Vendor Profile

Veracode

Veracode is an established application security testing platform that offers SAST, SCA, DAST, and penetration testing through a cloud-based service. Founded in 2006, Veracode pioneered the binary-level SAST approach that analyzes compiled code without requiring access to source code, making it suitable for testing third-party and legacy applications. Veracode provides a centralized platform for managing application security risk across large portfolios, with strong reporting for security program management and compliance.

Last updated

Founded
2006
Pricing
Custom enterprise pricing (typically $30K+ annually)
Verify with vendor
Deployment
Cloud
Enterprise Application Security

Key Features

+Binary-level SAST without source code access
+Software composition analysis for open-source risks
+Dynamic application security testing (DAST)
+Manual penetration testing services
+Application security program management dashboard
+Policy-based compliance enforcement
+Developer training through Veracode Security Labs
+Integration with major CI/CD platforms

Pros & Cons

Pros

  • +Binary-level SAST enables testing without source code access
  • +Comprehensive platform covering SAST, SCA, DAST, and pen testing
  • +Strong application portfolio management and risk scoring
  • +Developer security training integrated into the platform
  • +Proven track record with nearly two decades in the market

Cons

  • Binary analysis requires compilation, slowing scan integration in CI/CD
  • Developer experience is less intuitive compared to Snyk's workflow approach
  • Enterprise pricing is not transparent and requires sales engagement
  • Scan upload and processing times can be lengthy for large applications
  • SCA capabilities are less comprehensive than dedicated SCA tools like Snyk

Best For

Security teams managing application security across large application portfolios, especially when binary analysis of third-party or legacy applications is needed

Community & Practitioner Evidence

Community Sources

Q&A Threads
  • Veracode questions on Stack Overflow[Stack Overflow]

User Reviews

No reviews yet. Be the first to share your experience!

Sources & References

  1. Veracode — Official Website & Documentation[Vendor]
  2. Veracode Reviews on G2[User Reviews]
  3. Veracode Reviews on TrustRadius[User Reviews]
  4. Veracode Reviews on PeerSpot[User Reviews]
  5. Veracode questions on Stack Overflow[Technical Q&A]

Are you from Veracode?

Claim this listing to update your product information, respond to reviews, and ensure accuracy.