Overview
Veracode Continuous Software Security Platform seamlessly embeds application security into the software development lifecycle (SDLC). The platform streamlines workflows by bringing together development and security teams to provide a broad understanding of risk, remediation guidance, and progress at every stage of the development process.
The Veracode Continuous Software Security Platform enables users to define and manage security policy, gain a comprehensive view of software security across their application portfolio, and leverage rich analytics to make informed plans, communicate metrics, comply with policy, and meet regulatory requirements. Powered by almost two decades of data, the platform enables organizations to detect, predict, manage, and, ultimately, mitigate their security risk. These intelligent capabilities empower companies to deliver secure code at the speed and scale expected in today's world.
Veracode Static Analysis: Secure Software as you write it
You need a holistic, scalable way to reduce security risk, align teams, and enable developers. Veracode Static Analysis provides fast, automated feedback to your developers in the IDE and CI/CD pipeline, conducts a full Policy Scan before deployment, and gives clear guidance on how to find, prioritize, and fix issues fast and accurately, with a <1.1% false positive rate
Veracode Dynamic Analysis: Secure Software in the Runtime Environment
According to the 2020 Verizon Data Breach Investigations Report, web applications were the source of 43% of breaches, more than double that in 2019.
Veracode Dynamic Analysis scans runtime applications, providing the scale necessary to audit hundreds of target applications simultaneously, including APIs (Application Programming Interface). Used in conjunction with Static and Software Composition Analysis, Veracode Dynamic Analysis complements a shift-left approach to application security by verifying in production that vulnerabilities were addressed or mitigated before application release.
Veracode Software Composition Analysis: Secure the Software Supply Chain
With third-party components, including open-source libraries, making up as much as 80% of an application's codebase, it is critical to scan those libraries for vulnerabilities to reduce the introduction of risk into your apps. The recent log4j vulnerability only served to emphasize the importance of scanning and securing open-source libraries.
Veracode Software Composition Analysis (SCA) identifies risks from open-source libraries early so you can reduce unplanned work, covering both security and license risk. SCA helps Engineering keep roadmaps on track, Security achieves regulatory compliance (SBOM), and the Business make smart decisions.
Veracode SCA protects your applications from open-source risk by identifying known vulnerabilities in open-source libraries used by your applications. In addition to providing a list of vulnerabilities when your application is scanned, Veracode SCA can also alert you when new vulnerabilities are discovered after your application has been scanned or when existing known vulnerabilities have had their severity level upgraded. Integrated with CI (Continuous Integration) systems, you can fail your build based on vulnerabilities discovered as well as any components that your security team has blocked. As part of the Veracode Platform, Veracode SCA provides a unified experience to display all your security testing results in one place.
Security Labs: Enable developers Data from the 12th edition of Veracode's State of Software Security shows that developers who complete at least one training course from Veracode Security Labs fix security flaws over 35% faster than those who have not. With security absent from most Computer Science programs, it is critical to give your development team a leg up both on the competition and on bad actors.
Veracode Security Labs shifts software security knowledge left, giving you hands-on training to confidently tackle modern threats by exploiting and patching real code, and applying developer principles to deliver secure code on time.
Highlights
- Veracode platform unites dev & security teams; from integrated development environment, code repository, CLI, to dev pipeline. Developers address security findings with inline automated remediation advice & in-context learning, reducing time to fix.
- Provides flexible & powerful interface to define, manage, & apply policy. Rich reporting & insights gained from 2 decades of scanning provide understanding of app security posture, enhancing communications, meet GRC requirements, & mitigate risks.
- Cloud-native SaaS architecture: the platform provides elastic scalability, high performance, and lower costs to customers.
Unlock automation with AI agent solutions

Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Veracode Security Labs | Veracode Security Labs provides secure code training via live apps. | $750.00 |
Vendor refund policy
No refunds expressed or implied.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Veracode Documentation: https://docs.veracode.com/ Application Security Knowledge Base: https://www.veracode.com/security Veracode Developer Quick Start Guide: https://docs.veracode.com/r/r_supported_table Veracode Technical Support: https://www.veracode.com/resources/customers/technical-support Veracode's Support line can be reached by dialing 877-837-2203. All Veracode customers can also engage Veracode's Support team by either creating a case in our Community (the support case option can be found in the Login drop-down menu) via the Veracode Platform or by sending an email to support@veracode.com .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Uses advanced dependency insights to identify risks and uncover hidden assets
What is our primary use case?
My main use case for Veracode involves SAST scanning and SCA scanning of applications. In my workflow, I specifically use Veracode for SAST and SCA scanning by generating binaries of our many applications and uploading them onto Veracode, which then provides the scans. Additionally, I have integration with our Bamboo pipeline that generates these binaries and runs the scans.
What is most valuable?
In my opinion, SCA is more powerful than SAST in Veracode, as it has a very good interface showing all the SCA dependencies and the possible fixes, along with a very good sitemap feature and superior DAST capabilities.
Regarding the features, I would say the reporting is very good compared to its peer tools, such as Fortify or Semgrep , although the integrations are not as strong due to the limited API features. Usability of the web UI is very good.
Veracode has positively impacted my organization by helping secure our critical applications, and it has impacted very well. The sitemap feature allowed us to find some shadow IT, which is a significant benefit.
What needs improvement?
Veracode can be improved with more integrations, more automations, enhanced API features, and more advanced analytics. While its usability is very good, some features such as report generation could be much more intuitive.
Speed of scans should be improved, with the metrics regarding the speed of scan provided accurately, as it starts off with a higher estimate and then goes up. The right estimate should be given.
For how long have I used the solution?
I have been working in my current field for 10 years.
What do I think about the stability of the solution?
Veracode is very stable.
What do I think about the scalability of the solution?
Scalability of Veracode is very good.
How are customer service and support?
Customer support for Veracode is good.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used HP Fortify; we switched to Veracode because it is a newer tool.
What was our ROI?
I think there is no direct metric regarding return on investment, unless considering the impact on our defensive posture. It helped more than any measurable metric relating to fewer employees or money saved.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that it is very good.
Which other solutions did I evaluate?
Before choosing Veracode, we evaluated Snyk and HCL AppScan among other options.
What other advice do I have?
Finding shadow IT has impacted my team and organization by alerting the relevant teams who then took action to ensure that there is no shadow IT anymore in that region of applications.
My advice for others looking into using Veracode is to look at your applications and evaluate Veracode's capabilities beforehand. If it can handle your applications and if it is a good fit, then I recommend going for Veracode.
I chose a rating of eight because I did not give a higher score due to some limitations and issues, such as the automations and integrations I previously mentioned, but I did not give a lower score because it is not a bad platform and is fairly mature.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Has improved our remediation efforts and reduced manual vulnerability management
What is our primary use case?
What is most valuable?
The best features Veracode offers in my experience include product discovery, specifically library discoveries as well as remediation timelines, pull requests, and others. I also explored sandboxes.
The Remediation Timelines feature helps us in our workflow by ensuring we abide by certain compliance regulations, and it helped us prioritize high or critical vulnerabilities beforehand so that we pass the compliance checks.
For Library Discovery with Veracode, it was effective in terms of finding transitive dependencies, which allowed us to identify what libraries we need to update and recognize both direct and indirect vulnerabilities.
Veracode has positively impacted our organization by giving us a good chance to focus on development as we don't need to focus as much on compliance-related matters after we have ensured this level of security on the security posture management for our application. Veracode helped us focus on development by reducing our manual work, and the suggestions for fixes were valuable.
What needs improvement?
Veracode could be improved in terms of the UI platform as it could be more seamless, and if they allow different sessions in different browsers at the same time or in different tabs that would help tremendously. I feel Veracode doesn't need any additional improvements beyond what we have discussed.
For how long have I used the solution?
I have used Veracode for about two years in my previous organization.
What do I think about the stability of the solution?
Veracode is stable for me with no issues with uptime or reliability that I have experienced.
What do I think about the scalability of the solution?
Veracode handles growth and increased usage effectively.
How are customer service and support?
The customer support with Veracode is good, as I have interacted with their support team. I would rate the customer support of Veracode an eight on a scale of one to ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before using Veracode, we used SonarQube.
What was our ROI?
We did see a return on investment with Veracode, as we segregated our remediation efforts, which reduced our time to delivery as well as the number of engineers needed to help us in delivering a secure solution.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Veracode; we directly moved to Veracode.
What other advice do I have?
I would advise others looking into using Veracode to go for code scanning as well as library scans, and I would recommend adopting it. I would rate this review an eight out of ten.
Streamlined Security, Effortless Integration
Integrates security into the development process and improves team collaboration
What is our primary use case?
My main task involved integrating a security tool into a cloud platform. Once the integration was complete, we ran the pipeline. After completion, the overall metadata was fed into the security tool. The tool then scanned the data from the cloud platform and transferred it to the Veracode platform. Once Veracode processed the information, it scanned the overall metadata to identify vulnerabilities based on OWASP or application security top ten rules. The tool categorized the vulnerabilities as critical, high, or medium based on these rules. This was the workflow we implemented in the industry.
How has it helped my organization?
Veracode helps organizations develop software by reducing the risk of security vulnerabilities through developer enablement and applications focused on governance. You can utilize different levels of processes to achieve better performance or a more scalable service. Since I started working with it in 2022, I’ve found it to be cost-effective as well. Overall, Veracode is a user-friendly security tool.
It includes features such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). During the development phase, we can identify vulnerabilities in the application. This process occurs in the staging environment during development. When we're ready to go to production, we conduct a final check. Essentially, this tool helps identify vulnerabilities during the code development stage, including both high-level vulnerabilities and those related to open-source software composition. We utilize specific methodologies for this purpose. Additionally, it offers a feature that allows us to set up policies based on client requirements. This means we can customize the tool to meet the specific needs of our clients, ensuring that they receive the appropriate level of security in their applications.
Veracode is user-friendly as well. Compared to other tools, their scans take 15 minutes or under. If you have a large scale of libraries or data, it might take longer, but based on my personal experience, the scan usually runs within fifteen minutes.
For my case study using the Veracode tool, I worked on an internal project following industry standards. We used Veracode to improve our security posture and speed up the time to market by streamlining the development process. This enhanced collaboration between developers, operations, and security teams. The automated scanning process helped identify and fix vulnerabilities earlier in the development process. We maintained compliance with regulatory requirements, avoided fines, and built customer trust by integrating security into the development process.
When we conduct this scan, we receive data on a list of vulnerabilities. This information improved our communication and increased transparency, which leads to better reports about the efforts being put in. This results in a more effective and efficient collaboration process, making it user-friendly for all involved. When considering costs, if we resort to manual processes, it can be time-consuming. Therefore, we utilize automated scans to identify and fix security issues. This allows us to address vulnerabilities early in the development process, as we discussed previously. This applies both to our in-house code and third-party libraries, using Software Composition Analysis (SCA) agent-based scans. In the future, we will also implement SCA agent-based scans as a separate feature within Veracode, which can help organizations avoid the expensive and time-consuming consequences of security issues. Furthermore, we have seen an increase in compliance, helping to maintain adherence to regulatory requirements and industry standards, thereby avoiding fines and reputational damage associated with noncompliance.
Additionally, by integrating security into the development process, we enhance customer trust in our organization and its products.
What is most valuable?
Veracode is a modular cloud-based solution for application security with features such as SASTÂ , DAST, SCAÂ , IAST, and pen testing. It helps organizations reduce the risk of a security breach through analysis, developer enablement, and AppSec governance. The tool integrates into cloud platforms to scan metadata, identify vulnerabilities based on OWASP Top 10 rules, and set up policies according to client requirements. It's also time-efficient, scalable, cost-friendly, and enhances customer trust.
What needs improvement?
I have been using Veracode for four years and have found some areas that need improvement. When we implement a policy, it can be very difficult to locate. Running SASTÂ and DAST simultaneously can be challenging. The initial deployment was not easy, and the internal training was quite difficult. However, after using it for about a month, it became more user-friendly.
For how long have I used the solution?
I have been using Veracode since 2022.
What do I think about the scalability of the solution?
Veracode is time-efficient compared to other tools, taking nearly 15 minutes for standard scans. When dealing with large-scale libraries or data, it may require more time. Veracode's price is lower and the solution is more scalable.
How are customer service and support?
The technical support team provides immediate responses. We can resolve multiple issues during the calls. They provide good technical support, and I would rate their support as seven out of ten.
In response to our inquiry, they provide an update within 24 hours. They share detailed information via email, including screenshots or further clarification about the issue. If we are experiencing a significant backlog in processing technical issues, we arrange a call with our senior technical team. They will provide guidance and help resolve the issue during the call.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
For quality and SAST-based purposes, we can use SonarQube and ShiftLeft . ShiftLeft only provides SAST and SCA based scans. For DAST, we work with Acunetix or Burp Suite. We compared ShiftLeft, Veracode, and GitHub Advanced Security . While Veracode has five features, ShiftLeft provides SAST and SCA, and GitHub only handles secret scanning. Veracode was ultimately the best choice.
How was the initial setup?
The initial deployment wasn't easy. During the internal training, I found it quite challenging. However, after about fifteen to twenty days of use, or nearly a month, it became user-friendly.
What about the implementation team?
As for the deployment team, we had specific client requirements. They had multiple applications, which meant we needed more than one person. Initially, we started with two people, and then one intern joined us later on. In total, we had three members working on approximately 120 applications.
What's my experience with pricing, setup cost, and licensing?
When considering pricing, Veracode stands out due to its lower cost per service and more scalable options. It offers nearly five security testing features within its own service, making it a competitive choice compared to other tools. Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
What other advice do I have?
I would rate Veracode as eight out of ten.
Automated monthly code scans increase security awareness and prompt quick remediation
What is our primary use case?
My usual use case for Veracode involves integrating automatic scans for each of our pipelines, which starts every month automatically without my intervention. I review the results, and if there are any changes, such as new issues, flaws, or outdated components, I address this task with our developers.
How has it helped my organization?
Veracode has improved my organization's ability to fix flaws because before Veracode, we did not even know about issues from the security side. Application security is relatively new in our company. The fact that we started to remediate these issues is a good step towards security, which has positively impacted us.
Veracode's ability to prevent vulnerable code from going into production is excellent. I implemented it as a pipeline into our CI/CD, and if there are vulnerabilities above our level, such as high or very high severities, the pipeline will not build. Developers can contact security personnel if they need clarification.
Veracode has helped developers save approximately 15%-20% of time. Our security posture has improved as expected.
What is most valuable?
We do not have many Veracode features yet. We are going to discuss expanding the subscription next year. Currently, Static Analysis is really good at scanning our code for vulnerabilities. Software Composition Analysis is also required for the upcoming rights from the EU Cyber Resilience Act, which is quite useful, and I am using them both. Both features are really important for us since we're using only Veracode.
What needs improvement?
The areas of Veracode that I would want to see improved or enhanced in the future are primarily related to user interface experience. I noticed they have started working on it as the main page has a new design, but other pages appear somewhat old and not intuitive. The interface needs to be more user-friendly, but otherwise, everything is acceptable.
For how long have I used the solution?
I have been working with Veracode for approximately a year and a half.
What do I think about the stability of the solution?
Every time I wanted to work with Veracode, it worked, so there are no downsides. It was available every time.
What do I think about the scalability of the solution?
Regarding scalability, Veracode is really good for our needs. You need many subscriptions because you need to include every developer who produces code. Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
How are customer service and support?
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material. They understood us immediately and helped us with our problems within half an hour. It was incredible. I would rate them a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use a different solution before Veracode. Veracode is our first solution.
I did not work directly with competing solutions similar to Veracode, but I attended several meetings with different companies to explore similar tools. They did not provide anything better than Veracode, and since I had already implemented Veracode in our CI/CD, there was no need to change the solution. I only saw Checkmarx as a competing solution. Though I did not try it myself, from what they showed me, it appeared quite similar but was not better than Veracode.
How was the initial setup?
Without the documentation, the deployment and initial setup is complex. I tell my developers who are interested in Veracode that with this documentation, everything is possible because it is really thorough and helpful. At first, it was somewhat complicated, but with the documentation and time, it became a really good experience. After that, it became very easy and quick.
What was our ROI?
Since the Cyber Resilience Act is in motion, we need to provide static analysis and dynamic analysis, which we do not have right now. We must do it, and Veracode is a great tool for this purpose. We cannot sell our products without complying with this act, so Veracode is helping us achieve this.
Which other solutions did I evaluate?
When I joined the company, I was given Veracode. The decisions were made before I joined the organization. They had just bought it and needed a specialist for this, and I was the specialist.
What other advice do I have?
I am working with the latest version of the features. Since starting with Veracode, I would rate the benefits as six or seven out of ten. It could be better if we had more high severity issues, but fortunately, we do not. It is a good sign that developers who are not in cybersecurity understand its value.
Regarding the solution's policy reporting for ensuring compliance with industry standards and regulations, I am using standard policies. I rated it five out of ten because we have not used it properly yet.
Veracode provides visibility into application status at development phases. We tried IDEÂ scans for the developer stage of products, but it was not fully compatible with our IDEÂ . It works in CI/CD as mentioned.
We do not currently have the Veracode Fix feature that produces AI-generated fixes. The fact that Veracode does not scan source code, only binary code, does not concern us as we have other tools for that purpose.
I would rate Veracode an eight out of ten.
