Check Point CloudGuard WAF vs Veracode comparison

Cancel
You must select at least 2 products to compare!
Check Point Software Technologies Logo
442 views|127 comparisons
100% willing to recommend
Veracode Logo
25,659 views|17,134 comparisons
90% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Check Point CloudGuard WAF and Veracode based on real PeerSpot user reviews.

Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed Check Point CloudGuard WAF vs. Veracode Report (Updated: March 2024).
769,599 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"It is a highly scalable solution with a quick turnaround time for deployment and running of the software across any IT system.""It provides advanced analytics that gives each team time to prepare for any threat that might occur in the future.""The features I have found most valuable are the comprehensive threat prevention capabilities, automated policy management, and seamless integration with cloud environments.""The app control is very sensitive, and the threat detection and prevention is better than other Check Point solutions. There is a centralized management console for threat protection and self-inspection.""The solution offers continuous security monitoring and alerting, which can help organizations detect and respond to security incidents in real time.""We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and it was amazing to see the results.""The first valuable feature is that it is not a complex process to get it up and running. It was not complex at all. We were in a close relationship with the team that developed the app, and it worked in a few hours. The second valuable feature is the information that comes out of it.""It offers high performance and improved productivity for users."

More Check Point CloudGuard WAF Pros →

"With the pipeline scanner, it's easier for developers to scan their products, as they don't have to export anything from their computers. They can do everything with the command line on their computer.""One of the features they have is Software Composition Analysis. When organizations use third-party, open source libraries with their application development, because they're open source they quite often have a lot of bugs. There are always patches coming out for those open source applications. You really have to stay on your toes and keep up with any third-party libraries that might be integrated into your application. Veracode's Software Composition Analysis scans those libraries and we find that very valuable.""Veracode provides guidance for fixing vulnerabilities. It enables developers to write secure code from the start by pointing them to the problematic line of code, and saying, "This function/method has security vulnerabilities," then suggests alternatives to fix it. Then, we adopt their suggestions of the tool. By implementing it in the right way, we can fix the issue. For example, if the tool has found a method where it copied one piece of memory into another piece of memory in the code. The tool points to problematic methods with the vulnerability and provides ways to code it more securely. By adopting their suggestions, we are fixing this vulnerability.""Considering that in my project, we are mostly using Software Composition Analysis as a part of Static Code Analysis, for me, the main part is reporting and highlighting necessary vulnerabilities. Veracode platform has a rather good database of different vulnerabilities in different libraries and different sources. So, finding vulnerabilities in third-party libraries is the main feature of Software Composition Analysis that we use. It is the most important feature for us.""They also have what's called a Software Composition Analysis that can point out errors and fixes for third-party software frameworks, which is very nice.""The Security Labs [is] where I have the developers training and constantly improving their security, and remembering their security techniques. That way, they are more proactive and make sure things are correct. They're faster because they're doing it in the first place.""It has an easy-to-use interface.""Veracode does not require any maintenance."

More Veracode Pros →

Cons
"For the next release, I would suggest considering features like enhanced threat intelligence integration.""The coding configurations can be simplified to save time for IT teams and developers.""There are occasions when it interfaces with other systems, leading to a loss of visibility.""Cost reduction and trial period extension should be considered with some lucrative discount offerings in buying standard versions.""We would like to have a solution of this type for the administration of applications from mobile devices.""A feature we'd like to see in the future is something that could protect against other attack vectors, with a focus on application protection.""There should be automation of threat detection, risk mitigation, and report generation.""They should improve in the delivery of more detailed reports with more information."

More Check Point CloudGuard WAF Cons →

"I'd like to see an improved component of it work in a DevOps world, where the scanning speed does not impede progress along the AppSec pipeline.""The scanning could be improved, because some scans take a bit of time.""The interface is basic and has room for improvement.""I would love to be able to do a dynamic sandbox scan. I think that that would allow us to really get a lot more buy-in from the software development teams.""When Veracode updates the pool of tests and security checks, it could be a little more transparent about what it is releasing. It's not clear what it's adding. They do thousands of checks, and when they add more, there aren't many details about what the new tests are doing.""The documentation is poor and the technical support isn't helpful.""I've seen slightly better static analysis tools from other companies when it comes to speed and ease of use.""The GUI requires significant simplification, as its current complexity creates a steep learning curve for new users."

More Veracode Cons →

Pricing and Cost Advice
  • "The tool's licensing costs are yearly and competitive."
  • "The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
  • "Check Point CloudGuard Application Security's pricing is not friendly."
  • "Considering all the benefits we've observed, we find the price to be satisfactory."
  • "It is not cheap, but it is worth it."
  • "I find the pricing to be reasonable."
  • "If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because of the differentials. There are different deltas year to year over a five-year period. It is very difficult to explain. It would be easier to digest for our executives if there was a flatter scale"
  • "Check Point CloudGuard Application Security's pricing is comparable to other products in the market."
  • More Check Point CloudGuard WAF Pricing and Cost Advice →

  • "Its complexity makes it quite expensive, but it’s all worth it, with all the engineering in the background."
  • "The pricing is pretty high."
  • "The worst part about the product is that it does not scale at all. Also, microservices apps will cost you a fortune."
  • "I think licensing needs to be changed or updated so that it works with adjustments. Pricing is expensive compared to the amount of scanning we perform."
  • "It's worth the value"
  • "Pricing seems fair for what is offered, and licensing has been no problem. All developers are able to get the access they need."
  • "It can be expensive to do this, so I would just make sure that you're getting the proper number of licenses. Do your analysis. Make sure you know exactly what it is you need, going in."
  • "The licensing and prices were upfront and clear. They stand behind everything that is said during the commercial phase and during the onboarding phase. Even the most irrelevant "that can be done" was delivered, no matter how important the request was."
  • More Veracode Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
    769,599 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and it was amazing to see the results.
    Top Answer:This is where I have a different opinion. If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because… more »
    Top Answer:In terms of features, I do not have any negatives. Their integration is extremely quick. It is better than others I have been involved with in the past. Their pricing model, however, can be better.
    Top Answer:SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use… more »
    Top Answer:The SAST and DAST modules are great.
    Top Answer:The product’s price is a bit higher compared to other solutions. However, the tool provides good vulnerability and database features. It is worth the money.
    Ranking
    Views
    442
    Comparisons
    127
    Reviews
    26
    Average Words per Review
    608
    Rating
    8.9
    Views
    25,659
    Comparisons
    17,134
    Reviews
    101
    Average Words per Review
    976
    Rating
    8.1
    Comparisons
    Also Known As
    Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
    Crashtest Security , Veracode Detect
    Learn More
    Overview

    Check Point CloudGuard Web Application Firewall (WAF) is a cloud-based security solution engineered to safeguard web applications and APIs against diverse cyber threats. Offering protection against sophisticated attacks, it identifies vulnerabilities listed in the OWASP Top 10 and blocks new threats. Utilizing contextual AI, the system reduces false positives, allowing security professionals to focus on genuine threats. With a zero-configuration setup, it automatically adapts to application changes, ensuring minimal configuration requirements. Promising swift deployments in as little as 48 hours and robust API security, CloudGuard WAF aims to streamline application security management while delivering comprehensive protection.

    Veracode is a leading application security platform that helps organizations to develop and deliver secure software. Veracode's solution provides comprehensive capabilities for static analysis, dynamic analysis, software composition analysis, and manual penetration testing.

    Veracode's static analysis solution scans source code for various security vulnerabilities, including common web application attack vectors, injection flaws, cross-site scripting, and insecure direct object references. Veracode's dynamic analysis solution simulates real-world attacks to identify vulnerabilities that may not be detectable by static analysis alone. Veracode's software composition analysis solution scans open-source and third-party components for known vulnerabilities. Veracode's manual penetration testing service is performed by experienced security professionals who use a variety of techniques to identify vulnerabilities in software applications.

    Many organizations, including Fortune 500 companies, government agencies, and startups, use Veracode's solution. Veracode's customers rely on Veracode to help them to improve the security of their software applications and to reduce the risk of data breaches and other security incidents.

    Here are some of the benefits of using Veracode:

    • Veracode provides capabilities for static analysis, dynamic analysis, software composition analysis, and manual penetration testing to help organizations identify and fix security vulnerabilities in their software applications early in the development process.
    • Veracode helps organizations reduce the risk of data breaches and other security incidents by identifying and fixing security vulnerabilities in their software application. 
    • Veracode helps organizations to comply with industry regulations. Many industries have regulations that require organizations to implement security measures to protect their customers' data. Veracode's solution can help organizations to comply with these regulations by providing them with the tools and resources they need to identify and fix security vulnerabilities in their software applications.
    Sample Customers
    Information Not Available
    Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
    Top Industries
    REVIEWERS
    Security Firm19%
    Financial Services Firm14%
    Cloud Solution Provider10%
    Comms Service Provider10%
    VISITORS READING REVIEWS
    Security Firm33%
    Financial Services Firm19%
    Comms Service Provider8%
    Healthcare Company7%
    REVIEWERS
    Computer Software Company26%
    Financial Services Firm23%
    Insurance Company9%
    Comms Service Provider6%
    VISITORS READING REVIEWS
    Financial Services Firm18%
    Computer Software Company15%
    Manufacturing Company8%
    Government6%
    Company Size
    REVIEWERS
    Small Business61%
    Midsize Enterprise18%
    Large Enterprise21%
    VISITORS READING REVIEWS
    Small Business39%
    Midsize Enterprise14%
    Large Enterprise48%
    REVIEWERS
    Small Business31%
    Midsize Enterprise20%
    Large Enterprise49%
    VISITORS READING REVIEWS
    Small Business17%
    Midsize Enterprise13%
    Large Enterprise70%
    Buyer's Guide
    Check Point CloudGuard WAF vs. Veracode
    March 2024
    Find out what your peers are saying about Check Point CloudGuard WAF vs. Veracode and other solutions. Updated: March 2024.
    769,599 professionals have used our research since 2012.

    Check Point CloudGuard WAF is ranked 11th in Application Security Tools with 29 reviews while Veracode is ranked 2nd in Application Security Tools with 194 reviews. Check Point CloudGuard WAF is rated 9.0, while Veracode is rated 8.2. The top reviewer of Check Point CloudGuard WAF writes "Automation capabilities also help streamline security processes and smooths down API integration processes and detects API availability". On the other hand, the top reviewer of Veracode writes "Helps to reduce false positives and prevent vulnerable code from entering production, but does not support incremental scanning ". Check Point CloudGuard WAF is most compared with SonarQube and Checkmarx One, whereas Veracode is most compared with SonarQube, Checkmarx One, Fortify on Demand, Snyk and OWASP Zap. See our Check Point CloudGuard WAF vs. Veracode report.

    See our list of best Application Security Tools vendors.

    We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.