Skip to main content
TrustRadius
Veracode

Veracode

Overview

What is Veracode?

Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.

Read more
Recent Reviews

Best in Security

10 out of 10
March 03, 2024
Incentivized
It's being used across whole organization, multiple engineering teams are using it for third-party libraries scan i.e. software …
Continue reading

Veracode to the Rescue!

10 out of 10
February 27, 2024
Veracode DAST is used on app applications in the portfolio. SAST/SCA scans and DAST scans are run monthly for all Critical application in …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons

Video Reviews

1 video

Veracode Review: Provides Helpful Support When Troubleshooting Security Needs
02:38
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Veracode?

Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

941 people also want pricing

Alternatives Pricing

What is SonarQube?

SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.

What is Indusface WAS?

Indusface Web Application Scanner provides an application security audit to detect a range of high-risk Vulnerabilities, Malware, and Critical CVEs.

Return to navigation

Product Details

What is Veracode?

The Veracode platform is a software security solution that aims to be pervasive but not invasive, embedded into the environments that developers work in, with recommended fix and in-context learning. Security teams can use Veracode to manage policy, gain a comprehensive view of an organization's security posture though analytics and reporting, mitigate risks, and produce the evidence necessary to meet regulatory requirements.

It is presented as an always-on, continuous orchestration of secure development that gives organizations the confidence that the software being built is secure and meets compliance requirements.

Veracode Features

  • Supported: Continuous Scanning to reduce risks at every phase of development - Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Test throughout SDLC.
  • Supported: Developer Experience - Finds and fixes laws in line with security integration into where developers work, automated remediation guidance, and in-context learning.
  • Supported: Comprehensive Platform Experience - Streamlined governance, risk and compliance processes through flexible policy management, unified reporting and analytics, and peer benchmarking to mitigate risks fast and deliver a successful DevSecOpsprogram.
  • Supported: Market Expansion - To meet data residency needs in EU with cloud-native instance built in Frankfurt, Germany on AWS.
  • Supported: Contextual Platform Data - Fine-tuned with nearly 2 decades of scanning and customer learning. Predicts future vulnerabilities with self-healing capabilities through applying machine learning and artificial intelligence to the data.
  • Supported: Cloud-native SaaS Architecture - Provides elastic scalability, high performance, and lower costs with cloud-native SaaS architecture.

Veracode Screenshots

Screenshot of The Veracode Platform HomepageScreenshot of Static Analysis ScansScreenshot of Findings Status and History DashboardScreenshot of The Veracode Platform

Veracode Videos

Veracode Static Analysis Demo
Veracode Software Composition Analysis Demo
Veracode Dynamic Analysis Demo

Watch The Veracode Platform

Veracode Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesNorth America, EMEA, APAC, LATAM
Supported LanguagesJava, .NET, PHP, Android, iOS, JavaScript, Python

Frequently Asked Questions

Veracode is an application security platform that performs five types of analysis; static analysis, dynamic analysis, software composition analysis, interactive application security testing, and penetration testing. Veracode offers on-demand expertise and aims to help companies fix security defects.

Checkmarx, Snyk, and SonarQube are common alternatives for Veracode.

Reviewers rate Support Rating highest, with a score of 8.

The most common users of Veracode are from Enterprises (1,001+ employees).

Veracode Customer Size Distribution

Consumers0%
Small Businesses (1-50 employees)18%
Mid-Size Companies (51-500 employees)65%
Enterprises (more than 500 employees)17%
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(197)

Attribute Ratings

Reviews

(1-25 of 66)
Companies can't remove reviews or game the system. Here's why
Score 7 out of 10
Vetted Review
Verified User
Incentivized
My team has contacted Veracode support several times, sometimes regarding how to get it set up, sometimes giving them feedback on false positives, and the Veracode team is always responsive and receptive to our needs. Their security support team is excellent at explaining how a potential flaw works and what the path to remediation looks like.
Teresa Kosinski | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Veracode Support has been great. Any time I have had a question, they have responded in a prompt manner. I'd say nine out of ten times they are able to resolve any issues that have come up with a short email exchange. For issues requiring a bit more investigation, their consultants are tops.
February 27, 2024

Veracode to the Rescue!

Score 10 out of 10
Vetted Review
Verified User
Veracode bends over backwards to make sure that customers are successful in ALL aspects of application security - from lifecycle-related activities to individual application scan activities. When developers have questions, the Veracode Community likely has the answers!
Score 8 out of 10
Vetted Review
Verified User
Incentivized
I interact with Veracode Support several times and they provide me a great support. In general, depends on who interact from the other side and some response can be a little tricky. All settle up, the environment works great and that’s what is important with a help from the support team.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Overall, Veracode support is helpful, community support is great, and documentation is available for self-service. Our Customer Success Manager is very helpful and reaches out regularly to see if we need assistance. We have not utilized many of the other resources offered by Veracode, however, in the future we would like to leverage secure coding training for our Development teams.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Vericode has been very responsive to our questions and has been proactive in getting us plugged into any new offerings. They provide regular email blasts for opportunities to participate in webinars and provide much online material for consumption. We have not yet taken advantage of their development training program but have run our top technical software engineers through the toolset training.
Christine Canassa | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
I thank the vendor team for continuous support on implementation of tasks and projects. Secure coding training has enabled my team to come up with best solution for most challenges affecting production in the organization. They do a well orchestrated follow-up to ensure the success of most projects after launching.
Score 8 out of 10
Vetted Review
Verified User
Customer support and the ability to talk with a security consultant was very handy so that we can better understand the security reports and the results. This allowed us to come up with solutions. There are still some gaps that Veracode needs to resolve such as false positives in the static scanning.
January 10, 2023

Veracode For your Code

Score 10 out of 10
Vetted Review
Verified User
Incentivized
Veracode has an option of consultation call that the developers can schedule any time if they face any kind of difficulties n performing the scans or mitigation of any flaws that may seems to be difficult in mitigating. Moreover it has a well organized FAQ and engaged community to carry on with the queries.
Mike Clarkson | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
I had one support case open with them about an issue I noticed, but it was nothing. The module list stated that a PDB file was missing, but the PDB file was generated and included in the zip file submitted. However, the PDB file it was complaining about was for a library we didn't have. The support technician was very helpful and gave me a couple of suggestions about how I can improve my submissions.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Veracode offers the developers to call their consultation team anytime if they face any difficulties in either performing the scan or mitigating any flaws that the scan founds. The consultation is easy to schedule. It has a good community where we can shoot our queries. The documentation is prepared in a good, convenient, and understandable manner.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
The information, which is Veracode provides about the flaws is very helpful, and teleconsulting is great. You can explain your specific problems, and the consultants have the ability and the time to help. You can get an appointment quickly.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
The Customer support is super good, and the consultant did a superb job! Unfortunately, the first appointment was not attended by Veracode. Therefore it took longer than expected to fix the issues. The overall experience was very good, though!
Score 8 out of 10
Vetted Review
Verified User
Incentivized
The documentation is poor, and this prevents me from leaving a perfect score. On its own, the documentation is not verbose enough to provide self-sufficiency. However, the level of human support we have received has been excellent. I had challenges trying to get the developer training labs to function properly. As a developer who came into this product fresh, I had difficulty trying to find basic answers, such as what does the scan do? How would it be integrated? Does it use AI? Does it support the latest languages in frameworks? How to integrate it into our CI/CD. What files need to be sent? How would I scan an Angular project that also uses an in-house npm library.
Their marketing website uses a lot of flowerily, catch phrase, buzzword business jargon, but it does not speak to anyone with technical knowledge who is coming in just trying to figure out what it does and how it can help our software development.
Score 9 out of 10
Vetted Review
ResellerIncentivized
Secure code training it's a great option to enable developers in the security world, it's a dynamic platform that helps to understand the vulnerabilities and how to fix them in a real environment, and the documentation contains all the information you need to understand all the functions of the Veracode platform.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Having worked with their support and program management teams now for over 5 years, I've been exposed to many support requests, concerns, and issues. We have even had one negative issue with their support team process, that was immediately addressed at their upper levels, and those upper-level management persons worked with me directly on the concerns. We recently had an issue with their mitigation process, and although it did take time to resolve, it was handled very professionally and escalated to the highest levels to address our concerns. Needs that have arisen from us as a customer have been addressed immediately and worked out with me directly by some of their most senior personnel to make sure our concerns are met. Again, their support services are among the best out there.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We have only had to contact support a few times in the nine years we've used their products. For the most part, Veracode has been very responsive either via email or on calls. These requests have either been for something that did not seem to be right in the interface or for scan-finding call-outs.
Christopher Sawyer | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Veracode support is prompt and always there to help. They are willing to get on a call with you to resolve the issue as much as possible. I have wanted more information from them at times but I have only interacted with a few support staff. They will have to escalate to other team members depending on complexity.
Mohana Chintalapati | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Account managers are extremely helpful, always ready to assist with any issues we have. I've seen vendors with account executives that schedule too many meetings and send too many emails in the process of trying to be helpful and I've seen vendors who don't really care about the customers, too. However, Veracode has just the right amount of communication. Neither more nor less. It makes them easier to work with.

Responses from the support team are pretty quick as well.
Śrinivāsa Rao Kuruba | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
- Easy to create support cases, right from the platform itself instead of visiting any other website or customer support portal.
- Privilege to create the cases granted to all users of the platform by default instead of restricting to only the Admins.
- Responses/updates to the case very promptly given. Escalation channels available via the customer success managers.
- Delegation of the user-generated cases to the platform admins of the organisation very quickly done, the scope permitting.
- Security consultation, a form of support unique to Veracode, can be very easily availed post-scan.
Return to navigation