No more typing reviews! Try our Samantha, our new voice AI agent.

Ox Security vs Veracode comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex Cloud by Palo Alto N...
Sponsored
Ranking in Application Security Posture Management (ASPM)
6th
Average Rating
8.6
Reviews Sentiment
5.7
Number of Reviews
11
Ranking in other categories
Vulnerability Management (18th), Cloud Workload Protection Platforms (CWPP) (10th), Cloud Security Posture Management (CSPM) (10th), Cloud-Native Application Protection Platforms (CNAPP) (9th), Data Security Posture Management (DSPM) (10th), Software Supply Chain Security (6th), Cloud Infrastructure Entitlement Management (CIEM) (4th), Cloud Detection and Response (CDR) (5th)
Ox Security
Ranking in Application Security Posture Management (ASPM)
10th
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Static Application Security Testing (SAST) (24th), Software Composition Analysis (SCA) (14th), Software Supply Chain Security (9th)
Veracode
Ranking in Application Security Posture Management (ASPM)
2nd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st)
 

Featured Reviews

SJ
Technical Solutions Architect at IBM
Cloud security has improved as AI-driven runtime protection detects threats and reduces incidents
In my opinion, Cortex Cloud by Palo Alto Networks could be improved or enhanced in various ways. I don't have an idea about that yet because for that you actually need to use two or three different other tools to make a basic comparison. If you ask me how good the tool is, I would fairly rate it quite high. The tool is very popular, and customers can already see that it is one of the cloud leaders in the security space. The platform had a very good feature which provides documentation links about how to use a specific feature on the UI. It takes you to the proper documentation page where it suggests what to do and tells you about the steps that need to be done for a resource deployment. My thoughts about improving the product which I believe could greatly aid vendors is that it used to be a very user-friendly tool, but now they have incorporated everything under one umbrella. It has XDR, XSOAR, and Cortex Cloud by Palo Alto Networks. Before, we used to have separate modules and separate environments for each of these capabilities or features. Right now, it is a little complex and users would take their own time to know the tool better. This is something that would have been way better, but I would say there would be different opinions on this. Talking about user-friendliness, it has decreased now.
Yossi Shmulevitch - PeerSpot reviewer
Owner at SoftContact
Experience has raised visibility into vulnerabilities but still demands deeper customization options
Regarding threat detection capability, I think that Ox Security is not used for that matter. The CISO mainly focuses on dev sec ops rather than runtime security or real-time security. I figure that the most important metrics for the analytics feature are the critical issues dashboard, which helps understand whether there is a leak of a secret or a very critical vulnerability that is not being used. Another important aspect is the integration with other products like JFrog and X-ray, which shows not all the findings but mostly focuses on what Ox Security considers the most important issues. For instance, we found some issues that were flagged by JFrog, but Ox Security dismissed them, leading to discussions about whether those issues are real, as there are often false positives in the security world, as well as considerations about the attack surface for each vulnerability and whether these are truly critical issues or not. I work extensively with JFrog X-ray, which is my major tool for another customer. I believe that JFrog is more pinpointing, and I have some integration with JFrog with the build system, the CI/CD and X-ray vulnerabilities meter. It's quite useful, but I think that they serve different purposes; JFrog comes mostly from the artifact management side and less from security. Ox Security is mostly focused on the DevSecOps and areas that cannot be detected. In terms of vulnerability management, Ox Security has strong integration, but sometimes there are vulnerabilities that are disputed or dismissed, which creates an interesting intersection between the two products. From what I talked about with the DevOps team, deployment is quite straightforward. My overall review rating for Ox Security is zero.
reviewer2753535 - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
Integrates security into the development process and improves team collaboration
Veracode helps organizations develop software by reducing the risk of security vulnerabilities through developer enablement and applications focused on governance. You can utilize different levels of processes to achieve better performance or a more scalable service. Since I started working with it in 2022, I’ve found it to be cost-effective as well. Overall, Veracode is a user-friendly security tool. It includes features such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). During the development phase, we can identify vulnerabilities in the application. This process occurs in the staging environment during development. When we're ready to go to production, we conduct a final check. Essentially, this tool helps identify vulnerabilities during the code development stage, including both high-level vulnerabilities and those related to open-source software composition. We utilize specific methodologies for this purpose. Additionally, it offers a feature that allows us to set up policies based on client requirements. This means we can customize the tool to meet the specific needs of our clients, ensuring that they receive the appropriate level of security in their applications. Veracode is user-friendly as well. Compared to other tools, their scans take 15 minutes or under. If you have a large scale of libraries or data, it might take longer, but based on my personal experience, the scan usually runs within fifteen minutes. For my case study using the Veracode tool, I worked on an internal project following industry standards. We used Veracode to improve our security posture and speed up the time to market by streamlining the development process. This enhanced collaboration between developers, operations, and security teams. The automated scanning process helped identify and fix vulnerabilities earlier in the development process. We maintained compliance with regulatory requirements, avoided fines, and built customer trust by integrating security into the development process. When we conduct this scan, we receive data on a list of vulnerabilities. This information improved our communication and increased transparency, which leads to better reports about the efforts being put in. This results in a more effective and efficient collaboration process, making it user-friendly for all involved. When considering costs, if we resort to manual processes, it can be time-consuming. Therefore, we utilize automated scans to identify and fix security issues. This allows us to address vulnerabilities early in the development process, as we discussed previously. This applies both to our in-house code and third-party libraries, using Software Composition Analysis (SCA) agent-based scans. In the future, we will also implement SCA agent-based scans as a separate feature within Veracode, which can help organizations avoid the expensive and time-consuming consequences of security issues. Furthermore, we have seen an increase in compliance, helping to maintain adherence to regulatory requirements and industry standards, thereby avoiding fines and reputational damage associated with noncompliance. Additionally, by integrating security into the development process, we enhance customer trust in our organization and its products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The AI and automation features in detecting and responding to high-risk threats are impressive; it's one of the best tools regarding AI technology and unifies security in one platform in real-time, improving vulnerability analysis, incident response, and compliance reporting."
"Previously with Cortex Cloud by Palo Alto Networks, I deployed this product for one of my customers, and after three to four months, they said that previously they had around four hours of MTTR, and now it has reduced to just 15 to 20 minutes."
"The capabilities of Cortex Cloud by Palo Alto Networks are valuable because it is the best product in the market."
"I have seen several benefits from using Cortex Cloud by Palo Alto Networks: It was easy to use and easy to migrate from the IBM platform."
"Cortex Cloud by Palo Alto Networks' cloud runtime security in terms of stopping attacks in real time is impressive."
"I have absolutely seen improvements in our incident close rates, with mean time to detect and respond reduced significantly, sometimes by at least forty to fifty percent."
"Cortex Cloud by Palo Alto Networks has impacted our organization positively by keeping our machines secure and our team using the dashboard to find issues quickly."
"The most beneficial aspect of Cortex Cloud by Palo Alto Networks and Palo Alto in general is that there is a single platform for all cloud providers for securitization."
"Ox Security has positively impacted my organization by helping to reduce the amount of noise we received from vulnerabilities because of the prioritization scoring it has and all of the context it provides."
"As a service provider, I believe the biggest advantage of Ox Security is its simplicity and the clarity of the issues, along with a very good dashboard showing the state of the company."
"Just off the cuff, the cost of the license is small in comparison to the value it brings."
"The Veracode technical support is very good. They are responsive and very knowledgeable."
"We do not pass our release without performing a static and a dynamic scan, and mitigating the flaws identified."
"The source composition analysis component is great because it gives our developers some comfort in using new libraries."
"Provides consistent evaluation and results without huge fluctuations in false positives or negatives."
"The coding standards in our development group have improved. From scanning our code we've learned the patterns and techniques to make our code more secure. An example would be SQL injection. We have mitigated all the SQL injection in our applications."
"The capability to identify vulnerable code is the most valuable feature of Veracode."
"Veracode has a nice API that they provide to allow for custom things to be built, or automation. We actually have integrated Veracode into our software development cycle using their API. We actually are able to automatically, every time a new build of a software is completed, submit that application, kick off a scan, and we get results in a much more automated fashion."
 

Cons

"The negative aspects or areas for improvement in the product include the fact that the cost might be a bit high, which challenges commercials, but not technically."
"My thoughts about improving the product which I believe could greatly aid vendors is that it used to be a very user-friendly tool, but now they have incorporated everything under one umbrella."
"Cortex Cloud by Palo Alto Networks is not the cheapest solution in the market, but I know that is the best solution for SOC and Cloud once have all tools to connect cloud issues with SOC procedures, because we are partners with T-Systems."
"From the commercial perspective, we have some limitations because Palo Alto has a minimum number of users of endpoints set at 200, which is quite high for the Italian market."
"Overall, I rate Cortex Cloud by Palo Alto Networks as an eight out of ten. I think that it could improve on price, as I know that the Google solution has the best price, and this is one of the conditions."
"Some aspects of the GUI can be confusing and make it difficult for me to find certain options or navigate where needed."
"Cortex Cloud by Palo Alto Networks is creating some confusion in terms of names because this is recent."
"As per my experience with Cortex Cloud by Palo Alto Networks, the UI could be simpler."
"The main pain point I have with Ox Security as a tool is the user interface, which can feel quite complex when navigating large datasets."
"My overall review rating for Ox Security is zero."
"Number one, I need analytics, analytics, and more analytics. It is all about risk based management and better decision support, that is why."
"We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time."
"But the support is a little bit expensive and it could be a little bit better."
"Sometimes, the scans halt or drop for some reason, and we need to get help from Veracode to fix it."
"One feature I would like would be more selectivity in email alerts. While I like getting these, I would like to be able to be more granular in which ones I receive."
"I've found that Veracode is not particularly suitable for Dynamic Application Security Testing."
"We have approximately 900 people using the solution. The solution is scalable, but there is a high cost attached to it."
"The user interface can sometimes be a little challenging to work with, and they seem to be changing their algorithm on what is an issue. I understand why they do it, but it sometimes causes more work on our end."
 

Pricing and Cost Advice

Information not available
Information not available
"Veracode's pricing is on the higher end, but it is acceptable."
"The worst part about the product is that it does not scale at all. Also, microservices apps will cost you a fortune."
"Aside from the standard licensing fees, we also have to pay for a competent Success Manager."
"The solution is expensive."
"Veracode's price is reasonable."
"Without getting too specific, I'd say the average yearly cost is around $50,000. The costs include licensing and maintenance support."
"The pricing of the product depends upon the number of codes or the number of applications."
"I'm unfamiliar with the solution's pricing, but it must be worth the cost from a company perspective, as we have been using it for years and have no plans to move away from it."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
912,069 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
16%
Construction Company
11%
Financial Services Firm
8%
Outsourcing Company
8%
Financial Services Firm
14%
Manufacturing Company
13%
Computer Software Company
10%
Educational Organization
8%
Financial Services Firm
14%
Manufacturing Company
11%
Outsourcing Company
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise1
Large Enterprise4
No data available
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What is your experience regarding pricing and costs for Cortex Cloud by Palo Alto Networks?
I am not fully aware of the pricing and licensing of Cortex Cloud by Palo Alto Networks. The pricing is also based on...
What needs improvement with Cortex Cloud by Palo Alto Networks?
In my opinion, Cortex Cloud by Palo Alto Networks could be improved or enhanced in various ways. I don't have an idea...
What is your primary use case for Cortex Cloud by Palo Alto Networks?
The usual use cases for Cortex Cloud by Palo Alto Networks that I have been working with mostly are as simple as dete...
What needs improvement with Ox Security?
I'm not sure about flexibility because I didn't try it, so I can't comment on that, but as far as I understand, most ...
What is your primary use case for Ox Security?
I worked with Ox Security as a service provider, not as a representative, but as a user. I use it in my employee capa...
What advice do you have for others considering Ox Security?
Regarding threat detection capability, I think that Ox Security is not used for that matter. The CISO mainly focuses ...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed Ap...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

No data available
No data available
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Ox Security vs. Veracode and other solutions. Updated: August 2026.
912,069 professionals have used our research since 2012.