Securing the World's Largest Pest Control Company: Rentokil Initial's AppSec Journey with Checkmarx
Rentokil Initial is the world's leading pest control company, operating in more than 90 countries with over 60,000 colleagues and $7.25 billion in 2026 revenue. Following its landmark acquisition of Terminix, Rentokil became the world’s leading commercial pest control company in North America and built a global digital infrastructure supporting approximately 200+ developers, 350–400 repositories, and hundreds of applications spanning B2B services, field operations, and customer platforms.
Inflexible Tools at Global Scale
When Mauricio Giraldo joined Rentokil as Lead Cloud and Application Security Architect, the company was using Veracode for SAST and DAST — a tool he knew well but found increasingly limiting. Compiled Java applications had to be packaged and shipped to Veracode’s platform, CI/CD pipelines required constant customization, and the licensing model made it difficult to scale across a growing, globally distributed developer base.
The process led to noise, high false-positive rates, and challenges for developers and AppSec teams alike. They needed a scalable and dynamic unified platform that accommodates the complexities of their global operations.
After evaluating Snyk, Black Duck, Veracode, and Checkmarx One, the decision was clear. Checkmarx offered direct source-control integration, required no pipeline changes, and outscored all competitors across flexibility, ease of integration, and fit for a contributor-based licensing model.
Products that Perform
Rentokil adopted Checkmarx One across its global AppSec program, deploying:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Infrastructure as Code (IaC) Secrets scanning
The platform was integrated with Okta for identity management and embedded directly into Rentokil’s change-control workflows, meaning nothing reaches production without a Checkmarx scan approval.
Giraldo refers to Checkmarx as more of a “speed enabler than a tool that slows you down.” Catching vulnerabilities earlier doesn’t just cut remediation costs, it gives developers back their most valuable resource: time to build.
Scaling Faster Than Expected
In the first year, Rentokil planned to onboard around 20 repositories. They reached that target within the first four months — ultimately onboarding four to five times more projects than planned. The framework Checkmarx uses to scale removed blockers, with new repos scanning immediately, developers requiring minimal pipeline rework, and the contributor-based licensing keeping costs reasonable as the program grew.
Developers Embraced It — Even “Gamified” It
Ricky Gutiérrez-Flores, who leads user management and vulnerability review, describes the UI as a three-step process: open your project, run the scanner, see your results. The simplicity drove genuine adoption without mandates.
“Developers see Checkmarx as part of their lifecycle now, says Gutiérrez-Flores. “I’m in there every day — and I have never once had a complaint about the UI.”
The India development team took this a step further — running an internal competition to see who could remediate the most Checkmarx-flagged vulnerabilities. Developers pulled their own reports, tracked progress by team, and proved results to their managers.
Results:
-
4–5× planned onboarding velocity achieved in the first year
-
100% developer adoption — no mandate required
-
Zero application-level findings across multiple external penetration tests on Checkmarx-scanned applications
-
Checkmarx embedded in change-control: all production deployments require a passing scan
-
Monthly security metrics reported to leadership with vulnerability counts trending consistently downward
What’s Next
Rentokil is actively exploring Checkmarx DAST to consolidate its dynamic testing alongside SAST, SCA, and Secrets. The team is also evaluating AI-assisted developer tooling like Developer Assist, Triage and Remediation Assist as AI-generated code becomes a growing part of its development pipeline.
For Rentokil, the Checkmarx relationship has become something more than a vendor contract. It’s a shared commitment to building security into the fabric of how the business operates, at every level and in every region.
“Checkmarx is doing what it is meant to do, says Giraldo, “making our life easier and our applications more secure.”
“Developers see Checkmarx as part of their lifecycle now — and I have never once had a complaint about the UI.”