Skip to content
SocialAtoZ

Veracode

Verified

Application security testing delivered as a service with policy scanning

Not yet rated. Be the first to review Veracode.

Veracode screenshot See all screenshots
  • Deployment Cloud Based
  • Starting price Not published
  • Free trial Available
  • Best for Medium Business, Large Enterprise

What is Veracode?

Veracode provides application security testing as a service, covering static, dynamic and composition analysis alongside developer training. Delivering scanning as a service rather than as software the customer installs was the company's original distinguishing choice and it still shapes the product.

The service model removed a real obstacle. Static analysis tools required tuning, infrastructure and expertise the buying organisation frequently did not have, and a scan submitted to a service that returns verified results avoids the situation where a tool sits unconfigured because nobody had time to learn it properly.

Policy based scanning is the other structural idea and it suits how large organisations actually govern software. Rather than presenting every finding equally, a scan is assessed against a defined policy so that an application either passes or does not, which converts a long list into a decision somebody can act on.

Third party attestation is a use case worth knowing about. Enterprises increasingly require software vendors to demonstrate their applications have been assessed, and a recognised independent assessment is more persuasive to a customer's security team than a supplier's assurance that they scan internally.

No pricing is published, and this end of the market is priced by application count and scan frequency, typically under an annual contract with a minimum commitment.

Key Features of Veracode

  • Static application security testing
  • Dynamic application security testing
  • Software composition analysis
  • Policy based pass or fail scanning
  • Manual penetration testing services
  • Developer security training
  • Third party application attestation
  • Remediation guidance
  • CI pipeline integration
  • Compliance reporting

Veracode Pricing

Not published

Not published

No pricing is published. Priced by application count and scan frequency, usually under an annual minimum commitment.

Veracode Specifications

Deployment
  • Cloud Based
Desktop
  • Web App
Built for
  • Medium Business
  • Large Enterprise
Support
  • Email
  • Knowledge Base
  • Phone
Public API
Yes
Free trial
Yes
Free plan
No
Runs in browser
No
Customisable
No
Website
veracode.com

Veracode Videos

Veracode Screenshots

Veracode Comparisons

Veracode Reviews

No reviews yet

Used Veracode? Share your experience and help other buyers decide.

Veracode FAQs

No pricing is published. This end of the market is priced by application count and scan frequency, usually under an annual minimum commitment.

It removes the tuning, infrastructure and expertise an installed tool demands, which is why so many installed scanners sit unconfigured.

Assessing a scan against a defined policy so an application passes or fails, converting a long list of findings into a decision somebody can act on.

Enterprises increasingly require vendors to show their software has been assessed, and an independent assessment persuades where self assurance does not.

Yes, manual penetration testing is offered alongside the automated scanning, which covers the logic flaws automated tools reliably miss.