Fortinet Penetration Testing Service vs Veracode comparison

Cancel
You must select at least 2 products to compare!
Fortinet Logo
299 views|167 comparisons
100% willing to recommend
Veracode Logo
347 views|199 comparisons
90% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Fortinet Penetration Testing Service and Veracode based on real PeerSpot user reviews.

Find out in this report how the two Penetration Testing Services solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed Fortinet Penetration Testing Service vs. Veracode Report (Updated: March 2024).
770,458 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The platform is stable.""We didn't use customer service often, but my opinion is that they are really good."

More Fortinet Penetration Testing Service Pros →

"The most valuable features are that you can do static analysis and dynamic analysis on a scheduled basis and that you can push the findings into JIRA.""The feature I like most in Veracode is that it clearly specifies the line in the entire file where a vulnerability is found.""Veracode's most valuable aspect is continuous integration. It helps us integrate with other applications so that it can monitor the security process.""I like Veracode's API. You can put it into a simple bash script and run your own security testing from your MacBook in less than 15 minutes.""Scanning of .war and .jar is key for us.""It does software composition analysis, discovering open source software weaknesses.""It has the ability to scale, and the fact that it doesn't produce a lot of false positives.""You can easily integrate it with Azure DevOps. This is an added value because we work with Azure DevOps. Veracode is natively supported and we don't have to work with APIs."

More Veracode Pros →

Cons
"I think the Fortinet Penetration Testing could be further improved by making it more robust than what it is now.""The product needs to enhance the interaction feature in terms of speed. Sometimes, when we need to get a virtual view of websites, the speed of notifications between customers and the site works slowly."

More Fortinet Penetration Testing Service Cons →

"They should improve on the static scanning time.""I do expect large applications with millions of lines of code to take a while, but it would be nice if there was a possibility to be able to have a baseline initial scan. I know that Veracode touts that there are Pipeline Scans that are supposed to take 90 seconds or less, and we've tried to do that ourselves with our ERP application. However, it actually times out after two hours of scanning. If the static scan itself or another option to run a lower tier scan can be integrated earlier on into our SDLC, it would be great. Right now, it takes so long that we usually leave it till a bit later in the cycle, whereas if it ran faster, we could push it to the time when a developer will be checking in code. That would make us feel a lot more confident that we'd be able to catch things almost instantaneously.""Veracode does not support scans for .NET Blazor server applications.""There are many times when their product goes to check my code and it dies, and I don't know why. I've contacted support and they're not really helpful with this particular problem. I go to the logs and I look at what I can but I can't tell why the check process has essentially just died in the middle of checking.""Another thing I need is continued support for the new languages today that are popular. Most of them are scripting languages more so than real, fourth-generation, commercial grade stuff; we're evolving. Most applications are using so much open-source that, quite frankly, it would be great to see Veracode, or anybody else, extend their platform to where they are able to help secure open-source platforms or repositories.""Veracode doesn't really help you so much when it comes to fixing things. It is able to find our vulnerabilities but the remediation activities it does provide are not a straight out-of-the-box kind of model. We need to work on remediation and not completely rely on Veracode.""The solution could improve the Dynamic Analysis Security Testing(DAST).""There are certain shortcomings in Veracode's static analysis engine. I would improve Veracode's static analysis engine to make it capable of identifying vulnerabilities with low false positives."

More Veracode Cons →

Pricing and Cost Advice
  • "They offer license models for a year, three years, or an extra five-year license."
  • More Fortinet Penetration Testing Service Pricing and Cost Advice →

  • "Its complexity makes it quite expensive, but it’s all worth it, with all the engineering in the background."
  • "The pricing is pretty high."
  • "The worst part about the product is that it does not scale at all. Also, microservices apps will cost you a fortune."
  • "I think licensing needs to be changed or updated so that it works with adjustments. Pricing is expensive compared to the amount of scanning we perform."
  • "It's worth the value"
  • "Pricing seems fair for what is offered, and licensing has been no problem. All developers are able to get the access they need."
  • "It can be expensive to do this, so I would just make sure that you're getting the proper number of licenses. Do your analysis. Make sure you know exactly what it is you need, going in."
  • "The licensing and prices were upfront and clear. They stand behind everything that is said during the commercial phase and during the onboarding phase. Even the most irrelevant "that can be done" was delivered, no matter how important the request was."
  • More Veracode Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Penetration Testing Services solutions are best for your needs.
    770,458 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:The product needs to enhance the interaction feature in terms of speed. Sometimes, when we need to get a virtual view of websites, the speed of notifications between customers and the site works… more »
    Top Answer:We use Fortinet Penetration Testing Service for patch updates. We get notifications from Fortinet about updates and enhancements for issues and implementing any remediation. It allows our customers to… more »
    Top Answer:SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use… more »
    Top Answer:The SAST and DAST modules are great.
    Top Answer:The product’s price is a bit higher compared to other solutions. However, the tool provides good vulnerability and database features. It is worth the money.
    Ranking
    Views
    299
    Comparisons
    167
    Reviews
    2
    Average Words per Review
    329
    Rating
    8.0
    Views
    347
    Comparisons
    199
    Reviews
    101
    Average Words per Review
    984
    Rating
    8.1
    Comparisons
    Also Known As
    FortiGuard Pentest
    Crashtest Security , Veracode Detect
    Learn More
    Overview

    This service allows FortiGuard Pentest Team to conduct a series of technical assessments on your organization’s security controls to determine the weakness on computer hardware infrastructure and software application. Our team will apply commercial automated tools to discover unintended services made publicly available by your network and we also apply real-world attackers’ methodologies to discover unknown vulnerabilities on the given target.

    Veracode is a leading application security platform that helps organizations to develop and deliver secure software. Veracode's solution provides comprehensive capabilities for static analysis, dynamic analysis, software composition analysis, and manual penetration testing.

    Veracode's static analysis solution scans source code for various security vulnerabilities, including common web application attack vectors, injection flaws, cross-site scripting, and insecure direct object references. Veracode's dynamic analysis solution simulates real-world attacks to identify vulnerabilities that may not be detectable by static analysis alone. Veracode's software composition analysis solution scans open-source and third-party components for known vulnerabilities. Veracode's manual penetration testing service is performed by experienced security professionals who use a variety of techniques to identify vulnerabilities in software applications.

    Many organizations, including Fortune 500 companies, government agencies, and startups, use Veracode's solution. Veracode's customers rely on Veracode to help them to improve the security of their software applications and to reduce the risk of data breaches and other security incidents.

    Here are some of the benefits of using Veracode:

    • Veracode provides capabilities for static analysis, dynamic analysis, software composition analysis, and manual penetration testing to help organizations identify and fix security vulnerabilities in their software applications early in the development process.
    • Veracode helps organizations reduce the risk of data breaches and other security incidents by identifying and fixing security vulnerabilities in their software application. 
    • Veracode helps organizations to comply with industry regulations. Many industries have regulations that require organizations to implement security measures to protect their customers' data. Veracode's solution can help organizations to comply with these regulations by providing them with the tools and resources they need to identify and fix security vulnerabilities in their software applications.
    Sample Customers
    edward jones, panasonic, steelcase, United Learning, Harry Rosen, Volkswagen Groupe Retail France
    Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
    Top Industries
    No Data Available
    REVIEWERS
    Computer Software Company26%
    Financial Services Firm23%
    Insurance Company9%
    Comms Service Provider6%
    VISITORS READING REVIEWS
    Financial Services Firm18%
    Computer Software Company15%
    Manufacturing Company8%
    Government6%
    Company Size
    No Data Available
    REVIEWERS
    Small Business31%
    Midsize Enterprise20%
    Large Enterprise49%
    VISITORS READING REVIEWS
    Small Business17%
    Midsize Enterprise13%
    Large Enterprise70%
    Buyer's Guide
    Fortinet Penetration Testing Service vs. Veracode
    March 2024
    Find out what your peers are saying about Fortinet Penetration Testing Service vs. Veracode and other solutions. Updated: March 2024.
    770,458 professionals have used our research since 2012.

    Fortinet Penetration Testing Service is ranked 5th in Penetration Testing Services with 2 reviews while Veracode is ranked 2nd in Penetration Testing Services with 194 reviews. Fortinet Penetration Testing Service is rated 8.0, while Veracode is rated 8.2. The top reviewer of Fortinet Penetration Testing Service writes "Flexible to use product with good technical support services ". On the other hand, the top reviewer of Veracode writes "Helps to reduce false positives and prevent vulnerable code from entering production, but does not support incremental scanning ". Fortinet Penetration Testing Service is most compared with Cobalt.io, whereas Veracode is most compared with SonarQube, Checkmarx One, Fortify on Demand, Snyk and OWASP Zap. See our Fortinet Penetration Testing Service vs. Veracode report.

    See our list of best Penetration Testing Services vendors.

    We monitor all Penetration Testing Services reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.