What is Black Duck Polaris?
Integrate AppSec to match the speed, scale, and ambition of AI-powered development with the Black Duck Polaris™ Platform. When innovation moves fast, your security must move faster. Accelerate modern software development with agentic AI AppSec that secures every line of code with no friction or delay.
Company Details
Need Assistance?
We're here to help you with understanding our reports and the data inside to help you make decisions.
Get AssistanceBlack Duck Polaris Ratings
Real user data aggregated to summarize the product performance and customer experience.
Download the entire Product Scorecard
to access more information on Black Duck Polaris.
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
90 Likeliness to Recommend
1
Since last award
83 Plan to Renew
1
Since last award
86 Satisfaction of Cost Relative to Value
1
Since last award
Emotional Footprint Overview
Product scores listed below represent current data. This may be different from data contained in reports and awards, which express data as of their publication date.
+90 Net Emotional Footprint
The emotional sentiment held by end users of the software based on their experience with the vendor. Responses are captured on an eight-point scale.
How much do users love Black Duck Polaris?
Pros
- Helps Innovate
- Continually Improving Product
- Trustworthy
- Unique Features
How to read the Emotional Footprint
The Net Emotional Footprint measures high-level user sentiment towards particular product offerings. It aggregates emotional response ratings for various dimensions of the vendor-client relationship and product effectiveness, creating a powerful indicator of overall user feeling toward the vendor and product.
While purchasing decisions shouldn't be based on emotion, it's valuable to know what kind of emotional response the vendor you're considering elicits from their users.
Footprint
Negative
Neutral
Positive
Feature Ratings
SDLC Integration
Policy Engine and Enforcements
Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA)
Mobile Application Security Testing
Interactive Application Security Testing (IAST)
Integrated Development Environment (IDE) plug-in
False Positive Remediation
Risk Scoring
Static Application Security Testing (SAST)
Container Security Testing
Vendor Capability Ratings
Ease of IT Administration
Ease of Data Integration
Vendor Support
Availability and Quality of Training
Business Value Created
Breadth of Features
Ease of Customization
Quality of Features
Ease of Implementation
Usability and Intuitiveness
Product Strategy and Rate of Improvement
Black Duck Polaris Reviews
Adnan K.
- Role: Information Technology
- Industry: Engineering
- Involvement: End User of Application
Submitted Nov 2024
Black Duck - leader in application security testin
Likeliness to Recommend
What differentiates Black Duck Polaris from other similar products?
Real-Time Alerts and Notifications
What is your favorite aspect of this product?
snippet scanning
What do you dislike most about this product?
Higher Cost for Licensing and Deployment. Black Duck is often considered a premium solution, and its cost can be a barrier for smaller teams or companies. License costs can grow significantly with larger codebases and complex configurations.
What recommendations would you give to someone considering this product?
Synopsys software integrity group is now operating as an independent company - Black Duck. This product is no longer a part of Synopsys offering.
Pros
- Enables Productivity
- Trustworthy
- Unique Features
- Altruistic
Rakesh S.
- Role: Information Technology
- Industry: Other
- Involvement: End User of Application
Submitted Sep 2026
Comprehensive security testing platform.
Likeliness to Recommend
What differentiates Black Duck Polaris from other similar products?
Instead of managing separate tools for SAST, SCA, DAST, IaC and secrets scanning it provides a unified view of application security. This makes it easier for development teams to understand the overall risk of an application and prioritize what actually needs to be fixed.
What is your favorite aspect of this product?
I like most is the developer focused approach. It makes it easier to identify security issues early in the development cycle and gives developers actionable findings without requiring them to constantly switch between different security tools.
What do you dislike most about this product?
For larger codebases scans can take some time to complete. This isn't a major issue for smaller projects but it can become noticeable when working with large applications or multiple repositories.
What recommendations would you give to someone considering this product?
I would suggest starting with a small pilot instead of rolling it out across the entire organization immediately. Test it on a few real applications, check the quality of the findings, false positive rate, scan performance and how easily developers can act on the results. Then decide whether it provides enough value to scale.
Pros
- Reliable
- Trustworthy
- Effective Service
- Saves Time
Cons
- Less Inspiring
Ram S.
- Role: Information Technology
- Industry: Engineering
- Involvement: IT Development, Integration, and Administration
Submitted Apr 2026
Comprehensive open source security tool
Likeliness to Recommend
What differentiates Black Duck Polaris from other similar products?
Strong focus on open source (SCA) security and license compliance Extensive vulnerability and component knowledge base Accurate detection of open source dependencies (including transitive)
What is your favorite aspect of this product?
Deep visibility into open source risks and licenses Reliable and accurate dependency detection Clear policy-based risk management
What do you dislike most about this product?
Setup and onboarding can be complex Scans may take time on large codebases UI can feel less intuitive in some areas
What recommendations would you give to someone considering this product?
Start with policy configuration before running scans Integrate early into CI/CD for better results Train teams on license compliance and security usage
Pros
- Performance Enhancing
- Inspires Innovation
- Caring
- Saves Time