Revolutionizing Application Security | RSAC Virtual 2025
“Developers haven’t learned secure coding!” is a common lament from security teams. And while that’s often true, it’s not their fault—we need to do a better job of teaching them. When a developer is assigned a vulnerability, what assistive tools and information can AppSec teams provide to prevent them from spending hours researching a fix? Checkmarx One tells developers which issues to fix, where they’re located, and how to fix them—fast. Backed by a powerful engine that handles scanning, correlation, and prioritization, Checkmarx One delivers a seamless developer experience with features designed to help developers work more efficiently.
Transcript
Hey, everyone. We're back here, live at RSA conference in Moscone West, kind of, you know, this time of day everyone's in sessions, the din dies down. So you can hear me.
Um, excuse me. I'm happy to introduce you to my next guest if you follow Techstrong at all. He's been on a number of times and he's the CEO of check marks.
And if you, again, follow Techstrong, you know, we have a very tight relationship with check marks and we feature them a lot. But let me introduce you to Sandeep. Jari.
Yeah. Did I say it right? Yeah.
Yeah. Jari. Yeah.
Jari, Sandeep Jari. I know Sandeep actually from before Check Marks and Tricentis, and he has a long, a long track record of making successful companies. Sandeep, welcome to Textron tv.
How are You? Thank you. I'm doing good.
Uh, thanks for having me. My pleasure to have you here. Always here.
A year ago, we were here two, two years ago. Yes, we were in the same booth. Yeah.
They've giving you the same booth every year. So, Sandeep, it's been about two years now with check marks. You've really, I mean, not that it needed a turnaround, don't get me wrong, but you've really left your mark in print on check marks.
We see, I see it in the personnel. I see it in the messaging. I see it in the product direction.
I see it in its standing in the market. Right. Check marks has kinda reclaimed its spot as a leader in the AppSec market.
Mm-hmm. Right? Um, but you know how it is.
If you're not moving forward, you're dying in this market, right? Yes. Yeah.
So a lot of things going on. If you wouldn't mind share with our audience a little bit of what you see as the big things going on with check marks. So at at check marks, you know, two years ago, uh, we launched, or four years ago, we launched a product called, uh, called Check Marks one.
Yes. Which was our cloud native platform, but was, uh, a comprehensive platform. And when we talked two years ago, we had just started mainstreaming our customers.
Over the last two years, we've made incredible progress on check marks. One, uh, one, it now is more than 50% of our installed base, and we are scanning over 450 billion lines of code every month. Uh, we have also, it, it, it has, it is the most comprehensive platform for AppSec.
It has, uh, SaaS, obviously SCA, but we've added malicious code, we've added secrets containers, we have added das. So it's really the most comprehensive platform, which is why most of our customers are now moving. We are at more than 50% by the end of this year.
We should be at 70 to 75% of our customers having moved. We'll have some laggards, primarily government agencies and, uh, and some very large enterprises. But the move to check Marks one has been quite incredible.
It's, it's one of the fastest moves to a cloud native platform from an on-prem, uh, solution. And, uh, like I said, we are scanning literally, uh, more than a million, uh, uh, projects a month. More than four 50 billion.
Almost a half a trillion. Yeah. Yeah.
We, we Lines of go to month. Yeah, well, a half a trillion, which is, you know, rapidly increasing. As of the end of last year, we were doing three 50.
So literally in one quarter it's gone from three 50 to four 50. So it's really as accelerating. And the reason for that is check marks one is not only a comprehensive platform, but it's also a very dev centric platform.
Yes. So we, uh, we have IDE plugins all the way, so it really shifts left, and that's what's driving a lot of the increased, uh, scanning because now developers individually can kick off scans, uh, you know, as they're writing code, literally with every pull request they can scan. And that's what's, uh, driving it.
So that's been, that's been a huge, uh, huge, uh, focus for us. You know, to me it, it's riding on two very important trends, waves in the market. One is, it's a platform.
I was, we were talking, we, I did Tech Techron gang this morning. I don't know if you saw Palo Alto acquired some AI company yesterday. I need a move towards a platform.
You know, you've been in security a long time, as long as I have, you know this in security, small companies make products. Medium companies buy the small companies. And those products become features.
Yeah. Bigger companies buy the medium companies and those products and features get rolled into a platform, Uhhuh. 'cause with a platform, you have an ecosystem.
You have the company's entire platform of things that plug in. You have third party partners, whether it's API or however that plug in. And it allows you to do things that you can't do at just a product level.
Mm-hmm. It's that platform. So I think it's really, especially when we talk about like the move to cloud native, moving from on-prem, modern app application modernization, microservices a product, a point product, it just doesn't cover it.
You need mm-hmm. You need that platform. Secondly, is the idea of who's the user of this platform.
I think unfortunately the road is littered with security companies who thought they were gonna do DevSecOps Nirvana mm-hmm. By building security products for security people that app dev would use. Mm-hmm.
App dev doesn't use security products. Yeah. It's just, that's for security people.
I think a lot of companies got hung up on that. Mm-hmm. One of the nice things about check marks, one is it is a security product, but designed for the app dev audience.
Yes. Mm-hmm. And that, that's, it sounds subtle, but it's not subtle.
It's, it's a major to do here. So I, I think that is a big reason for the success. Yeah.
Actually, when I joined the company, I met with literally, uh, uh, reached out to a hundred of our CISOs and they raised exactly the two points you're saying we want, we don't want point solutions. It's too noisy. We want a single platform, and two, we wanna shift left, move away from only security using it to developers using it.
So those were the two design centers of check marks one. And over the last two years, we have spent a lot of effort on making sure that the developer experience is incredible, because developers at the end of the day don't care much about security. They don't like security.
It's a barrier to their speed of innovation. And therefore, our job as security vendors is to make sure that while we give them the efficacy of, of having good deep security, we make it also easier. So we have spent a lot, and one of the things we've announced recently is we have an A SPM built into our platform, but the A SPM originally was targeted in, initially was targeted at the security professionals who could take feeds from all the engines and then have an A SPM to kind of sort it out and do correlations and exploitability and the like.
And what we've done, we just recently announced is, uh, we brought the A SPM capability right into the IDE again for the benefit of the developer, so that it makes it very easy for the developer to be able to remediate, to understand the priorities of, of which vulnerabilities they should be working on, and then be able to remediate. So we've also added, uh, ai, uh, help, help capability in the IDE. So when you get a vulnerability, you get told how one, it explains to you what it is, and it gives you suggestions on how to remediate it.
So that's all driven towards making life really easy for the developer. Wonderful. Not everyone watching this is a security person.
So let me ask you. A SPM stands for application, Application security. Posture management.
So it, it allows you to take, uh, vulnerabilities that are identified by multiple, uh, multiple application security engines, uh, static analysis, open source and the like, and pull it all together in one area. One place where you can do core and prioritization. So that's what A SPM does.
Absolutely. You know, you were describing the mission of trying to create an environment that allow developers to go fast and secure and get code out. And that really describes the whole platform engineering mm-hmm.
Mission, if you will. org community, uh, on our platform engineering show. We, I did a, uh, I actually did a round table webinar, I think last week.
Yeah. With some of the check marks and other people. We get tremendous, the audience is so involved asking questions, they drive the whole thing, but it really is where the rubber's meeting the road right now.
Mm-hmm. You mentioned AI as well, Sunday, this whole show here this year is AI uhhuh, and I get it. Everyone wants to have, you know, remember when the cloud came out, what's your cloud story?
Every vc SU what's your cloud story today? It's what's your AI story? It's hard to stand out with 600 vendors on that floor, and they're all touting their ai.
Mm-hmm. Talk to us about the check marks AI strategy, if you will. Yeah.
So, uh, our, our AI strategy is multifold. One, we are using AI and ag agent, uh, products to redefine AppSec. The traditional way of doing AppSec was, like you said, the security people would look at the results, prioritize things, and then send it over to, to developers.
Today with AgTech, uh, solutions, what we can do is take all those vulnerabilities, prioritize them, and allow developers with one click to be able to fix them. So we, we are a strategy is to have agents that are targeted at different personas. One agent targeted at the developer, another agent targeted at the AppSec administrator, or the AppSec team that does the prioritization, sets the policies, sets, uh, you know, policies across different projects and the like.
And the third agent targeted at executives that want to look at application security from a risk perspective. And so we plan to have three such agents out in the market shortly. And so that's around what can we use AI to make AppSec a whole lot better?
Gonna redefine ec, if you may, on, on how it's used at an enterprise and platform engineering becomes really important there, because every enterprise that I'm talking to wants to move from DevOps to DevSecOps. And you can't do that Yeah. Without integrating this fully.
So our agents will help further speed up the remediation of, um, of vulnerabilities, which is ultimately the goal of AppSec. The second part is a whole set of new vectors that get introduced because of ai, because of LLM. So we have, uh, our research team is doing a lot of work on what are the new threat vectors that come about because of ai.
And this is things like, uh, you know, uh, prompt injection or hallucinations. How do we capture that? It's a lot of what Palo Alto bought in protect ai.
Right. We actually were partnering with them as well, really. But we continue to have our own products on that.
So, so it's both, it's twofold, if you may. So absolutely. Um, $700 million on acquisition, a lot of money, But everyone needs the buzz.
So Buy a lot of buzz for 700 million. But anyway, let me ask you another question, though. Again, you've been in security, you're a successful multi-time CEO.
Do you worry about what are we going to do? Will we have too many agents? Everybody has two agents, three agents, another agent here.
They're an agent here, an agent everywhere. An agent. How many is too many?
Yeah. I, I think, uh, I, I think the way to think about agents is, uh, they're really, uh, I, I know agents are defined as really some things that are operating con fully autonomously. I think that's a long ways off in that.
You, uh, I was talking to a CISO of a large bank yesterday, and he said, you know, for security, we actually want agents that can help, uh, resolve things. But we don't want autom remediation, we want human intervention. So like you, like we were talking earlier, AI is one of those things which, uh, you know, it's not that AI will replace humans completely.
AI will replace humans with humans that are enabled with ai. Right? Right.
Or AI enabled humans will replace humans, not that AI will replace humans. And we think of it that way. Our developer focused agent, for example, uh, will have the ability for, uh, for human intervention where, where we think of it as you can do auto remediation.
At some point, you might be comfortable enough to be able to do that for a certain class of vulnerabilities, but for a different class of vulnerabilities, for the more critical ones, people would want some human intervention to have some oversight on it. To your question of too many agents, well, we'll see how, how these go. Some of these agents are just AI washing.
They're not really a whole lot different than what people have had before. They're presented in a different way. Uh, so I, I think there might be a little bit of over-hyping, if you may.
Mm-hmm. But the other aspect is that with, uh, with MCP and A to a, you will have agents talking to each other and what every enterprise we talk to are just as worried about the governance. Yes.
Around these agents where you need auditability, you need traceability. Like the bank CISO I was talking to, he said one of the main things, one, one of the big things they need to be able to demonstrate to their regulators is not just that they don't have any vulnerabilities, but the ones that they discovered, how did they resolve them? How did they discover them?
How did they resolve them? And the, is there a record of all of that? So, um, you know, it's, it's, it's still evolving.
I think it's really exciting. All the agent tech stuff where you're making it, I think of it as a dramatically simpler user interface, if you may, with a lot of intelligence built in. So, agreed.
Agreed. I think of them almost as ephemeral, right? Because they're not, they do a specific job and when they're done doing that job, they go back into the box.
You know what I mean? Um, but I do think what you said about we will have humans empowered by ai, not humans replaced by ai. Correct.
At least, at least for as long as you and I are gonna be involved down the road may be different, but who knows? Um, I mean, if you take even code, uh, you know, the, the, the, the quintessential use case of using, uh, using code, uh, coding agents, even there, the most powerful coding agents are the ones where they assist humans and humans are involved. We are not having people write things automatically without any human oversight.
So absolutely. Just one last area I want to talk return to check marks. So you've got the check marks one platform got so much going on, AppSec is such a dynamic market right now for our audience out here, what do you think over the next year, we'll sit down maybe, well, we're gonna sit down in a month or two, but not in person uhhuh, but for the next year, what should we focus on?
What, where should the focus be? So, I I, the, the trend I see in AppSec is really what we talked about earlier, which is, uh, how do we, every enterprise I'm talking to is looking at consolidating their functions, uh, consolidating their AppSec vendors. And, and I think this year is gonna further accelerate that with agents that are sitting over all of these engines.
I think it further accelerates that. The other aspect is people really want to get, uh, the shift left, move, it's not yet fully happened. They're still large enterprises that are trying to embed security into the development, uh, workflow.
And I think we'll continue to see that. So at check marks, we continue to focus on the developer experience, continue to drive functionality across the platform, like we've added, uh, secrets, we've added containers, we've added dast to really make it completely com comprehensive. So there's only one, I don't think there'll be a consolidation of all security platforms as you were talking about, where a Palo Alto buys up everything from code to cloud.
But we are very focused on AppSec and being the best enterprise solution for AppSec. And that's what we are focused on. That's what we hear from customers that they want, uh, especially the larger enterprises that have complex environments.
So that's what we are focused on. Love it. com.
Yes. com. com.
Sandeep a pleasure. Okay. One of the great gentlemen in the valley here, if you ever get a chance to meet him in person.
Thank you. We're live. Thank you.
We're live here at RSA. We'll be back in a moment with more coverage. Stay tuned.
Thank you. Thank you.