{"kind":"atlas-fold-dated-history","notice":"Documentation research, not measured product performance. The first snapshot is a baseline, not a trend. Compare unchanged scope and rubric; research corrections are not product momentum.","segment":"application-security","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"application-security","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"appsec-testing-platforms","name":"Application security testing platforms","scope":"Commercial offerings evaluated with at least SAST and SCA. Additional DAST modules are explicit in edition scope; no registry-only, hardened-image or ASPM-only comparison."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented scan-to-triage operating workflow in the selected combined testing scope. Refinement credit can apply to a specifically selected module; it does not establish the same workflow across every testing engine. Each credited component states its module boundary.","question":"Can operators configure scans, inspect findings and apply policy to results?","anchors":["The vendor explicitly states that application testing is unavailable in this edition.","A documented standalone scan.","Scans produce reviewable findings.","Documented scan configuration, findings review and policy evaluation or delivery gates.","Stage 3 plus repeat scans, accepted-risk/exception lifecycle and scan execution diagnostics.","Stage 4 plus documented restoration/recovery and controlled configuration promotion."],"refinements":[{"base":3,"criteria":[{"id":"repeat-scans","label":"Documented repeat scans and continuity of results within the evaluated testing scope","weight":3},{"id":"exception-lifecycle","label":"Documented accepted-risk or exception lifecycle with explicit module boundaries","weight":4},{"id":"scan-diagnostics","label":"Documented scan execution diagnostics within the evaluated testing scope","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented workflows relative to established multi-engine application testing and delivery integration.","question":"Is there a substantiated shipped workflow beyond ordinary SAST/SCA, findings triage and CI policy gates?","anchors":["The vendor explicitly states that this edition has no testing automation.","A single automated scan.","Scanning connected to a delivery workflow.","Established baseline: multiple testing techniques with developer workflow integration or policy gates; no novelty claim.","A concrete shipped workflow beyond the baseline with evidenced differentiation and scope limits.","Multiple documented beyond-baseline workflows with controls and explicit operating limits."]},{"id":"breadth","name":"Capability breadth","description":"Testing techniques documented in the explicitly selected combined commercial scope, not detection coverage rates.","question":"Which testing techniques are documented for the selected modules?","anchors":["The vendor explicitly states that testing is unsupported.","One testing technique.","Both static code analysis and software composition analysis.","Stage 2 plus documented dynamic web/API testing in the selected commercial modules.","Stage 3 plus infrastructure/container testing and a shared cross-technique findings workflow.","Stage 4 plus documented language/framework coverage and test-type limitations throughout the selected bundle."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented paths into source control, development tools and delivery pipelines.","question":"How do scans and findings connect to the existing development toolchain?","anchors":["The vendor explicitly states that external integration is unsupported.","Manual upload or an isolated console workflow.","A documented SCM, CLI or API integration path.","Documented source-control and delivery-pipeline integration paths.","Stage 3 plus IDE and ticketing integration with stated permissions or data-flow requirements.","Stage 4 plus custom extension APIs with version/compatibility and authentication guidance."]},{"id":"governance","name":"Governance & control","description":"Documented testing policies and identity/access controls; no compliance certification inference.","question":"What controls govern policy decisions and access to findings?","anchors":["The vendor explicitly states that policy and access controls are absent.","Configurable security policy or delivery checks.","Stage 1 plus documented centralized authentication or operator roles.","Stage 2 plus scoped policy administration and audit of policy or finding changes.","Stage 3 plus an approved exception lifecycle and separation of administration from assessment.","Stage 4 plus documented organization-wide controls and exportable evidence of changes."]},{"id":"operations","name":"Operator enablement","description":"Documented configuration, findings review and remediation guidance for operators and developers.","question":"What procedures help a team run scans and act on the findings?","anchors":["The vendor explicitly states that operator tooling is absent.","Instructions for launching a scan.","Scan configuration plus findings inspection.","Stage 2 plus documented remediation or policy-failure workflows.","Stage 3 plus troubleshooting, scan diagnostics and documented language/framework limitations.","Stage 4 plus repeatable rollout, recovery and operator training procedures."]}],"assessments":[{"vendor":"checkmarx-one","cohort":"appsec-testing-platforms","edition":"Checkmarx One with SAST, SCA and DAST modules explicitly selected; confirm separate engine entitlements","asOf":"2026-09-21","status":"research-preview","summary":"Public engine and policy procedures support a combined application-testing workflow. The evaluated configuration requires the named modules; purchasing the platform name alone does not establish entitlement.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Scan configuration, findings review and delivery policy establish stage 3. Documented continuity across repeated scans adds 0.3; DAST execution logs add 0.3. The score is 3.6. A full accepted-risk/exception lifecycle across the selected scope was not established, and a false-positive state alone is not treated as accepted risk.","sourceIds":["c1","c2","c4","c6","c7"],"refinement":{"base":3,"evidence":[{"criterion":"repeat-scans","rationale":"The vulnerability lifecycle describes recurring findings across subsequent project scans and persistence of triage metadata. This establishes repeat-scan continuity; it does not prove remediation efficacy.","sourceIds":["c6"]},{"criterion":"scan-diagnostics","rationale":"The selected DAST module documents successful scan history and download of scan logs for investigating unsuccessful executions. This credit is scoped to that module, not every engine.","sourceIds":["c7"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Combined scanning and PR/build policy checks meet the established application-testing baseline. No beyond-baseline innovation is inferred from AI or platform branding.","sourceIds":["c1","c2","c4"]},"breadth":{"score":3,"confidence":"medium","rationale":"Separate procedures document SAST, SCA and DAST in the selected research configuration. All three modules require appropriate entitlement; this is not an actual procurement quote. Language and target support still need validation.","sourceIds":["c1","c2","c3"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Source-control and pipeline paths remain established. VS Code setup documents browser/API-key authentication and regional connection settings; Jira setup specifies Browse Projects/Create Issues permissions, authentication and ticket limits. These satisfy stage 4 for the selected SAST/SCA workflow. No universal integration coverage or extra scanner entitlement is implied. Custom-extension compatibility across the bundle is not established for stage 5.","sourceIds":["c4","c5","c8","c9"]},"governance":{"score":null,"confidence":"low","rationale":"Policy administration and named platform roles are documented, including a permission to access the audit trail. The public Audit Trail landing page redirects to a separate API reference whose policy/finding-change coverage was not verified in this pass. A complete scoped access-and-audit stage for the selected bundle remains unknown; a permission name alone is not an audited change record.","sourceIds":["c4","c11"]},"operations":{"score":4,"confidence":"medium","rationale":"Existing configuration, findings and policy-failure procedures are supplemented by DAST scan-history/log diagnostics, IDE troubleshooting flags and a SAST language/framework support matrix with exclusions. This satisfies stage 4; diagnostics and language limits remain module-specific. A complete rollout, recovery and training procedure for the selected bundle is not established for stage 5.","sourceIds":["c1","c2","c4","c7","c8","c10"]}},"constraints":["Confirm SAST, SCA and DAST licensing independently; the fetched bundles URL returned404 and was not evidence.","DAST needs an authorized reachable target and suitable application authentication; source scanning does not prove runtime test coverage.","PR-specific net-new-vulnerability rules differ from scanner-specific policy rules.","CxLink is connectivity tooling, not evidence that all customer data remains local."],"sources":[{"id":"c1","title":"Checkmarx SAST scanner","url":"https://docs.checkmarx.com/en/34965-324470-sast-scanner.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c2","title":"Checkmarx SCA scanner","url":"https://docs.checkmarx.com/en/34965-322318-sca-scanner.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c3","title":"Checkmarx DAST","url":"https://docs.checkmarx.com/en/34965-433898-checkmarx-dast.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c4","title":"Creating a Checkmarx policy","url":"https://docs.checkmarx.com/en/34965-320944-creating-a-policy.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c5","title":"CxLink","url":"https://docs.checkmarx.com/en/34965-361930-cxlink.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c6","title":"Managing (triaging) vulnerabilities","url":"https://docs.checkmarx.com/en/34965-68516-managing--triaging--vulnerabilities.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c7","title":"Checkmarx DAST: viewing results","url":"https://docs.checkmarx.com/en/34965-154701-dast-viewing-results.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c8","title":"Checkmarx One VS Code extension setup","url":"https://docs.checkmarx.com/en/34965-123549-installing-and-setting-up-the-checkmarx-vs-code-extension.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c9","title":"Checkmarx One Jira feedback integration","url":"https://docs.checkmarx.com/en/34965-68752-jira.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c10","title":"Checkmarx One SAST language and framework support","url":"https://docs.checkmarx.com/en/34965-149060-sast-scanner---supported-languages-and-frameworks.html","accessedAt":"2026-09-21","kind":"documentation"},{"id":"c11","title":"Checkmarx One role management","url":"https://docs.checkmarx.com/en/34965-68603-managing-roles.html","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"veracode","cohort":"appsec-testing-platforms","edition":"Veracode commercial platform with Static Analysis, Software Composition Analysis and DAST entitlements","asOf":"2026-09-21","status":"research-preview","summary":"Separate testing modules connect to policy evaluation and development integrations. This selected combination does not imply that every Veracode subscription includes all scan types.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"The scan, findings and policy workflow meets stage 3. Static Analysis sandbox history establishes repeated scans; a Mitigation Approver can accept or reject proposed flaw mitigations; prescan results and fatal/non-fatal error procedures establish execution diagnostics. Together these satisfy stage 4 within the selected Static Analysis module. No common exception or diagnostic mechanism across all engines is implied, and controlled recovery/configuration promotion for stage 5 is unverified.","sourceIds":["v1","v4","v6","v7","v8","v11"]},"innovation":{"score":3,"confidence":"medium","rationale":"Multiple testing techniques and developer integrations establish the current application-testing baseline. This is not evidence of a distinctive new workflow or higher effectiveness.","sourceIds":["v1","v2","v5"]},"breadth":{"score":3,"confidence":"medium","rationale":"Static Analysis, SCA and DAST are documented testing techniques in the selected licensed combination. DAST remains dependent on reachable targets and authentication configuration.","sourceIds":["v1","v2","v3"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"The integrations guide documents paths into SCM and build pipelines, alongside IDE and ticketing tools. Stage 4 is not asserted without auditing the relevant permission and data-flow requirements.","sourceIds":["v5"]},"governance":{"score":null,"confidence":"low","rationale":"The platform documents Policy Administrator, Reviewer and Mitigation Approver roles and retrievable mitigation history. However, the captured mitigation API evidence applies to Static Analysis/Dynamic Analysis and does not by itself establish equivalent audit coverage for the separately selected DAST product. The complete selected-bundle governance stage remains unknown rather than borrowing a neighboring product boundary.","sourceIds":["v4","v10","v11"]},"operations":{"score":4,"confidence":"medium","rationale":"Scan and policy-failure procedures remain supported. The troubleshooting guide explains prescan results, fatal errors and unsupported-framework handling, while the Static Analysis support matrix specifies supported language/platform versions. These satisfy stage 4 for the selected Static Analysis workflow. Bundle-wide repeatable rollout, recovery and operator training for stage 5 are not established.","sourceIds":["v1","v2","v4","v8","v9"]}},"constraints":["Static Analysis, SCA and DAST are selected commercial entitlements; confirm the contracted combination.","Source/build packaging and supported languages affect static analysis; a successful upload is not proof of complete coverage.","Policy compliance is a configured vendor status, not a legal compliance conclusion.","Authenticated DAST needs explicit target configuration and approved testing scope."],"sources":[{"id":"v1","title":"Veracode static analysis","url":"https://docs.veracode.com/r/c_static_overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v2","title":"Veracode software composition analysis","url":"https://docs.veracode.com/r/Software_Composition_Analysis","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v3","title":"Veracode DAST","url":"https://docs.veracode.com/r/DAST","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v4","title":"Veracode security policies","url":"https://docs.veracode.com/r/c_appsec_policies","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v5","title":"Veracode integrations","url":"https://docs.veracode.com/r/Veracode_Integrations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v6","title":"Scan code in a sandbox","url":"https://docs.veracode.com/r/c_about_sandbox","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v7","title":"Veracode mitigation acceptance and rejection","url":"https://docs.veracode.com/r/Accept_and_reject_mitigations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v8","title":"Veracode API and scan troubleshooting","url":"https://docs.veracode.com/r/c_troubleshooting","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v9","title":"Veracode Static Analysis supported languages and platforms","url":"https://docs.veracode.com/r/r_supported_table","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v10","title":"Veracode roles and permissions","url":"https://docs.veracode.com/r/c_role_permissions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"v11","title":"Veracode mitigation and comments API","url":"https://docs.veracode.com/r/c_using_mitigat_API","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"snyk","cohort":"appsec-testing-platforms","edition":"Snyk Enterprise with Snyk Code, Snyk Open Source and separately entitled Snyk API & Web; Container and IaC excluded","asOf":"2026-09-21","status":"research-preview","summary":"Code, dependency and dynamic web/API testing are documented modules with developer integrations. This research configuration includes all three; it is not a claim that every Enterprise subscription bundles them.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Code/Open Source scan and PR workflows meet stage 3. Within the selected Open Source module, monitor retains a project snapshot for repeat checks and requires resubmission after code changes; ignore supplies reason/expiry; command exit codes, debug logs and failed-project behavior provide execution diagnostics. Together these satisfy stage 4. Monitor explicitly does not support Snyk Code, and no shared API & Web lifecycle or stage-5 recovery/promotion process is inferred.","sourceIds":["y1","y2","y3","y8","y9"]},"innovation":{"score":3,"confidence":"medium","rationale":"Static/dependency scanning connected to PR checks is ordinary current application-testing functionality. No novelty or automatic-fix effectiveness is inferred from the AI branding.","sourceIds":["y1","y2","y3"]},"breadth":{"score":3,"confidence":"medium","rationale":"Code and Open Source cover static code and dependency analysis; current API & Web guidance documents dynamic web/API target configuration, authentication and scanning. All three modules are included in this research configuration, with separate entitlement to confirm. No efficacy figures are adopted.","sourceIds":["y1","y2","y6","y7"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"SCM and CLI/pipeline paths are complemented by IDE integrations with regional endpoint and supported-version guidance, plus Jira integration with explicit permissions, authentication and data-copy steps. This satisfies stage 4 for Code/Open Source. API & Web integration parity is not inferred. A complete custom-extension compatibility/authentication contract across the bundle is not established for stage 5.","sourceIds":["y1","y2","y3","y10","y11"]},"governance":{"score":null,"confidence":"low","rationale":"PR checks and Enterprise SSO are documented for the core Snyk platform, but this pass does not establish the authentication and policy-administration boundary across the added API & Web module. The complete bundle governance stage remains unknown.","sourceIds":["y3","y4","y6"]},"operations":{"score":4,"confidence":"medium","rationale":"The existing findings/remediation workflow is supplemented by CLI exit codes, debug logs, failure-handling cautions and IDE troubleshooting, with product-specific language/package-manager support and Open Source release/tag limitations. These meet stage 4 for Code/Open Source; they do not establish identical diagnostics for API & Web. The full recovery/rollout/training loop for stage 5 is unverified.","sourceIds":["y1","y2","y3","y9","y11","y12"]}},"constraints":["The evaluated configuration selects Code, Open Source and API & Web consistently with the other multi-module testing suites. Exact commercial entitlements must be confirmed; no actual procurement quote was reviewed.","API & Web needs authorized targets, ownership verification and suitable authentication; validate access to internal applications and data handling.","Enterprise is selected because core-platform SSO documentation makes that entitlement explicit; API & Web authentication and administration need a separate check.","Container and IaC are outside this selected research configuration. Supported languages, frameworks and dependency managers must match the repositories."],"sources":[{"id":"y1","title":"Snyk Code","url":"https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-code","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y2","title":"Snyk Open Source","url":"https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-open-source","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y3","title":"Snyk pull request checks","url":"https://docs.snyk.io/scan-fix-and-prevent/prevent/pull-request-checks","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y4","title":"Snyk enterprise single sign-on","url":"https://docs.snyk.io/platform-administration/user-management/single-sign-on-sso-for-authentication-to-snyk","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y5","title":"Snyk platform overview","url":"https://docs.snyk.io/whats-snyk","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y6","title":"Snyk API & Web target configuration and scanning","url":"https://learn.snyk.io/lesson/snyk-web-and-api-scan-configuration-via-web/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y7","title":"Snyk API & Web product scope","url":"https://snyk.io/product/dast-api-web/","accessedAt":"2026-09-21","kind":"product"},{"id":"y8","title":"Snyk CLI ignore command","url":"https://docs.snyk.io/developer-tools/snyk-cli/commands/ignore","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y9","title":"Snyk CLI monitor command and diagnostics","url":"https://docs.snyk.io/developer-tools/snyk-cli/commands/monitor","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y10","title":"Snyk Jira integration setup and permissions","url":"https://docs.snyk.io/developer-tools/integrations/jira-and-slack-integrations/jira-integration","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y11","title":"Snyk IDE plugins, supported versions and troubleshooting","url":"https://docs.snyk.io/developer-tools/integrations/snyk-ide-plugins-and-extensions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"y12","title":"Snyk language, package manager and framework support","url":"https://docs.snyk.io/supported-languages/supported-languages-package-managers-and-frameworks","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"delivery-gates","name":"Delivery policy checks","description":"Understand which scan and policy workflows are practical for the development process.","priorities":["operations","ecosystem","governance"],"questions":["Which tests run before merge and which require a separate pipeline or target?","How are findings reviewed, exceptions approved and policy changes audited?"]},{"id":"testing-scope","name":"Required testing techniques","description":"Check the selected modules against code, dependency and running-application requirements.","priorities":["breadth","maturity"],"questions":["Does the quote include SAST, SCA and any required DAST separately?","Which languages, package managers and authenticated runtime targets are supported?"]}],"researchNotes":["These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.","The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.","The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.","Snyk API & Web is included alongside Snyk Code and Open Source to make the selected testing bundles comparable. Separate module entitlements and target prerequisites still need confirmation.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","AppSec maturity refinement credits a documented workflow in a named module included in the selected scope. It does not require or imply equivalent behavior in every engine. Apply this interpretation consistently to each offering; validate cross-engine consistency separately during evaluation.","All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged."]},"changes":[]}]}