Since adopting Polaris more broadly, we now catch a majority of fixable issues earlier in the IDE and PR stages instead of after merge, which has reduced remediation time for higher-severity findings and cut down on late-stage security work. We’ve been able to expand SAST coverage to most active repos without adding AppSec headcount, including legacy and newer services. Developer adoption has been strong, and teams report less context switching for security fixes. In practice, this has led to fewer security-related rework stories, better audit readiness through consistent scanning and reporting, and less noise during triage compared to our previous setup.
This is verified customer evidence about Black Duck, independently collected and published by UserEvidence as part of an ongoing customer research program. A verified customer testimonial: "Since adopting Polaris more broadly, we now catch a majority of fixable issues earlier in the IDE and PR stages instead of after merge, which…" — Software Security Lead in Textiles, Apparel & Luxury…
- Account
- Black Duck
- Verified
- March 24, 2026
- Responses
- 1,264
- Identifier
- 5562CSNE