Black Duck Polaris is a cloud-native application security testing platform that combines analysis across the software development life cycle. Its engines cover static analysis through Polaris fAST Static, software composition analysis through Polaris fAST SCA, and dynamic analysis through Polaris fAST Dynamic; it also scans infrastructure as code and detects secrets. Unified dashboards, intelligent correlation, contextual enrichment, portfolio analytics, and role-based views support risk prioritization. Polaris can generate software bills of materials from package-manager, signature, binary, and container analysis. It produces automated compliance reports for PCI DSS, HIPAA, GDPR, SOC 2, and ISO 27001, and maps findings to OWASP Top 10 and CWE. Repository integrations include Azure DevOps, Bitbucket, GitHub, and GitLab. Issue tracking supports Azure DevOps, Jira Cloud and Data Center, and ServiceNow, with two-way synchronization for Jira and ServiceNow. APIs cover issue data, triage, test automation, service accounts, and repository integrations. Pricing is on request, and a free trial is available. The service description limits an application to 1 million lines of code and a subscription application to five supporting projects.
Who it is for
Polaris suits software teams seeking coordinated application security analysis, reporting, and integrations across development workflows. Its stated application and project limits are important for teams assessing fit.
What is good
- Combines SAST, SCA, DAST, IaC analysis, and secrets detection.
- Generates SBOMs from four analysis approaches.
- Automates reports for five named compliance frameworks.
- Jira and ServiceNow support two-way synchronization.
- Free trial is available.
What to know first
- Pricing is available on request.
- Each application is limited to 1 million lines of code.
- A subscription application may have up to five supporting projects.
Verdict
Polaris combines multiple security analyses with portfolio-level views, compliance reporting, and development-tool integrations. Teams should check the stated code-size and supporting-project limits against their application setup.
Black Duck Polaris plans and pricing
All plansCompared on DevSecOps platforms
- Deployment model
- cloud
- Container scanning
- Yes
- Policy as code
- Yes
- Remediation workflows
- Yes
- SBOM management
- Yes
- Compliance reporting
- Yes






