Checkmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)
N/A
Pantheon
Score 9.8 out of 10
N/A
Pantheon is a WebOps platform where marketers and developers collaborate to drive results. The vendor states that with Pantheon, site owners maximize their capacity to update website design and functionality, responding to market trends, catering to consumer behavior, and adding real value to the business's bottom line. Today, companies compete on the basis of digital experiences, and the best results emerge from an agile build-test-learn process. Whether it's publishing content,…
If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
Pantheon is excellent for medium-large websites that require high availability and a managed workflow. It would be inappropriate for small websites because of the cost or for situations where more control of the environment is appropriate. We find it useful because we rarely do anything outside of the Drupal application.
Their API based customizations which I leveraged to create an ASPM package, which is developer friendly and can extend above the dashboard features, other ones are UI which is great and feels clutter free. Menu and navigation is also good so as support. Only drawback is sometimes scan takes longer which I feel so can be reduced
Pantheon is an easy system, especially to the users with previous experience with other similar platform and the interface is clear enough to easily understand how things operates. On the Cloud deployment everything also works effectively and the technical team from Pantheon community are very helpful on providing the necessary assistant to their customers.
Even tier 1 Pantheon chat and ticket support are knowledgeable, competent, and useful. They routinely understand and promptly resolve urgent, complex, and/or unusual issues that other hosts need to escalate to tier 2 or tier 3 support personnel. I honestly can't think of a truly negative or disappointing support experience in the years I've used Pantheon hosting for client websites.
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems
Although it may seem a good fit for a company that needs extra control over the deployment process and development process, for a firm that is mainly concentrating on SEO, it would be an overkill. Pantheon provides that sweet automation that allows us to shed some weight on development and focus on our business activities.