


Checkmarx One and Tanium compete in the IT security software category, focusing on distinct security domains. Checkmarx One has an edge in application security vulnerability detection while Tanium excels in endpoint management and real-time data aggregation.
Features: Checkmarx One provides static application security testing with detailed vulnerability insights, support for multiple programming languages, and native integration with key repositories like Git and SVN. Tanium offers threat hunting, vulnerability management, and real-time data aggregation across various OS environments, excelling in IT operations and security management.
Room for Improvement: Checkmarx One could reduce false positives, enhance language support, and improve report customizations. Users find pricing and licensing complex and request better dashboard flexibility and faster scan times. Tanium faces challenges with scalability, a complex pricing model, and frequent false positives, needing improvements in user interface and network optimization.
Ease of Deployment and Customer Service: Checkmarx One supports both on-premises and cloud deployment models, providing responsive customer service. Some users experience delays, but the staff is knowledgeable. Tanium also offers flexible deployment mainly focusing on on-premises and hybrid solutions, with effective customer support despite complexities in usability requiring more guidance.
Pricing and ROI: Checkmarx One is perceived as expensive but offers significant ROI through reduced vulnerabilities and improved development efficiency. Its modular pricing is flexible and negotiable based on enterprise needs. Tanium is costly, particularly in Latin America, yet its endpoint management capabilities justify the investment. Both products contribute to minimizing security risks, with Checkmarx impacting development efficiency and Tanium enhancing operational security.
| Product | Mindshare (%) |
|---|---|
| Qualys TotalCloud | 1.0% |
| Checkmarx One | 1.6% |
| Tanium | 1.7% |
| Other | 95.7% |

| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 3 |
| Large Enterprise | 28 |
| Company Size | Count |
|---|---|
| Small Business | 32 |
| Midsize Enterprise | 9 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 3 |
| Large Enterprise | 12 |
Qualys TotalCloud enhances security posture across cloud environments with continuous monitoring, vulnerability management, and risk visualization, ensuring efficient threat assessment and automated remediation for improved cyber risk reduction.
Qualys TotalCloud offers a robust suite of security tools essential for organizations managing multi-cloud infrastructures. By integrating cloud accounts and automating workflows, it supports AWS, Azure, and GCP, offering comprehensive vulnerability management and zero-day detection. The platform's user-friendly design, combined with its extensive risk management and unified threat assessment capabilities, enables organizations to prioritize and remediate vulnerabilities effectively. TruRisk Insights provides clear insights on cyber risks, while the automation options streamline patch management and scanning processes. API integration across IaaS and SaaS environments further enhances resource allocation efficiency and saves time, addressing misconfigurations across cloud environments.
What are the most important features of Qualys TotalCloud?Qualys TotalCloud is deployed in sectors needing rigorous vulnerability management, such as finance and healthcare. Companies utilize it to secure multi-cloud environments like AWS, Azure, and GCP, focus on compliance, and integrate security into CI/CD pipelines to detect and remedy threats pre-deployment.
Checkmarx One delivers robust security through seamless integration with SCM and CI/CD tools, ensuring reliable SAST and SCA. Primarily used by organizations for vulnerability detection, it supports cloud and on-premises deployment to enhance secure coding practices.
Checkmarx One provides organizations with comprehensive tools for secure software development, integrating effectively with CI/CD pipelines to scan thousands of applications. Its capabilities extend to identifying vulnerabilities in both code bases and third-party software. Enhancing workflow by supporting SCM solutions, it assists in maintaining secure coding standards and compliance. While excelling in various areas, it requires improvements in scan speed, reduction of false positives, and broader platform integration, particularly for COBOL and Swift. Its pricing model is noted as high, and demand exists for better tutorials and documentation.
What are the key features of Checkmarx One?Industries implement Checkmarx One for secure coding compliance and vulnerability management across varying environments, choosing between cloud and on-premises deployment based on requirements. Its extensive language support and integration with DevSecOps practices make it a popular choice for organizations aiming to enhance software security.
Tanium offers robust endpoint protection, patching, and inventory management, consolidating the functions of tools like BigFix with capabilities in incident response, network security, and cloud or on-premise deployments.
Known for real-time capabilities, Tanium provides detailed analytics, security features, and device management. Users benefit from quick implementation, real-time updates, and patching campaigns. Despite its strengths, integration and custom plugin expansion remain areas to improve, along with data visualization and network optimization. Reporting enhancements and user training could advance its usability, and some UI elements may require updates for clarity and security.
What are the essential features of Tanium?Tanium's deployment spans industries focusing on endpoint protection and compliance, ensuring reliable device and server management in settings where safety and quick adaptation are critical. Organizations use it for application deployment, compliance checks, and integrating it as an EDR solution, enhancing overall security and operational efficiencies.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.