Veracode False-Positive Rate
What is your impression of the solution’s false-positive rate? Please explain.
SA
Shahnawaz Azam
Manager IT at a tech company with 201-500 employees
We see a few false positives in Veracode but not many. It's negligible.
View full review »Veracode's false positive rate is very low based on what we have found.
View full review »The false positive rate we haven't really looked into. We need to learn more about it.
View full review »At first, we experienced a high number of false positives, but the Veracode team provided guidance that enabled us to significantly reduce the count.
View full review »Veracode has the lowest false positive rate in the market. Its results are accurate. In some cases, it is very difficult to see a false positive. We report it to the engineers, and they analyze it. If it is truly a false positive, the engineers will update the engine to provide better results at the next scan. The false positive rate of the static analysis has not affected the time we spend on tuning policies.
View full review »After the scanning is completed, with other solutions from a DAST perspective, we would receive a report. If there are any false positives, we would have to identify them ourselves. However, with Veracode, one of their engineers or a support team member will verify the information, which helps to minimize the number of false positives.
View full review »RB
Rajeev B.
Security Analyst at a insurance company with 10,001+ employees
When it comes to visibility, I am not sure whether it is through Veracode, but we have our pipelines built on Azure. We do get to see whenever a scan is kicked off and whether the Veracode check has passed. There is no direct visibility in Veracode apart from the dashboard, which does have information about what type of scan has been performed and whether it is a policy sandbox or just a testing sandbox.
View full review »There are very few false positives. I'd rate the false positive rate as nine out of ten. It's very good. It's very positive on developer confidence.
View full review »SM
Swarup M
Security Analyst at a tech services company with 11-50 employees
The false positives depend on the code. Veracode provides around 5% false positives.
View full review »AU
AnantUpadhyay
CEO at CareerCraftly
The false positive rate is quite low, which is critical.
View full review »PB
Pradeep Honaganahalli Basavaraju
ML engineer at a consultancy with 10,001+ employees
The false positive rate of static analysis can affect the time spent on tuning policies. It took at least one day for me to raise that mitigation and approval ticket to look into it.
View full review »The product's false-positive rate is low.
View full review »When it comes to eliminating false positives, you're never going to have 100%. While it did introduce a little frustration, what did remediate that was the explanations that the software provided.
View full review »GR
Gangadhar Reddy
System Engineer at a tech vendor with 10,001+ employees
Veracode's false positive rate is low.
View full review »I recently encountered a Veracode false positive, but we immediately mitigated it on our end. Veracode also filed the case and will include it in their code to mark it as a false positive. We took action after that.
View full review »We can see that false positives are quite low, around five to ten percent.
View full review »We don't have many false positives. We're using the tool's default rules and haven't done much customization. We can feel confident in the solution's results.
View full review »