Atlas Fold / APPSEC

APPSEC, unfolded.

Application & software supply-chain security

Atlas Fold / APPSEC / First edition

Application & software supply-chain security

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Commercial offerings evaluated with at least SAST and SCA. Additional DAST modules are explicit in edition scope; no registry-only, hardened-image or ASPM-only comparison.

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Veracode ARM platform (medium confidence) and Snyk (medium confidence) are tied at documented score 4.0 for Operational maturity among assessed offerings in this comparison group.

Checkmarx One (medium confidence) and Veracode ARM platform (medium confidence) and Snyk (medium confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Checkmarx One: Governance & control
  • Veracode ARM platform: Governance & control
  • Snyk: Governance & control

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Checkmarx One · Checkmarx

Checkmarx One with SAST, SCA and DAST modules explicitly selected; confirm separate engine entitlements · Assessed 2026-09-21 · Research preview

Operational maturity

Can operators configure scans, inspect findings and apply policy to results?

Documented scan-to-triage operating workflow in the selected combined testing scope. Refinement credit can apply to a specifically selected module; it does not establish the same workflow across every testing engine. Each credited component states its module boundary.

Public engine and policy procedures support a combined application-testing workflow. The evaluated configuration requires the named modules; purchasing the platform name alone does not establish entitlement.

Score3.6 / 5.0medium confidence

Rationale and sources

Scan configuration, findings review and delivery policy establish stage 3. Documented continuity across repeated scans adds 0.3; DAST execution logs add 0.3. The score is 3.6. A full accepted-risk/exception lifecycle across the selected scope was not established, and a false-positive state alone is not treated as accepted risk.

How this score is built

3.0 anchor + 0.6 credited progress = 3.6

Next anchor: 4 — Stage 3 plus repeat scans, accepted-risk/exception lifecycle and scan execution diagnostics.

  • +0.3 · Documented repeat scans and continuity of results within the evaluated testing scope

    The vulnerability lifecycle describes recurring findings across subsequent project scans and persistence of triage metadata. This establishes repeat-scan continuity; it does not prove remediation efficacy.

    Managing (triaging) vulnerabilities

  • Not credited: 0.4 · Documented accepted-risk or exception lifecycle with explicit module boundaries

    Not established by this assessment; no credit. This does not establish absence.

  • +0.3 · Documented scan execution diagnostics within the evaluated testing scope

    The selected DAST module documents successful scan history and download of scan logs for investigating unsuccessful executions. This credit is scoped to that module, not every engine.

    Checkmarx DAST: viewing results

Weights are shared editorial rules for this dimension and anchor interval. They are not measured performance differences.

Constraints

  • Confirm SAST, SCA and DAST licensing independently; the fetched bundles URL returned404 and was not evidence.
  • DAST needs an authorized reachable target and suitable application authentication; source scanning does not prove runtime test coverage.
  • PR-specific net-new-vulnerability rules differ from scanner-specific policy rules.
  • CxLink is connectivity tooling, not evidence that all customer data remains local.

Sources

0–5 rubric anchors

  • 0 — The vendor explicitly states that application testing is unavailable in this edition.
  • 1 — A documented standalone scan.
  • 2 — Scans produce reviewable findings.
  • 3 — Documented scan configuration, findings review and policy evaluation or delivery gates.
  • 4 — Stage 3 plus repeat scans, accepted-risk/exception lifecycle and scan execution diagnostics.
  • 5 — Stage 4 plus documented restoration/recovery and controlled configuration promotion.
Assessed offerings inApplication security testing platforms. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
Checkmarx One3.6 (medium)3.0 (medium)3.0 (medium)4.0 (medium)Unknown4.0 (medium)
Veracode ARM platform4.0 (medium)3.0 (medium)3.0 (medium)3.0 (medium)Unknown4.0 (medium)
Snyk4.0 (medium)3.0 (medium)3.0 (medium)4.0 (medium)Unknown4.0 (medium)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.

The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.

The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.

Snyk API & Web is included alongside Snyk Code and Open Source to make the selected testing bundles comparable. Separate module entitlements and target prerequisites still need confirmation.

Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.

AppSec maturity refinement credits a documented workflow in a named module included in the selected scope. It does not require or imply equivalent behavior in every engine. Apply this interpretation consistently to each offering; validate cross-engine consistency separately during evaluation.

All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.
  • The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.
  • The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.
  • Snyk API & Web is included alongside Snyk Code and Open Source to make the selected testing bundles comparable. Separate module entitlements and target prerequisites still need confirmation.
  • Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.
  • AppSec maturity refinement credits a documented workflow in a named module included in the selected scope. It does not require or imply equivalent behavior in every engine. Apply this interpretation consistently to each offering; validate cross-engine consistency separately during evaluation.
  • All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.

Application security testing platforms

Commercial offerings evaluated with at least SAST and SCA. Additional DAST modules are explicit in edition scope; no registry-only, hardened-image or ASPM-only comparison.

Find your next idea.

Tip: press / to open search. Escape closes this window.