Black Duck
Enterprise SCA platform with deep open-source detection, license compliance, and code origin analysis
Pricing: Custom enterprise pricing
Updated February 2026.
What is Black Duck?
Black Duck (a Synopsys product) is an enterprise-grade software composition analysis platform that provides deep visibility into open-source risks, license compliance, and code origin analysis. Black Duck's multi-factor open-source detection uses package managers, file-level analysis, and code snippet matching to identify open-source components even when they are not declared in manifests, making it the most thorough SCA tool for auditing software acquisitions, M&A due diligence, and regulatory compliance. Black Duck is part of Synopsys's broader application security portfolio alongside Coverity (SAST) and Polaris.
Key Features
Are you Black Duck? Improve this listing with screenshots, case studies and more.
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent Black Duck? Request a correction.
Quick Info
| Pricing | Custom enterprise pricing |
| Model | Enterprise license (project-based) |
| Founded | 2002 |
| Cloud | Yes |
| Self-Hosted | Yes |
Last updated: Feb 20, 2026
Black Duck Alternatives
View All AlternativesDeveloper-first application security platform for finding an...SonarQube
Open-source code quality and security analysis platform with...Checkmarx
Enterprise application security platform with deep SAST, SCA...Veracode
Cloud-based application security testing platform with SAST,...Semgrep
Lightweight, open-source static analysis with intuitive patt...