Avatao’s security training goes beyond simple tutorials and videos offering an interactive job-relevant learning experience to developer teams, security champions, pentesters, security analysts and DevOps teams. Avatao's approach to secure coding training The Avatao platform immerses developers in high-profile cases and provides them with real, in-depth experience with challenging security breaches. Engineers learn to hack and patch the bugs themselves. The vendor…
N/A
Checkmarx
Score 9.1 out of 10
N/A
Checkmarx, an Israeli headquartered company with US offices, provides a suite of application security software delivered via the Checkmarx Software Security Platform. Individual modules and capabilities include Checkmarx Static Application Security Testing, Checkmarx Software Composition Analysis, Checkmarx Interactive Application Security Testing (CxIAST)
Avatao is playing a great role in providing fantastic services. The great feature that I like the most in Avatao that it does not support only one programming language, it ranges its security protocols from various programming languages like Python, java, C#, and C++. Avatao …
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into …
We actually use Checkmarx along with the other tools. However, the reason we chose Checkmarx is its wide support for languages and useful fix recommendations. The flowcharts help better understand the data flow and give a clear picture of what needs to be fixed and how. Also, …
Avatao is an excellent tool for learning about secure coding and IT security in general. It can help you gain a lot of useful knowledge without feeling like it's a chore. The tutorials and challenges cover a lot of topics, at various difficulty levels. The UI looks nice and it's also user-friendly.
If you are going with SAST process or want to improve overall security posture then go for it like integrating it with post deployment steps. If you are more concerned about proactive controls better choose other options such as pee-commit hooks and CI security. Also choose other tools for DAST and API scans.
[I feel] it needs to be more functional while integrating with other platforms. Not the biggest drawback but there is a need to add more languages to it like PHP, Go, and Scala which is also very much developed and used in the organization.
[I believe] the support team needs to be more active and responsive while dealing with the customers.
Checkmarx's usability is generally good, but it can be a bit complex for new users. The interface may take some time to get used to, especially for those unfamiliar with security tools. Once you become familiar with it, it’s effective and integrates well into development workflows.
Avatao is playing a great role in providing fantastic services. The great feature that I like the most in Avatao that it does not support only one programming language, it ranges its security protocols from various programming languages like Python, java, C#, and C++. Avatao bot is also very helpful in simple operation as when you get stuck somewhere the bot can actually help and make you out of that easily.
Checkmarx is easier to integrate with development tools and gives quick feedback during coding, which is helpful for developers. Veracode is more focused on scanning and reporting for compliance, but it’s more complex to set up. We chose Checkmarx because it fits better into our development process, offering faster scans and more useful suggestions for fixing problems