Polaris Platform
Integrated SaaS application security platform that combines static analysis, software composition analysis and dynamic testing with centralised policy, workflow and reporting for development and security teams working at scale.
Black Duck Software is an application security testing company headquartered in Burlington, Massachusetts. Formerly the Synopsys Software Integrity Group, it became an independent company on 1 October 2024 following its acquisition by Clearlake Capital and Francisco Partners. More than 4,000 organisations rely on its tools and services, and it has been recognised as a Leader in the Gartner Magic Quadrant for Application Security Testing eight times.
Black Duck Software is an application security testing company headquartered in Burlington, Massachusetts. Formerly the Synopsys Software Integrity Group, it became an independent company on 1 October 2024 following its acquisition by Clearlake Capital and Francisco Partners. More than 4,000 organisations rely on its tools and services, and it has been recognised as a Leader in the Gartner Magic Quadrant for Application Security Testing eight times.
The portfolio spans static analysis, software composition analysis, interactive testing, fuzzing and application security posture management, delivered on-premises or through the Polaris SaaS platform. For enterprises and government bodies in the Middle East that build software in-house or procure it from suppliers, Black Duck provides the evidence base for secure development, open-source licence compliance and emerging regulatory obligations such as the EU Cyber Resilience Act.
Integrated SaaS application security platform that combines static analysis, software composition analysis and dynamic testing with centralised policy, workflow and reporting for development and security teams working at scale.
Static application security testing that finds defects and vulnerabilities in source code across languages including Rust, now with AI-assisted triage, a Model Context Protocol server for coding agents and CRA-aligned checkers.
Software composition analysis that identifies open-source and third-party components, known vulnerabilities and licence obligations, and generates software bills of materials for software supply chain security programmes.
Interactive application security testing that instruments running applications during functional and QA testing to detect exploitable vulnerabilities with runtime context, verified findings and minimal false positives for web application teams.
Agentic AI application security purpose-built for AI-generated code, integrating through MCP and APIs with coding assistants, IDEs and pipelines to assess risk, validate findings and automate remediation continuously.
Black Duck's AI strategy addresses the speed and volume of code produced by AI coding assistants. Black Duck Signal, generally available since March 2026, combines large language model reasoning with ContextAI, the company's application security model built on petabytes of human-validated security intelligence, to deliver higher-fidelity analysis and automated fixes inside agentic development workflows.
Across the wider portfolio, Coverity now offers AI-assisted issue triage and an MCP server that lets AI coding agents query results, running on the customer's own LLM of choice. In September 2026 Black Duck joined Anthropic's Project Glasswing, applying the Mythos model across its portfolio for AI-accelerated vulnerability discovery, and Black Duck Signal debuted on the Claude Directory.
Where Black Duck fits in the four-layer AI stack we bring to partners.
Explore the layerBlack Duck joined the industry initiative to secure critical software infrastructure with advanced AI, applying the Mythos model across its application security portfolio to combine AI-accelerated vulnerability discovery with trusted remediation and compliance-driven governance.
New Coverity capabilities include AI-assisted triage, a Model Context Protocol server for coding agents, IDOR detection for JavaScript and TypeScript, Rust 1.92 support, a Security Impact Lens and CRA-aligned checkers, all generally available.
Gartner evaluated 18 vendors on Completeness of Vision and Ability to Execute in the first edition of this Magic Quadrant, recognising Black Duck's software composition analysis and supply chain security capabilities.
Signal secures AI-generated code in autonomous development workflows, integrating through MCP and APIs with AI coding assistants, IDEs and pipelines, and using ContextAI to reduce false positives and automate remediation at AI speed.
Architecture, sizing and proof-of-concept support so partners propose the right configuration first time.
02Certification paths, workshops and demo access that build partner capability around the portfolio.
03Local stock, professional services, escalation and RMA handling across Saudi Arabia and the region.
Speak with our team about availability, solution design and partner enablement.