Black Duck Polaris

6.9easy start · #11of 26
in DevSecOps Platforms
  • Free trialyes
  • Well documentedyes
  • Runs where you workno

Runs on api, Web.

Black Duck Polaris is a cloud-native application security testing platform that combines analysis across the software development life cycle. Its engines cover static analysis through Polaris fAST Static, software composition analysis through Polaris fAST SCA, and dynamic analysis through Polaris fAST Dynamic; it also scans infrastructure as code and detects secrets. Unified dashboards, intelligent correlation, contextual enrichment, portfolio analytics, and role-based views support risk prioritization. Polaris can generate software bills of materials from package-manager, signature, binary, and container analysis. It produces automated compliance reports for PCI DSS, HIPAA, GDPR, SOC 2, and ISO 27001, and maps findings to OWASP Top 10 and CWE. Repository integrations include Azure DevOps, Bitbucket, GitHub, and GitLab. Issue tracking supports Azure DevOps, Jira Cloud and Data Center, and ServiceNow, with two-way synchronization for Jira and ServiceNow. APIs cover issue data, triage, test automation, service accounts, and repository integrations. Pricing is on request, and a free trial is available. The service description limits an application to 1 million lines of code and a subscription application to five supporting projects.

Who it is for

Polaris suits software teams seeking coordinated application security analysis, reporting, and integrations across development workflows. Its stated application and project limits are important for teams assessing fit.

What is good

  • Combines SAST, SCA, DAST, IaC analysis, and secrets detection.
  • Generates SBOMs from four analysis approaches.
  • Automates reports for five named compliance frameworks.
  • Jira and ServiceNow support two-way synchronization.
  • Free trial is available.

What to know first

  • Pricing is available on request.
  • Each application is limited to 1 million lines of code.
  • A subscription application may have up to five supporting projects.

Verdict

Polaris combines multiple security analyses with portfolio-level views, compliance reporting, and development-tool integrations. Teams should check the stated code-size and supporting-project limits against their application setup.

Black Duck Polaris plans and pricing

All plans
Standard package Polaris fAST Static · IaC analysis · secrets detection · Polaris fAST SCA · dependency and CodePrint scanning · Polaris fAST Dynamic · API scanning · DevOps integrations · centralized policy configuration · dashboards and reporting blackduck.com · 1 Oct 2026
Build your own (à la carte) Flexible packaging · comprehensive application security blackduck.com · 1 Oct 2026

Compared on DevSecOps platforms

Deployment model
cloud
Container scanning
Yes
Policy as code
Yes
Remediation workflows
Yes
SBOM management
Yes
Compliance reporting
Yes

Best Black Duck Polaris alternatives

See all 20