No more typing reviews! Try our Samantha, our new voice AI agent.

Trellix IVX for Enterprise Applications vs Veracode comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Trellix IVX for Enterprise ...
Ranking in Application Security Tools
30th
Average Rating
8.0
Reviews Sentiment
5.3
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Veracode
Ranking in Application Security Tools
3rd
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Static Application Security Testing (SAST) (3rd), Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (3rd)
 

Mindshare comparison

As of October 2026, in the Application Security Tools category, the mindshare of Trellix IVX for Enterprise Applications is 0.4%, up from 0.0% compared to the previous year. The mindshare of Veracode is 4.2%, down from 7.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Veracode4.2%
Trellix IVX for Enterprise Applications0.4%
Other95.4%
Application Security Tools
 

Featured Reviews

HA
General Manager at CyberTech Computer
Long-term endpoint security has protected our organization from ransomware and data loss
Trellix IVX for Enterprise Applications Collaboration is not something we are currently using. We are not using FireEye Email Security right now. We are not using the cloud version of this product. It is not difficult to manage because our team is very well trained and aware of Trellix IVX for Enterprise Applications endpoint security because we have been using it for more than 20 years. Our team is very well trained on the endpoint security. However, because we have a very distributed architecture of our organization, it is very difficult to change or replace on laptop or desktop computers. At most, only two or three engineers are involved. Trellix IVX for Enterprise Applications is very robust and easy to handle data loss protection, which are very good features. We are also using Fortinet products. The vendor team is also monitoring and does proactive measures to protect from ransomware and other security threats. We have a service level agreement with the local vendor to maintain the solution and solve other issues. The overall review rating for this product is 8 out of 10.
YS
Software Development Engineer II at Rocket Software
Monthly scans have provided baseline security but still miss critical vulnerabilities
Veracode can improve to stand in this market. They do not have to do much; they just need to improve their UI experience and add more documentation within the application rather than just creating documentation pages on different websites. They need to ensure their web application guides whoever uses it. Since whoever uses Veracode must be a technical person, they just need to guide them to the actual points. They can also improve their security capabilities by adding more filters to identify what vulnerabilities their application has. They need to improve their scanning engine to scan for more critical defects. Also, the integration part can be enhanced by adding features to integrate with a CLI, such as introducing a CLI version or a Jenkins plugin. If such features exist, they should show it as a pop-up, signaling that they have a new feature. Currently, it feels Veracode from two years ago is still the same, so that is something Veracode needs to improve. They can improve the security part. Some of the severe security issues were never caught by Veracode in the reports. In fact, I have never seen any high or critical severity issues pop up in my Veracode report. That is one thing they can improve on their scanning ability to catch high severity issues. Next is integration; Veracode does not provide any tools to integrate with Jenkins or CLI. I do not even know if there is any CLI for Veracode that I can use to automate in my pipeline. The last thing is the UI interface that they have, as it is a bit confusing. I remember we did not have the capability to handle authentications of our internal application. We had to write Selenium code using a Selenium IDE. To write a Selenium script for a Veracode scan, you have to download a Selenium IDE, record it, and then paste that file into Veracode. I can see that Selenium IDE is already decommissioned, so it is no longer used by anyone. Still, we have to use it because Veracode only supports that kind of file for Selenium to automate. They can add more ways to authenticate our application using normal JavaScript or Python or Shell script. I feel these are the four main points. They can document it more by adding tooltips into the application that explain why a parameter is required and what other options are available. For the same example with the Selenium script, they can add a link to their documentation that explains what other kinds of scripts can be written for authentication. I feel they can also make the UI more intuitive so that whoever uses it can guide themselves, as whoever uses Veracode is already a technical person.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Trellix IVX for Enterprise Applications has positively impacted my organization over the past four years, serving as one of the best security tools I have used."
"Trellix IVX for Enterprise Applications positively impacts my organization by increasing security and reducing time, especially by using threat intelligence to validate signatures across all platforms, thus minimizing manual work."
"Trellix IVX for Enterprise Applications is very robust and easy to handle data loss protection, which are very good features."
"We actually saw reduced incidents with Trellix IVX for Enterprise Applications, and it has reduced the response time for us because if there is a detection of high severity, Trellix IVX for Enterprise Applications detects it quickly and we are able to respond to it promptly."
"It has also helped to increase our fix rate by almost 100 percent."
"One thing that I like about Veracode is that it is quite a good tool for dynamic application testing."
"Right now, I couldn't ask another thing from them."
"It is SaaS hosted. That makes it very convenient to use. There is no initial time needed to set up an application. Scanning is a matter of minutes. You just log in, create an application profile, associate a security configuration, and that's about it. It takes 10 minutes to start. The lack of initial lead time or initial overhead to get going is the primary advantage."
"Veracode has saved us the cost of hundreds of employee hours by streamlining our vulnerability discovery process in legacy code, and by improving the quality of code released into production."
"The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs."
"The Static and Dynamic Analysis capabilities are very valuable to us. They've improved the speed of the inspection process."
"Another feature of Veracode is that they provide e-learning, but the e-learning is not basic, rather it is quite advanced... in the e-learning you can check into best practices for developing code and how to prevent improper management of some component of the code that could lead to a vulnerability. The e-learning that Veracode provides is an extremely good tool."
 

Cons

"Overall I find the platform useful; however, there should be ease of navigation and more actionable reporting to make investigations faster and the overall experience more efficient."
"The weak side is that it sometimes slows down the desktop computer or laptop computer."
"Customer support for Trellix IVX for Enterprise Applications is very good in theory. However, you must follow up with them for weeks and weeks for a single issue."
"I think Trellix IVX for Enterprise Applications can be improved by adding more involvement of artificial intelligence."
"Veracode needs to shift to a more modern approach because it still feels traditional in its way of doing code scanning compared with others, such as Snyk."
"One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications."
"Another thing I need is continued support for the new languages today that are popular. Most of them are scripting languages more so than real, fourth-generation, commercial grade stuff; we're evolving. Most applications are using so much open-source that, quite frankly, it would be great to see Veracode, or anybody else, extend their platform to where they are able to help secure open-source platforms or repositories."
"The overall reporting structure is complicated, and it's difficult to understand the report."
"CA still has some difficulties integrating the Veracode team in their support services."
"The only areas that I'm concerned with are some of the newer code libraries, things that we're starting to see people dabble with. They move quickly enough to get them into the Analysis Engine, so I wouldn't even say it is a complaint. It is probably the only thing I worry about: Occasionally hitting something that is built in some other obscure development model, where we either can't scan it or can't scan it very well."
"One area for improvement is the navigation in the UI. For junior developers or newcomers to the team, it can be confusing. The UI doesn't clearly bundle together certain elements associated with a scan. While running a scan, there are various aspects linked to it, but in the UI, they appear separate. It would be beneficial if they could redesign the UI to make it more intuitive for users."
"In the next release, I would like a proper way of packaging files for scanning and the packing of IOS apps and API Dynamic scan methodology."
 

Pricing and Cost Advice

Information not available
"The cost has been a barrier to wider use here. I think my team is the only one at the university. Other folks might like to use it, but it's pretty pricey. You could see what else is in the market, but I hear that's the price for most solutions. You might not find a better deal in the market, or it might be an incomplete solution. I mean, for the level of interaction we get with Veracode staff, it's been pretty good."
"I recommend going for a one-year licensing with CA, because currently they are the leaders in this field with more features and a much better turn around time with a cheaper position, but there are a lot of new companies coming up in the market and they are building up their platforms."
"They have just streamlined the licensing and they have a number of flexible options available, so overall it is quite good, albeit pricey."
"I think it's a great value. It's at a price point that a small company like mine can afford to use versus, if it was too exorbitant, I wouldn't be able to use this product. The cost of the license is small in comparison to the value it brings"
"The price of Veracode Static Analysis is on the higher side."
"Regarding licensing, pay very close attention to what applications you're going to need to do dynamic scanning for, versus static. Right now, the way the licensing is set up, if you don't have any static elements for a website, you can certainly avoid some costs by doing more dynamic licenses. You need to pay very close attention to that, because if you find out later that you have static code elements - like Java scripts, etc. - that you want to have scanned statically, having the two licenses bundled together will actually save you money."
"I believe the price is fair according to market standards."
"The pricing is really fair compared to a lot of other tools on the market."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Financial Services Firm
14%
Manufacturing Company
13%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What needs improvement with Trellix IVX for Enterprise Applications?
Endpoint services in Trellix IVX for Enterprise Applications can occasionally stop and require manual intervention. Content updates such as DAT and AMCore require troubleshooting in some environmen...
What is your primary use case for Trellix IVX for Enterprise Applications?
We have been using Trellix IVX for Enterprise Applications for one of our clients, and the console is quite intuitive. Day-to-day operations such as reviewing detection, managing endpoints, and cre...
What advice do you have for others considering Trellix IVX for Enterprise Applications?
We actually saw reduced incidents with Trellix IVX for Enterprise Applications. It has reduced the response time for us. If there is a detection of high severity, Trellix IVX for Enterprise Applica...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

No data available
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Trellix IVX for Enterprise Applications vs. Veracode and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.