Black Duck

Black Duck is an application security company whose open source audits and software composition analysis are a standard component of tech/code due diligence in M&A.

Black Duck provides application security and software composition analysis (SCA) solutions, including Black Duck Audits used in M&A technical due diligence to analyze a target's codebase for open source components, license compliance issues and security vulnerabilities. Formerly the Synopsys Software Integrity Group, the business was acquired by Clearlake Capital and Francisco Partners in 2024 and relaunched as the independent company Black Duck Software, Inc. Its products serve development, security and M&A teams at over 4,000 organizations.

Key Features

  • Open source software audits for M&A due diligence

  • Software composition analysis (Black Duck SCA)

  • Open source license compliance analysis

  • Security vulnerability detection

  • Snippet/code-matching analysis

  • Static analysis (Coverity)

  • Polaris SaaS application security platform

  • Web services and API risk assessment

AI Capabilities

Offers AI-powered application security capabilities (e.g., Black Duck Signal) and addresses risks from AI-generated code via snippet matching and analysis.

Integrations

CI/CD tools (Jenkins, GitLab CI, Azure DevOps), IDEs (Visual Studio, IntelliJ), issue trackers (Jira) and major source‑code repositories.

What sets it apart

  1. De facto standard for open source M&A audits

  2. Extensive open source component and vulnerability knowledge base

  3. Full application security portfolio beyond SCA

Key Facts

Category
Tech / Code / IT Due Diligence & Carve-out
Founded
2002
Pricing
Custom enterprise subscription; typical contracts in the ~22,500 USD/year range for smaller teams and 50,000–250,000+ USD/year for broader deployments
Deal Stage
Transaction
Target Market
Corporate M&A, Private Equity, Investment Banking, Legal