# Checkmarx vs Endor Labs

**Leader by vioscaleAI score:** Endor Labs

| Attribute | Checkmarx | Endor Labs |
|---|---|---|
| **vioscaleAI score** | 53.6 (46% (low)) | 67.3 (71% (medium)) |
| content.faq | `[{"answer":"Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. It is indexed under DevSecOps Tools.","source":"https://checkmarx.com","question":"What is Checkmarx?","confidence":0.6},{"answer":"Checkmarx does not publish its prices. Pricing is quoted on request, across 3 plans (Essentials, Professional and Enterprise), so the figure depends on your seat count and requirements. We record this as a pricing-transparency signal rather than guessing a number. Pricing changes often, so verify at source before relying on it.","source":"https://checkmarx.com","question":"How much does Checkmarx cost?","confidence":0.6},{"answer":"We have confirmed browser-based access to Checkmarx. That is the extent of what we could verify from public sources, so it may well offer desktop or mobile clients we have not indexed.","source":"https://checkmarx.com","question":"What platforms does Checkmarx support?","confidence":0.6},{"answer":"We have only confirmed a cloud / SaaS deployment for Checkmarx, so it appears to be vendor-hosted. If a self-hosted option exists we have not found it documented publicly.","source":"https://checkmarx.com","question":"Can Checkmarx be self-hosted?","confidence":0.6},{"answer":"We have independently confirmed SOC 2, ISO 27001 and GDPR for Checkmarx. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Checkmarx not holding them. Always confirm compliance directly before you rely on it.","source":"https://checkmarx.com/blog/security-in-vibe-coding/","question":"What security certifications does Checkmarx have?","confidence":0.7},{"answer":"Checkmarx is available in Australia, Germany, France, the United Kingdom, Israel, India, Portugal and Singapore. The vendor is headquartered in Israel.","source":"https://checkmarx.com","question":"Where is Checkmarx available?","confidence":0.75}]` | `[{"answer":"An application security platform that uses AI agents to identify and fix vulnerabilities in code and dependencies with context-aware analysis. It prioritizes reachable, exploitable vulnerabilities and integrates directly into developer tools and CI pipelines to reduce manual triage. It is indexed under DevSecOps Tools.","source":"https://www.endorlabs.com/learn/cyber-insurers-are-pricing-based-on-patching-speed","question":"What is Endor Labs?","confidence":0.6},{"answer":"Endor Labs offers a free tier, so you can start without paying. Paid plans are also available: Developer, Core and Pro. Pricing changes often, so verify at source before relying on it.","source":"https://www.endorlabs.com/pricing","question":"Is Endor Labs free?","confidence":0.6},{"answer":"Endor Labs supports the web and a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.","source":"https://www.endorlabs.com/learn/cyber-insurers-are-pricing-based-on-patching-speed","question":"What platforms does Endor Labs support?","confidence":0.6},{"answer":"Yes. Endor Labs can be deployed cloud / SaaS and self-hosted, so it does not have to run on the vendor's infrastructure.","source":"https://www.endorlabs.com/learn/cyber-insurers-are-pricing-based-on-patching-speed","question":"Can Endor Labs be self-hosted?","confidence":0.6},{"answer":"We have confirmed 10 integrations for Endor Labs, including GitHub, GitLab, BitBucket, Azure DevOps, AWS Marketplace, Microsoft Azure, Google Cloud Marketplace and Wiz, plus 2 more. This is what we could verify from public sources, so the vendor may support others we have not indexed.","source":"https://www.endorlabs.com/learn/cyber-insurers-are-pricing-based-on-patching-speed","question":"What does Endor Labs integrate with?","confidence":0.6},{"answer":"We have independently confirmed SOC 2 for Endor Labs. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Endor Labs not holding them. Always confirm compliance directly before you rely on it.","source":"https://www.endorlabs.com","question":"What security certifications does Endor Labs have?","confidence":0.48},{"answer":"Endor Labs is available worldwide. Its primary market is the United States. The vendor is headquartered in the United States.","source":"https://www.endorlabs.com/pricing","question":"Where is Endor Labs available?","confidence":0.75}]` |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"self_hosted":true}` |
| description.long | Checkmarx integrates static analysis (SAST), dynamic analysis (DAST), dependency scanning (SCA), and specialized AI-based analysis to detect vulnerabilities across code, dependencies, and AI components. It prioritizes findings by exploitability and reachability while embedding directly into development tools and CI/CD pipelines. | An application security platform that uses AI agents to identify and fix vulnerabilities in code and dependencies with context-aware analysis. It prioritizes reachable, exploitable vulnerabilities and integrates directly into developer tools and CI pipelines to reduce manual triage. |
| features.capabilities | `{"sca":true,"dast":true,"sast":true,"sbom":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"iac_scanning":true,"reachability":true,"secret_scanning":true}` | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":false,"iac_scanning":false,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}` |
| integrations.count | 1 | 10 |
| integrations.list | `[{"name":"Wiz"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"BitBucket"},{"name":"Azure DevOps"},{"name":"AWS Marketplace"},{"name":"Microsoft Azure"},{"name":"Google Cloud Marketplace"},{"name":"Wiz"},{"name":"Cursor AI"},{"name":"Microsoft Defender for Cloud"}]` |
| market.availability | `{"hqCountry":"IL","primaryMarkets":[],"availabilityScope":"global","availableCountries":["AU","DE","FR","GB","IL","IN","PT","SG","US"],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"quote","plans":[{"free":false,"name":"Essentials","summary":"Custom quote required","features":["SAST","SCA","API Security","ASPM visibility","Core reporting"],"description":"Core application security coverage. Establish a unified foundation for identifying, managing, and reporting application risk.","contactSales":true},{"free":false,"name":"Professional","summary":"Custom quote required","features":["Everything in Essentials","DAST","IaC Security","AI Security","Advanced ASPM","PR Decorations"],"description":"Advanced protection and AI-powered security. Scale your AppSec program with AI-assisted remediation and deeper multi-layer coverage.","contactSales":true},{"free":false,"name":"Enterprise","summary":"Custom quote required","features":["Everything in Professional","Supply Chain Security","Container Security","Runtime Protection","Custom Policies","Executive Reporting"],"description":"Complete coverage and full compliance. Maximum coverage and control for organizations with the most demanding security requirements.","contactSales":true}],"summary":"All three tiers require custom quote. No published per-seat or usage-based pricing.","freeTier":false,"sourceUrl":"https://checkmarx.com","retrievedAt":"2026-08-05T14:23:25.473Z"}` | `{"type":"subscription","plans":[{"free":true,"name":"Developer","summary":"Free for individual developers","features":["Local scanning","Read-only vulnerability data"],"description":"Free tier for individual developers with local scanning and read-only access to vulnerability data","contactSales":false},{"free":false,"name":"Core","description":"Team-oriented tier with reachability analysis, prioritization, and policies","contactSales":false},{"free":false,"name":"Pro","description":"Enterprise-scale tier with advanced detection, triage, and fix capabilities across application layers","contactSales":false}],"summary":"Seat-based subscription pricing with free Developer tier; specific pricing available on request","currency":"USD","freeTier":true,"sourceUrl":"https://www.endorlabs.com/pricing","retrievedAt":"2026-08-14T09:22:26.641Z","billingPeriods":["month","year"]}` |
| pricing.free_tier | no | yes |
| pricing.model | commercial | free |
| pricing.price_level | unknown | free |
| pricing.transparent | no | no |
| reliability.sla_pct | - | 99.9 |
| reliability.status_page | - | yes |
| security.certifications | `[{"name":"SOC 2 Type II","status":"active"},{"name":"ISO 27001","status":"active"}]` | - |
| security.disclosure_policy | - | yes |
| security.fedramp | yes | yes |
| security.gdpr | yes | - |
| security.iso27001 | yes | - |
| security.pci | - | yes |
| security.soc2 | yes | yes |
| security.trust_center | https://checkmarx.com/blog/security-in-vibe-coding/ | https://www.endorlabs.com/use-cases/digital-operational-resilience-act-dora-compliance |

## Capabilities (DevSecOps Tools)

| Capability | Checkmarx | Endor Labs |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | ✓ |
| DAST (dynamic analysis) | ✓ | ✗ |
| SCA / dependency scanning | ✓ | ✓ |
| Secret scanning | ✓ | ✓ |
| Container / image scanning | - | ✓ |
| IaC misconfiguration scanning | ✓ | ✗ |
| **Governance** |  |  |
| OSS licence compliance | - | ✓ |
| SBOM generation (SPDX/CycloneDX) | ✓ | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | ✓ |
| **Licensing** |  |  |
| OSS engine available | - | ✗ |

*Source: vioscaleAI. Generated 2026-09-21T03:36:50.902Z. "-" = undocumented, not absent.*
