Listing Thumbnail

    Veracode: A Continuous Software Security Platform

     Info
    Sold by: Veracode 
    Deployed on AWS
    Veracode is a 9x leader in Gartner Magic Quadrant for Application Security Testing. The Veracode Continuous Software Security Platform is a comprehensive software security solution that is pervasive not invasive throughout the SDLC. The Veracode platform enables security teams to define & manage policy, gain view of security posture of your application portfolio, leverage rich analytics and reporting to make informed plans, produce evidence to meet regulatory requirements, and deliver a successful DevSecOps program. Your development teams enjoy tools that are seamlessly embedded into their SDLC to continuously scan & prioritize potential issues, provide guidance on how to fix, and offer in-context education to avoid future issues. This always-on orchestration of secure development provides confidence that your software is secure while empowering developers with frictionless support & guidance needed to code securely.

    Overview

    Veracode Continuous Software Security Platform seamlessly embeds application security into the software development lifecycle (SDLC). The platform streamlines workflows by bringing together development and security teams to provide a broad understanding of risk, remediation guidance, and progress at every stage of the development process.

    The Veracode Continuous Software Security Platform enables users to define and manage security policy, gain a comprehensive view of software security across their application portfolio, and leverage rich analytics to make informed plans, communicate metrics, comply with policy, and meet regulatory requirements. Powered by almost two decades of data, the platform enables organizations to detect, predict, manage, and, ultimately, mitigate their security risk. These intelligent capabilities empower companies to deliver secure code at the speed and scale expected in today's world.

    Veracode Static Analysis: Secure Software as you write it

    You need a holistic, scalable way to reduce security risk, align teams, and enable developers. Veracode Static Analysis provides fast, automated feedback to your developers in the IDE and CI/CD pipeline, conducts a full Policy Scan before deployment, and gives clear guidance on how to find, prioritize, and fix issues fast and accurately, with a <1.1% false positive rate

    Veracode Dynamic Analysis: Secure Software in the Runtime Environment

    According to the 2020 Verizon Data Breach Investigations Report, web applications were the source of 43% of breaches, more than double that in 2019.

    Veracode Dynamic Analysis scans runtime applications, providing the scale necessary to audit hundreds of target applications simultaneously, including APIs (Application Programming Interface). Used in conjunction with Static and Software Composition Analysis, Veracode Dynamic Analysis complements a shift-left approach to application security by verifying in production that vulnerabilities were addressed or mitigated before application release.

    Veracode Software Composition Analysis: Secure the Software Supply Chain

    With third-party components, including open-source libraries, making up as much as 80% of an application's codebase, it is critical to scan those libraries for vulnerabilities to reduce the introduction of risk into your apps. The recent log4j vulnerability only served to emphasize the importance of scanning and securing open-source libraries.

    Veracode Software Composition Analysis (SCA) identifies risks from open-source libraries early so you can reduce unplanned work, covering both security and license risk. SCA helps Engineering keep roadmaps on track, Security achieves regulatory compliance (SBOM), and the Business make smart decisions.

    Veracode SCA protects your applications from open-source risk by identifying known vulnerabilities in open-source libraries used by your applications. In addition to providing a list of vulnerabilities when your application is scanned, Veracode SCA can also alert you when new vulnerabilities are discovered after your application has been scanned or when existing known vulnerabilities have had their severity level upgraded. Integrated with CI (Continuous Integration) systems, you can fail your build based on vulnerabilities discovered as well as any components that your security team has blocked. As part of the Veracode Platform, Veracode SCA provides a unified experience to display all your security testing results in one place.

    Security Labs: Enable developers Data from the 12th edition of Veracode's State of Software Security shows that developers who complete at least one training course from Veracode Security Labs fix security flaws over 35% faster than those who have not. With security absent from most Computer Science programs, it is critical to give your development team a leg up both on the competition and on bad actors.

    Veracode Security Labs shifts software security knowledge left, giving you hands-on training to confidently tackle modern threats by exploiting and patching real code, and applying developer principles to deliver secure code on time.

    Highlights

    • Veracode platform unites dev & security teams; from integrated development environment, code repository, CLI, to dev pipeline. Developers address security findings with inline automated remediation advice & in-context learning, reducing time to fix.
    • Provides flexible & powerful interface to define, manage, & apply policy. Rich reporting & insights gained from 2 decades of scanning provide understanding of app security posture, enhancing communications, meet GRC requirements, & mitigate risks.
    • Cloud-native SaaS architecture: the platform provides elastic scalability, high performance, and lower costs to customers.

    Details

    Categories

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Veracode: A Continuous Software Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Veracode Security Labs
    Veracode Security Labs provides secure code training via live apps.
    $750.00

    Vendor refund policy

    No refunds expressed or implied.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Veracode Documentation: https://docs.veracode.com/  Application Security Knowledge Base: https://www.veracode.com/security  Veracode Developer Quick Start Guide: https://docs.veracode.com/r/r_supported_table  Veracode Technical Support: https://www.veracode.com/resources/customers/technical-support  Veracode's Support line can be reached by dialing 877-837-2203. All Veracode customers can also engage Veracode's Support team by either creating a case in our Community (the support case option can be found in the Login drop-down menu) via the Veracode Platform or by sending an email to support@veracode.com .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Testing
    Top
    25
    In Continuous Integration and Continuous Delivery
    Top
    10
    In Testing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Static Code Analysis
    Automated scanning of source code to detect security vulnerabilities with less than 1.1% false positive rate
    Dynamic Application Security Testing
    Runtime scanning of web applications and APIs to identify security vulnerabilities in production environments
    Software Composition Analysis
    Comprehensive scanning and identification of security risks in third-party and open-source libraries used in application development
    Continuous Integration Security
    Integrated security scanning capabilities within CI/CD pipelines to detect and block vulnerabilities during build processes
    Developer Security Training
    Hands-on security training platform that enables developers to learn and apply secure coding principles through practical exploitation and remediation exercises
    Application Security Scanning
    Continuous end-to-end security scanning across source control, CI/CD, registry, and cloud environments with real-time monitoring
    Vulnerability Prioritization
    Advanced threat assessment using contextual analysis of vulnerability exploitability, reachability, and business impact
    Pipeline Security Tracking
    Proprietary Pipeline Bill of Materials (PBOM) framework for tracking complete software lineage and ensuring build integrity
    Automated Remediation
    No-code workflow capabilities for automatically blocking vulnerabilities, risky code, and configuration changes
    Software Supply Chain Protection
    Comprehensive security coverage across software development lifecycle with integrated risk prevention mechanisms
    Static Application Security Testing
    Flexible solution capable of identifying vulnerabilities across 25+ programming languages and frameworks
    Software Composition Analysis
    Comprehensive scanning of open source software and third-party libraries to identify and prioritize potential vulnerabilities and license risks
    Infrastructure as Code Analysis
    Detection of security misconfigurations in infrastructure templates to prevent potential deployment errors and security risks
    Multi-Scan Integration
    Single event trigger for simultaneous scanning of source code, dependencies, and infrastructure templates with centralized result aggregation
    Vulnerability Detection Mechanism
    Advanced scanning of uncompiled code with targeted re-scanning of new or modified code segments for efficient threat identification

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.8
    12 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    50%
    50%
    0%
    0%
    12 AWS reviews
    |
    88 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Andrei Kriukov

    Automated monthly code scans increase security awareness and prompt quick remediation

    Reviewed on Aug 11, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My usual use case for Veracode  involves integrating automatic scans for each of our pipelines, which starts every month automatically without my intervention. I review the results, and if there are any changes, such as new issues, flaws, or outdated components, I address this task with our developers.

    How has it helped my organization?

    Veracode has improved my organization's ability to fix flaws because before Veracode, we did not even know about issues from the security side. Application security is relatively new in our company. The fact that we started to remediate these issues is a good step towards security, which has positively impacted us.

    Veracode's ability to prevent vulnerable code from going into production is excellent. I implemented it as a pipeline into our CI/CD, and if there are vulnerabilities above our level, such as high or very high severities, the pipeline will not build. Developers can contact security personnel if they need clarification.

    Veracode has helped developers save approximately 15%-20% of time. Our security posture has improved as expected. 

    What is most valuable?

    We do not have many Veracode features yet. We are going to discuss expanding the subscription next year. Currently, Static Analysis is really good at scanning our code for vulnerabilities. Software Composition Analysis is also required for the upcoming rights from the EU Cyber Resilience Act, which is quite useful, and I am using them both. Both features are really important for us since we're using only Veracode.

    What needs improvement?

    The areas of Veracode that I would want to see improved or enhanced in the future are primarily related to user interface experience. I noticed they have started working on it as the main page has a new design, but other pages appear somewhat old and not intuitive. The interface needs to be more user-friendly, but otherwise, everything is acceptable.

    For how long have I used the solution?

    I have been working with Veracode for approximately a year and a half.

    What do I think about the stability of the solution?

    Every time I wanted to work with Veracode, it worked, so there are no downsides. It was available every time.

    What do I think about the scalability of the solution?

    Regarding scalability, Veracode is really good for our needs. You need many subscriptions because you need to include every developer who produces code. Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.

    How are customer service and support?

    I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material. They understood us immediately and helped us with our problems within half an hour. It was incredible. I would rate them a ten out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We did not use a different solution before Veracode. Veracode is our first solution.

    I did not work directly with competing solutions similar to Veracode, but I attended several meetings with different companies to explore similar tools. They did not provide anything better than Veracode, and since I had already implemented Veracode in our CI/CD, there was no need to change the solution. I only saw Checkmarx as a competing solution. Though I did not try it myself, from what they showed me, it appeared quite similar but was not better than Veracode.

    How was the initial setup?

    Without the documentation, the deployment and initial setup is complex. I tell my developers who are interested in Veracode that with this documentation, everything is possible because it is really thorough and helpful. At first, it was somewhat complicated, but with the documentation and time, it became a really good experience. After that, it became very easy and quick.

    What was our ROI?

    Since the Cyber Resilience Act is in motion, we need to provide static analysis and dynamic analysis, which we do not have right now. We must do it, and Veracode is a great tool for this purpose. We cannot sell our products without complying with this act, so Veracode is helping us achieve this.

    Which other solutions did I evaluate?

    When I joined the company, I was given Veracode. The decisions were made before I joined the organization. They had just bought it and needed a specialist for this, and I was the specialist.

    What other advice do I have?

    I am working with the latest version of the features. Since starting with Veracode, I would rate the benefits as six or seven out of ten. It could be better if we had more high severity issues, but fortunately, we do not. It is a good sign that developers who are not in cybersecurity understand its value.

    Regarding the solution's policy reporting for ensuring compliance with industry standards and regulations, I am using standard policies. I rated it five out of ten because we have not used it properly yet.

    Veracode provides visibility into application status at development phases. We tried IDE  scans for the developer stage of products, but it was not fully compatible with our IDE . It works in CI/CD as mentioned.

    We do not currently have the Veracode Fix feature that produces AI-generated fixes. The fact that Veracode does not scan source code, only binary code, does not concern us as we have other tools for that purpose.

    I would rate Veracode an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    reviewer2724171

    Manual configuration challenges overshadow efficient static code analysis

    Reviewed on Jul 15, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I have experience with Veracode , as I did download it, and our cyber team manages that. I've used Veracode  for quite some time, more from a user perspective, not really as an admin person to run the scans. I share my role with Veracode by normally receiving the results and then analyzing them from there, as I was looking for options.

    What is most valuable?

    My impressions of Veracode's best features indicate that it doesn't have what I need. It's hard to integrate and perform hybrid analysis mapping. The threat modeling components aren't detailed enough. The deciphering of the results is challenging as they're hidden, making it difficult for a non-security user or normal IT developer to understand it.

    We have about 100 to 200 licenses, with a very big portfolio of 500 systems, and people still don't understand it. Training 7,000 developers isn't feasible. We had training with Veracode where they conducted a major session, but nobody understood it. These developers can't be expected to remediate and configure the tool properly for comprehensive scanning. Instead, they turn everything off and only scan a very small line of code, which doesn't benefit the agency.

    What needs improvement?

    I wouldn't promote Veracode because it's not automated enough, and it has many configuration issues. Manual configuration is required, requiring expertise in Veracode. My thoughts on Veracode's development over time are that they have had sufficient time to figure it out, and I'm disappointed that it remains such a technical tool. It's a tool that everybody purchased when it was released, but it still isn't user-friendly.

    For how long have I used the solution?

    I've used Veracode for quite some time, more from a user perspective, not really as an admin person to run the scans.

    How are customer service and support?

    I would rate Veracode's customer service or technical support as not great, probably a four out of ten. Anytime we use the advisory to speak with an advisor, they are either too technical or have no understanding. We have a weekly meeting with Veracode because we have our own business relationship manager. He attends the calls without a technical person or lead architect to facilitate questions. When 40 people are on a call asking questions about turning off the API or fixing issues, the response is often that they cannot answer. The service is either a hit or miss, which is why I rank it low.

    How would you rate customer service and support?

    Positive

    Which other solutions did I evaluate?

    I wouldn't be inclined to take a 10-minute callback to discuss my experience with Veracode because I don't prefer it, so I don't think it would be a very good review. I'm looking to replace it.

    What other advice do I have?

    My impressions of Veracode's policy reporting for compliance with industry standards and regulations are hit or miss. While it has industry standards built in, our organization has different policies that are more structured. Each policy must be set up individually, requiring comprehensive legwork.

    For example, if there's a policy for a deprecated protocol in an internal-only system, Veracode still reports it as an issue. This creates unnecessary work for internal systems that aren't public-facing and have lower risk. Configuring the tool to align with policies for sensitive, public-facing systems based on law and NIST requirements requires reviewing each line individually, which becomes a two-year project.

    My impressions of Veracode's ability to prevent vulnerable code from going into production is that the static code analyzer portion is adequate.

    On a scale of 1-10, this solution rates a 5.

    reviewer2731785

    Helps ensure secure code generation but needs better integration for modern tools

    Reviewed on Jun 30, 2025
    Review from a verified AWS customer

    What is our primary use case?

    We use the scan and code scanning functionality. Those are the main ones. I just changed my role, so this company is using Veracode , but I've been using it for quite some time before joining this new company. It is currently only managing the source code review. We have other tools that we integrate as such as infrastructure as code, container security, cloud misconfiguration reviews, and others. So it's part of the overall security posture. I can't say that it's solely for our entire security posture because it just manages a subset of one of the security requirements, which is the source code review.

    What is most valuable?

    It has met the company's requirements. Nowadays, we are talking about AI code generation. The company is required to leverage the existing code scan to see whether it can support scanning the code that is generated from GenAI before pushing that code to the developers. The developer wouldn't know whether this code is secure or not. Usually, we do the static scan first, but now with a code generator, we want to ensure that it generates secure code.

    It did the job. Just before production, we did a scan and ensured that there were no critical or high-criticality issues before going to production. I think that helps to sanitize the code without going into a peer review. We have an automatic scan that catches all these things first, so it's beneficial.

    This is especially true for the library because most of these static code scans or software component analyses scan the third-party library that has a CVE or CVSS finding. But if it's a custom-built library that isn't known to the public, it's unclear whether there's a vulnerability or not. Currently, it lacks the ability to trigger on those. We probably have to use a different solution for that.

    What needs improvement?

    There should be a feature where we can actually scan code that has been generated by GenAI, such as ChatGPT  or Copilot. When they generate this code, they should have some kind of third-party integration feature that can suggest to us, 'This code is clean' or 'this code is good to be used for the developer.' 

    We are also looking at Black Duck . They introduced a new feature. We were testing on this secure code for AI, so they do have some tools that we are currently exploring to see whether they can do secure AI code.

    Regarding remediation, based on my experience, the recommendation from Veracode  on remediation is quite helpful. It gives valid reasoning, and the recommendation is fixed. 

    The developers actually understand how to fix that. However, some of the recommendations, such as upgrading a certain library to version XYZ, sometimes don't go deeper because some of these libraries are not as simple as just changing the version to fix them. There are interdependencies with other third-party components. 

    Sometimes, when the recommendation asks to upgrade the version to XYZ, when we actually upgrade it, there will be another issue with other things. We usually face difficulty with that one. Sometimes we take an exemption because we can't upgrade this without breaking certain things, so we decide to go for the risk exception.

    For how long have I used the solution?

    I just changed my role, so this company is using Veracode, but I've been using it for quite some time before joining this new company.

    What do I think about the stability of the solution?

    The stability is acceptable overall.

    How are customer service and support?

    I didn't get involved much with asking them questions. During the initial phase when we started integrating, they were very helpful, but after they deployed the license and everything, we haven't reached out to them to ask any other questions. It's gone into autopilot. Once you have the license, everything just continues as it is.

    How would you rate customer service and support?

    Which solution did I use previously and why did I switch?

    In my last company, they used Veracode, and then they transitioned to Snyk . The price point was the first priority we looked at. Secondly was the integration—whether it had deeper integration with our system, and was easy for our developers to enroll and use. After a trial of 12 months with Veracode, we decided to move to Snyk .

    Which other solutions did I evaluate?

    Previously, we did a comparison between Veracode, Synopsys (which is Black Duck ), and Snyk. We did our own internal review. Veracode needs to shift to a more modern approach because it still feels traditional in its way of doing code scanning compared with others, such as Snyk. They still use a base app, although they have a web version as well, but the integration part could be more seamless. I'm comparing it side-by-side with Snyk, as I'm also a heavy user of Snyk. Those aspects can be improved.

    What other advice do I have?

    The integrated IDE  tool enables users to get instant feedback in real-time on the code itself, rather than waiting for it to go through the CI/CD pipeline and get the result. They can instantly review their code on demand, which is quite beneficial.

    For my previous company, when they first adopted source code review, they went for the open-source option first. I always advocate for people to go with the open-source option to understand what the features are and how exactly the source code scanning looks. Once comfortable with it, or if certain features are needed, then look for the enterprise version. Sometimes for different companies, especially small businesses, they couldn't afford Veracode because of the steep price.

    Regarding integration, apps such as Jira  and Confluence  are important. The main thing was that it's fully and deeply integrated with the user and the repository, like Confluence . Every  time there's a report, we can immediately generate a ticket from Snyk to Jira . It helps the developer get notified about issues after the scan. Then they fix the issue, tag the ticket as resolved, and once it's marked as resolved, we will do the rescan.

    As a beginner, the interface is quite straightforward. People will not get confused. The technical report is professional and can be used by regulators. I can simply export it as a PDF and then share it with a regulator or any auditor for their review.

    Regarding mobile code support, such as iOS, Kotlin, and others, the results were not really promising. For Java and C#, it's very good. They are pioneers in that. But for mobile development, if you're a mobile company that builds mobile apps and you have iOS, Objective-C, Swift, and Kotlin, that area needs to be polished.

    I rate Veracode a seven out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Dristi Kurre

    Helps ensure that third-party libraries we're using are safe, but the scanning process can be more streamlined

    Reviewed on May 29, 2025
    Review from a verified AWS customer

    What is our primary use case?

    We have used Veracode only for third-party libraries until now. We have automated that and have onboarded the Dev team to directly scan from their pipeline. We have integrated the CI/CD in that way. We try to see whether the third-party libraries they have been using are safe versions, and if not, we are able to guide them along. For static scan, we primarily use Fortify. With Veracode, I do not have much experience because Fortify is our main tool. 

    We are the security personnel. We give proper guidance to the development team and use Veracode whenever scans are in queue or stuck, helping to provide clarity on findings. We have guided the development team with the tool so that, as security auditors, we do not have to do that. We have given guidance to the development team since every release needs code without vulnerable dependencies or vulnerable code. We have guided them in a way that they can access such tools, where they can see the report, and where vulnerable code is present.

    How has it helped my organization?

    Veracode's policy reporting for ensuring compliance with industry standards and regulations is satisfactory. Veracode provides visibility into application status at every phase of development.

    What is most valuable?

    Veracode has impacted our overall security posture because we are from a security background. Every week, we review the dashboards of open findings. We use both Veracode and Fortify findings, as we are using two separate tools - one for SAST  and one for dependency-related issues. When we highlight these in our meetings every day, it gives us a picture of the timeline needed to fix the code. We are using that feature regularly, and it helps significantly.

    What needs improvement?

    The product could be improved in its reporting. The scanning process could be more streamlined as it has certain limitations when performing manual scans. It has some checks when the content is in ZIP format or other formats, which takes two or three more steps than Fortify does. From a technical point of view, I may not be the best person to answer that since I haven't used it regularly. Other than the scanning process, I think it is acceptable.

    For how long have I used the solution?

    I have been using Veracode for a couple of years.

    What do I think about the stability of the solution?

    I would rate its stability as a six out of ten based on my personal opinion.

    What do I think about the scalability of the solution?

    It is scalable. I do not face any issues with the product's scalability.

    How are customer service and support?

    The technical support by Veracode is good because we have encountered problems before, and the team supported us effectively. For technical support, it deserves a rating of eight out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It is somewhat complex compared to Fortify. As a Fortify user for almost five years, I find Veracode complex, but others in my team who have used it for eight to nine years don't find such issues. When we were doing manual scans before CI/CD integration, it was easier.

    It took approximately four to five months to onboard the solution because it was new to developers as well. There was a certain process to be followed to get access and integrate it into the CI/CD tools. We had to explain the report format to them, showing where they could find vulnerabilities and how they could fix the code, including finding safer versions of libraries and dependencies. This took almost half of 2023, and now in 2025, they do not need our help except for technical problems when there are numerous scans in the pipeline.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is reasonable compared to other tools.

    What other advice do I have?

    I haven't used the Veracode Fix feature that produces AI-generated fixes. 

    The fact that Veracode doesn't scan source code, only binary code, is not a concern because we have certain projects that work with this approach. The AI functionality could be innovative, though I haven't experienced it yet. Regarding the breadth of Veracode's end-to-end testing versus competing solutions, I would rate it as eight out of ten.

    Overall, I would rate Veracode a seven out of ten.

    SrikanthRaghavan

    Early detection of vulnerabilities saves significant amount of time and effort

    Reviewed on May 19, 2025
    Review provided by PeerSpot

    What is our primary use case?

    It helps with intelligent software composition, ISC, allowing us to test fast and get fast feedback around third-party library vulnerabilities, and have a quality gate around the CVEs, and so on.

    I work as a digital consultant helping customers with their digital transformation side, with the primary focus on reliability engineering, SecDevOps, and Cloud. I have multiple clients using this same product. My clients are from different industries such as retail, consumer goods, travel, hospitality, and energy.

    How has it helped my organization?

    Veracode provides visibility into application status at every phase of development, as it's how we stitch it together, allowing us to introduce it at various phases to gain fast feedback. This capability increases the velocity in DevSecOps  processes as developers receive feedback on vulnerabilities before committing, reducing the overall rework.

    It helps developers save time significantly. For instance, if I take a library and assume it's going to work until it reaches QA or UAT, where we find out there's a vulnerability, that can require extensive effort for code refactoring or redesigning; Veracode helps prevent that before the pull request is merged.

    Veracode impacts the overall security posture by maintaining data integrity, ensuring we are not exposed to threats from third-party libraries with known vulnerabilities. From my perspective as a SecDevOps evangelist, Veracode is crucial for an organization's shift-left security strategy. Veracode's SCA  perspective offers tools that facilitate shift-left security by providing feedback before failures occur in the development process.

    What is most valuable?

    All three of Veracode 's offerings are valuable: SCA, SAST , and DAST. It helps identify security loopholes right in the development phase, allowing developers to get feedback around what kind of vulnerabilities exist as soon as they check in the code or even before that in their IDE .

    What needs improvement?

    It would be better if we had a channel for direct communication with the engineering team to speed up the process of providing feedback. 

    I think Veracode has most areas covered, but I'm not sure if they have something around container scanning yet, which is important as workloads become containerized or serverless.

    Regarding innovative features offered by Veracode, it would be beneficial for them to open up a channel to broadcast new developments and features to help us adapt. We are currently integrating Veracode using their GitHub  Workflow app, but it's not yet mature.

    For how long have I used the solution?

    It has been more than five years. 

    How are customer service and support?

    We have an enterprise license and direct connection with the Veracode team. I consulted their team about a couple of issues or bugs in the product that weren't matching our requirements, and we provided feedback that they took back to address. 

    I would assess their help as eight out of ten in terms of how they assist with the issues I bring to them. It's good to have access to their team at no extra cost with the license, as most SaaS platforms include consulting as part of their offerings, but access to the engineering team is crucial for faster feedback on the product fix process.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I do have experience with other testing tools such as Mend and Polaris . The main differences between Mend, Polaris , and Veracode lie in the specific functionalities and how each integrates with enterprises. Overall, the basic functionalities remain similar. In comparing Veracode's breadth of end-to-end testing versus Mend, I find Veracode to clearly be a winner in the SCA  segment. Other than that, both are pretty much equal in the SAST  and DAST areas.

    How was the initial setup?

    When it comes to the initial setup, it's both straightforward and complex. While the product is mature, it requires integrators. For example, I'm using GitHub Flow, but the GitHub  app to plug in is not sufficiently mature.

    What's my experience with pricing, setup cost, and licensing?

    I have not examined Veracode's pricing in detail, but from an industry perspective, I see that there is a tendency toward Veracode, which suggests competitive pricing.

    What other advice do I have?

    I would rate Veracode's ability to prevent vulnerable code from going into production at an eight out of ten because AI is evolving, and there are other tools emerging that help by proactively changing the code without needing the developer to take action, ensuring that pull requests are handled before going into production. 

    We just got the Veracode Fix feature, but we need to understand it more deeply to know if it just performs code fixes or handles dependencies as well. Can it arrange or adjust my versions to make sure that the library that I'm using does not have any vulnerabilities? We have not enabled AI-generated fixes because we need to try it out and see how it performs, especially concerning human intervention in auto-upgrading or automatic patching in production. I am yet to explore the continuous delivery and continuous deployment aspects to provide feedback on that. 

    I would recommend Veracode to others, as it maintains strong industry adoption.

    Overall, I would rate Veracode an eight out of ten.

    View all reviews