I have been using Veracode for the last two years, which is one of the security scans that is part of our organization and is mandatory for all products to be scanned by this tool.
We use Veracode for DAST scans, which involves dynamic scanning of our web application. Veracode only supports web application scanning for security vulnerabilities, and it performs black box testing on our application for security issues and cybersecurity testing methodology.
Our product is in the backup and recovery space and has a web interface for it. Since it is a relatively new product that we have, we perform Veracode scans every month to ensure that whatever we are developing is in compliance with Veracode standards. To identify any early vulnerabilities we introduce in our development process, we conduct monthly scans. Initially, I used to perform scans manually by logging into Veracode and following the step-by-step procedure to execute a scan, but now we have automated it somewhat. Although Veracode does not provide a tool for automating scans, we have found a workaround using Selenium to automate it ourselves. We are using Veracode to identify early security issues in our development.