Try our new research platform with insights from 80,000+ expert users
it_user335091 - PeerSpot reviewer
Senior Security Consultant at a retailer with 1,001-5,000 employees
Real User
We were able to easily integrate static code testing into the SDLC process, moving from the waterfall to the agile methodology while still able to integrate Veracode testing within both.

What is most valuable?

Static code analysis is a valuable feature.

How has it helped my organization?

We were able to easily integrate static code testing into the SDLC process. We moved from the waterfall to the agile methodology, and were still able to integrate Veracode testing within both methodologies.

What needs improvement?

It's been over a year since I used the product. But when I did, I found there were too many false positives.

For how long have I used the solution?

I used it for one year.

Buyer's Guide
Veracode
April 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,963 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and support?

Customer Service:

8/10

Technical Support:

8/10

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Managing Director at Harrods
Real User
Provides the capability to track remediation and the handling of identified vulnerabilities. The application does not support API or Dynamic Application Security Testing
Pros and Cons
  • "Allows us to track the remediation and handling of identified vulnerabilities."
  • "Provides the capability to track remediation and the handling of identified vulnerabilities."
  • "The security team can track the remediation and risk acceptance statistics."
  • "The solution does not support Dynamic Application Security Testing."
  • "The current version of the application does not support testing for API."

What is our primary use case?

We are planning on introducing a static code analysis tool to support a DevOps effort in our environment. The objective of the solution is to allow the team to identify vulnerabilities in the source code and improve the hygiene of the developed code before deployment.

How has it helped my organization?

This is currently still under evaluation, and it is pending review and assessment against other static code analysis solutions.

What is most valuable?

The solution provides the capability for the application teams to track remediation and the handling of identified vulnerabilities. The system provides workflow capabilities for the application teams to send the completed scans to the security teams for their review. In addition, the security team can track the remediation and risk acceptance statistics.

What needs improvement?

The solution currently does not support Dynamic Application Security Testing which is an important facet of application security testing. In addition, the current version of the application does not support testing for API.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Veracode
April 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,963 professionals have used our research since 2012.
SeshagiriSriram - PeerSpot reviewer
Head IT Architecture at a tech vendor with 11-50 employees
Real User
Top 20
Enables us to perform security checks with ease
Pros and Cons
  • "We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes."
  • "One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications."

What is our primary use case?

We used it for performing security checks. We have many Java applications and Android applications. Essentially it was used for checking the security validations for compliance purposes.

How has it helped my organization?

Technically there is nothing wrong with Veracode. The only issue that we have here is uploading the code, the process of actually uploading and getting our results back. All of that is a little cumbersome. 

What needs improvement?

Technically there is nothing wrong with Veracode. The only issue that we have is uploading the code, the process of actually uploading and getting our results back. All of that is a little cumbersome. 

One of the things that we have from a reporting point of view, is that we would love to see a graphical report. If you look through a report for something that has come back from Veracode, it takes a whole lot of time to just go through all the pages of the code to figure out exactly what it says. We know certain areas don’t have the greatest security features but those are usually minor and we don’t want to see those types of notifications. So we would like to see a kind of a graphical representation of the problem areas. I would like to know which file is the biggest source of issues for me so that I can focus on resolving the issue, as a project manager. With how it is now, I am able to do this but I have to take out the whole PDF file and extract it. It takes up a lot of my time. I would like to see better strategic reporting. It would be great to get better graphical reporting.

For how long have I used the solution?

We have been using it for three years.

What do I think about the stability of the solution?

Stability is very good and there were no issues. I will give it five stars.

What do I think about the scalability of the solution?

It's very good; really very good. I would strongly recommend that. Technically I would be expecting a double concept for Veracode. I would still say this is one of the best products ever on that website. I don't have any issues with the scalability. 

How are customer service and technical support?

I had no technical issues at all.

How was the initial setup?

The initial setup can be a little complex for people or for organizations that don't have technical skills. Another small thing is that you need to have one person who's fluent and technically knowledgeable to help during the upload process. But otherwise, it's pretty much straightforward. It's not an issue, it's perfect.

What other advice do I have?

I would strongly recommend doing an internal analysis first, before setting it across to Veracode to proceed and to use it more as a final verification point. My point is that Veracode is very good, and I would strongly recommend it. I have seen other solutions on the market and that's why I say: don't waste your time on other products, just get Veracode.

I would rate it an eight out of ten. Not a ten because of the reporting issues I mentioned that I would like to see improved.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
AVP, IS Manager at a financial services firm with 1,001-5,000 employees
Real User
Substantially reduces the number of unmitigated flaws in our code

What is our primary use case?

We use Veracode to scan custom-developed code for flaws.

How has it helped my organization?

  • The volume of unmitigated flaws in our applications has been substantially reduced.
  • In terms of AppSec best practices, the team at Veracode has provided industry benchmarks against which we are measuring our improvement.
  • Our customers have benefited from the added security assurance of our applications, although they may not know it.

What is most valuable?

The identification of flaws.

What needs improvement?

We would like to see improvement in reporting, in particular, end dates on mitigations.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

It has handled all the expansion we have required from it.

How is customer service and technical support?

Technical support is highly competent.

How was the initial setup?

It was already implemented when I joined the organization. However, we have expanded greatly.

What's my experience with pricing, setup cost, and licensing?

We are about to enter discussions for renewal. I have heard there may be some changes to pricing. I will reserve judgment until the discussions are complete.

What other advice do I have?

I would recommend it. It covers all our custom-developed applications and will expand as new applications and services are added.

We have 50-plus users of Veracode. Their roles include InfoSec, developers, development managers, QA, and configuration management. In terms of deployment and maintenance, we have four people in configuration management and InfoSec.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Jesus Montes Ceron - PeerSpot reviewer
Architect of solutions at IPComMx
Reseller
Top 10
Utilized for scanning containers and integrated within DevOps workflows
Pros and Cons
  • "The coverage of backdoors attacks on security that's the most valuable for my clients."
  • "There is room for improvement in documentation."

What is our primary use case?

We used Barracuda for scanning containers. And in all in DevOps workflow.

What is most valuable?

The coverage of backdoors attacks on security that's the most valuable for my clients.

What needs improvement?

There is room for improvement in documentation. Maybe the documentation about how to configure something. It is difficult to get the expected result. 

For how long have I used the solution?

I have been using this solution for two years. 

What do I think about the stability of the solution?

It's stable. It works very well in the parameter like an enterprise solution. We don't have any problems with that.

How are customer service and support?

We are very pleased with the support.

How would you rate customer service and support?

Positive

How was the initial setup?

I would rate my experience with the initial setup a six out of ten, where one is difficult and ten is easy to set up. 

What about the implementation team?

We work on the deployment process. The solution is deployed both on-prem and in the cloud environment.

The solution doesn't require any maintenance. 

What was our ROI?

It took two years to see ROI for our clients.

What's my experience with pricing, setup cost, and licensing?

Veracode is expensive. But the solution is worth it. 

What other advice do I have?

Overall, I would rate the solution a nine out of ten. It is a good solution for security. In my personal opinion, there are not many products like Veracode in the market. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
DevOps and Cloud Architect at a marketing services firm with 51-200 employees
Real User
Great for automatic penetration testing and providing the ability to investigate problems
Pros and Cons
  • "Provides the ability to understand the black zones in our system."
  • "Security can always be improved."

What is our primary use case?

I'm the manager of DevOps and cloud architecture.

How has it helped my organization?

This product has given us the ability to investigate and understand the black zones in our system. 

What is most valuable?

Veracode can emulate the most sophisticated attack and create unique or specific use cases around automatic penetration testing. It gives us the ability to investigate any sensitivities to vulnerabilities that we may have.

What needs improvement?

Security can always be improved. I'd like to know how we can better prevent intrusions to our systems and create risk analysis use cases and understand them. What is the level of risk for what we want to do? How can we understand the process better? I'd like to have a better overview of what's going on. 

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

There are three layers of technical support and we have used all of them over time. We are happy with the service they provide. 

What other advice do I have?

It's important to understand your environment and know the specific use cases for your organization. Creating good orchestration application metrics is very important.

I rate this product eight out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Raj Nachiappan - PeerSpot reviewer
Director of Solutions Architecture at VetsEZ
Real User
Penetration Testing solution used by development team for static code analysis
Pros and Cons
  • "Our development team use this solution for static code analysis and pen testing."
  • "The runtime code analysis could be improved so that we can see every element in one place."

What is our primary use case?

Our development team use this solution for static code analysis and pen testing.

What needs improvement?

The runtime code analysis could be improved so that we can see every element in one place.

For how long have I used the solution?

I have used this solution for two years. 

What other advice do I have?

I would rate this solution an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user854049 - PeerSpot reviewer
Chief Compliance Officer at a financial services firm with 51-200 employees
Real User
Ad-hoc scanning during the development cycle, reporting for audits, are key features
Pros and Cons
  • "Ad-hoc scanning during the development cycle and reports for audits are valuable features."
  • "I would like to see these features: entering comments for internal tracking; entering a priority; reports that show the above."

What is our primary use case?

We test each major release of our software using Veracode static and dynamic testing. We also do manual penetration testing annually.

How has it helped my organization?

Ensures our code and system are 100% compliant. In terms of APPSec best practices and guidance to our team, the Knowledgebase available on the Veracode system is a great resource for our developers.

For our customers, the added security assurance is a requirement.

What is most valuable?

  • Ad-hoc scanning during the development cycle
  • Reports for audits

In terms of integrating Veracode into our existing software development lifecycle, there are regular milestones in the SDLC to perform Veracode scans.

What needs improvement?

  • Entering comments for internal tracking
  • Entering a priority
  • Reports that show the above

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

No issues with scalability.

How are customer service and technical support?

Excellent.

Which solution did I use previously and why did I switch?

We did use a previous solution. It didn't satisfy our needs technically, and the customer service and its cost were not satisfactory.

How was the initial setup?

Easy.

What was our ROI?

We don't do a detailed enough analysis to reflect on any cost savings relating to code fixes made since we implemented Veracode.

What's my experience with pricing, setup cost, and licensing?

Negotiate some, but their prices are reasonable.

Which other solutions did I evaluate?

HPE Fortify.

What other advice do I have?

Have them guide you through your first scan - make sure to add hours to your initial contract for that.

I am very likely to recommend Veracode to colleagues.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.