No more typing reviews! Try our Samantha, our new voice AI agent.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
Real User
Top 20
Apr 18, 2025
Enables collaboration and customizations and improves security
Pros and Cons
  • "The good thing about Veracode is that when one scans the respective application code, all the people who are part of the transformation project can update their reviews. If there are any security flaws or vulnerabilities identified, they are able to provide sufficient justification or details about the security flaws."
  • "Veracode helped with policy compliance."
  • "Its cost and the long scanning times for large applications are the areas for improvement."

What is our primary use case?

We have now switched to another solution but our use case was SAST.

Veracode was crucial to our shift-left security strategy, as we implemented it into our transformation projects. We defined internal strategies to use Veracode in the earlier stages of application development. Each sprint received application code, and we consistently scanned it using Veracode, reducing many security flaws early in development. This proactive approach helped developers to address any remaining flaws. Additionally, we defined a Jira workflow specifically for SAST bugs to track and manage security issues effectively.

How has it helped my organization?

Veracode helped with policy compliance. We have proposed Veracode for SAST to our stakeholder in the banking plarform. They have specific security policies that the code needs to accommodate. We have two sets of policies defined: one is the default policy in Veracode, and the other is provided by stakeholders from the chief security team, who have imported policies relevant to the banking platform. The default policy is not sufficient to ensure the code is secure, so stakeholders provided more security policies relevant to their domain and the platform.

Our actual application code was a CAT-A application, meaning it had to pass SAST and DAST testing for deployment into production. This was a mandatory check from our perspective to get the code deployed into production. We have internal strategies to implement Veracode in different phases of our application deployment. Before going into production, we do SAST testing in lower environments and then one round of testing in higher environments based on bug-fixing code. We are cautious about deploying directly into production after completing security testing in Veracode because we continually receive bug-fixing code from different applications. So, we defined our strategy this way.

Veracode provided visibility into application status at every phase of development, including static analysis, dynamic analysis, composition, and penetration.

Most of the fixes relate to password encryption or some kind of SQL injections. If there are any security flaws verified against the policies defined by our stakeholders, as well as Veracode's, and if they pose a potential risk of breaches, Veracode provides excellent recommendations for fixing those security flaws. This detail helps us address the issues efficiently, as it specifies where fixes need to be applied and the implications of ignoring them. The options for developers to provide false positive comments or justification through Jira tickets if a fix cannot be implemented for a particular release are also very useful. These features in Veracode significantly aid developers in addressing security flaws in the code.

Because scanning takes a long time for uploading any kind of large application code, I would estimate we saved around 30% to 40%. After implementing our strategy for SAST within our platform, we started doing SAST scanning in Veracode for every sprint. This frequency is crucial because, without Veracode, it could be very difficult to implement such a strategy in the earliest stages of application development.

Veracode had a positive impact on our security posture. 

What is most valuable?

The good thing about Veracode is that when one scans the respective application code, all the people who are part of the transformation project can update their reviews. If there are any security flaws or vulnerabilities identified, they are able to provide sufficient justification or details about the security flaws. This helps developers fix the respective flaws in the application code, which we appreciated because it made it very easy for us to assist with fixing the application code from the development perspective.

What needs improvement?

Its cost and the long scanning times for large applications are the areas for improvement. We had integrated Veracode with other tools in the DevOps pipeline, such as Ansible and Jenkins. However, we faced a challenge, so we implemented Veracode offline, out of the DevOps pipeline. We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments. We defined different strategies to utilize Veracode for analyzing static-related security bugs in application code.

Buyer's Guide
Veracode
August 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,422 professionals have used our research since 2012.

What do I think about the stability of the solution?

I would rate it a seven out of ten for stability. If the Veracode server is down, we experience many issues during the scan, and sometimes the scan gets interrupted, requiring us to restart it.

What do I think about the scalability of the solution?

For scalability, I would rate it a nine. It has a good capacity to scale effectively.

We had 15 to 20 licenses.

How are customer service and support?

We never used Veracode support. We only worked with the stakeholders provided by the customer. They were supportive. 

The responsiveness and quality of documentation from Veracode are notable compared to other tools we are currently using, where we often struggle to find the same level of support.

How was the initial setup?

It was easy.

What was our ROI?

I estimate we saved around 60% to 70% of our resources with Veracode.

What's my experience with pricing, setup cost, and licensing?

Pricing-wise, I find it a bit expensive because it's based on the number of users requesting access to Veracode.

Lower budget products may struggle to incorporate all of Veracode's capabilities into their processes.

Which other solutions did I evaluate?

We were looking for a tool in the market that could provide support for SAST or static analysis security testing. We wanted to implement it in the earlier phases of our transformation project. We looked into the analysis of different tools in the market, and then we decided that Veracode was the right tool at the time to provide more support for the SAST testing in our transformation project.

Veracode stands out when compared to other solutions, especially regarding predefined security policies and their support for implementing the DevSecOps pipeline.

What other advice do I have?

I do not have concerns about Veracode not scanning source code, only binary code. In previous scans of the same code with different tools, Veracode has identified more security flaws, so I don't worry about the scanning process. It effectively spots the security flaws.

I would recommend Veracode to other users, but you must consider the cost aspect. If an organization has sufficient funds for spending on this SAST tool, I would still strongly recommend it because of the extensive documentation and defined policies. 

Veracode allows for customized policies based on domain and platform, which is beneficial for collaboration among multiple users and teams. 

I would rate Veracode an eight out of ten. Implementing Veracode has been challenging in the DevOps pipeline due to long durations, which can delay production deployments. Hence, we established a separate strategy solely for SAST scanning, leading to my rating of eight.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

IBM
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2700198 - PeerSpot reviewer
IT App Security Senior Analyst at a transportation company with 10,001+ employees
Real User
Top 20
May 2, 2025
Helps with compliance and fixing flaws quickly
Pros and Cons
  • "The most valuable features include the total developer experience, along with regulator exposure and DevOps pipeline. It encompasses everything as an enterprise solution."
  • "Veracode is a very good tool, especially from a compliance standpoint."
  • "A nice addition would be if it could be extended for scenarios with custom cleansers."
  • "Veracode isn't important to the organization's shift-left security strategy itself. It's a tool."

How has it helped my organization?

It helps our organization's ability to fix flaws very quickly. It helps in that aspect. We have fixes, remediation guidance to help fix issues. Veracode provides a training platform for developers to ensure they have awareness and knowledge, so they have a place to get information. It helps our developers save time, but we don't have many metrics on that.

When it's used, it's helpful. That's about making people use it and requiring it to be used. It has been used at times, and we could get issues resolved and things fixed. It was quite advantageous for some time. I'm in a different part of the team now, and I've seen that since I've left, the numbers have gone the other way. Somebody was showing me how they just got big old backlogs of things, and they're not even able to keep up with issues. That's when they're working with Code Fix. They try to get them to use Veracode Fix, which will speed up things for development, so the security team's support team will not be backlogged.

It gives notifications to prevent vulnerable code from going into production. It doesn't stop anything from going into production, but it notifies you. You can then consider not promoting that code. The values and assessments it provides can be introduced in the different areas in our development cycle and pipeline.

Regarding visibility into application status in every phase of development, such as static analysis, dynamic analysis software, and SAST, I would say that's not possible when considering every phase of development, such as requirements and architecture, as it's not part of that. However, from where it is engaged in the software development lifecycle standpoint, it provides that information.

What is most valuable?

The most valuable features include the total developer experience, along with regulator exposure and DevOps pipeline. It encompasses everything as an enterprise solution. In an enterprise, you want developers to be able to do things easily. You want to be able to monitor development in IDEs and the environment states of working pipelines. You want to integrate DevOps pipelines that do scan assessments and evaluation, and promotion to later stages in the pipeline and testing cycles. You still want your security team to be able to access data or pull information for evaluations or regulatory compliance, and report back to corporate compliance.

For the teams that use it, it does affect the time to remediate security flaws. It fixes issues directly in the IDE while you're doing it.

What needs improvement?

Many teams now have IDE plug-ins and the ability to generate fixes in the code. It's becoming more of a standard thing. They focus on creating security fixes and tools. A nice addition would be if it could be extended for scenarios with custom cleansers.

For how long have I used the solution?

I've used Veracode for a while now.

How are customer service and support?

Their support is pretty good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I don't know why they switched, but it was the decision made before I joined the company, and then the pandemic hit. It was delayed, but it had already been paid for, so eventually the switch happened.

Which other solutions did I evaluate?

They did evaluate other options before choosing Veracode. I'm not familiar with the process they used, but they absolutely did evaluate. I've seen documentation, and Checkmarx was on that list as well.

What other advice do I have?

From a policy standpoint, industry policy and related matters, you have to adjust and adapt things for systems and solutions. It's capable, but another part of the company is responsible for some of that. We may not necessarily get feedback, so with the ability to use it effectively, I don't think we've matured as an organization to take advantage of it effectively.

Veracode isn't important to the organization's shift-left security strategy itself. It's a tool. You have the strategy, you set the strategy, and you find a solution that will adhere to and work with the strategy. That's generally the goal. Veracode works well with the strategy once you decide and define it. Strategy is set, and then you select the tool.

Veracode is a very good tool, especially from a compliance standpoint. I would rate it an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Veracode
August 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,422 professionals have used our research since 2012.
reviewer2724171 - PeerSpot reviewer
Manager at a government with 10,001+ employees
Real User
Top 20
Jul 15, 2025
Manual configuration challenges overshadow efficient static code analysis
Pros and Cons
  • "The static code analyzer portion is adequate."
  • "I wouldn't promote Veracode because it's not automated enough, and it has many configuration issues."

What is our primary use case?

I have experience with Veracode, as I did download it, and our cyber team manages that. I've used Veracode for quite some time, more from a user perspective, not really as an admin person to run the scans. I share my role with Veracode by normally receiving the results and then analyzing them from there, as I was looking for options.

What is most valuable?

My impressions of Veracode's best features indicate that it doesn't have what I need. It's hard to integrate and perform hybrid analysis mapping. The threat modeling components aren't detailed enough. The deciphering of the results is challenging as they're hidden, making it difficult for a non-security user or normal IT developer to understand it.

We have about 100 to 200 licenses, with a very big portfolio of 500 systems, and people still don't understand it. Training 7,000 developers isn't feasible. We had training with Veracode where they conducted a major session, but nobody understood it. These developers can't be expected to remediate and configure the tool properly for comprehensive scanning. Instead, they turn everything off and only scan a very small line of code, which doesn't benefit the agency.

What needs improvement?

I wouldn't promote Veracode because it's not automated enough, and it has many configuration issues. Manual configuration is required, requiring expertise in Veracode. My thoughts on Veracode's development over time are that they have had sufficient time to figure it out, and I'm disappointed that it remains such a technical tool. It's a tool that everybody purchased when it was released, but it still isn't user-friendly.

For how long have I used the solution?

I've used Veracode for quite some time, more from a user perspective, not really as an admin person to run the scans.

How are customer service and support?

I would rate Veracode's customer service or technical support as not great, probably a four out of ten. Anytime we use the advisory to speak with an advisor, they are either too technical or have no understanding. We have a weekly meeting with Veracode because we have our own business relationship manager. He attends the calls without a technical person or lead architect to facilitate questions. When 40 people are on a call asking questions about turning off the API or fixing issues, the response is often that they cannot answer. The service is either a hit or miss, which is why I rank it low.

How would you rate customer service and support?

Positive

Which other solutions did I evaluate?

I wouldn't be inclined to take a 10-minute callback to discuss my experience with Veracode because I don't prefer it, so I don't think it would be a very good review. I'm looking to replace it.

What other advice do I have?

My impressions of Veracode's policy reporting for compliance with industry standards and regulations are hit or miss. While it has industry standards built in, our organization has different policies that are more structured. Each policy must be set up individually, requiring comprehensive legwork.

For example, if there's a policy for a deprecated protocol in an internal-only system, Veracode still reports it as an issue. This creates unnecessary work for internal systems that aren't public-facing and have lower risk. Configuring the tool to align with policies for sensitive, public-facing systems based on law and NIST requirements requires reviewing each line individually, which becomes a two-year project.

My impressions of Veracode's ability to prevent vulnerable code from going into production is that the static code analyzer portion is adequate.

On a scale of 1-10, this solution rates a 5.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Solutions Architect at IDS Comercial
Real User
Top 5
Apr 5, 2025
Flexibility to define rules and real-time updates enhances network security
Pros and Cons
  • "It makes it very easy to track and monitor activity."
  • "Using an automated tool brings cost reduction and more security."
  • "Maybe the boards could be made easier to understand or easier to customize."

What is our primary use case?

I use Veracode to implement solutions with security and to define rules, for example, for the network and the traffic of the network. Those are the main scenarios where I have interacted with Veracode. I use Veracode in the banking sector.

How has it helped my organization?

It makes it very easy to track and monitor activity. The visibility via the boards is very good. It enhances operations. 

What is most valuable?

The flexibility to define rules and the ability to update those rules on the fly are valuable features. It has boards where it is easy to track or monitor the activity. This is something that brings value and enhances the operation. Whenever we need to update a rule or make changes, you need to do it quickly, and this makes it possible. 

What needs improvement?

Maybe the boards could be made easier to understand or easier to customize.

For how long have I used the solution?

I've had some interactions with this solution. 

What do I think about the stability of the solution?

It's quite stable. It's a very good solution.

What do I think about the scalability of the solution?

This is easy to scale. If I need to add new infrastructure, I just need to start scanning or include new segments of the network. It will automatically include new infrastructure or it will escalate. Cloud solutions are easier to scale than on-premise solutions.

How are customer service and support?

I haven't interacted with support. However, it's got good support. They respond very quickly since security is something critical. It will depend on the severity of the requests.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I was using a legacy solution, and we tried to migrate to a new solution like Veracode. However, I was not a part of deciding which solution to move to.

How was the initial setup?

I was not involved in the initial deployment. 

What was our ROI?

Especially in banking, security is a must-have. If we have weaknesses in security, it will cost a lot. For example, hacking or people trying to access their networks. The scanners of Veracode bring status of the weaknesses in the current infrastructure. 

It scans and provides reports regarding the servers, the network, and the applications running on those servers. It's a very valuable kind of solution. Trying to do it manually would be costly and increase the risk of mistakes if we try to identify all those bugs in the architecture. Using an automated tool brings cost reduction and more security.

What's my experience with pricing, setup cost, and licensing?

The pricing is competitive. It's not the most expensive solution. It also brings some benefits in comparison to other options. 

What other advice do I have?

I would give Veracode an eight out of ten. 

I do not have any specific advice for people considering using Veracode.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2731785 - PeerSpot reviewer
Information Security Strategy at a insurance company with 10,001+ employees
Real User
Top 5
Jun 30, 2025
Helps ensure secure code generation but needs better integration for modern tools
Pros and Cons
  • "The integrated IDE tool enables users to get instant feedback in real-time on the code itself, rather than waiting for it to go through the CI/CD pipeline and get the result."
  • "Veracode needs to shift to a more modern approach because it still feels traditional in its way of doing code scanning compared with others, such as Snyk."

What is our primary use case?

We use the scan and code scanning functionality. Those are the main ones. I just changed my role, so this company is using Veracode, but I've been using it for quite some time before joining this new company. It is currently only managing the source code review. We have other tools that we integrate as such as infrastructure as code, container security, cloud misconfiguration reviews, and others. So it's part of the overall security posture. I can't say that it's solely for our entire security posture because it just manages a subset of one of the security requirements, which is the source code review.

What is most valuable?

It has met the company's requirements. Nowadays, we are talking about AI code generation. The company is required to leverage the existing code scan to see whether it can support scanning the code that is generated from GenAI before pushing that code to the developers. The developer wouldn't know whether this code is secure or not. Usually, we do the static scan first, but now with a code generator, we want to ensure that it generates secure code.

It did the job. Just before production, we did a scan and ensured that there were no critical or high-criticality issues before going to production. I think that helps to sanitize the code without going into a peer review. We have an automatic scan that catches all these things first, so it's beneficial.

This is especially true for the library because most of these static code scans or software component analyses scan the third-party library that has a CVE or CVSS finding. But if it's a custom-built library that isn't known to the public, it's unclear whether there's a vulnerability or not. Currently, it lacks the ability to trigger on those. We probably have to use a different solution for that.

What needs improvement?

There should be a feature where we can actually scan code that has been generated by GenAI, such as ChatGPT or Copilot. When they generate this code, they should have some kind of third-party integration feature that can suggest to us, 'This code is clean' or 'this code is good to be used for the developer.' 

We are also looking at Black Duck. They introduced a new feature. We were testing on this secure code for AI, so they do have some tools that we are currently exploring to see whether they can do secure AI code.

Regarding remediation, based on my experience, the recommendation from Veracode on remediation is quite helpful. It gives valid reasoning, and the recommendation is fixed. 

The developers actually understand how to fix that. However, some of the recommendations, such as upgrading a certain library to version XYZ, sometimes don't go deeper because some of these libraries are not as simple as just changing the version to fix them. There are interdependencies with other third-party components. 

Sometimes, when the recommendation asks to upgrade the version to XYZ, when we actually upgrade it, there will be another issue with other things. We usually face difficulty with that one. Sometimes we take an exemption because we can't upgrade this without breaking certain things, so we decide to go for the risk exception.

For how long have I used the solution?

I just changed my role, so this company is using Veracode, but I've been using it for quite some time before joining this new company.

What do I think about the stability of the solution?

The stability is acceptable overall.

How are customer service and support?

I didn't get involved much with asking them questions. During the initial phase when we started integrating, they were very helpful, but after they deployed the license and everything, we haven't reached out to them to ask any other questions. It's gone into autopilot. Once you have the license, everything just continues as it is.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

In my last company, they used Veracode, and then they transitioned to Snyk. The price point was the first priority we looked at. Secondly was the integration—whether it had deeper integration with our system, and was easy for our developers to enroll and use. After a trial of 12 months with Veracode, we decided to move to Snyk.

Which other solutions did I evaluate?

Previously, we did a comparison between Veracode, Synopsys (which is Black Duck), and Snyk. We did our own internal review. Veracode needs to shift to a more modern approach because it still feels traditional in its way of doing code scanning compared with others, such as Snyk. They still use a base app, although they have a web version as well, but the integration part could be more seamless. I'm comparing it side-by-side with Snyk, as I'm also a heavy user of Snyk. Those aspects can be improved.

What other advice do I have?

The integrated IDE tool enables users to get instant feedback in real-time on the code itself, rather than waiting for it to go through the CI/CD pipeline and get the result. They can instantly review their code on demand, which is quite beneficial.

For my previous company, when they first adopted source code review, they went for the open-source option first. I always advocate for people to go with the open-source option to understand what the features are and how exactly the source code scanning looks. Once comfortable with it, or if certain features are needed, then look for the enterprise version. Sometimes for different companies, especially small businesses, they couldn't afford Veracode because of the steep price.

Regarding integration, apps such as Jira and Confluence are important. The main thing was that it's fully and deeply integrated with the user and the repository, like Confluence. Every time there's a report, we can immediately generate a ticket from Snyk to Jira. It helps the developer get notified about issues after the scan. Then they fix the issue, tag the ticket as resolved, and once it's marked as resolved, we will do the rescan.

As a beginner, the interface is quite straightforward. People will not get confused. The technical report is professional and can be used by regulators. I can simply export it as a PDF and then share it with a regulator or any auditor for their review.

Regarding mobile code support, such as iOS, Kotlin, and others, the results were not really promising. For Java and C#, it's very good. They are pioneers in that. But for mobile development, if you're a mobile company that builds mobile apps and you have iOS, Objective-C, Swift, and Kotlin, that area needs to be polished.

I rate Veracode a seven out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kv Rao - PeerSpot reviewer
Site Leader (India) at Industrial Scientific
Real User
Top 5
Dec 12, 2024
Integrates pipelines smoothly and fortifies code against vulnerabilities
Pros and Cons
  • "The ease of integration with Bitbucket pipelines and Git pipelines is vital for us."
  • "Veracode allows us to easily summarize issues and provide quick, actionable insights."
  • "Veracode can improve the licensing model as it is a bit confusing."

What is our primary use case?

I use Veracode in multiple places including static code analysis, penetration testing, and dynamic code analysis. It is part of our pipeline and integrates well with Bitbucket and Git pipelines.

What is most valuable?

The ease of integration with Bitbucket pipelines and Git pipelines is vital for us. Veracode allows us to easily summarize issues and provide quick, actionable insights. It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.

What needs improvement?

Veracode can improve the licensing model as it is a bit confusing. 

Additionally, threat modeling and asset management could be made more general rather than very specific.

For how long have I used the solution?

I have had experience with Veracode for a few years now, at least a couple of years.

How are customer service and support?

I have seen an upward rating of eight or more out of ten. They are very responsive and quick to help with queries within our scope.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We considered other solutions but have stuck with Veracode due to an enterprise level licensing deal and it serving our immediate important needs.

What's my experience with pricing, setup cost, and licensing?

The licensing model is a little confusing, but we have a good relationship in terms of how it is set up. The pricing and model align with the needs of the developer community and the cybersecurity office.

What other advice do I have?

I would recommend this solution as it is adaptable for threat modeling and penetration testing on contemporary tech stacks. 

Overall, I rate the solution an eight out of ten.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Application Security Specialist at Herrenknecht
Real User
Top 20
Aug 12, 2025
Automated monthly code scans increase security awareness and prompt quick remediation
Pros and Cons
  • "Veracode has improved my organization's ability to fix flaws because before Veracode, we did not even know about issues from the security side."
  • "The areas of Veracode that I would want to see improved or enhanced in the future are primarily related to user interface experience."

What is our primary use case?

My usual use case for Veracode involves integrating automatic scans for each of our pipelines, which starts every month automatically without my intervention. I review the results, and if there are any changes, such as new issues, flaws, or outdated components, I address this task with our developers.

How has it helped my organization?

Veracode has improved my organization's ability to fix flaws because before Veracode, we did not even know about issues from the security side. Application security is relatively new in our company. The fact that we started to remediate these issues is a good step towards security, which has positively impacted us.

Veracode's ability to prevent vulnerable code from going into production is excellent. I implemented it as a pipeline into our CI/CD, and if there are vulnerabilities above our level, such as high or very high severities, the pipeline will not build. Developers can contact security personnel if they need clarification.

Veracode has helped developers save approximately 15%-20% of time. Our security posture has improved as expected. 

What is most valuable?

We do not have many Veracode features yet. We are going to discuss expanding the subscription next year. Currently, Static Analysis is really good at scanning our code for vulnerabilities. Software Composition Analysis is also required for the upcoming rights from the EU Cyber Resilience Act, which is quite useful, and I am using them both. Both features are really important for us since we're using only Veracode.

What needs improvement?

The areas of Veracode that I would want to see improved or enhanced in the future are primarily related to user interface experience. I noticed they have started working on it as the main page has a new design, but other pages appear somewhat old and not intuitive. The interface needs to be more user-friendly, but otherwise, everything is acceptable.

For how long have I used the solution?

I have been working with Veracode for approximately a year and a half.

What do I think about the stability of the solution?

Every time I wanted to work with Veracode, it worked, so there are no downsides. It was available every time.

What do I think about the scalability of the solution?

Regarding scalability, Veracode is really good for our needs. You need many subscriptions because you need to include every developer who produces code. Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.

How are customer service and support?

I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material. They understood us immediately and helped us with our problems within half an hour. It was incredible. I would rate them a ten out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We did not use a different solution before Veracode. Veracode is our first solution.

I did not work directly with competing solutions similar to Veracode, but I attended several meetings with different companies to explore similar tools. They did not provide anything better than Veracode, and since I had already implemented Veracode in our CI/CD, there was no need to change the solution. I only saw Checkmarx as a competing solution. Though I did not try it myself, from what they showed me, it appeared quite similar but was not better than Veracode.

How was the initial setup?

Without the documentation, the deployment and initial setup is complex. I tell my developers who are interested in Veracode that with this documentation, everything is possible because it is really thorough and helpful. At first, it was somewhat complicated, but with the documentation and time, it became a really good experience. After that, it became very easy and quick.

What was our ROI?

Since the Cyber Resilience Act is in motion, we need to provide static analysis and dynamic analysis, which we do not have right now. We must do it, and Veracode is a great tool for this purpose. We cannot sell our products without complying with this act, so Veracode is helping us achieve this.

Which other solutions did I evaluate?

When I joined the company, I was given Veracode. The decisions were made before I joined the organization. They had just bought it and needed a specialist for this, and I was the specialist.

What other advice do I have?

I am working with the latest version of the features. Since starting with Veracode, I would rate the benefits as six or seven out of ten. It could be better if we had more high severity issues, but fortunately, we do not. It is a good sign that developers who are not in cybersecurity understand its value.

Regarding the solution's policy reporting for ensuring compliance with industry standards and regulations, I am using standard policies. I rated it five out of ten because we have not used it properly yet.

Veracode provides visibility into application status at development phases. We tried IDE scans for the developer stage of products, but it was not fully compatible with our IDE. It works in CI/CD as mentioned.

We do not currently have the Veracode Fix feature that produces AI-generated fixes. The fact that Veracode does not scan source code, only binary code, does not concern us as we have other tools for that purpose.

I would rate Veracode an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
David-Robertson - PeerSpot reviewer
Director Enterprise Architecture at Exeter Finance Corp.
Real User
Jun 23, 2024
Static scanning and software composition analysis are very helpful, but the usability needs improvement
Pros and Cons
  • "Static scanning and software composition analysis are very helpful. I and my colleagues don't need to be an expert on all of those ancillary things, so we can focus more on the business deliverables."
  • "The usability isn't good in Veracode. Sometimes, it will show a problem, but it's difficult to go into their tool and figure out where it is. You primarily use a web browser to access their system. It requires a lot of clicks. The static analysis is a separate part of their system from the SCA, so that's a bit difficult. They haven't fully integrated that. It's difficult for the consumer."

What is our primary use case?

Static scanning is one component of Veracode. That feature we use heavily to scan all the custom code we write weekly. We use another component called software composition analysis to scan all of our open-source packages. These are the two primary use cases that we have for Veracode.

It flags any security flaws or bad practices. Veracode has its own database for many vulnerabilities identified on the SCA side. They use a tool called SourceClear, which validates vulnerabilities in any of these packages. The scanner itself is pretty good at identifying some of the flaws in either the code or the open-source packages.

How has it helped my organization?

Our organization is more secure than without Veracode. It has improved our security posture because we're running it. It's hard to gauge what that would be without it because we haven't had any security issues since I joined the company. 

Veracode is very good at ensuring compliance with industry standards. It has helped us fix flaws. We know what's there, and there's generally a decent explanation for fixing each flaw. It's a quicker time to market. It's easy to figure out the problem and solve it so that we don't have exposed vulnerabilities in the market. 

It has helped developers save time. We generally resolve all our flaws within seven to 20 business days after they are identified. Veracode is crucial to our shift-left strategy. We have automated scans, so we scan all our code every weekend. Today is one of those days, so it's usually the time when we come in, see there's a new problem, and immediately start working on it.

What is most valuable?

Static scanning and software composition analysis are very helpful. My colleagues and I don't need to be experts on all of those ancillary things, so we can focus more on the business deliverables.

They have a pretty good tool that allows me to run scans of my local integrated development environment. I can find a lot of those flaws a lot sooner than I would if I had to wait for these cloud-based scans. They've come out with some sort of automated fix feature. I haven't used it, but they gave us a demo of it, and that one looks promising. I don't know if it's ready for prime time yet. 

What needs improvement?

The usability isn't good in Veracode. Sometimes, it will show a problem, but it's difficult to go into their tool and figure out where it is. You primarily use a web browser to access their system. It requires a lot of clicks. The static analysis is a separate part of their system from the SCA, so that's a bit difficult. They haven't fully integrated that. It's difficult for the consumer.

For how long have I used the solution?

We have used Veracode for about five years. 

What do I think about the stability of the solution?

Veracode's stability is 50-50. They deploy new versions of their engine. Recently, the new version identified flaws in the code that were six months to a year old.  

What do I think about the scalability of the solution?

Veracode seems to scale pretty well. We scan 60 to 70 applications every weekend without any problems. 

How are customer service and support?

I rate Veracode's support engineers eight and their frontline support four. Their engineers are typically good and helpful. If I open a tech support ticket, I usually get a Veracode engineer. Those guys are good. I would rate their other support people poorly. 

How would you rate customer service and support?

Neutral

How was the initial setup?

Veracode is straightforward to deploy. It's a general automated dev ops strategy. It's a responsibility shared among 20 to 30 people.

What's my experience with pricing, setup cost, and licensing?

Veracode is a decent value, depending on what you're trying to achieve. It's pretty good for security flaws.

What other advice do I have?

I rate Veracode six out of 10. I would recommend Veracode to others. The scanner is best in class, but the rest, not so much. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Jan Pašek - PeerSpot reviewer
Tech Lead at a financial services firm with 10,001+ employees
Real User
Nov 3, 2023
Provides clear visibility into flaws, and helps improve security posture, but the false positive rate is high
Pros and Cons
  • "I like the way the flaws are reported in the system."
  • "The area with the most room for improvement is the speed and responsiveness of the query, as it is usually very slow."

What is our primary use case?

We have some applications that connect to external providers or provide external services that users can access from the public internet. We are uploading these applications to Veracode to assess the security threats that our code may pose.

How has it helped my organization?

Veracode's analytical capabilities are very good, but I'm not sure if they have prevented security vulnerabilities from going into production in our case because we haven't been using them optimally. We're now working on integrating them into our development pipeline so that we can test applications before they're released. This will also allow us to familiarize ourselves with the sandboxes during development. I believe that if we start using Veracode correctly, it will be very beneficial in preventing security vulnerabilities from going live.

The main benefit of Veracode is the software composition analysis because it helped us identify that we were using some libraries with security flaws. This is important because the individual software components are owned by different smaller teams, and all of those teams contribute to one overall large application. Therefore, there is no single person who would be able to take care of all of the third-party libraries that we are using. Veracode analyzing the libraries that we use is therefore beneficial to us.

Veracode's policy reporting for insurance compliance depends on how our organization uses it. I'm not sure if we're using it to the best of our ability because, for example, I discovered that there is a central space where we can run analysis and sandboxes. Based on what the Veracode expert I spoke to told me, policies should be reported from the danger space, but in our organization, we're reporting them from the Prod CI sandbox. This doesn't seem to be a good solution because the overall application is displayed on the main page, which doesn't reflect what our compliance teams think about our applications. Besides that, I think it comes down to how we're using Veracode within our firm. Overall, I think it's great that the firm can configure certain policies to monitor applications, and the flaw report also enables us to see the flaws that need to be fixed to become compliant, which is a good feature. From Veracode's perspective, everything looks fine.

Over the past year, we discovered a severe security flaw in Lot 4j 1.2.15. We initially believed that this version had been replaced with a newer version that does not have the flaw, but our software composition analysis reports revealed that this is not the case. We still have a few binaries that depend on Lot 4j 1.2.15, which is vulnerable. The software composition analysis results prompted us to schedule a replacement with a new version, which is currently underway.

Veracode has helped us fix flaws effectively. Our security teams enforce monitoring and fix deadlines for reported flaws. If a reported flaw cannot be accepted as a false positive, we must fix it promptly to maintain a high success rate.

Veracode has improved our security posture and will continue to do so as we learn to use the solution more effectively.

What is most valuable?

I like the way the flaws are reported in the system. It is quite clearly visible where the flaw is coming from, and it is possible to upload the code to see exactly which line was identified as a security threat. I also like the software composition analysis that Veracode provides, because we can see third-party libraries that are used in our software and check if there are any known security flaws in those libraries.

What needs improvement?

There are many false positives, especially one particular type: reported hard-coded passwords in the code. We do not have hard-coded passwords in our code, but we are using third-party libraries that have variables with passwords in their names. For example, a variable might be named "passwordForCommonFixFile" or "passwordForSecurityStore." Veracode's keyword analysis probably assesses these variables as hard-coded passwords. This is problematic because the false positives are coming from third-party libraries, and we cannot easily check the flaws to see if they are false positives. To fix the problem, we have to compile the code, which we should not have to do. We are forced to accept the false positives because we know from the software and system design that there cannot be hard-coded passwords in the third-party libraries we are using. If the libraries were generic, then there would be no chance that they would have hard-coded passwords for the specific services that we are connecting to. To reschedule the scan, we have to go through some bureaucracy. 

Despite the presence of many false positives, we remain confident in Veracode. However, the impact on developer confidence is negative, as it leads to resistance to enforcing certain development processes, including the use of Veracode in the development pipeline. This is understandable, given the complexity of the process required to reschedule the flaw for a single false positive. This process requires approval from the system owner, a senior manager, and the cybersecurity team.

Veracode has increased the work time of our developers because of the false positives.

The area with the most room for improvement is the speed and responsiveness of the query, as it is usually very slow. I am not sure if there is a specific space allocated for us that can cause this, but when I open an application and want to click through multiple scans to see the differences, or if I want to do anything else, everything loads very slowly. This makes it much less user-friendly to play around with the GUI and explore the features.

For how long have I used the solution?

I have been using Veracode for three months.

What do I think about the stability of the solution?

Veracode is stable but a bit slow.

How are customer service and support?

I have only one experience with Veracode support, but it was very positive. I used the schedule consultation feature in the GUI, which was very useful. We had some questions about how to correctly upload a code, and I was able to schedule a call with a Veracode expert. The support person who helped me provided me with many insights, answered all of my questions, and even went beyond what I asked to explain how to use the feature and improve our process.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial deployment is complex because our system is huge, consisting of hundreds of different binaries. Dozens of teams contribute to the releases, and as a result, a large number of changes are deployed at the same time. This makes it very easy to break something, and there are many people involved in the process.

The deployment required a core team of five, with some additional people on hand to support if anything went wrong. The maximum time for deployment was one day.

What other advice do I have?

I give Veracode a seven out of ten due to the slow speed and the false positives.

We only use Veracode for static analysis. We do not use the other features at all.

We have infrastructure deployed in multiple locations around the world. In my team, 50 people use Veracode. Across the entire organization, it is used by hundreds, if not thousands, of users.

I advise everyone to use Veracode in their development pipelines, so that scans can run very frequently, at least once during each nightly build. This will ensure that reports and flaws are addressed effectively. From my development perspective, I recommend against enforcing specific rules on using Veracode, giving deadlines to fix flaws, or introducing additional bureaucracy. This can worsen the developer experience and lead to developers finding ways to avoid having flaws reported, such as by decreasing the frequency of scans. In my opinion, the more processes and bureaucracy we add, the less useful Veracode will be. 

Which deployment model are you using for this solution?

On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
ML engineer at a consultancy with 10,001+ employees
Real User
Sep 19, 2023
Effective at preventing vulnerable code from going into production and provides valuable insights through code scans
Pros and Cons
  • "The most valuable feature is Veracode SDP, which allows for something related to third-party vulnerabilities. When we build a product, we use a lot of third-party libraries instead of building everything from scratch. We just use a library which is already been built; we just use that component in our product. Sometimes, these libraries may have bugs or issues, and it's hard to keep track of them because we use thousands of them."
  • "One area for improvement is the navigation in the UI. For junior developers or newcomers to the team, it can be confusing. The UI doesn't clearly bundle together certain elements associated with a scan. While running a scan, there are various aspects linked to it, but in the UI, they appear separate. It would be beneficial if they could redesign the UI to make it more intuitive for users."

What is our primary use case?

We use Veracode mainly for identifying any vulnerabilities in the software. We do a lot of development, and before we deploy any product to our client environment, we want to make sure there are no vulnerabilities in the code and also follow best practices. 

We run scans to identify the criticality of these bugs and vulnerabilities, and we try to mitigate them. If it's not possible, we get an exception. At least we are aware of the vulnerabilities in our code, making sure our code is secure and not exposed to any threats like hacking.

How has it helped my organization?

In my organization, we have a policy in place. Every company has a different policy; at least our company has specific requirements where we expect everyone to build the tool or the software to some extent, following some best practices. 

Veracode helps us embed those policies into the scan. When we run the scan, the administrators have already set the policy, defining what needs to be checked and what can be ignored. It helps us when we run the scan because it provides a score based on the policy level. This score certifies how well the tool has scanned the code. 

We can then show this certification to demonstrate that the product meets the required standards and can be trusted without any issues. So, we are working with the solutions policy reporting to ensure compliance with the industry standard.

For our product, we use static analysis. We're not using any agent-based solutions, but we are planning to hook it into the CI/CD pipeline in the future.

Veracode has been helpful because, in the past, we used to integrate Veracode scanning into our CI/CD pipeline. Sometimes, what happens is a junior developer sees a third-party library and thinks, "Oh, this tool is helpful," and they bring it into our system to build something.

However, even if it's a third-party tool, we don't know what vulnerabilities that code may have. At least now, whenever we push code, Veracode can catch any vulnerabilities, and if it fails our build, it prevents us from deploying that code into our environment. It clearly states, "This code has a vulnerability; I can't deploy it." So, it effectively blocks us from deploying risky or vulnerable code in our tool. It helps us quickly assess the risk of third-party tools and take action promptly instead of building something and realizing two months later that we need to go back and fix it. That's not going to happen; we can identify and resolve issues within a day.

The tool is great in terms of ensuring our code is clean, recommending best practices, and capturing the flaws in third-party components.

Veracode has an impact on our organization's overall security posture. Because when we do development for internal purposes, we don't run a Veracode scan very often. But when we work in a client environment, if they want us to build something for them, we absolutely need to ensure that we haven't introduced any flaws or problematic code into their system.

Veracode helps us maintain the reputation and branding of our company, which is crucial for us. It's important to ensure the code is free from vulnerabilities and not exposed to hacks. It is very important to us.

What is most valuable?

The most valuable feature is Veracode SDP, which allows for something related to third-party vulnerabilities. When we build a product, we use a lot of third-party libraries instead of building everything from scratch. We just use a library which has already been built; we just use that component in our product. Sometimes, these libraries may have bugs or issues, and it's hard to keep track of them because we use thousands of them.

Veracode's tool scans every single library and gives a dashboard showing the number of libraries, high and low criticality issues, and whether a product has any issues. It helps us assess the libraries and decide whether to resolve the issues or replace the library to minimize risks.

I like the solution's ability to prevent vulnerable code from going into production. It does a pretty good job in most cases, but I have seen a few false positives in the code scan. It means that sometimes, like recently, we run a scan where we encounter a part of JavaScript code where it's just a string evaluation. Despite not posing any real threat, the system flagged it as a potential vulnerability, suggesting it could be exploited to hack into the system. We looked into that code and found it wasn't the case; it was a false positive. It wasn't a big issue because we reported it to Veracode, and they made an exception and resolved it. It does a pretty good job, but sometimes it can be very misleading.

However, the solution's false positive is not a big deal because it's very minimal. Veracode does a very good job, but 99% of the time, it works well. Only, like, 1% - 2%. Like, sometimes we manage false positives. It's not a big blocker as well. Every software is not perfect. Also, these are very minimal fixes. Sometimes, if we raise a support ticket to mitigate this issue, the response is also pretty good, and it can be resolved within one or two days. So it's not that big of a deal.

What needs improvement?

One area for improvement is the navigation in the UI. For junior developers or newcomers to the team, it can be confusing. The UI doesn't clearly bundle together certain elements associated with a scan. While running a scan, there are various aspects linked to it, but in the UI, they appear separate. It would be beneficial if they could redesign the UI to make it more intuitive for users.

In future releases, I would like to see some features. For example, there's a library we use as a third-party library. Sometimes, Veracode indicates that we can't use a particular tool because it has a lot of vulnerabilities in the code. It would be nice if Veracode's scan could show an alternative library to use instead of the one flagged as problematic

So instead of us having to go back and research, trying to figure out what other tool we can use as an alternative, if Veracode could provide those recommendations within the tool itself, it would be nice.

For how long have I used the solution?

I've used the product for almost three to four years, but it's been a while since I haven't used the tool. But I started using this solution again. I started working on it again in the past month.

What do I think about the stability of the solution?

Veracode is 100% stable. We haven't encountered any issues.

What do I think about the scalability of the solution?

It is a scalable solution. Veracode has a concept called Sandboxes, which is an amazing feature and pretty useful. I can kick off multiple scans, and they all run independently. There's no interference between scans. So, it's highly scalable, and we haven't had any issues with it. It is good.

For our team, we currently use it for two projects.

How are customer service and support?

I've personally interacted with the customer service and support recently for a few issues, and their support is amazing.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is very easy. It's not that complicated.

Moreover, the false positive rate of static analysis can affect the time spent on tuning policies. It took at least one day for me to raise that mitigation and approval ticket to look into it. Veracode needed to spend, like, six to eight hours, which essentially goes up to a day to resolve it.

The solution has 100% helped our developers save time. 100% right now in terms of ensuring the code is good and deploying it safely. Veracode definitely helps us be very confident when we go for product releases. It has helped our developers save time.

As a lead developer, it takes me one or two days to set up everything in Veracode scan. Once it's set up, the junior developers don't need to do a single thing. They just push their code, and they don't even realize that a scan is running in the background. So they don't need to worry about it. However, in terms of readiness for the production release, Veracode definitely helps us be confident and quickly identify the risks. There's a huge benefit in that area.

What about the implementation team?

In the beginning, two or three years back, we were pretty new to Veracode, and we did seek help from the Veracode consulting team. Their support is amazing. If I send an email for any help, they respond within 30 minutes. Their response time is good, and they provide clear guidance.

I've personally interacted with them recently for a few issues, and their support is amazing.

So, initially, we did take consultation when we set it up, but once we became comfortable and familiar with the process and the documentation was also clear, we started managing it ourselves.

For the implementation process, a developer pushes changes to the master branch or a feature branch the first step is to trigger the Veracode scan in the CI/CD pipeline. We use Azure DevOps for this.

The next step is to include the code in the Veracode scan. This is the second step. Before going into further steps like building the Docker image and containerizing the application for deployment, we have a condition in place. If the Veracode scan doesn't complete successfully, we don't proceed to the next step, and the entire build fails.

We don't need a lot of members for the deployment part. It's only me and my technical expertise, like, one or two people. Any DevOps is enough.

We don't see much need for maintenance. It's pretty easy to manage. Veracode is also maintained by a dedicated team internally, and they provide support for everyone within the organization. So, if there are any upgrades or maintenance required, they take care of it. But from our team's perspective, there's no need for ongoing maintenance. We set it up once, and that's it.

What's my experience with pricing, setup cost, and licensing?

The solution reduced the cost of the development setups for your organization. It is a key feature of Veracode. Once you set it up for the first time and integrate your CI/CD pipeline with our DevOps cycle and the Veracode scan, it takes two or three days to set it up initially. 

But after that, it's a one-time effort. You don't need to do anything further. You need to kick off the pipeline, and it runs the scans automatically, providing artifacts for you to review in the report. So it helps in the long run. Once you have your project set up correctly, there's no need for manual intervention at all once it's hooked up. It's a significant long-term benefit.

Which other solutions did I evaluate?

We have a dedicated team that handles research, but I personally have only used Veracode for scanning. Our team used to use SonarQube.

Our company used to run both Veracode and SonarQube scans for certain projects. Sometimes, some of the scans were not included in Veracode, so the team used SonarQube for those. However, this was quite a while ago, about two years back.

What other advice do I have?

I would suggest starting Veracode scans at the earliest stage of development. It's crucial to catch vulnerabilities and risks early on so you don't invest too much time building something only to realize later that it can't be used due to a lot of issues, especially with third-party components. Using these tools as early as possible will benefit you in the long run and allow you to ship your product more quickly.

Overall, I would rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.