I have manually worked in CI/CD pipelines without Veracode. We could get automatic reports after integrating Veracode plugins into the build tool. The pipeline has become much more automatic by integrating the solution.
External reviews
External reviews are not included in the AWS star rating for the product.
Can perform software composition analysis along with static and dynamic scans
How has it helped my organization?
What is most valuable?
The best feature of Veracode is that we can do static and dynamic scans. Veracode performs software composition analysis, and we can use the solution to download different reports like the summarized report. Veracode’s interface is good.
What needs improvement?
Veracode should include the feature to run multiple scales at a time.
For how long have I used the solution?
I have been using Veracode for one year.
What do I think about the stability of the solution?
Veracode is a stable solution, except on one occasion when I faced some issues. I rate Veracode a nine out of ten for stability.
What do I think about the scalability of the solution?
Veracode has good scalability. In our organization, Veracode is used only by our team, which consists of seven members.
Which solution did I use previously and why did I switch?
We have used the JFrog XRAY tool for SCA (software composition analysis).
How was the initial setup?
Veracode’s initial setup was easy and straightforward.
What about the implementation team?
Implementing Veracode doesn't take much time. It takes only a few hours to implement the solution. Veracode was deployed by a team consisting of two to three members.
What other advice do I have?
I am into DevOps, and we have integrated Veracode into our DevOps pipeline.
I would recommend Veracode to other users.
Overall, I rate Veracode a nine out of ten.
Has an automatic scanning feature and no issues with stability and scalability, but the time it takes to scan large projects could be faster
What is our primary use case?
We are a software company providing software to paper manufacturing organizations, and we have an extensive ERP product along with many add-on products.
With the need to increase security awareness and vulnerabilities, we decided that we needed to scan our software, so that was how we started using Veracode.
We found Veracode eye-opening because we had many third-party libraries in our application, and we found vulnerabilities and had to upgrade those libraries or seek alternatives.
Our use cases for Veracode were to make our software more secure and provide a better competitive advantage over our competitors by telling our clients that we have secure software.
What is most valuable?
What we found most valuable in Veracode is the ability to do automatic scans of our software. We've incorporated the solution into our SDLC process, so we take our builds before they get released and put them through scans to ensure any new vulnerabilities haven't occurred.
We found Veracode good at preventing vulnerable code from going into production.
We also use the Software Bill of Materials (SBOM) as we run many applications through Veracode. We use SBOM to discover all the different vulnerabilities and what that stack looks like.
We also found Veracode very good in helping us manage risks, such as supply chain, licensing, and security. The solution allows us to see where the risks are and if updates are available and identify how to remediate our software quickly.
Our company also found it moderately easy to use Veracode when creating a report via the Software Bill of Materials. There may be a bit of a learning curve, but once users have done it, they'll run the same report.
As for policy reporting in Veracode to ensure compliance with industry standards and regulations, we have not used the solution that way. Instead, we rely on the different statuses to achieve the levels we want to achieve and be able to use that on marketing material.
Veracode offers visibility into the application status at every development phase throughout the software development life cycle, but we have not implemented that. That feature is built into the development tool, so developers will get alerts as they code, but we plan to do that in the coming year.
We found a moderate false positive rate in Veracode. There were a few false positives. Veracode can identify vulnerabilities, which we found nice. We could flag false positives on Veracode so they don't continue to pop up and hunt them down, and the solution will ignore those in the future.
The false positive rate in Veracode doesn't affect developer confidence in the solution when fixing vulnerabilities because we realized that our application is huge. False positives will happen in large applications just because of the different ways of implementation and features. No toolset can handle all those different features and interactions, so we can't say they relate to vulnerability.
Veracode dramatically impacted our company's ability to have security awareness and achieve a level of confidence that we can put out to the marketplace.
We also saw how Veracode affected our company's overall security posture, explicitly being able to put the solution into automatic scanning mode, then through our SDLC cycles, and achieve a Veracode-verified status. We can use that as a marketing advantage and say that we've achieved Veracode-verified status with one of the leading vendors of security scanning software. We've reached a level of status with them, and we continually scan our software so our clients can be confident that our software has been scanned for security files before implementing a new software release.
What needs improvement?
An area for improvement in Veracode is the time that it takes to scan large projects, as that makes it difficult to fit into our CI/CD pipelines.
One of our app scans times out after two hours, which requires uploading and scanning that particular application manually. Still, there's no visibility into the CI system with the vulnerabilities found. My company cannot incorporate that into the automatic cycle and has to scan manually, so Veracode could improve on that.
For how long have I used the solution?
I've been using Veracode for about two years.
What do I think about the stability of the solution?
Veracode is very stable. I have no concerns with its stability.
What do I think about the scalability of the solution?
Veracode is very scalable from the perspective of ERP applications, though we aren't sure if other clients have applications larger than ours. For reference, we have five million lines of code in our application.
How are customer service and support?
I've contacted the Veracode technical support team and found the support responsive. The team also got back to me quickly. I didn't find any issues with Veracode support.
I would rate technical support as eight, just because you still need to do manual scans, as Veracode still has not addressed that issue.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used a product called Mend.io, formerly WhiteSource, before Veracode to look at vulnerabilities.
How was the initial setup?
I was part of the initial deployment of Veracode, and it was straightforward because Veracode had excellent training programs and onboarding procedures. The Veracode team also helped along the way and was very supportive in answering questions and keeping my team plugged into any new offerings.
What about the implementation team?
We implemented Veracode in-house with only three people involved.
What's my experience with pricing, setup cost, and licensing?
I found Veracode very expensive, though I'm not the person paying for it. I was surprised to find out how much the subscription costs and that the executive board approved it, but it was a no-brainer because now my company has better security scans.
What I can tell others looking into Veracode but concerned about its price is that the price or cost is justified. After all, you can tell potential clients that your software is better than competitor software because you're scanning it and Veracode-verified.
The verification levels of Veracode are essential because you can use Veracode to start climbing up the ladder to say that your software's even more secure than anybody else because it achieved this level of verification.
In terms of Veracode reducing the cost of DevSecOps in our company, we find that tough to determine because we never had a real concentration on DevSecOps before Veracode. It was forced on us by the fact that the industry was becoming more vulnerable, so now we are experiencing an increase in price in DevSecOps because we're paying attention to it now. We used to skate by and weren't affected by vulnerabilities. Still, because the industry had more vulnerabilities, our customers asked if we were scanning our software, so we had to find a solution and add DevSecOps to address industry needs.
Which other solutions did I evaluate?
I did a Gartner search on the top three solutions and looked at their reviews, and Veracode came out to be the leader, so I just went with the leader from a partner perspective.
What other advice do I have?
My company has a hybrid Veracode deployment. It's a cloud-based solution, so it's tied to the company's automatic build cycles, where you can access and do scans through the cloud.
Veracode doesn't require maintenance. The only maintenance my company performs is fixing vulnerabilities found by Veracode.
Overall, my rating for Veracode is seven out of ten.
I advise others looking to evaluate Veracode to utilize the presales marketing side first. For example, my company was able to utilize Veracode in a presales environment and do the scans to find out how vulnerable my company's software is and compare Veracode with the previous tool, WhiteSource. My company found additional vulnerabilities and was able to do that before signing the contract. It may be best to do a test run of Veracode to find out what the tool is all about and how it looks to your company.
Best security tool to have in the organization
Good visibility and reporting with few false positives
What is our primary use case?
It's a fast solution, so we use it to search for vulnerabilities in our code, software composition analysis, and to search for vulnerabilities in our libraries.
How has it helped my organization?
We have some security gates and it's not possible to release some applications from production. We can look at the solution and see medium, high, or critical vulnerabilities with ease at every stage.
What is most valuable?
The speed is the most valuable aspect.
Veracode's ability to prevent vulnerable code from going into production is very good since we have a few false positives. I'd rate this feature nine out of ten.
Veracode's policy reporting for ensuring compliance with industry standards and regulations is great. It has a detailed report that we can look at to see our landscape easily.
Veracode provides visibility into application status at every phase of development Verticode static analysis, dynamic analysis, software composition analysis, and manual penetration test throughout your SDLC. It positively affects our DevSec processes. It's not possible to bypass Veracode. It's very secure.
There are very few false positives. I'd rate the false positive rate as nine out of ten. It's very good. It's very positive for developer confidence. They understand security development very well and Veracode provides excellent transparency.
It's reduced the time we've spent on tuning policies. We've saved around two hours. We used to waste around 3 hours and now we can do what we need to in 30 minutes.
It's helped our team fix flaws. The security gate helps our developers learn how to fix vulnerabilities. The solution has also helped them save time in their efforts. It provides descriptions of how to fix certain items. It saves them from having to search on the internet for fixes.
The solution has had a positive effect on our security posture. I'd rate it nine out of ten. We have very secure applications.
What needs improvement?
They could improve how they fix vulnerabilities. They could have more support in place to help the developers. That would help a lot of users.
The pricing can be improved. It is really, really expensive.
For how long have I used the solution?
I've been using the solution for five years.
What do I think about the stability of the solution?
I'd rate the scalability nine out of ten.
What do I think about the scalability of the solution?
We have about 500 end users of Veracode in our organization.
I'd rate the scalability ten out of ten. It's very good.
How are customer service and support?
Technical support is good. They are always communicative and share news and new technologies. They offer new languages and frameworks regularly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Checkmarx in the past, as well as Fortify. I used it in another company. However, in banking, it's not possible to use something like Checkmarx. Veracode is more secure and more trusted.
How was the initial setup?
I was involved in the deployment. It was not complex to deploy. It was straightforward. The implementation strategy included looking at different flags and vulnerabilities and deploying in phases.
We had five to seven people to deploy the solution.
I'm not sure if there may be maintenance required.
What about the implementation team?
We used a third party to help with the deployment. Our experience was good.
What was our ROI?
I'm not sure of the exact amount saved, however, we have noted an ROI. We have avoided application vulnerabilities in production. We don't need to rework things since we look at the vulnerabilities right in development instead of after deployment.
It has reduced the cost of dev backups in our organization.
What's my experience with pricing, setup cost, and licensing?
The pricing is expensive.
However, if you have applications and not enough people to analyze the flags, you must use Veracode as it delivers very few false positives.
Which other solutions did I evaluate?
I did evaluate other options before choosing Veracode. I looked at Checkmarx and Fortify as well as a solution made in Brazil.
What other advice do I have?
We are a customer and end-user.
I'd rate the solution nine out of ten.
I'd recommend the solution to others.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Good reporting and excellent SAST scan, but the DAST needs improvement
What is our primary use case?
We utilize Veracode in three primary ways. The first is through Dynamic Scans, followed by Static Scans, and Software Composition Analysis Scans. I find this tool to be highly effective. We have various forms of support available. For instance, we can initiate our scans through the CI/CD pipeline or manually if needed. Additionally, we can create separate sandboxes for each of our code modules. Since development involves distinct code modules, each catering to different functionalities, we can conveniently set up corresponding sandboxes within Veracode. This allows us to scan any module whenever required, which is quite advantageous.
How has it helped my organization?
From a SAST perspective, Veracode can prevent vulnerable code from entering production by adhering to our manual checklist.
We haven't utilized the Software Bill of Materials; however, we have employed Software Composition Analysis. Whenever we scan a codebase, any third-party applications or libraries that have been incorporated into the code are automatically analyzed. Subsequently, a comprehensive report is generated. This report outlines the third-party libraries and applications that have been utilized in the codebase, along with their respective versions. Additionally, if any of these versions are found to have vulnerabilities, they are promptly detected.
Veracode is efficient. I have used various other tools such as DAST or SAST, and employing those tools usually takes between five and eight hours. In contrast, Veracode completes the task in two to three hours. For each scan, there is a consultation button available. Clicking on that button allows us to schedule a call with a Veracode support team member. During the call, they explain any issues, clarify why certain problems are false positives, and discuss the reasons behind issue detections. There's also a consolidation part and a support button, where we can raise tickets. I have found that their maximum response time to these tickets is within one day. Before starting the scan, Veracode offers a pre-scan functionality. This functionality performs connection and server checks in the pre-scan phase. It's similar to the SAST side of things for all the tools, where the code base is examined before initiating the SAST application to determine if it's sound. However, in Veracode's case, this is implemented in the DAST system. It checks whether the server is operational if the provided call scripts are correct, and if the provided login scripts are accurate. This pre-scan functionality doesn't run during the actual scan but rather at the very beginning to ensure that all prerequisites are met. Once everything is verified, then we can proceed to initiate the actual scan.
Using Veracode policy regulations, we can offer predefined rules. When setting up any application, we establish the application name and other necessary details. Following this, there is a section where we can input this information. Essentially, there exist predefined regulations which we can either directly utilize if they suit our needs, or adjust them based on the requirements of our project team. Therefore, we have a pre-existing set of rules and functionalities available.
We do have a dashboard in Veracode that offers visibility into the status of applications. There is a section where we can view the application names, and next to each name, there is a status report such as "The SAST has been completed" or "in progress," and the same goes for DAST.
After the scanning is completed, with other solutions from a DAST perspective, we would receive a report. If there are any false positives, we would have to identify them ourselves. However, with Veracode, one of their engineers or a support team member will verify the information, which helps to minimize the number of false positives.
Before using Veracode, we used to perform many tasks manually. We had a checklist for the SAST. We would go through each line of code, attempting to determine its compliance and level of security. Even with the DAST, we used to carry out this process manually. Completing the DAST scan took a considerable amount of time. For each module, we had to dedicate at least two to three days. However, since adopting Veracode, we can now not only perform this process for each module, but we can also initiate scans for all the modules simultaneously. As a result, we can obtain the results within a maximum of three to four hours. Time-saving for fixing flaws is one of the significant benefits that Veracode has provided us, helping reduce the time by almost 60 percent.
What is most valuable?
Regarding Software Composition Analysis, an exceptional feature is that during a SAST scan, SCA is seamlessly conducted in the background. Once we scan all modules and obtain SAST results, switching to the SCA section reveals the associated reports. This integrated approach eliminates the need for separate SAST and SCA scans, as is required by other tools.
The reporting feature is noteworthy. The reports are well-structured, providing comprehensive details for each vulnerability. Information about the vulnerability itself, its origin, the specific section of code it pertains to, and even the exact line of code involved are all included.
What needs improvement?
I've found that Veracode is not particularly suitable for Dynamic Application Security Testing. Unlike other tools equipped with their own crawlers, Veracode necessitates the use of a Selenium script for crawling. However, the tool's compatibility with all functions is limited, which can be frustrating. For instance, functions like upload, download, or those triggering new tabs are challenging to handle within the DAST section due to Selenium's inadequacies when used with Veracode.
In contrast to other tools where we can monitor requests and responses during a scan, Veracode lacks this capability. The scan initiates, and we must wait until completion to see the results. There's no opportunity to check if the right requests are being sent or if certain components are being excessively targeted. Once the scan starts, we're essentially locked in until it concludes, and only then can we access the results. Furthermore, even after the scan, we're only provided with a summary of scanned URLs and the number of requests made, without the specifics of the request or response contents.
For how long have I used the solution?
I have been using Veracode for four months.
What do I think about the stability of the solution?
Veracode is stable, and we have not encountered any issues.
What do I think about the scalability of the solution?
The cloud version of Veracode can scale according to the file size.
How are customer service and support?
I have engaged in two different types of experiences with technical support. One involves the ticketing system, and the other involves consultation calls. The consultation calls revolved around static analysis. During these calls, we presented all the vulnerabilities we discovered. We conducted our analysis and demonstrated how Veracode identified certain vulnerabilities. However, we also explained instances where these were false positives due to specific reasons. During the call, they acknowledged these issues. They pointed out some of Veracode's limitations, highlighting that it solely scans the code and doesn't consider the framework side. This implies that they accept these limitations. Furthermore, they provided us with insights into how they plan to implement fixes in the future, which is quite beneficial.
Additionally, whenever we had inquiries or doubted Veracode's detection of false positives, they provided detailed explanations. They shared the specific Veracode setup and rules within the SAST side that led to the detection of certain vulnerabilities. They also explained that by incorporating certain mitigations at the code level, these vulnerabilities could be addressed.
Regarding the ticketing system, for minor issues or questions, we would raise a ticket. They consistently responded within a maximum of one day, providing us with the necessary information.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before transitioning to Veracode, the client had been utilizing a free community version tool. However, the count of false positives was exceedingly high with that specific tool. This prompted the client to seek a solution that could deliver superior results with fewer false positives. As a result, the decision was made to switch to Veracode.
What other advice do I have?
I would rate Veracode a seven out of ten because the DAST has room for improvement.
The maintenance is completed by the Veracode team because we are using the cloud version.
For individuals seeking exclusively SAST and SCA capabilities, rather than DAST, Veracode stands out as the most suitable tool. However, if someone intends to utilize Veracode solely for DAST, I believe they should explore alternative tools. The effectiveness of Veracode's DAST functionality is limited, and using other tools might yield better results. Additionally, Veracode provides comprehensive training resources through its portal, including a list of documents and video tutorials. These resources are readily accessible and offer adequate guidance for initiating the use of Veracode.
Showed us where errors were and helped us track their status, but reporting could have been more detailed
What is our primary use case?
We used it for static and dynamic testing to check if there were any vulnerabilities in the code. If there were any vulnerabilities, we would check the report downloaded from the Veracode portal and try to fix the code before deploying it.
How has it helped my organization?
Veracode helped me remove errors, and it didn't take a long time to fix any issue because I had an answer regarding where the code needed to be fixed. That feature helped us test our cases and get them deployed. It helped me fix vulnerabilities and any other errors before deployment to the applications.
The SAST and DAST scans—we used it both before code was deployed and after it was deployed—helped us run through the issues and keep track of their status. It was deployed in the pipelines, through Jenkins, and checked the logs in Kubernetes.
The solution also saved us time. I really liked the automatic scanning because there was no way to know where an issue was. Human tendency is to make mistakes, but Veracode helped us find the exact spot where an error was and change it. The reporting helped us do that in a short amount of time.
For our team, it had a very good impact. My manager used to suggest that before taking code to the next level, it was a really good idea to scan it.
What is most valuable?
I liked that I could easily find out where my errors were. Instead of going through the whole code and the scripts, it showed me where the errors were and gave me an idea of how to fix them.
What needs improvement?
The reporting was detailed, but there were some things that were missing. It showed us on which line an error was found, but it could have been more detailed.
Also, with upgrades, we had quite a difficult time tracking the reports, so there was some maintenance around that.
For how long have I used the solution?
I used Veracode for 13 months.
What do I think about the stability of the solution?
I had a situation that was due to a slow network, and I couldn't get results within a specific time. Because of that, there was a lag in production; we couldn't deploy the code on time. There was a crash, and because of that, we couldn't meet our production deadline.
The downtime happened two or three times. I thought it was due to a network issue when it happened once, but then I came to understand that it was a maintenance issue.
What other advice do I have?
Veracode is really not difficult or complex to understand. The whole concept is simple. It takes some time to get used to the tool, but it is a very simple tool to work with.
It was quite fast. Scanning my code took 25 to 30 minutes, which was quite good.
Low false positive rate, good reports, and fair price
What is our primary use case?
I helped customers to build and start the journey of SecOps with Veracode.
How has it helped my organization?
Veracode helps to know and prevent vulnerable code or applications from being deployed. We can scan, consume reports, and fix vulnerabilities before deploying an application.
It is very good for ensuring compliance with industry standards and regulations. We can have many dashboards and reports related to policy management.
Veracode provides visibility into application status at every phase of development. We can have many analytics dashboards and reports, and we can build a custom dashboard to have this visibility. This visibility is essential for DevSecOps processes. We need this visibility and information to have a strategic approach and mature our security.
Veracode has the lowest false positive rate in the market. Its results are accurate. In some cases, it is very difficult to see a false positive. We report it to the engineers, and they analyze it. If it is truly a false positive, the engineers will update the engine to provide better results at the next scan. The false positive rate of the static analysis has not affected the time we spend on tuning policies.
It has had a very good effect on our organization’s ability to fix flaws. We are developing a new feature, and Veracode will help to quickly fix any flaws.
It has helped our developers save time, but I do not have the metrics.
What is most valuable?
All features are valuable. I especially like SAST and ADO.
It is scalable and quick to deploy into the site and the pipelines. The reports and analytics are good, and the false positive rate is low. It gives true results.
What needs improvement?
There should be more APIs, especially in SCA, to get some results or automate some things.
For how long have I used the solution?
I have been using this solution for almost three years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is very scalable. I help other companies to deploy. Some of them are small, and some of them are big.
How are customer service and support?
Their support is good. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have not used any other solution previously. I have only worked with Veracode.
How was the initial setup?
It is a SaaS solution. Its initial setup is straightforward. I started with the most critical applications and automated the scanners inside the pipeline. After getting the results, I aligned the security policies. I prioritized the most critical vulnerabilities and assigned these reports to different groups and teams. I also integrated the other plugins into the IDE.
What about the implementation team?
I implemented it myself. I work with DevOps and security teams. In some cases, I also work with developers.
It does not require any maintenance. Because it is a SaaS solution, the maintenance is provided by them.
What was our ROI?
The ROI is in terms of time savings and mature security. When you deploy a solution like Veracode, you can have these quickly.
It reduces the cost of DevSecOps for the organization when you use it for more than one year.
What's my experience with pricing, setup cost, and licensing?
Its pricing is fair.
What other advice do I have?
It is essential and perfect for preventing vulnerable code from going into production. Nowadays, it is very important and sensible to have a solution like Veracode to know all the vulnerabilities and manage and prioritize the ones that are more critical and better for security posture.
I have not used the Software Bill of Materials (SBOM) feature much, but it is easy to create a report using the SBOM feature. It is important for the supply chain that your software uses.
I would rate Veracode a nine out of ten.
Easy to integrate and provides good visibility, but the reporting can be more detailed
What is our primary use case?
We use Veracode to test for errors in the code in the applications we are building within our service pipelines.
How has it helped my organization?
Veracode assists in preventing vulnerable code from entering production. It is essential to ensure that our applications entering production are free from errors.
It has assisted our organization by providing a report that we can share with our developers, identifying vulnerabilities in their code. This enables them to address the issues before the code is put into production.
Ever since the implementation of Veracode, I have noticed that the processes for rectifying the issues in our pipelines have become much easier.
Veracode helps our developers save time. The solution has simplified the coding process for our developers.
I would rate Veracode's impact on our organization's overall security posture as nine out of ten. The solution has been beneficial to us daily, and we haven't encountered any issues with their solution so far.
What is most valuable?
The capability to identify vulnerable code is the most valuable feature of Veracode.
What needs improvement?
There are times when certain modules cannot be scanned automatically, requiring us to manually select these modules and initiate the scanning process on our side.
The vulnerability report has potential for improvement and should encompass more detailed information about the vulnerability, rather than solely identifying it.
For how long have I used the solution?
I have been using Veracode for three years.
What do I think about the stability of the solution?
Veracode is stable.
What do I think about the scalability of the solution?
I believe Veracode is scalable, but I am not certain.
What other advice do I have?
I rate Veracode a seven out of ten.
I recommend Veracode. The solution only requires a one-time configuration into the pipeline and the testing is done automatically.
Integrating Veracode with our pipelines is an easy process. We simply use VML files and the integration is done automatically for us.
We currently have approximately 55 microservices, composed of various teams. Altogether, there are about 170 people utilizing Veracode.
I recommend becoming as familiar as possible with Veracode before using it. Even watch online tutorials to ensure that the deployment goes as smoothly as possible.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Utilized for scanning containers and integrated within DevOps workflows
What is our primary use case?
We used Barracuda for scanning containers. And in all in DevOps workflow.
What is most valuable?
The coverage of backdoors attacks on security that's the most valuable for my clients.
What needs improvement?
There is room for improvement in documentation. Maybe the documentation about how to configure something. It is difficult to get the expected result.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
It's stable. It works very well in the parameter like an enterprise solution. We don't have any problems with that.
How are customer service and support?
We are very pleased with the support.
How would you rate customer service and support?
Positive
How was the initial setup?
I would rate my experience with the initial setup a six out of ten, where one is difficult and ten is easy to set up.
What about the implementation team?
We work on the deployment process. The solution is deployed both on-prem and in the cloud environment.
The solution doesn't require any maintenance.
What was our ROI?
It took two years to see ROI for our clients.
What's my experience with pricing, setup cost, and licensing?
Veracode is expensive. But the solution is worth it.
What other advice do I have?
Overall, I would rate the solution a nine out of ten. It is a good solution for security. In my personal opinion, there are not many products like Veracode in the market.
Good scanning, manages security risks, and prevents vulnerable code from going into production
What is our primary use case?
We have data deployments for B2B and B2C with the product. Before we used a deployment center like Jenkins. We use it for backend content.
What is most valuable?
We've only used the solution for a year; it hasn't been that long.
The deployment mode is very useful.
We like that it can prevent vulnerable code from going into production.
We use the low-level elements and do greenlight deployment through Veracode.
It helps us manage our licensing and security risks. However, we are in the implementation process right now. So far, it's okay and working fine.
It's good that we can do a full code scan, front to back, or vice versa.
We mostly use the policy scan and vulnerability scan mostly.
The security is okay.
What needs improvement?
The reporting can be difficult. It's not very easy.
It's taking too much time to do a quality scan. It hasn't saved us much time. Deployment was three or four months ago. We did a policy scan using a greenlight deployment. When we do the deployment in Jenkins, we can do it faster. In Veracode, it can take four hours or even eight hours.
We don't like how long it takes to do a deployment. It should deploy more quickly.
For how long have I used the solution?
I've used the solution for a year.
What do I think about the stability of the solution?
While there is no lagging or crashing, it takes too much time to deploy.
What do I think about the scalability of the solution?
We haven't had any issues with scalability. That said, currently we are not scaling. Previously it was fine. Currently, we're not scaling.
How are customer service and support?
Currently, we do not use support. We don't communicate with them.
Which solution did I use previously and why did I switch?
We have used SAP and Jenkins in the past.
How was the initial setup?
The deployment takes too long.
I was not directly involved in the deployment of Veracode. I generally use Jenkins only.
Two people are typically involved in the deployment.
Every week, on Friday, we put the servers down, and every Monday, we put them back up, to save on costs.
What about the implementation team?
The deployment is automated using Jenkins. We just need some parameters to deploy the code to the environment.
What's my experience with pricing, setup cost, and licensing?
The pricing is worth it. However, users need to go through the documentation first to get a handle on the implementation. Users might need the help of a support platform.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this solution.
What other advice do I have?
I'm not sure how much visibility we are getting using the solution.
The false positive rate we haven't really looked into. We need to learn more about it.
We are just end users, not partners.
I'd rate the solution eight out of ten.
It's a good idea to look at the documentation. Be very cautious when implementing servers.