No more typing reviews! Try our Samantha, our new voice AI agent.

Appvance AIQ Platform vs Veracode comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Appvance AIQ Platform
Ranking in Static Application Security Testing (SAST)
28th
Average Rating
7.6
Reviews Sentiment
7.6
Number of Reviews
2
Ranking in other categories
Performance Testing Tools (8th), Functional Testing Tools (20th), Load Testing Tools (8th), Regression Testing Tools (9th), Test Automation Tools (18th), AI-Augmented Software-Testing Tools (5th)
Veracode
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (3rd)
 

Mindshare comparison

As of October 2026, in the Static Application Security Testing (SAST) category, the mindshare of Appvance AIQ Platform is 0.4%, up from 0.1% compared to the previous year. The mindshare of Veracode is 4.9%, down from 7.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Veracode4.9%
Appvance AIQ Platform0.4%
Other94.7%
Static Application Security Testing (SAST)
 

Featured Reviews

reviewer2798913 - PeerSpot reviewer
QA Engineer at a computer software company with 1,001-5,000 employees
Automated regression has reduced repetitive testing and now needs simpler setup and reporting
I think that Appvance AIQ Platform can be improved by making some of the advanced features easier to configure and more intuitive for new users. The platform has a broad range of capabilities, so the learning curve can be a little easier when you first start working with it. I would also like to see more flexibility in customizing dashboards and reports for different QA teams and projects. It is a strong platform for automated testing, particularly for expanding regression coverage and reducing repetitive manual testing. But I would leave some room for improvement around the learning curve, as I mentioned earlier, and reporting customization, making some advanced features more accessible would be really useful for new users.
YS
Software Development Engineer II at Rocket Software
Monthly scans have provided baseline security but still miss critical vulnerabilities
Veracode can improve to stand in this market. They do not have to do much; they just need to improve their UI experience and add more documentation within the application rather than just creating documentation pages on different websites. They need to ensure their web application guides whoever uses it. Since whoever uses Veracode must be a technical person, they just need to guide them to the actual points. They can also improve their security capabilities by adding more filters to identify what vulnerabilities their application has. They need to improve their scanning engine to scan for more critical defects. Also, the integration part can be enhanced by adding features to integrate with a CLI, such as introducing a CLI version or a Jenkins plugin. If such features exist, they should show it as a pop-up, signaling that they have a new feature. Currently, it feels Veracode from two years ago is still the same, so that is something Veracode needs to improve. They can improve the security part. Some of the severe security issues were never caught by Veracode in the reports. In fact, I have never seen any high or critical severity issues pop up in my Veracode report. That is one thing they can improve on their scanning ability to catch high severity issues. Next is integration; Veracode does not provide any tools to integrate with Jenkins or CLI. I do not even know if there is any CLI for Veracode that I can use to automate in my pipeline. The last thing is the UI interface that they have, as it is a bit confusing. I remember we did not have the capability to handle authentications of our internal application. We had to write Selenium code using a Selenium IDE. To write a Selenium script for a Veracode scan, you have to download a Selenium IDE, record it, and then paste that file into Veracode. I can see that Selenium IDE is already decommissioned, so it is no longer used by anyone. Still, we have to use it because Veracode only supports that kind of file for Selenium to automate. They can add more ways to authenticate our application using normal JavaScript or Python or Shell script. I feel these are the four main points. They can document it more by adding tooltips into the application that explain why a parameter is required and what other options are available. For the same example with the Selenium script, they can add a link to their documentation that explains what other kinds of scripts can be written for authentication. I feel they can also make the UI more intuitive so that whoever uses it can guide themselves, as whoever uses Veracode is already a technical person.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a great performance testing tool."
"We saw the biggest improvement in testing time and regression coverage with Appvance AIQ Platform, as automation reduced the amount of manual execution required and allowed us to run a larger set of tests more frequently, making our regression cycles roughly 30 to 40% faster while increasing automated test coverage with more scenarios and data variations."
"The Veracode support team is excellent."
"The best feature is definitely the detailed reports. It provides code-related queries in the order of high, medium, and low depending on what we need to do. Veracode is user-friendly as well."
"In terms of secure development, the SAST scan is very useful because we are able to identify security flaws in the code base itself, for the application."
"Another feature of Veracode is that they provide e-learning, but the e-learning is not basic, rather it is quite advanced... in the e-learning you can check into best practices for developing code and how to prevent improper management of some component of the code that could lead to a vulnerability. The e-learning that Veracode provides is an extremely good tool."
"One benefit is that we have automated the scanning process."
"The most valuable feature is the seamless automation of Veracode via the pipeline, in comparison to other solutions like Fortify SSC, which are complex to integrate through the pipeline."
"The valuable features are the static analysis and the dynamic analysis."
"We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes."
 

Cons

"Reporting features can be improved to provide more flexibility, collation, exporting in different formats, etc."
"I think that Appvance AIQ Platform can be improved by making some of the advanced features easier to configure and more intuitive for new users."
"The scans were sometimes not accurate in version 2022. There were some false positives in the vulnerability reports. We used to get false positives, and we were responsible for checking all of the alerts and determining whether they were true positives or false positives. They might have already improved it. If they have not, they can look into how to mitigate false positives."
"The user interface could be more sleek. Some scanning requirements aren't flexible. Some features take some time for new users to understand (like what exactly "modules" are)."
"Veracode would benefit greatly from more training resources. The videos are great, but I would like more hands-on training writing a script, validating a script with a unit test in a different language, etc. That's something that would be very valuable."
"One feature I would like would be more selectivity in email alerts. While I like getting these, I would like to be able to be more granular in which ones I receive."
"The scanning process could be more streamlined as it has certain limitations when performing manual scans. It has some checks when the content is in ZIP format or other formats, which takes two or three more steps than Fortify does."
"In my opinion, Veracode lacks significantly in most parts, including its UI, its reporting, ease of use, and the features that it provides."
"Scheduling can be a little difficult. For instance, if you set up recurring scheduled scans and a developer comes in and says, "Hey, I have this critical release that happened outside of our normal release patterns and they want you to scan it," we actually have to change our schedule configuration and that means we lose the recurring scheduling settings we had."
"The static scans on Java lack microservices architecture scanning. We have developed an in-house pattern for this and the scans can't take care of it as a single entity."
 

Pricing and Cost Advice

Information not available
"Veracode is a very expensive product."
"They just changed their pricing model two weeks ago. They went from a per-app license to a per-megabyte license. I know that the dynamic scan was $500 per app. Static analysis was about $4500 yearly. The license is only for the number of users, it doesn't matter what data you put in there. That was the old model. I do not know how the new model works."
"It is very reasonably priced compared to what we were paying our previous vendor. For the same price, we are getting much more value and reducing our AppSec costs from 40 to 50 percent."
"I don't have firsthand knowledge of Veracode pricing, but based on client feedback, it seems to be expensive with additional fees for certain features."
"The licensing and prices were upfront and clear. They stand behind everything that is said during the commercial phase and during the onboarding phase. Even the most irrelevant "that can be done" was delivered, no matter how important the request was."
"It is pricey. There is a lot of value in the product, but it is a costly tool."
"We pay based on the number of developers working on a particular project."
"The pricing is a little on the high side but since we combine our product into one suite, it is easy to do and works well for us."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Manufacturing Company
15%
Computer Software Company
12%
Comms Service Provider
10%
Financial Services Firm
14%
Manufacturing Company
13%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What is your experience regarding pricing and costs for Appvance AIQ Platform?
I would describe the pricing and licensing for Appvance AIQ Platform as reasonable for an enterprise-grade automation platform, although it is more of an enterprise investment than a low-cost testi...
What needs improvement with Appvance AIQ Platform?
I think that Appvance AIQ Platform can be improved by making some of the advanced features easier to configure and more intuitive for new users. The platform has a broad range of capabilities, so t...
What is your primary use case for Appvance AIQ Platform?
My main use case for Appvance AIQ Platform is automated functional and regression testing. For example, I could use Appvance AIQ Platform to automate an end-to-end regression flow for a web applica...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

Appvance
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Cisco, Bell Canada, CBS, UBC, PepsiCo, 7-11, BenefitVision, Kabbage, Catalent Pharmaceuticals, McKesson, Veritas, Cherwell, QAT Global, Sony, SiriusXM, CoPart, Auto Parts Alliance, PPD
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Appvance AIQ Platform vs. Veracode and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.