and real-world exploitability rather than static severity scores. Remediation Assist generates review-ready fixes directly inside pull requests, so developers stay in flow.
Keep Your
Protection Current
Get news about product releases, early access invitations and the research behind them.