Veracode and Wiz are key players in the application security and cloud security sectors, respectively. Veracode leads in static application security testing, whereas Wiz excels in providing extensive cloud security insights through its agentless approach and data visualization capabilities.
Features: Veracode is notable for static application security testing, offering detailed reports to pinpoint and classify security vulnerabilities. This assists users in keeping undeployable code out of production. Its static code analysis, OWASP integration, and compliance reporting are highly valued. Wiz shines with its cloud security feature set, notably the Security Graph, offering a comprehensive view of risks across cloud environments. Its capacity to conduct agentless scans across cloud layers simplifies assessing risks effectively for users.
Room for Improvement: Users of Veracode mention challenges with false positives, complex reporting, and sluggish scanning times as needing improvement. Enhanced integration with other tools and more user-friendly interfaces are also sought after. While Wiz has been praised for prompt receptiveness to feedback, users look for more advanced executive dashboards, improved reporting, and better detection and remediation features, alongside more automation with alert handling to reduce alert fatigue.
Ease of Deployment and Customer Service: Veracode is generally installed in public and hybrid cloud environments and is supported by competent technical service despite occasional slow responses for intricate issues. Wiz, primarily utilized in public cloud environments, is appreciated for its straightforward installation and robust customer service, coupled with a supportive setup experience and proactive community engagement.
Pricing and ROI: Veracode is perceived as a premium service with a high cost but is regarded as a solid investment due to its comprehensive security features, despite the price being expensive for some. Wiz is also on the pricier side but offers significant value through tool consolidation and comprehensive visibility across cloud settings. Its evolving pricing model and substantial cloud visibility elevate its value perception. Both serve well in delivering robust security solutions, although pricing perceptions and ROI differ based on organizational scale and needs.
The solution provides a good ROI, especially for regular customers, offering discounts for three-year licenses.
I don't think the tool in itself is very capable of doing that, but we have XSOAR and other tool integrations done on the platform, so this can be accomplished.
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
We did see a return on investment with Veracode, as we segregated our remediation efforts, which reduced our time to delivery as well as the number of engineers needed to help us in delivering a secure solution.
doing everything manually would take a lot of work and effort, and Wiz reduces both the workload and the need for manual thinking and human feedback.
Wiz Code allows us to scan all accounts within minutes.
I think we're reaching the point where we'll see a return on investment, and we'll be there by the end of the year.
If I make it a high priority, they have resolved one query within 20 minutes.
If local Indian support cannot resolve an issue, global tech support aligns promptly within the agreed SLA.
Fast response times and knowledgeable staff who understand the intricacies of the system.
Access to the engineering team is crucial for faster feedback on the product fix process.
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material.
They share detailed information via email, including screenshots or further clarification about the issue.
On a scale from 1 to 10, I would give Wiz's support a 10.
The vendor was readily available to assist us over calls, clarifying both technical aspects and theoretical insights.
If I were to put Wiz support on a scale from one to ten, I would give them a ten.
For stability, scalability, mean time to response, and potential incident investigation improvements, I would give it a nine or probably even a ten.
Onboarding endpoints and assets on Cortex Cloud by Palo Alto Networks is very easy.
The platform is able to auto-shut certain resources that are not in use through the agentless scan feature.
Cloud solutions are easier to scale than on-premise solutions.
It has a good capacity to scale effectively.
Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
Our environment quadrupled in size. We didn’t have to make any adjustments or configuration changes; it just accommodated the growth.
In terms of scalability, I don't feel any issues.
In terms of cloud environment scalability, this is where Wiz Code generally excels, being built to handle thousands of AWS accounts, multi-cloud environments, and millions of cloud resources.
My impression of Cloud Runtime Security in stopping attacks in real-time is that I have never had an issue where it has let something through, causing an outage or concerns to the customer.
However, now in Cortex Cloud, I have not seen any lag or buffer.
My evaluation of how stable and reliable Cortex Cloud by Palo Alto Networks is very positive.
If the Veracode server is down, we experience many issues during the scan.
I have observed that it is not that reliable in terms of security because Veracode was not able to find some security threats in our application that existed since the product was developed.
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
The stability of Wiz has been good, with no downtime, bugs, or glitches.
The best part is that their entire solution is built on APIs, allowing for easy integration without a codeless approach.
The services were stable, and we did not experience any downtime.
Regarding the generative AI security tool, I know for sure it's Agentic.
The solution is quite premium in cost compared to alternatives such as Wiz.
There is not a clear MSP model compared to other vendors such as CrowdStrike.
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
A nice addition would be if it could be extended for scenarios with custom cleansers.
One significant area for improvement would be increasing automation. While they excel at identifying issues, we need assistance in minimizing the human hours required for tasks.
Adding AI-driven features could significantly assist developers in addressing vulnerabilities more efficiently, thereby improving deployment times and adherence to deadlines.
Governance is the area where Wiz Code actually shines; for large enterprises, governance is not just finding vulnerabilities; it includes ownership, accountability, exceptions, policies, risk acceptance, and auditability.
The solution is costly, with high-end capabilities suitable for enterprises.
Today, it is smart and easy to calculate the licenses.
It's not the most expensive solution.
Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
If there's a security gap, you'll never know the cost or effect.
I don’t think there’s anyone else out there offering the same level, scale, or efficiency.
If you are a small scale enterprise organization, you probably would not pay such a hefty amount of money to protect your organization.
Wiz is less expensive than Microsoft and Palo Alto.
AI/ML aids in anticipating remediation for misconfigurations and vulnerabilities, and automatic remediation can be easily configured.
Cortex Cloud by Palo Alto Networks has reduced the time spent on incident investigations, and if I had to estimate, I would say it has cut our investigation time in half.
This simplifies the management of shared responsibility among different people and entities, allowing you to use one single tool instead of having dozens of different tools to orchestrate and integrate.
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
The ability to scan every layer without agents is a huge selling point because we're multi-agent.
My favourite is the EASM/External Exposure view and overall package - full risk visibility. It allows us to prioritize, and I mean truly prioritize, what should be addressed first.
The granularity of visibility that the platform provides is the most valuable aspect.

| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 1 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 70 |
| Midsize Enterprise | 46 |
| Large Enterprise | 114 |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 12 |
| Large Enterprise | 48 |
Cortex Cloud by Palo Alto Networks enhances cloud security with features like AI/ML threat detection and automated remediation, ensuring real-time protection and efficient management across cloud environments.
Cortex Cloud by Palo Alto Networks offers comprehensive cloud security posture management and runtime protection. It reduces manual tasks and accelerates incident investigation through advanced threat detection and AI-driven anomaly detection. With integration to the MITRE ATT&CK framework, it boosts threat response while reducing incident resolution time. Although users find the UI complex and pricing high, its capabilities in securing AWS, Azure, and other environments, as well as its potential integration with CyberArk, emphasize its enterprise-ready design for cloud transformation across diverse industry sectors.
What are the key features of Cortex Cloud by Palo Alto Networks?Cortex Cloud by Palo Alto Networks is deployed across industries like telecom, BFSI, and manufacturing for robust cloud security. It's leveraged for detecting misconfigurations and vulnerabilities, aiding cloud transformation and compliance with standards such as GDPR and NIST. The integration across cloud infrastructures, including AWS and Azure, supports policy creation and threat management strategies for diverse enterprises.
Veracode is a leading provider of application security solutions, offering tools to identify, mitigate, and prevent vulnerabilities across the software development lifecycle. Its cloud-based platform integrates security into DevOps workflows, helping organizations ensure that their code remains secure and compliant with industry standards.
Veracode supports multiple application security testing types, including static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), and manual penetration testing. These tools are designed to help developers detect vulnerabilities early in development while maintaining speed in deployment. Veracode also emphasizes scalability, offering features for enterprises that manage a large number of applications across different teams. Its robust reporting and analytics capabilities allow organizations to continuously monitor their security posture and track progress toward remediation.
What are the key features of Veracode?
What benefits should users consider in Veracode reviews?
Veracode is widely adopted in industries like finance, healthcare, and government, where compliance and security are critical. It helps these organizations maintain strict security standards while enabling rapid development through its integration with Agile and DevOps methodologies.
Veracode helps businesses secure their applications efficiently, ensuring they can deliver safe and compliant software at scale.
Wiz enhances cloud security with features like CSPM, risk prioritization, and centralized visibility. Users benefit from agentless scanning and integration with CI/CD tools, improving threat detection and compliance management.
Wiz offers a comprehensive security solution for cloud environments by providing functionalities like threat intelligence, detailed risk analysis, and automated compliance mapping. It supports vulnerability management and risk analysis, utilizing agentless deployment for seamless integration across multi-cloud settings. The platform's ability to streamline workflows and reduce false positives enables users to improve remediation speed and bolster security posture. Despite impressive capabilities, there is a need for improvement in reporting, security functionality for Kubernetes, handling false positives, and integration with APIs. Enhanced dashboards and more flexibility in automation processes are also required.
What are the key features of Wiz?Industries integrate Wiz for cloud security posture management, ensuring compliance and managing vulnerabilities in multi-cloud environments. Users leverage its agentless capabilities to protect cloud-native applications, integrating with CI/CD pipelines to enhance security operations and automate remediation. This comprehensive approach offers robust cloud security solutions.
We monitor all Container Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.