No more typing reviews! Try our Samantha, our new voice AI agent.

Aqua Cloud Security Platform vs Veracode comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Aqua Cloud Security Platform
Ranking in Container Security
25th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
16
Ranking in other categories
Cloud and Data Center Security (17th), Cloud Workload Protection Platforms (CWPP) (21st), Cloud-Native Application Protection Platforms (CNAPP) (19th), Software Supply Chain Security (16th), DevSecOps (15th)
Veracode
Ranking in Container Security
10th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
207
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (1st)
 

Mindshare comparison

As of May 2026, in the Container Security category, the mindshare of Aqua Cloud Security Platform is 2.9%, down from 3.4% compared to the previous year. The mindshare of Veracode is 2.6%, down from 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security Mindshare Distribution
ProductMindshare (%)
Veracode2.6%
Aqua Cloud Security Platform2.9%
Other94.5%
Container Security
 

Featured Reviews

Burak AKCAGUN - PeerSpot reviewer
Business Development Manager at Axoft Ukraine
A robust and cost-effective solution, excelling in scalability, on-premises support, and responsive technical support, making it well-suited for enterprises navigating stringent regulatory environment
The most crucial aspect is runtime protection, specifically image scanning before preproduction and deployment. Customers find it invaluable to have the ability to check for vulnerabilities in an image before deployment, similar to a sandbox environment. This feature ensures that customers can identify any potential issues with the image, such as misconfigurations or vulnerabilities, before integrating it into their workloads and infrastructure. In their source pipeline, companies can identify issues before deploying changes. This is crucial because customers prefer resolving any problems or misconfigurations before the deployment process. Software change security, including GSPM Cloud, is a key feature customers seek in their infrastructure.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The DTA, which stands for Dynamic Threat Analysis, allows me to analyze Docker images in a sandbox environment before deployment, helping me anticipate risks."
"We find the Docker and Kubernetes support for container security most valuable."
"Aqua Security helps us to check the vulnerability of image assurance and check for malware."
"The ROI is clear; we could not live without it because now we are getting back a picture of the vulnerability and we are able to fix severe security and vulnerability bugs."
"The container security element of this product has been very valuable to our organization."
"We previously used Alcide; Aqua gives us more features and is more solid in terms of security, and Aqua is more of a market share leader with more of a technology advantage."
"The most valuable features are that it's easy to use and manage."
"Aqua Security allowed us to gain visibility into the vulnerabilities that were present in the container images, that were being rolled out, the amount of risk that we were introducing to the platform, and provided us a look into the container environment by introducing access control mechanisms. In addition, when it came to runtime-level policies, we could restrict container access to resources in our environment, such as network-level or other application-level access."
"Overall, we've never had any problem with vulnerable code going into production."
"Compared to when we started versus now, we have done a phenomenal job, year on year our security debt has been continuously decreasing by 10 to 12 percent."
"The capability to identify vulnerable code is the most valuable feature of Veracode."
"There are really three solutions at the top of the industry ratings, and Veracode is the best, in my opinion."
"The integration with DevOps pipelines is seamless."
"The product’s policy reporting for ensuring compliance with industry standards and regulations is great."
"Veracode provides faster scans compared to other static analysis security testing tools."
"My point is that Veracode is very good, and I would strongly recommend it."
 

Cons

"They want to release improvements to their product to work with other servers because now they are more focused on the Kubernetes environment."
"I would like Aqua Security to look into the development of a web security portal."
"Aqua Security could improve the forwarding of logging into Splunk and into other tools, it should be easier."
"It's a bit hard to use the user roles. That was a bit confusing."
"In the next release, Aqua Security should add the ability to automatically send reports to customers."
"In the next release, Aqua Security should add the ability to automatically send reports to customers."
"It's a bit hard to use the user roles. That was a bit confusing."
"The user interface could be improved, especially in terms of organization and clarity."
"Those pages need to be redesigned."
"Sometimes, I get feedback from a developer saying, "They are scanning a Python code, but getting feedback around Java code.""
"It would be ideal if it was able to demonstrate higher levels of cybersecurity certifications like becoming FedRAMP compliant or working in those areas."
"Scanning large amounts of code can be a time-consuming process and there is scope for improvement."
"We tried to create an automatic scanning process for Veracode and integrate it into our billing process, but it was easier to adopt it to repositories based on GIT."
"It does nearly everything, but penetration testing."
"Technical support was difficult at times due to off-shore support that seemed to be reading from a script and not really understanding our issue."
"In the future, I would like to see the RASP capability built-in."
 

Pricing and Cost Advice

"It comes at a reasonable cost."
"The pricing of this solution could be improved."
"Aqua Security is not cheap, and it's not very expensive, such as Splunk, they are in the middle."
"Dealing with licensing costs isn't my responsibility, but I know that the licenses don't depend on the number of users, but instead are priced according to your workload."
"They were reasonable with their pricing. They were pretty down-to-earth about the way they pitched their product and the way they tried to close the deal. They were one of the rare companies that approached the whole valuation in a way that made sense for our company, for our needs, and for their own requirements as well... They will accommodate your needs if they are able to understand them and they're stated clearly."
"The pricing and licensing are reasonable, and relatively straightforward, and different licensing and subscription models are available."
"We are still considering it at the enterprise level. It has a subscription-based model. We find its price a little high based on the features it provides."
"Veracode is one of the more expensive solutions in the market, but it is worth the expense because of the eLearning and the security consultations; everything is included in the license."
"Veracode's price is high. I would like them to better optimize their pricing."
"Users in some forums mentioned that pricing for this solution can be quite high."
"Veracode is expensive. But the solution is worth it."
"I think it's a great value. It's at a price point that a small company like mine can afford to use versus, if it was too exorbitant, I wouldn't be able to use this product. The cost of the license is small in comparison to the value it brings"
"For the value we get out of it, coupled with the live defect review sessions, we find it an effective value for the money. We are a larger organization."
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
22%
Government
9%
Computer Software Company
8%
Manufacturing Company
8%
Financial Services Firm
16%
Manufacturing Company
11%
Computer Software Company
11%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise10
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise45
Large Enterprise114
 

Questions from the Community

What do you think of Aqua Security vs Prisma Cloud?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valuable feature and their speed of integration is very good. The initial setup was ...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

Aqua Security Platform, CloudSploit, Argon
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

HPE Salesforce Telstra Ellie Mae Cathay Pacific HomeAway
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Aqua Cloud Security Platform vs. Veracode and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.