Black Duck is an application security company whose open source audits and software composition analysis are a standard component of tech/code due diligence in M&A.
Black Duck provides application security and software composition analysis (SCA) solutions, including Black Duck Audits used in M&A technical due diligence to analyze a target's codebase for open source components, license compliance issues and security vulnerabilities. Formerly the Synopsys Software Integrity Group, the business was acquired by Clearlake Capital and Francisco Partners in 2024 and relaunched as the independent company Black Duck Software, Inc. Its products serve development, security and M&A teams at over 4,000 organizations.
Key Features
Open source software audits for M&A due diligence
Software composition analysis (Black Duck SCA)
Open source license compliance analysis
Security vulnerability detection
Snippet/code-matching analysis
Static analysis (Coverity)
Polaris SaaS application security platform
Web services and API risk assessment
AI Capabilities
Offers AI-powered application security capabilities (e.g., Black Duck Signal) and addresses risks from AI-generated code via snippet matching and analysis.
Integrations
CI/CD tools (Jenkins, GitLab CI, Azure DevOps), IDEs (Visual Studio, IntelliJ), issue trackers (Jira) and major source‑code repositories.
What sets it apart
-
De facto standard for open source M&A audits
-
Extensive open source component and vulnerability knowledge base
-
Full application security portfolio beyond SCA
Key Facts
- Category
- Tech / Code / IT Due Diligence & Carve-out
- Founded
- 2002
- Pricing
- Custom enterprise subscription; typical contracts in the ~22,500 USD/year range for smaller teams and 50,000–250,000+ USD/year for broader deployments
- Deal Stage
- Transaction
- Target Market
- Corporate M&A, Private Equity, Investment Banking, Legal