Checkmarx, a prominent application security provider, has acquired Tromzo, a platform specializing in accelerating risk remediation from code to cloud, for an undisclosed amount. This corporate acquisition marks a strategic move by Checkmarx to bolster its offerings in the evolving application security landscape.
Tromzo’s AI-powered platform is designed to help security teams prioritize and remediate critical risks by leveraging deep code context and reachability analysis. It unifies security findings from various sources like SAST, DAST, SCA, CSPM, and CNAPP into a comprehensive security data lake, enabling automated vulnerability governance and reporting. Tromzo aims to make security accessible for developers while improving security throughout the software development lifecycle, offering capabilities such as Application Security Posture Management and Risk-Based Vulnerability Management.
This acquisition is strategically significant for Checkmarx, aiming to integrate Tromzo's advanced AI-driven capabilities into its existing application security portfolio. The combination is expected to enhance Checkmarx's ability to provide enterprise-grade reasoning and autonomous remediation agents, addressing the growing need for efficient and accurate vulnerability management. By centralizing security data and automating triage, the combined entity can offer a more cohesive and intelligent approach to securing modern software development lifecycles.
The synergy lies in complementing Checkmarx's foundational security tools with Tromzo's intelligent orchestration, correlation, and remediation features. This integration is anticipated to streamline security workflows, reduce false positives, and enable organizations to accelerate the remediation of actual risks across the entire software supply chain. Looking ahead, the combined Checkmarx and Tromzo entity is positioned to deliver a more comprehensive and AI-enhanced application security solution, fostering a proactive security culture from code to cloud.

