It's decent
Updated February 23, 2021

It's decent

Anonymous | TrustRadius Reviewer
Score 1 out of 10
Vetted Review
Verified User

Modules Used

  • Static Analysis (SAST)
  • Dynamic Analysis (DAST)

Overall Satisfaction with Veracode

It is used for scanning our iOS/Android apps and to flag out any potential security issues with the code since it uses SAST/DAST.
  • It flags out issues so we are able to take action on it
  • UI is not modern
  • Complex UI
  • Slow upload speeds
  • Extra work required to compile and submit your build
  • Feel of security, but this does not mean pentest is not required.
We are actually also exploring Gitlab's Ultimate edition to leverage on their SAST and DAST as well as many other security scannings.

Do you think Veracode delivers good value for the price?

Not sure

Are you happy with Veracode's feature set?

Yes

Did Veracode live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Veracode go as expected?

Yes

Would you buy Veracode again?

No

It is well suited if you are running SAST/DAST, but as with any solutions, there is no one size fits all, and it definitely had false positives as well, like any other scanners. I did not have a hand in deciding to purchase this, but it works decent and we can automate it. However I am located in SEA, and I find the upload speeds are very very slow. Something to take note of.

Update: 22 Nov 2020. In spirit of transparency, I dropped the rating from 7 to 2 because I was invited to write the review by the vendor (Principal of Customer Advocacy) on 9 October in exchange for a small incentive for my time. However more than a month has passed and there have been no replies despite followup emails to them. I would have expected much better and am sorely disappointed. I treat timely emails very seriously and especially not getting a single reply from vendors. Granted this is not a technical support ticket, but still unprofessional and not something I would expect from someone from Customer Advocacy. This is the main reason for the rating drop. Please draw your own conclusions from this experience I have.

Veracode Support

No replies and emails were ignored from Principal, Customer Advocacy
ProsCons
None
Slow Resolution
Poor followup
Problems left unsolved
Not kept informed
Need to explain problems multiple times
Slow Initial Response
Did not purchase premium support. There should be no need for premium support if all goes well.

Using Veracode

You can do the upload process manually or automated the upload via CICD as well. It takes a long long time to upload it to the servers (from SEA region at least) and the UI is kinda confusing to me. There was some kind of refresh on the UI last year, but UX can be improved.

Relationship with Veracode

No response from the Principal, Customer Advocacy at Veracode.
Give another vendor a try.