Veracode and Wiz Code are key players in the application security domain. Veracode has an advantage in pricing and support, while Wiz Code's extensive features are often viewed as worth the cost.
Features: Veracode is known for static analysis, integration capabilities, and comprehensive policy management. Wiz Code provides advanced dynamic analysis, cloud-native security features, and extensive integration with emerging technologies.
Ease of Deployment and Customer Service: Veracode's established deployment model supports easy integration with robust customer service. Wiz Code aligns with DevOps practices through its agile deployment process, yet leans on automated support channels without extensive customer service.
Pricing and ROI: Veracode has a more affordable initial setup with high ROI due to stable long-term savings. Wiz Code requires a higher upfront investment, justified by advanced capabilities enhancing security in cloud environments.
The solution provides a good ROI, especially for regular customers, offering discounts for three-year licenses.
I don't think the tool in itself is very capable of doing that, but we have XSOAR and other tool integrations done on the platform, so this can be accomplished.
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
We did see a return on investment with Veracode, as we segregated our remediation efforts, which reduced our time to delivery as well as the number of engineers needed to help us in delivering a secure solution.
Wiz Code allows us to scan all accounts within minutes.
Now, with the security graph automatically correlating findings, critical issues are identified in 30 minutes, resulting in a 90 percent plus reduction in investigation effort.
If I make it a high priority, they have resolved one query within 20 minutes.
If local Indian support cannot resolve an issue, global tech support aligns promptly within the agreed SLA.
Fast response times and knowledgeable staff who understand the intricacies of the system.
Access to the engineering team is crucial for faster feedback on the product fix process.
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material.
They share detailed information via email, including screenshots or further clarification about the issue.
They've set up regular connects with the team, they share new updates, and they want to get feedback in terms of what we think could be done differently.
the response time or RTO is longer than expected, indicating where they need to improve.
Whenever we encounter any blockers or require information or permission issues in Wiz Code, they promptly address our tickets.
For stability, scalability, mean time to response, and potential incident investigation improvements, I would give it a nine or probably even a ten.
Onboarding endpoints and assets on Cortex Cloud by Palo Alto Networks is very easy.
The platform is able to auto-shut certain resources that are not in use through the agentless scan feature.
Cloud solutions are easier to scale than on-premise solutions.
It has a good capacity to scale effectively.
Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
In terms of cloud environment scalability, this is where Wiz Code generally excels, being built to handle thousands of AWS accounts, multi-cloud environments, and millions of cloud resources.
My impression of Cloud Runtime Security in stopping attacks in real-time is that I have never had an issue where it has let something through, causing an outage or concerns to the customer.
However, now in Cortex Cloud, I have not seen any lag or buffer.
My evaluation of how stable and reliable Cortex Cloud by Palo Alto Networks is very positive.
If the Veracode server is down, we experience many issues during the scan.
I have observed that it is not that reliable in terms of security because Veracode was not able to find some security threats in our application that existed since the product was developed.
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
The best part is that their entire solution is built on APIs, allowing for easy integration without a codeless approach.
Wiz Code is stable, and we can customize it according to our requirements.
Wiz Code is stable now.
Regarding the generative AI security tool, I know for sure it's Agentic.
The solution is quite premium in cost compared to alternatives such as Wiz.
There is not a clear MSP model compared to other vendors such as CrowdStrike.
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
A nice addition would be if it could be extended for scenarios with custom cleansers.
Governance is the area where Wiz Code actually shines; for large enterprises, governance is not just finding vulnerabilities; it includes ownership, accountability, exceptions, policies, risk acceptance, and auditability.
If a particular vulnerability is compromised, it could be a low severity, but if it's compromised, what business impact does it have?
When discussing IaC policies, you want to ensure engineers cannot merge anything non-compliant to your environment.
The solution is costly, with high-end capabilities suitable for enterprises.
Today, it is smart and easy to calculate the licenses.
It's not the most expensive solution.
Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
If there's a security gap, you'll never know the cost or effect.
If you are a small scale enterprise organization, you probably would not pay such a hefty amount of money to protect your organization.
Wiz Code scans your containers twice, first during runtime and then during shift-left when you build the Kubernetes manifest, which causes Wiz Code to charge separately for running the agent on the containers to give runtime posture, as well as for scanning images in the environment during shift-left.
I would say the pricing is not too high.
AI/ML aids in anticipating remediation for misconfigurations and vulnerabilities, and automatic remediation can be easily configured.
Cortex Cloud by Palo Alto Networks has reduced the time spent on incident investigations, and if I had to estimate, I would say it has cut our investigation time in half.
This simplifies the management of shared responsibility among different people and entities, allowing you to use one single tool instead of having dozens of different tools to orchestrate and integrate.
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
Wiz Code takes CNAPP to the next level by offering AppSec capabilities on top of CSPM functionality.
Wiz Code is a platform that serves most of these features as a single entity, which has definitely reduced the time for triaging the security aspects of vulnerabilities and helps in overall innovation for the team.
Since using Wiz Code, we have reduced the number of our vulnerabilities by 50%, criticals by 90%, so we are very satisfied with it.
| Product | Mindshare (%) |
|---|---|
| Veracode | 10.1% |
| Wiz Code | 3.8% |
| Cortex Cloud by Palo Alto Networks | 2.2% |
| Other | 83.9% |

| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 1 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 69 |
| Midsize Enterprise | 46 |
| Large Enterprise | 114 |
| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 2 |
| Large Enterprise | 11 |
Cortex Cloud by Palo Alto Networks enhances cloud security with features like AI/ML threat detection and automated remediation, ensuring real-time protection and efficient management across cloud environments.
Cortex Cloud by Palo Alto Networks offers comprehensive cloud security posture management and runtime protection. It reduces manual tasks and accelerates incident investigation through advanced threat detection and AI-driven anomaly detection. With integration to the MITRE ATT&CK framework, it boosts threat response while reducing incident resolution time. Although users find the UI complex and pricing high, its capabilities in securing AWS, Azure, and other environments, as well as its potential integration with CyberArk, emphasize its enterprise-ready design for cloud transformation across diverse industry sectors.
What are the key features of Cortex Cloud by Palo Alto Networks?Cortex Cloud by Palo Alto Networks is deployed across industries like telecom, BFSI, and manufacturing for robust cloud security. It's leveraged for detecting misconfigurations and vulnerabilities, aiding cloud transformation and compliance with standards such as GDPR and NIST. The integration across cloud infrastructures, including AWS and Azure, supports policy creation and threat management strategies for diverse enterprises.
Veracode is a leading provider of application security solutions, offering tools to identify, mitigate, and prevent vulnerabilities across the software development lifecycle. Its cloud-based platform integrates security into DevOps workflows, helping organizations ensure that their code remains secure and compliant with industry standards.
Veracode supports multiple application security testing types, including static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), and manual penetration testing. These tools are designed to help developers detect vulnerabilities early in development while maintaining speed in deployment. Veracode also emphasizes scalability, offering features for enterprises that manage a large number of applications across different teams. Its robust reporting and analytics capabilities allow organizations to continuously monitor their security posture and track progress toward remediation.
What are the key features of Veracode?
What benefits should users consider in Veracode reviews?
Veracode is widely adopted in industries like finance, healthcare, and government, where compliance and security are critical. It helps these organizations maintain strict security standards while enabling rapid development through its integration with Agile and DevOps methodologies.
Veracode helps businesses secure their applications efficiently, ensuring they can deliver safe and compliant software at scale.
Wiz Code is a cutting-edge tool designed to enhance business processes by offering dynamic solutions tailored to meet advanced technological demands. It delivers actionable insights and streamlines operations, making it an indispensable asset for businesses aiming for efficiency.
Renowned for its innovation, Wiz Code addresses complex business challenges through its robust features. With its adaptability, it assists organizations in optimizing workflows and improving productivity. By integrating advanced analytics, it offers unrivaled accuracy and speed, empowering decision-makers to act swiftly and confidently. Its broad array of functionalities ensures that companies can scale their operations while minimizing costs, thus optimizing overall performance.
What are the key features of Wiz Code?Industries implementing Wiz Code see streamlined operations, particularly in finance, healthcare, and logistics. In finance, it optimizes transaction processing and compliance checks. Healthcare providers rely on it for patient management and data analysis, while logistics companies benefit from improved supply chain management and inventory tracking. Its flexibility allows it to fit seamlessly into these sectors, driving efficiency and fostering growth.
We monitor all Application Security Posture Management (ASPM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.