Listing Thumbnail

    Check Point CloudGuard Code Security

     Info
    CloudGuard Code Security is a blazing-fast language-agnostic scanner for detecting secrets, CVEs, and compliance violations in code and IaC with CI/CD hardening features, which seamlessly integrates into everything from the IDE to git and build machine.
    Listing Thumbnail

    Check Point CloudGuard Code Security

     Info

    Overview

    Check Point CloudGuard Code Security is a powerful language-agnostic code scanner able to: Detect hardcoded secrets, keys, and credentials in any programming language with dynamic detectors in repos and host file systems.

    Detect and remove secrets from Jira and Confluence.

    Identify compliance violations against industry standards and regulatory requirements, including various AWS frameworks for Infrastructure as Code (IaC) template configurations.

    Seamlessly integrate with VS Code, GitHub, GitLab, and Bitbucket, as well as CI/CD tools like Jenkins, CircleCI, AWS CodePipeline, and many more, with pre-receive hooks for blocking risky commits to periodic repo scans using git bots.

    No reliance on cloud services, meaning your source code never leaves your environment.

    Harden CI/CD pipelines and limit source code access to mitigate code exfiltration risks and unauthorized access. Designed for developers but built for the CISO organization, CloudGuard Code Security is a DevSecOps/Shift-Left solution that ensures code security does not hinder development speed or burden developers with building intricate scanner rules and quality gates while empowering security practitioners with full visibility and control over rules and posture. It achieves this with: Blazing fast scan speed: approximately 10 MB in half a second.

    Detailed remediation playbooks, providing developers with solutions rather than problems.

    Dashboards designed to facilitate cooperation between developers and security practitioners from the VP R&D/CISO level down to the software engineer/SOC expert.

    2,800 out-of-the-box detectors, allowing security experts to enforce rules without requiring coding/DevOps skills. From identifying risky code (e.g., open ports, dated protocols, etc.) to detecting hard-coded keys and credentials and IaC violations of security farmwork, nothing escapes our detectors.

    Seamless integration with Check Point CloudGuard ecosystem, extending code security to runtime (including secrets, malware, and CVE detection in containers, VMs, and serverless).

    Highlights

    • No More Secrets: Regardless of programming language. Detect secrets like API keys and passwords in any programming language spanning your entire development pipeline from the IDE to the build machine, as well as Jira and Confluence.
    • Blazing Fast Performance: 10 MB of code in half a second. Scan 10 MB of code in about half a second with over 2800 active detectors out of the box, providing high-speed security without disrupting development workflows and without sending your code for scanning in the cloud.
    • Compliance Enforcement: From ISO, to NIST, CIS, PCI, and more. Identify compliance with various AWS frameworks for Infrastructure as Code (IaC) template configurations, ensuring your cloud infrastructure meets industry standards and best practices before configurations reach your cloud.

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Check Point CloudGuard Code Security

     Info
    Pricing is based on contract duration. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.

    12-month contract (2)

     Info
    Dimension
    Description
    Cost/12 months
    25 developer
    CloudGuard Code Security scans source code directly in the CI for secrets and misconfigurations. With easy integration and fast on-prem scanner that is customizable and powered by ML, it empowers developers to code securely by alerting them of any secrets or misconfigurations, while visualizing the entire codebase and supplying alerts, reports, and analytics.
    $6,955.00
    100 developer
    CloudGuard CS scans source code directly in the CI for secrets and misconfigurations. With easy integration and fast on-prem scanner that is customizable and powered by ML, it empowers developers to code securely by alerting them of any secrets or misconfigurations, while visualizing the entire codebase and supplying alerts, reports, and analytics.
    $22,780.30

    Vendor refund policy

    No Refunds.

    Custom pricing options

    Find a fit for enterprise or unique needs with a private offer.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    CloudGuard Code Security Support Information

    This offer includes Premium Support. For the full list of included support services visit: https://www.checkpoint.com/support-services/support-plans/ 

    • To open a support ticket, please have your Check Point user center account information available. If you do not have a user center account, sign up for one here: https://accounts.checkpoint.com . Need support? Contact us at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    19 external reviews
    External reviews are sourced from G2  and are not included in the star rating for this product.
    Computer Software

    Usefull for code integration and code security

    Reviewed on Oct 06, 2024
    Review provided by G2
    What do you like best about the product?
    It's main features such code security and code enhancement
    What do you dislike about the product?
    No nothing as of now can be point out as such dislies
    What problems is the product solving and how is that benefiting you?
    Code security and review during deployment of code into production
    Computer & Network Security

    Cloud infrastructure Security & Network Expert

    Reviewed on Aug 17, 2024
    Review provided by G2
    What do you like best about the product?
    Using it from quite a long time and as working cloud and network security domain this tool has been great help and evident in protecting and helping in identifying threats to the code and thorough monitoring.
    What do you dislike about the product?
    As per the my experience till now. There is no such dislikes about Checkpoint Cloudguard Code security from my side but as always there is always room for improvement.
    What problems is the product solving and how is that benefiting you?
    Code security review at my Infosys projects.
    Security and Investigations

    Great series of softwares from Check Point Cloud Guards

    Reviewed on Aug 13, 2024
    Review provided by G2
    What do you like best about the product?
    Amazing platform I have ever used for securing Cloud based applications. Great and amazing security APIs for the code analysis and code security.
    What do you dislike about the product?
    Integration with other cloud platform.
    What problems is the product solving and how is that benefiting you?
    Helping and benefits in our code security integration.
    Providing us real time slthrealt protection.
    Improved and advanced our Cloud applications.
    Computer & Network Security

    Source Code reviewer

    Reviewed on Aug 05, 2024
    Review provided by G2
    What do you like best about the product?
    Preventing and protection for ZD attacks. Easy to deploy and most useful tool for DevOps operations and team.
    Monitoring our assets like Cloud infrastructure and codes.
    Continuous monitoring of codes and assets.
    What do you dislike about the product?
    Integration to CI system. Support from Check point team was great.
    What problems is the product solving and how is that benefiting you?
    Code and CI infrastructure security for our DevOps Cloud projects.
    dharani a.

    Best agent based vulnerability detection solution

    Reviewed on Aug 05, 2024
    Review provided by G2
    What do you like best about the product?
    The agent based scanning will help us to find the vulnerabilities while the code is in development phase. It will indicate that the following code contains any package level vulnerabilities or it storing any secrets on code level.
    What do you dislike about the product?
    It will not able to detect the vulnerabilities once the code was build to image.
    What problems is the product solving and how is that benefiting you?
    To maintain our application code quality and address the vulnerabilities while the code is in development phase.
    View all reviews