My Veracode Review
September 04, 2020

My Veracode Review

Anonymous | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Modules Used

  • Static Analysis (SAST)
  • Dynamic Analysis (DAST)
  • Developer Training
  • Discovery

Overall Satisfaction with Veracode

Veracode is our primary tool for application security. We use Veracode to do static code analysis and dynamic analysis of the code deployed on web servers. It's used across the whole organization. Veracode helps identify the application vulnerabilities quickly and with a very low false-positive ratio, and you get direct access to Veracode's application security experts to help and understand what kind of remediation is required.
  • Application security consultants are real experts. Their suggestions on remediation help the team understand the vulnerabilities discovered.
  • Support team is quick to fix any issues.
  • Any issues or maintenance related to the environment are explained to users with sufficient details.
  • Their false positive ratio on the vulnerability discovery is very low.
  • One of the improvements I am looking for is to include multi-factor authentication for the applications.
  • Some of my users feel the application navigation experience is not very friendly.
  • Having a low false-positive ratio and direct access to application security experts from Veracode helps identify and remediate the issues quickly. I think this is very significant to make the application secure.
The customer support team is very responsive. They do not hesitate to jump on a conference call, understand the issue, and fix it. In some cases where I opened a ticket on the wrong queue or I was unable to determine the team or category, the support person was very quick to identify the right team and get me connected immediately.

Do you think Veracode delivers good value for the price?

Yes

Are you happy with Veracode's feature set?

Yes

Did Veracode live up to sales and marketing promises?

Yes

Did implementation of Veracode go as expected?

Yes

Would you buy Veracode again?

Yes

Integration with SDLC is very good. A lot of things can be automated using their API. Application static and dynamic analysis service is very good, but I think interactive application testing is still lacking