No more typing reviews! Try our Samantha, our new voice AI agent.

Trend Micro Cloud App Security [EOL] vs Veracode comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 26, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Trend Micro Cloud App Secur...
Average Rating
8.2
Reviews Sentiment
6.2
Number of Reviews
9
Ranking in other categories
No ranking in other categories
Veracode
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (2nd)
 

Featured Reviews

Anuradha Buluwala - PeerSpot reviewer
Head of Technical at Connex Information Technologies Pvt Ltd
Useful for cloud data protection, particularly for email and file-sharing systems
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto. The solution should also expand integration from the public cloud to the private cloud and add Cloud DLP and CASB features.
reviewer2753535 - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
Integrates security into the development process and improves team collaboration
Veracode helps organizations develop software by reducing the risk of security vulnerabilities through developer enablement and applications focused on governance. You can utilize different levels of processes to achieve better performance or a more scalable service. Since I started working with it in 2022, I’ve found it to be cost-effective as well. Overall, Veracode is a user-friendly security tool. It includes features such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). During the development phase, we can identify vulnerabilities in the application. This process occurs in the staging environment during development. When we're ready to go to production, we conduct a final check. Essentially, this tool helps identify vulnerabilities during the code development stage, including both high-level vulnerabilities and those related to open-source software composition. We utilize specific methodologies for this purpose. Additionally, it offers a feature that allows us to set up policies based on client requirements. This means we can customize the tool to meet the specific needs of our clients, ensuring that they receive the appropriate level of security in their applications. Veracode is user-friendly as well. Compared to other tools, their scans take 15 minutes or under. If you have a large scale of libraries or data, it might take longer, but based on my personal experience, the scan usually runs within fifteen minutes. For my case study using the Veracode tool, I worked on an internal project following industry standards. We used Veracode to improve our security posture and speed up the time to market by streamlining the development process. This enhanced collaboration between developers, operations, and security teams. The automated scanning process helped identify and fix vulnerabilities earlier in the development process. We maintained compliance with regulatory requirements, avoided fines, and built customer trust by integrating security into the development process. When we conduct this scan, we receive data on a list of vulnerabilities. This information improved our communication and increased transparency, which leads to better reports about the efforts being put in. This results in a more effective and efficient collaboration process, making it user-friendly for all involved. When considering costs, if we resort to manual processes, it can be time-consuming. Therefore, we utilize automated scans to identify and fix security issues. This allows us to address vulnerabilities early in the development process, as we discussed previously. This applies both to our in-house code and third-party libraries, using Software Composition Analysis (SCA) agent-based scans. In the future, we will also implement SCA agent-based scans as a separate feature within Veracode, which can help organizations avoid the expensive and time-consuming consequences of security issues. Furthermore, we have seen an increase in compliance, helping to maintain adherence to regulatory requirements and industry standards, thereby avoiding fines and reputational damage associated with noncompliance. Additionally, by integrating security into the development process, we enhance customer trust in our organization and its products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This is a very dependable solution and we are able to have a lot of Trend Micro security products integrated between each other."
"It has more intelligence features than other vendors."
"The most valuable feature of Trend Micro Cloud App Security is its stability across all platforms."
"Trend Micro Cloud App is easy to use and easy to install."
"Our business emails are very important and Trend Micro Cloud App Security has provided a high level of protection. Additionally, there are updating the solution frequently."
"I find Trend Micro Cloud App Security useful for scanning our email boxes. We can scan them one by one, which is a good feature. It's not just gateway-level protection - we integrate the email system with it. They have special protection and parameters for phishing emails."
"The initial setup is pretty straightforward."
"Trend Micro has DLP features in it, which separates it from other solutions."
"The integrated IDE tool enables users to get instant feedback in real-time on the code itself, rather than waiting for it to go through the CI/CD pipeline and get the result."
"It is SaaS hosted. That makes it very convenient to use. There is no initial time needed to set up an application. Scanning is a matter of minutes. You just log in, create an application profile, associate a security configuration, and that's about it. It takes 10 minutes to start. The lack of initial lead time or initial overhead to get going is the primary advantage."
"Static scanning and software composition analysis are very helpful. I and my colleagues don't need to be an expert on all of those ancillary things, so we can focus more on the business deliverables."
"It is a cloud-based platform, so every organization or every security team in the organization is concerned about uploading their code because ultimately the code is intellectual property. The most useful thing about Veracode is that if you want to upload the code, they accept only byte code. They do not accept the plain source code as an input. The code is converted into binary code, and it is uploaded to Veracode. So, it is quite secure. It also has the automation feature where you can integrate security during the initial stages of your software development life cycle. It is pretty much easy with Veracode. Veracode provides integration with multiple tools and platforms, such as Visual Studio, Java, and Eclipse. Developers can integrate with those tools by using Jenkins. The security consultation or the support that they provide is also really good. Its user management is also good. You can restrict the users for a particular application so that only certain developers will be able to see the code that has been scanned. Their reporting model is really good. For each customer, they provide a program manager. Every quarter, they have their reviews about how much it has scanned. They also ensure that the tool has been used efficiently."
"The most valuable feature is the seamless automation of Veracode via the pipeline, in comparison to other solutions like Fortify SSC, which are complex to integrate through the pipeline."
"Veracode has positively impacted our organization by giving us a good chance to focus on development as we don't need to focus as much on compliance-related matters after we have ensured this level of security on the security posture management for our application."
"Another feature of Veracode is that they provide e-learning, but the e-learning is not basic, rather it is quite advanced... in the e-learning you can check into best practices for developing code and how to prevent improper management of some component of the code that could lead to a vulnerability. The e-learning that Veracode provides is an extremely good tool."
"The most valuable features include the total developer experience, along with regulator exposure and DevOps pipeline. It encompasses everything as an enterprise solution."
 

Cons

"The cost of the license is on the high side."
"The pricing of this solution is quite high, about double what other similar solutions cost."
"For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto."
"There is room for improvement in the DLP component of Trend Micro Cloud App Security."
"They should provide separate corporate-level licenses for two to three instances."
"The granulation of the policy setup needs to be better. Right now, it is too basic."
"It would be great if Trend Mail Cloud App Security would be joined with a web security solution, making it a multiple-network solution."
"The solution's technical support services could be better."
"Sometimes Veracode gives us results about small glitches in the necessary packages. For example, we recently found issues with Veracode's native libraries for .NET 6 that were fixed in the next versions of those libraries. But sometimes you do not know which version of the library particular components are using. The downside of that is that one day, the solution found some issues in that library for the necessary package we spent. Another day, it found the same issues with another library. It will clearly state that this is the same stuff you've already analyzed. This creates some additional work, but it isn't significant. However, sometimes you see the same issue for two or three days in a row."
"The scanning takes a lot of time to complete."
"Because our application is large, it takes a long time to upload and scan."
"Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries."
"For one or two particular applications, the dynamic code analysis can take too much time. Sometimes, it takes three days or more."
"It does nearly everything, but penetration testing."
"We have not had much free expert support from the vendor. We have had to have a team of highly skilled individuals to make the solution work."
"I haven't heard about any problems so far. However, it would be great if Veracode automatically packaged stuff up for you."
 

Pricing and Cost Advice

"The pricing of the solution could be better."
"The price of Trend Micro Cloud App Security is expensive for regular users. There are not any hidden fees. First-time users of the solution should purchase implementation packages or professional services."
"The solution's price is mid-ranged."
"The cost of the license is on the high side. It's a yearly subscription."
"The product's pricing is reasonable compared to other vendors."
"Licensing cost is on a yearly basis and there are no additional costs, the pricing is straightforward."
"Compared to the typical software composition analysis solutions, Veracode is not so costly, although the static analysis part of it is a little costlier."
"Costs are reasonable. No special infrastructure is required and the license model is good."
"I believe the price is fair according to market standards."
"The pricing for Veracode is high, making it difficult for beginners to afford."
"It's worth the value"
"Veracode is costly. They have different license models for different customers. What we had was based on the amount of code that has been analyzed. The license that we had was capped to a certain amount, for example, 5 Gig. There would be an extra charge for anything above 5 Gig."
"The product’s price is a bit higher compared to other solutions."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
912,801 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
13%
Comms Service Provider
9%
Construction Company
8%
Outsourcing Company
8%
Financial Services Firm
14%
Manufacturing Company
11%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise2
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What needs improvement with Trend Micro Cloud App Security?
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto. The solut...
What is your primary use case for Trend Micro Cloud App Security?
We use the solution for cloud data protection, particularly for email and file-sharing systems. It integrates with Microsoft Office 365 and Google Suite to scan mailboxes for spam, viruses, and phi...
What advice do you have for others considering Trend Micro Cloud App Security?
We chose the solution because they've been Gartner leaders for over 15 years, have a good customer base, and are a well-established company. I'd rate the product an eight out of ten.
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

No data available
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

MedImpact Healthcare Systems, ClubCorp USA, Copa Airlines, Aava, Azra Solutions, BSN INET Co, Ltd, Carhartt
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Application Security Tools. Updated: September 2026.
912,801 professionals have used our research since 2012.