---
title: "Checkmarx Fusion"
date: "2026-07-17T20:43:58+00:00"
url: "https://staging.checkmarx.com/platform/checkmarx-fusion/"
description: "Most scanners force a choice: catch more, or get bogged down in noise or miss things that matter. Checkmarx Fusion achieves both, fusing deterministic precision with frontier AI coverage into one clean, verified result."
---

# Checkmarx Fusion

 Hybrid Scanning

# Checkmarx Fusion

Most scanners force a choice: catch more, or get bogged down in noise or miss things that matter. Checkmarx Fusion achieves both, fusing deterministic precision with frontier AI coverage into one clean, verified result.

 [Request a Demo](#form) [Learn More ](#more)

Checkmarx Fusion

## More Fidelity. Less Noise. Most Comprehensive. Built to Cover Everything.

Checkmarx Fusion delivers the highest fidelity and broadest coverage in enterprise AI scanning, at a cost that is known from the start.

  01  Find the Unfindable Zero-Day Detection    02   Choose Your Coverage Level Global Settings    03  Scan Multiple Projects at Once Portfolio Scale Scanning    04  View Results in ASPM  Unified View of Risk    05  One Architecture, Every Scan Type Expanding Coverage

Frontier AI Fidelity

### Find the Unfindable

Several curated AI models reason about your code simultaneously, each approaching it differently. No single model sees every blind spot. Together they surface vulnerabilities with no known rule and no prior CVE. Model-agnostic by design: no frontier model is assumed best, and no customer is locked to one. Model optionality lets users choose high or low cost models, according to their needs.

 [ See It in Action  ](#form) ![v2-composite_scan_find_the_unfindable](https://staging.checkmarx.com/wp-content/uploads/2026/07/v2-composite_scan_find_the_unfindable.webp)

Global Settings

###  Choose Your Coverage Level

Turn Checkmarx Fusion on or off at the global level. Teams that need the highest fidelity enable it; teams on standard scanning are unaffected. One setting, no workflow disruption.

 [ See It in Action  ](#form) ![v2-composite_scan_choose_your_coverage_level](https://staging.checkmarx.com/wp-content/uploads/2026/07/v2-composite_scan_choose_your_coverage_level.webp)

Portfolio Scale Scanning

### Scan Multiple Projects at Once

Run Checkmarx Fusion across your entire project portfolio in a single operation. Results stay organized by project, comparable across codebases, and visible in one place. Incremental scanning means faster and faster scans over time.

 [ See It in Action  ](#form) ![v2-composite_scan_scan_multiple_projects_at_once](https://staging.checkmarx.com/wp-content/uploads/2026/07/v2-composite_scan_scan_multiple_projects_at_once.webp)

Unified View of Risk

### View Results in ASPM

Checkmarx Fusion findings land directly in Checkmarx One, where our Risk Orchestration’s context-aware correlation scores and prioritizes them alongside every other signal in your portfolio. Scored, prioritized, and ready to act on, not a separate report to reconcile.

 [ See It in Action  ](#form) ![composite_scan_view_results_in_aspm_](https://staging.checkmarx.com/wp-content/uploads/2026/07/composite_scan_view_results_in_aspm_.webp)

Expanding Coverage

### One Architecture, Every Scan Type

Checkmarx Fusion starts with SAST and extends across Secrets Detection, IaC, API Security, and DAST on the same model.

• SAST: Available now
• Secrets Detection: COMING SOON
• Infrastructure as Code (IaC): COMING SOON
• API Security: COMING SOON

 [ See It in Action  ](#form) ![composite_scan_one_architecture_every_scan_type_](https://staging.checkmarx.com/wp-content/uploads/2026/07/composite_scan_one_architecture_every_scan_type_.webp)

Why Checkmarx Fusion

## The Scanner Trade-Off Ends Here

More of the risk that’s real. Less of what isn’t. And an architecture that doesn’t make you trade one for the other.

Problem

Rules-based SAST can’t catch vulnerabilities that require reasoning about how code will behave. Rules only cover what code contains, not how it executes. AI-generated code makes this gap worse.

 ![Shield AI Security](https://staging.checkmarx.com/wp-content/uploads/2026/06/Shield-AI-Security-1.svg)

Solution

### Coverage that keeps pace with AI

The AI-based engine extends coverage to every language your AI assistant writes in, including the ones your rules-based tool has never seen. If it ships, it gets scanned.

Problem

The window between disclosure and exploitation has collapsed.

 ![Visibility-V2](https://staging.checkmarx.com/wp-content/uploads/2026/06/Visibility-V2.svg)

Solution

### No grace period, no gaps

Anthropic’s own research found a working exploit generated within an hour of a patch shipping. A missed vulnerability isn’t a near-miss anymore. It’s an active risk. Detection has to be faster than attackers.

Problem

Standalone AI scanning burns through tokens at enterprise-killing costs, and still can’t guarantee the same answer twice.

 ![Careers](https://staging.checkmarx.com/wp-content/uploads/2026/06/Careers.svg)

Solution

### Consistent results at a predictable cost

Checkmarx Fusion runs a bounded, curated set of Checkmarx-validated models rather than open-ended frontier API calls. Security teams get consistent results at a predictable and optimized cost, not a token bill that compounds across every commit.

 [Schedule a Demo](#form)

The Numbers

## More Signal. Less Noise.

0.74 F1 in SAST. Three times the query-based baseline.
 The jump from 0.64 isn’t marginal. It’s catching the flaw that causes a breach.

 [Request a Demo ](#form)

 ![Gartner Logo - CTA Awards](https://staging.checkmarx.com/wp-content/uploads/2026/06/Gartner-Logo-CTA-Awards.svg) A Gartner® Magic Quadrant Leader™

 ![Forrester](https://staging.checkmarx.com/wp-content/uploads/2026/06/Forrester.svg) A Forrester Wave Leader™

 ![SOC2 Logo](https://staging.checkmarx.com/wp-content/uploads/2026/06/SOC2-Logo.svg) SOC 2 Type II Certified

Why Checkmarx Fusion

## What Checkmarx Fusion Gets You

The highest-fidelity scanning architecture available. A defensible risk picture your team can act on, and your CISO can take to the board.

 ![Insurance](https://staging.checkmarx.com/wp-content/uploads/2026/06/Insurance-1.svg)

### Best of Both Worlds

Deterministic precision and AI coverage, not a compromise between them. Full strength from both, in one verified result.

 ![Search](https://staging.checkmarx.com/wp-content/uploads/2026/06/Search-1.svg)

### The Same Answer Every Time

Scan it twice, get the same result. Standalone AI scanning can’t promise that. Checkmarx Fusion can.

 ![Risk Reduction](https://staging.checkmarx.com/wp-content/uploads/2026/06/Risk-Reduction-1.svg)

### Fewer False Positives

The Findings Analysis Engine strips noise before it reaches your team. Real findings, not alert triage.

 ![Rocketship](https://staging.checkmarx.com/wp-content/uploads/2026/06/Rocketship-1.svg)

### Built for Enterprise Scale

Incremental scanning means only new and changed code gets re-scanned. Faster scans, fewer delays, and performance that improves the larger your codebase gets.

 ![Rollout](https://staging.checkmarx.com/wp-content/uploads/2026/06/Rollout-1.svg)

### Predictable Cost

A bounded, curated set of Checkmarx-validated models. Higher or lower cost. You choose. Consistent results at a cost that doesn’t compound. The audit trail does.

 ![Checkmarx One](https://staging.checkmarx.com/wp-content/uploads/2026/06/Checkmarx-One-1.svg)

### The Full Platform Picture

Findings flow into Checkmarx One, where Risk Orchestration prioritizes by business risk, Triage Assist routes for action, and Remediation Assist turns findings into merge-ready fixes. One platform, nothing siloed.

 [Schedule a Demo](#form)

Customer Stories

## Why the World’s Top Teams Choose Checkmarx

 ![](https://staging.checkmarx.com/wp-content/uploads/2026/07/Case-Study_PatientPoint-Color-Logo.svg)

> “Checkmarx identified false positives and also gave developers the opportunity for human review. It was exactly what we wanted.”

 [ Read Full Case Study    ](https://staging.checkmarx.com/resources/on-point-fixes-how-patientpoint-outpaced-its-own-vulnerability-backlog/)

 ![](https://staging.checkmarx.com/wp-content/uploads/2026/07/PatientPoint-Video-Frame-scaled.webp)

  ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_gartner_peer_insights_3x.webp)

> “By far the best AppSec tooling decision we have made”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_cebu_pacific_3x.webp)

> “Checkmarx gave us a 90% reduction in vulnerabilities in just a few months.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_software_ag_3x.webp)

> “Unifying our AppSec tools with Checkmarx gave us a single source of truth.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_best_buy_3x.webp)

> “With 2.1B lines of code scanned monthly, Checkmarx gives us the scale and speed we need.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_trade_van_3x.webp)

> “Checkmarx fits seamlessly into our DevOps pipelines—it’s a truly scalable solution.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/IDC.svg)

> “From a buyer perspective, Checkmarx’s approach offers a structured and role-aware entry point into agentic security. ”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_dell_3x.webp)

> “Incorporating Checkmarx’s technology has revolutionized our development culture.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_gartner_peer_insights_3x.webp)

> “Checkmarx One made our security team and developers life easier.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/logo_allwyn_3x.webp)

> “The success of our AppSec program can be directly attributed to the tooling, processes and support provided by the Checkmarx managed services.”

   ![](https://staging.checkmarx.com/wp-content/uploads/2026/05/IDC-1.svg)

> “Bringing ASPM context directly into the IDE reflects a forward-looking approach to prioritizing security efforts based on risk earlier in the development process.”

  Take the next step

## Related Resources

     Explore the Topic      [Blog

### Proof, Not Promises: How We Drive Security Testing Accuracy With Better Data

The research behind Checkmarx’s F1-score methodology and why accuracy claims require evidence, not just positioning.

16 min. read

  Read Now     ](https://staging.checkmarx.com/zero-post/proof-not-promises-how-we-drive-security-testing-accuracy-with-better-data/) [ BlogYour Scanner’s Accuracy Claims Are Only Half the Story

  Read Now     ](https://staging.checkmarx.com/blog/your-scanners-accuracy-claims-are-only-half-the-story/)[ Presentation Getting to High Fidelity

  Watch Now     ](http://checkmarx.ai/on-demand-sessions)

    Learn the Landscape      [Solution Brief

### Checkmarx Fusion Solution Brief

The full Checkmarx Fusion story — architecture, proof points, and how the same approach extends across every scan type.

  Read Now     ](https://staging.checkmarx.com/resources/checkmarx-fusion-hybrid-sast-for-higher-detection-accuracy/) [ Solution BriefsCheckmarx SAST: AI-Powered Static Code Security Testing

  Read more     ](https://staging.checkmarx.com/resources/checkmarx-sast-solution-brief/)[ WebinarsAppSec in the Age of Mythos

  Watch now     ](https://staging.checkmarx.com/appsec-age-of-mythos/)

    Dig Into the Capabilities      [Solution brief

### Checkmarx SAST: AI-Powered Static Code Security Testing

Full feature and proof-point detail on the scanning foundation Checkmarx Fusion builds on.

  Read Now     ](https://staging.checkmarx.com/resources/checkmarx-sast-solution-brief/) [ Analyst ReportThe Forrester Wave™: Static Application Security Testing Solutions, Q3 2025

  Read Now     ](https://checkmarx.com/forrester-wave-2025/)[ Analyst ReportThe 2025 Gartner® Magic Quadrant™ for Application Security Testing

  Read Now     ](https://checkmarx.com/gartner_magic_quadrant_2025_report/)[ BlogWhat Is Checkmarx Fusion?

  Read more     ](https://staging.checkmarx.com/blog/what-is-checkmarx-fusion/)

 Checkmarx Fusion

## FAQ

  QUICK LINKS

 [ ![](https://staging.checkmarx.com/wp-content/uploads/2026/06/Documentation-Color.svg) Documentation ](https://docs.checkmarx.com/) [ ![](https://staging.checkmarx.com/wp-content/uploads/2026/06/Resources-Color.svg) Resources ](https://staging.checkmarx.com/resources/) [ ![](https://staging.checkmarx.com/wp-content/uploads/2026/06/Trust-Center-Color.svg) Trust Center ](https://staging.checkmarx.com/trust/) [ ![](https://staging.checkmarx.com/wp-content/uploads/2026/06/Schedule-a-Demo-Color.svg) Schedule a Demo ](https://staging.checkmarx.com/request-a-demo/) [ ![](https://staging.checkmarx.com/wp-content/uploads/2026/06/Schedule-a-Integrations-Color.svg) Integrations ](https://checkmarx.com/why-checkmarx/integrations/)

  What is Checkmarx Fusion?

Checkmarx Fusion is Checkmarx’s highest-fidelity scanning architecture. Depending on the language, either a rules-based engine or an AI-based engine runs first. Checkmarx Fusion then adds several curated frontier AI models on top. The Findings Analysis Engine combines all of those results, removes false positives, and deduplicates findings into one clean, verified output — the most comprehensive and highest-fidelity dataset available from any scanning approach.

 How is Checkmarx Fusion different from Next-Gen SAST?

Next-Gen SAST runs a rules-based or AI-based engine depending on the language, reconciles output through the Findings Analysis Engine, and scores 0.64 on the F1 scale. Checkmarx Fusion adds the frontier model layer on top — several models running in parallel, each approaching the code differently — pushing that to 0.74, with 60 to 70 percent fewer false positives than standalone AI scanning.

 What scan types does Checkmarx Fusion support?

SAST is available now. Secrets Detection, IaC, API Security, and DAST are being added

 What is the F1 score and why does it matter?

F1 measures detection accuracy on both dimensions at once. Precision asks: of all the findings reported, how many are real? Recall asks: of all the real vulnerabilities in the code, how many were found? A score of 0.74 means Checkmarx Fusion is strong on both, finding what matters without burying teams in noise. The industry average for query-based SAST is around 0.20.

 Does Checkmarx Fusion run in the IDE?

No. Checkmarx Fusion runs in CI/CD and pull request workflows. Developer Assist handles real-time, in-IDE security feedback separately.

 How do I enable Checkmarx Fusion?

Checkmarx Fusion is available within Checkmarx One for teams using credits. See the Checkmarx documentation for setup instructions. Without credits, hybrid scanning is available through the standard scanning engines.

 Is Checkmarx Fusion available on all Checkmarx deployments?

Checkmarx Fusion is available on Checkmarx One. It is not available on on-premises SAST tools.

 How does Checkmarx Fusion compare to running frontier AI models directly?

rontier AI models and rules-based engines find different things, and there is very little overlap between them. Rules-based scanning catches known, documented vulnerability classes with precision. Frontier models catch logic-based and novel patterns that rules can’t reach. Running frontier models alone means permanently missing everything in the rules-based category, no matter how much you spend or how low you get the noise. Checkmarx Fusion runs both, with the Findings Analysis Engine reconciling the results into one clean output. That’s the only way to get the full picture.

 Can Checkmarx Fusion find vulnerabilities in AI-generated code?

Yes, and it goes further than standard scanning. AI-generated code often contains logic-based flaws that rules alone can’t catch, specifically vulnerabilities that only surface when you reason about how the code will behave. Checkmarx Fusion’s frontier model layer is built for exactly that. Several models analyze the code in parallel, each approaching it differently, finding what neither rules-based nor single-model scanning would flag.

 ## Find What Your Current Scanner Is Missing

See it running on real code. Find the vulnerabilities your current tool doesn’t catch.

### Thank You!

Your Custom Checkmarx Demo Request was Successfully Sent!

 ![thank you page decoration](https://staging.checkmarx.com/wp-content/uploads/2026/05/get-a-demo-thank-you-1.webp)

Personalized Demo

## Find Critical Vulnerabilities in Your Code

 #### Best of Both Worlds

Deterministic precision and AI coverage, not a compromise between them. Full strength from both approaches.

 #### One Result Set

No manual correlation across tools or scan types. One clean verified result, scored in Checkmarx One ASPM.

 ####  0.74 F1 in SAST

More than three times the query-based SAST average: more of the risk that matters, fewer false alarms to chase.

 #### Predictable Cost

A bounded, curated set of models rather than open-ended frontier API calls. No token bill that compounds across every commit.

Get Started

## Stop Exposed Secrets Before They Cause a Breach

Every day your repositories go unscanned, credentials from years of commits remain available to attackers. Start finding them in minutes with Checkmarx Secrets Detection.

 [Schedule a Demo](#form) [Explore Checkmarx One](https://staging.checkmarx.com/product/application-security-platform/)

 ![Gartner Logo - CTA Awards](https://staging.checkmarx.com/wp-content/uploads/2026/06/Gartner-Logo-CTA-Awards.svg) A Gartner® Magic Quadrant Leader™

 ![Forrester](https://staging.checkmarx.com/wp-content/uploads/2026/06/Forrester.svg) A Forrester Wave Leader™

 ![SOC2 Logo](https://staging.checkmarx.com/wp-content/uploads/2026/06/SOC2-Logo.svg) SOC 2 Type II Certified
