Veracode and Prisma Cloud by Palo Alto Networks compete in application security and cloud security. Prisma Cloud's extensive cloud capabilities often make it a more comprehensive solution for cloud environments, while Veracode maintains strength in application-focused scenarios.
Features: Veracode focuses on robust static analysis and comprehensive security findings, ideal for securing applications during development. It supports a wide range of platforms and programming languages, offering remediation consulting and seamless integration with developer tools like Visual Studio and Eclipse. Prisma Cloud provides cloud security features such as compliance monitoring, threat detection, runtime protection, and policy management, enabling robust cloud security management.
Room for Improvement: Veracode can improve ease of use due to its learning curve and sometimes high false positive rates, which can slow down the development cycle. Fielding better integration with existing enterprise DevOps tools and enhancing user interface would be beneficial. Prisma Cloud could enhance its user interface for simpler navigation, expand automation capabilities, and improve integration with third-party services for broader security visibility.
Ease of Deployment and Customer Service: Prisma Cloud integrates seamlessly with CI/CD pipelines, and offers detailed documentation and a strong support network. Veracode provides straightforward integration but faces critique for a steeper learning curve related to its specific security tools. Prisma Cloud typically offers a smoother adoption experience due to its flexible deployment options and responsive support.
Pricing and ROI: Veracode's pricing is structured around application needs, providing ROI by reducing software vulnerabilities early in the lifecycle. Prisma Cloud might have a higher initial cost but offers substantial long-term ROI with comprehensive security features across multiple cloud domains. The decision may depend on whether an organization prioritizes application-specific security or comprehensive cloud security, affecting the considered enterprise ROI.
It eliminates the need for additional hardware, making it a financially and technically sound investment.
From a security standpoint, we have significantly enhanced our client's security posture by implementing Prisma Cloud.
The platform is not famous for being cheap. It is quite expensive, but we know that we have the protection, so there is enough value for what we pay for.
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
Whenever I have issues with the solution, I will get an immediate response from the product team and they will try to close the issue as soon as possible.
When you send them a message, you get a response in a minute or two.
They can respond with technical documentation or pass on the case to the next level because it requires the development of a new feature or changing a feature due to a bug.
Access to the engineering team is crucial for faster feedback on the product fix process.
They are very responsive and quick to help with queries within our scope.
They respond very quickly since security is something critical.
It's very scalable and very easy to use.
I would rate the scalability of Prisma Cloud as an eight out of ten.
I am highly impressed with the product's scalability.
Cloud solutions are easier to scale than on-premise solutions.
It has a good capacity to scale effectively.
I cannot recall any downtime with the solution.
I would rate it a ten out of ten for stability.
The tool responds well in small-scale infrastructures, functioning perfectly without any issues.
If the Veracode server is down, we experience many issues during the scan.
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
It is a SaaS solution, but some of my clients have a local regulatory requirement, and they want to install it locally on their premises.
From a developer's perspective, especially for organizations like banks developing their applications, ensuring API security before deploying them to the cloud is crucial.
Prisma Cloud is an excellent tool.
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
A nice addition would be if it could be extended for scenarios with custom cleansers.
Prisma Cloud is remarkably expensive.
The cost was not on the higher side.
That's why a lot of our clients are shifting from cloud-native to Prisma Cloud: because of its effectiveness and because it is budget-friendly as well.
It's not the most expensive solution.
If there's a security gap, you'll never know the cost or effect.
Pricing-wise, I find it a bit expensive because it's based on the number of users requesting access to Veracode.
Security posture management is the most valuable feature.
We could spread the Prisma Cloud platform to 16 countries without encountering any kind of problem.
Prisma Cloud provides risk clarity at runtime and across the entire pipeline, like, showing issues as they're discovered during the build phases.
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
Prisma Cloud by Palo Alto Networks delivers comprehensive security for cloud environments, focusing on workload protection, identity creation, and seamless AWS integration. Its cloud visibility and control, combined with thorough vulnerability scanning, help maintain robust security across multi-cloud platforms.
Prisma Cloud provides essential capabilities for cloud security posture management, container security, and compliance monitoring. Enterprises utilize it to secure cloud configurations, detect vulnerabilities, and ensure regulatory compliance, spanning AWS, Azure, and Google Cloud. Its runtime management, identity-based micro-segmentation, and threat detection enhance cybersecurity. Despite needing improvements in documentation, integration complexities, UI, and the need for role-based access control refinement, it remains pivotal for securing assets across cloud infrastructures, particularly with its capabilities for vulnerability scanning and CI/CD pipeline integration.
What are the key features?
What benefits or ROI should users expect?
In industries like finance, healthcare, and retail, Prisma Cloud is implemented to strengthen cybersecurity measures, facilitate regulatory compliance, and enhance governance. Organizations leverage its features to secure sensitive data, monitor configurations, and integrate security processes within CI/CD workflows, ensuring robust protection across complex cloud infrastructures.
Veracode is a leading provider of application security solutions, offering tools to identify, mitigate, and prevent vulnerabilities across the software development lifecycle. Its cloud-based platform integrates security into DevOps workflows, helping organizations ensure that their code remains secure and compliant with industry standards.
Veracode supports multiple application security testing types, including static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), and manual penetration testing. These tools are designed to help developers detect vulnerabilities early in development while maintaining speed in deployment. Veracode also emphasizes scalability, offering features for enterprises that manage a large number of applications across different teams. Its robust reporting and analytics capabilities allow organizations to continuously monitor their security posture and track progress toward remediation.
What are the key features of Veracode?
What benefits should users consider in Veracode reviews?
Veracode is widely adopted in industries like finance, healthcare, and government, where compliance and security are critical. It helps these organizations maintain strict security standards while enabling rapid development through its integration with Agile and DevOps methodologies.
Veracode helps businesses secure their applications efficiently, ensuring they can deliver safe and compliant software at scale.
We monitor all Container Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.