Black Duck helps you build trust in your software by enabling you to manage application security, quality, and compliance risks at the speed your business demands. Our application security tools and services integrate directly with your existing AWS environment. Optimize your DevOps workflows and transform the way you build and deliver software by aligning people, processes, and technology to intelligently address software risks across your portfolio and at all stages of the application lifecycle.
Pricing listed is for Black Duck Binary Analysis - contact Black Duck for additional products and Private Offer pricing.
Highlights
Secure code as fast as you write it: Find and fix security defects in both your code and open source dependencies, directly within the IDE, with Code Sight.
Automate testing without compromising velocity: Integrate and automate security, quality, and compliance analysis source code, binaries, and IaC into your CI pipelines with Coverity SAST, Black Duck SCA and Black Duck Binary Analysis. Automate testing and detection of vulnerabilities and data leakage issues in cloud applications and microservices with Seeker IAST. Identify hidden zero-day vulnerabilities and reliability defects in IoT and network device software with Defensics Fuzzing.
Identify and focus on the highest risk security defects: Cut through the noise of AST findings with Software Risk Manager machine learning-based vulnerability correlation and prioritization that focuses remediation efforts on issues that pose the highest business risk. Correlate and prioritize findings across your AST tools and activities with Software Risk Manager to focus remediation efforts where they will have the greatest impact.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing option: an annual license covering 50 team members for binary analysis in the cloud. You commit for a 12-month term, and pricing is tied to the number of team members using the tool, set here at 50. This is a fixed-quantity contract rather than a usage-based or tiered structure. Binary analysis lets you inspect application contents without access to source code. To adjust the number of team members or change the term, you would work with the vendor directly.
Top-of-mind questions for buyers
What counts as one team member for the 50-member license?
A team member is a named user who accesses the binary analysis tool. The license covers up to 50 such users. Team members are counted by user account, not by device or scan. Adding users beyond 50 requires a change worked out with the vendor.
What does binary analysis scan, and does it need my source code?
Binary analysis inspects compiled application files without access to source code. It can open binaries to detect modified files and identify open source components, vulnerabilities, and license obligations inside packaged applications and containers. This lets you check software you did not build yourself.
Does my bill change based on how many scans I run?
No. Cost is fixed by the 50 team-member annual license, not by scan volume or usage. You pay the same flat fee for the 12-month term regardless of how many applications or containers you scan. To change member count or term, contact the vendor.
www.blackduck.com
Helpful?
Vendor refund policy
All fees are non-refundable
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. Black is a popular automatic code formatter for Python designed to enforce consistent code style across projects. It reformats Python source code according to a strict, opinionated set of formatting rules, reducing time spent debating code style and improving overall readability. By automatically handling indentation, line breaks, spacing, and code layout, Black ensures that codebases remain clean, uniform, and easier to maintain.
This product has charges associated with it for seller support. Black is a popular opinionated Python code formatter that automatically formats Python code according to a consistent style.
BlackBerry® AtHoc® is an industry-leading critical event management (CEM) and crisis communications solution that combines a secure emergency notification system with incident response tools and capabilities so you can quickly deploy your response teams and enable them to better prepare for, respond to, and recover from critical events faster.
Colorize black and white pictures with AI. Our picture colorizer is based on the latest machine learning research and is used by consumers and companies around the world.
Web interface: https://hotpot.ai/colorize-picture
Accurate Vulnerability Insights and Remediation—A Must-Have SCA Platform
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
Black Duck is the world leader for its SCA platform. The platform gives accurate vulnerabilities, line-to-line, along with correct remediations to fix the code. Must to have in your organisation.
What do you dislike about the product?
Nothing so far. Everything is good as per any organisation requirements.
What problems is the product solving and how is that benefiting you?
It solves Software Composition Analysis vulnerabilities like any deprecated libraries or packages used in your organisation and to replace them with the updated ones.
Computer Software
Excellent Visibility into Open-Source Vulnerabilities
Reviewed on Jun 28, 2026
Review provided by G2
What do you like best about the product?
Black Duck provides excellent visibility into open-source vulnerabilities. It makes it very easy to track our dependencies and confirm we aren’t shipping code that contains known security flaws.
What do you dislike about the product?
At times, the scans return a high number of false positives, which creates extra manual work for our team to review and dismiss them.
What problems is the product solving and how is that benefiting you?
Black Duck helps us address the problem of hidden vulnerabilities in our open-source dependencies. The biggest benefit is that it significantly reduces our security risk by enabling developers to spot and remediate issues well before they make it into production.
Md Sarfaraz H.
Reliable Open Source Security Tool with Strong CI/CD Integration
Reviewed on Jun 25, 2026
Review provided by G2
What do you like best about the product?
I like that Black Duck SCA makes it easy to identify vulnerable open-source dependencies and keeps track of newly discovered security issues. The reports are clear, and the CI/CD integration fits well into the development workflow. It also helps with license compliance, which is a big plus. The AI-powered insights are useful for understanding and prioritizing risks. The only downside is the pricing—it can be expensive, especially for smaller teams, but the features and visibility it provides make it worthwhile for larger organizations.
What do you dislike about the product?
One thing I don't like is the pricing—it can be quite expensive, especially for smaller teams. The initial setup and configuration also take some time, and the interface can feel a bit overwhelming for new users. Occasionally, there are false positives that need manual review, and I'd like to see faster scans and more intuitive reporting and dashboards. Overall, it's a solid tool, but there's definitely room to improve usability and cost.
What problems is the product solving and how is that benefiting you?
Black Duck SCA helps us identify security vulnerabilities and license compliance issues in open-source dependencies before they become bigger problems. It gives us visibility into the components used across our applications and alerts us when new vulnerabilities are discovered. This helps our team fix issues earlier in the development cycle, reduces security risks, supports compliance requirements, and saves time during security reviews and audits.
I appreciate how Black Duck reduces audit stress with its automated compliance reporting. It strengthens DevSecOps workflows by embedding open-source risk management directly into the CI/CD process. I find the detailed dashboards for audits very useful, and I like the customizable rules for governance offered by the policy control features.
What do you dislike about the product?
The UI sometimes feels dated and requires expertise to configure effectively. Additionally, the setup is heavy and tough, with a need to make it lighter and reduce the installation process.
What problems is the product solving and how is that benefiting you?
Black Duck helps manage open-source risks by detecting vulnerabilities and ensuring license compliance. It automates compliance reporting, reducing audit stress, and strengthens DevSecOps workflows by integrating risk management into CI/CD pipelines.
Renato Z.
High-Performing and Effective, with Appreciated Automatic Alerts
Reviewed on Apr 07, 2026
Review provided by G2
What do you like best about the product?
Perfoming and effective. Automatic alerts are really appreciated and
What do you dislike about the product?
Prices are not affordable and UX interface not so easy. Sometimes scanning are a little slow
What problems is the product solving and how is that benefiting you?
Black Duck helped us to understand where our code was not performing well. We improved visibility and we were able to keep under control security and legal risks