Code scanning you can trust

Built for developers and backed by security teams, Coverity® Static Analysis provides unparalleled code scanning to help you deliver high-quality software that meets security, functional safety, and industry standards.

Uncover complex defects

Find and fix code quality and security issues across files and libraries.

Ensure compliance

Track and prioritize issues by security, functional safety, and industry standards.

Scan with confidence

Analyze large-scale applications with high accuracy.

Compliance made simple

Built-in static analysis reports provide insight into issue types and severity to help prioritize remediation efforts and track progress toward each standard across teams and projects.

•     MISRA    
•     AUTOSAR
•     ISO 26262
•     PCI DSS
•     CERT C/C++/Java

•     DISA STIG
•     ISO/IEC TS 17961
•     OWASP Top 10
•     OWASP Mobile Top 10
•     CWE Top 25

Improve code quality and security

Coverity provides in-depth support for 22 programming languages, more than 200 frameworks, and many popular infrastructure-as-code platforms. Learn about CWE coverage.

Build high-quality software, faster

The Code Sight™ IDE plugin helps developers find and fix code quality defects, security vulnerabilities, and hardcoded secrets as they code with real-time results, issue summaries, and code fixes for faster remediation.

Automate within developer workflows

Integrate your existing tools

IDE, SCM, and CI integrations help you find and fix defects within dev workflows.

Automate code scanning

Trigger scans on code commits and pull requests to uncover issues early.

Scale static analysis scanning

Expand to cover your full portfolio of applications and the teams that support them.
Using Coverity has helped enhance our mandate to ensure code quality and security as well as to enforce coding standards.”

Nicolas Leclercq

Product Security Officer for Software Engineering, Thales Alenia Space

Trusted analysis for complex software

Discover how Coverity customers reduce risk, ensure application resiliency, and rapidly deliver new functionality to market.

Coverity Static Analysis resources