Webinar Series | Secure Coding in the AI Era with Developer Assist Agent
Platform overview
Checkmarx One
Agentic AI
Checkmarx One Assist
AI-powered Agentic AppSec agents preventing and remediating threats autonomously.
Developer Assist
Developer-first AI agent for instant vulnerability prevention and fix.
Posture
ASPM
Unified visibility, control and prioritization across your entire AppSec posture.
PARTNERSHIPS & INTEGRATIONS
Partner Programs
Building stronger AppSec ecosystems through trusted partnerships.
Find a Partner
Discover certified partners to accelerate your AppSec journey.
SOLUTIONS FOR
Code
Supply Chain
Cloud
Services
Developer assist
Developer-first Al agent preventing and remediating vulnerabilities instantly in IDE.
SAST
Market leading developer friendly statio application security testing and analysis
DAST
Developer tailored dynamic application scanning for efficient security issues remediation.
API Security
Enterprise scale API security scanning for early detection of critical vulnerabilities.
SCA
Identify, prioritize, and remediate open-source vulnerabilities, malicious code, and license risks.
Malicious Package Protection
Reveal and eliminate malicious open-source packages using industry’s largest database.
Repository Health
Enhance security with full visibility into code repository health.
Software Supply Chain Security
Protect your entire software supply chain with industry-leading security across legacy, open source, and Al-generated code.
Container Security
Secure containerized applications across SDLC, from code to cloud runtime.
laC Security
Secure cloud infrastructure via advanced scanning and vulnerability detection.
Premium Support
Enhance security outcomes and ROl with proactive, expert technical support.
Premium Services
Accelerate AppSec program success while maintaining seamless developer experience.
Maturity Assessment
Assess your AppSec maturity and unlock actionable improvement steps.
Why Checkmarx
Customer Stories
Awards
Industry Recognition
Integrations
COMPARE CHECKMARX
vs. Snyk
vs. GitHub
vs. Veracode
vs. Fortify
vs. Black Duck
vs. Semgrep
RESEARCH
Checkmarx Zero
Research Blog
Disclosed Vulnerabilities
Open-Source Tools
Resources
Analyst Reports
Product Demos
Solution Briefs
Videos
Webinars
Whitepapers
LEARN
Blog
Documentation
Glossary
Knowledge Hub
Customer Enablement
The 2025 Gartner® Magic Quadrant™ for Application Security Testing
Read more
IDC MarketScape for ASPM 2025
The Forrester SAST Wave 2025
Checkmarx One Solution Brief
COMPANY
About Us
Leadership
Press Releases
Newsroom
Events
Careers
PARTNERS
Partner Directory
Become a Partner
GET IN TOUCH
Support Portal
Contact Us
Case Study Highlights
The Taiwan-based enterprise reduces scan time from 48 hours to three to five minutes
-
Trade-Van is a spin-off of CCAPP, responsible for continuing CCAPP duties while also developing state-of-the-art technology and providing network services. Given that Trade-Van’s projects house sensitive data, it turned to Checkmarx for a source code scanning tool.
Industry
Financial Services
Location
Taiwan
Checkmarx Solutions & Services
4 hours
to onboard Checkmarx One
4.4 million
lines of code scanned weekly
21+ applications
scanned every week
The Need
Trade-Van realized the importance of securing its software development life cycle (SDLC) and implemented a policy, “never launch without source code inspection.” Trade-Van’s internal developers were initially tasked with manual code reviews; however, due to a large number of applications and software updates, Trade-Van quickly realized that the only way to ensure a secure SDLC was to adopt a source code scanning tool.
The Solution
After prudent evaluations, Trade-Van selected Checkmarx Static Application Security Testing (SAST) for its source code scanning solution. With the execution of a proof of concept, it was confirmed that Checkmarx is not only faster than competitors but also allows for incremental scans. Checkmarx SAST can be automated and integrated into developers existing tools and processes and it can generate reports according to international regulatory requirements such as OWASP Top 10, OWASP Mobile Top 10, SANS Top 25, PCI DSS, etc.
The Results
Since launching Checkmarx SAST, Trade-Van is able to conduct scans at a much faster pace. Instead of taking up to 48 hours to conduct one scan, it now takes three to five minutes.
Trade-Van is able to meet compliance and policy requirements with ease. By setting regulatory and criticality-based flaw policies, Trade-Van receives alerts from Checkmarx when updates are required to remain compliant with specified regulations or when a flaw meets its criticality threshold.
There’s no longer a need for developers to stagger developments due to a low-efficiency scanning tool. They can scan as frequently as needed — significantly improving time to deployments.
With AppSec scans integrated and automated into developers’ existing tools and processes, and with scan times significantly reduced, developers are seeing AppSec in a favorable light instead of as a potential bottleneck. In fact, Trade-Van developers have been actively addressing errors and working on how to avoid repeating mistakes.
During 2011 and 2012, we actively assessed other source code scanning tools. It wasn’t until GSS introduced Checkmarx that we knew we found the right fit.
Ming-Sheng Chiu
Deputy Manager of the Quality Assurance Centre | Trade-Van