it_user841116 - PeerSpot reviewer
Information Security Lead Analyst at a consumer goods company with 10,001+ employees
Real User
We have learned from the recommended remediation strategies, making future code better
Pros and Cons
  • "It has caught lots of flaws that could have been exploited, like SQL injection flaws. It has also improved developer engagement with information security."
  • "In terms of application security best practices and guidance to our teams, their engineering staff is really excellent. They provide our developers with suggestions and they take those to heart. They've learned from the recommended remediation strategies provided by the Veracode security engineers. That makes all of their future code better."
  • "The scanning is a little slow, but other than that it's fine. It's usually when the binaries get up into the multi-hundred megabyte size."

What is our primary use case?

Security scanning.

How has it helped my organization?

It has caught lots of flaws that could have been exploited, like SQL injection flaws. It has also improved developer engagement with information security.

In terms of application security best practices and guidance to our teams, their engineering staff is really excellent. They provide our developers with suggestions and they take those to heart. They've learned from the recommended remediation strategies provided by the Veracode security engineers. That makes all of their future code better.

As for our customers, it lowers the risk for people visiting our site.

What is most valuable?

Catching coding flaws before they go live.

Regarding integrating Veracode into our software development lifecycle, we started out with it being used only as a web interface, and now developers are starting to use it right in their IDE on the desktop.

What needs improvement?

It's a pretty dynamic product. It's changing all the time and improving.

Buyer's Guide
Veracode
April 2024
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,065 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

The scanning is a little slow, but other than that it's fine. It's usually when the binaries get up into the multi-hundred-megabyte size.

What do I think about the scalability of the solution?

We haven't encountered any scalability issues with Veracode so far.

How are customer service and support?

They're awesome. Their timeliness is acceptable, but their expertise is phenomenal.

Which solution did I use previously and why did I switch?

Veracode is the first professional solution I've used. It was in place when I got to the company.

How was the initial setup?

We just use it as a cloud service for third-party developers.

What was our ROI?

In terms of cost savings relating to code fixes since implementing Veracode in our development process, I can't really give hard numbers.

What's my experience with pricing, setup cost, and licensing?

I'm not the pricing guy.

Licensing is pretty flexible. It's a little bit weird, it's by the size of the binary, which is a strange way to license a product. So far they've been pretty flexible about it.

What other advice do I have?

I recommend it all the time.

It's an important aspect of a complete security program. Not necessarily this product, but source code, fraud detection.

I'd give it an eight out of 10 because it's pretty straightforward, but you still have to mostly wrap it with organizational policies that encourages its use. It's not a product - and I don't think it's really a product category - that sells itself to the end-user. They see benefits, but they do have to be convinced to use it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Team Lead / Architect at a tech services company with 1,001-5,000 employees
User
We use its static analysis during development to eliminate vulnerability issues
Pros and Cons
  • "We use Veracode static analysis during development to eliminate vulnerability issues"
  • "I have found the user interface extremely helpful in prioritizing issues."
  • "They should improve on the static scanning time."

What is our primary use case?

I use Veracode to run scans on .NET applications, web applications and Windows/fat form applications. I also use it to make deployments in three-tier environments: the application server tier, web server tier and the database tier.

How has it helped my organization?

  • Veracode has improved our penetration testing process. 
  • We use Veracode static analysis during development to eliminate vulnerability issues.

What is most valuable?

  • I have found the user interface extremely helpful in prioritizing issues.
  • It allows me to prioritize the work to help resolve an issue.

What needs improvement?

They should improve on the static scanning time.

For how long have I used the solution?

Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user

We have heard the need for faster scan times and I see this was an area you wanted to see improvement. I wanted to give you an update regarding our Static scanning. We recently extended the Veracode Static Analysis product family to include three purpose-built scan types:

• IDE Scan, which provides fast, automated security feedback to developers in the IDE, in seconds
• Pipeline Scan, a new, first-of-its-kind offering, which runs on every build and provides security feedback on code at a team level, with a median scan time of 90 seconds
• Policy Scan, which returns a full security assessment of the code before release, in a median scan time of 8 minutes

If you would like more information on our static analysis improvements let me know!

Buyer's Guide
Veracode
April 2024
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,065 professionals have used our research since 2012.
it_user873405 - PeerSpot reviewer
Lead Security Engineer at a tech vendor with 201-500 employees
Real User
Our customers get the security of bug-free code, but raw file scans would help
Pros and Cons
  • "Scanning of .war and .jar is key for us."
  • "Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries."

What is our primary use case?

SAST. We have not yet integrated it into our software development lifecycle as it doesn't have the feature that enables us to integrate it with our repository.

How has it helped my organization?

It helps in achieving secure programming. Veracode provides us with industry best practices according to OWASP, CERT, and SANS. Our customers get the security of bug-free code and assurance regarding the application.

What is most valuable?

Scanning of .war and .jar.

What needs improvement?

Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries.

For how long have I used the solution?

Trial/evaluations only.

What do I think about the stability of the solution?

No stability issues yet.

What do I think about the scalability of the solution?

No scalability issues yet.

Which solution did I use previously and why did I switch?

We used SonarQube but to improve security in SAST we choose this.

How was the initial setup?

Setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing is good for static code analysis.

Which other solutions did I evaluate?

Checkmarx, SonarQube.

What other advice do I have?

Implement this solution if you see WAF and SOC in your future.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user920715 - PeerSpot reviewer
Managing Principal Consultant at a tech vendor with 11-50 employees
Consultant
Easy to scale and does a good job, but only for a limited number of technologies
Pros and Cons
  • "The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs."
  • "I would like to see expanded coverage for supporting more platforms, frameworks, and languages."

What is our primary use case?

Our primary use case for this solution is application security.

What is most valuable?

The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs.

What needs improvement?

This solution does a good job, but it is limited to only a few technologies. I would like to see expanded coverage for supporting more platforms, frameworks, and languages.

Specifically, I would like to see support for mobile frameworks like Xaramin and React JS, as well as extended support for iOS applications.

For how long have I used the solution?

Five years.

What do I think about the scalability of the solution?

This solution is quite scalable.

We have approximately fifty users, but we definitely have plans to add more.

How are customer service and technical support?

I have used their technical support and they are quite good.

Which solution did I use previously and why did I switch?

We did not use another solution prior to this one.

How was the initial setup?

The initial setup of this solution is straightforward.

What's my experience with pricing, setup cost, and licensing?

This solution is on the pricey side. They have just streamlined the licensing and they have a number of flexible options available, so overall it is quite good, albeit pricey.

Which other solutions did I evaluate?

We evaluated other options, but we chose Veracode.

What other advice do I have?

My advice for anybody who is interested in implementing this solution is to ensure that your technology is actually supported because the coverage is quite patchy. It is possible that if you use a framework or a language that Veracode does not support then it will give quite poor results.

I would rate this solution a six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Associate Consultant at a comms service provider with 201-500 employees
Consultant
Efficient at finding vulnerabilities but the number of false positives should be reduced
Pros and Cons
  • "The most valuable feature is the efficiency of the tool in finding vulnerabilities."
  • "A high number of false positives are reported and this should be reduced."

What is our primary use case?

I am a consultant and SourceClear is one of the solutions that I use to provide services.

This solution is used by people who want to verify the security of their own applications.

What is most valuable?

The most valuable feature is the efficiency of the tool in finding vulnerabilities.

What needs improvement?

A high number of false positives are reported and this should be reduced.

For how long have I used the solution?

I have been using SourceClear for about a year and a half.

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

We have no complaints about scalability. We have between 200 and 300 clients.

How are customer service and technical support?

We have not been in touch with Veracode's technical support.

Which solution did I use previously and why did I switch?

We have also used Checkmarx, where you can train the tool for false positives and ultimately reduce them.

How was the initial setup?

The initial setup is a little bit complex.

What about the implementation team?

It would be better to have some assistance when implementing this solution.

What other advice do I have?

Overall, SourceClear is working fine for us and our main complaint is in regard to the high number of false positives. Nonetheless, I would recommend Checkmarx over SourceClear.

I would rate this solution a six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user833550 - PeerSpot reviewer
VP of Services at a tech vendor with 51-200 employees
Real User
We're much more security conscious when writing code, to meet the benchmarks it gives us
Pros and Cons
  • "We use it to get our scan results and see where our software is vulnerable or not vulnerable."
  • "The user interface can sometimes be a little challenging to work with, and they seem to be changing their algorithm on what is an issue. I understand why they do it, but it sometimes causes more work on our end."

What is our primary use case?

Dynamic and static scanning.

How has it helped my organization?

We're being much more security conscious whenever we're writing code, and we're trying to make sure it's giving us a benchmark, and to make sure we meet that, on a release cycle.

In terms of AppSec best practices, it has made everybody more conscious about what they're trying to accomplish, because they know at the end of the release cycle we're going to be running scans. They basically need to make sure they adhere to all the rules.

Our customers have benefited from the added application security we offer because they're more confident that our software isn't going to expose their organizations to any risk.

What is most valuable?

The ability to run scans. It's a critical piece of why we use the platform. We use it to get our scan results and see where our software is vulnerable or not vulnerable.

It's part of our SDLC now.

What needs improvement?

The user interface can sometimes be a little challenging to work with, and they seem to be changing their algorithm on what is an issue. I understand why they do it, but sometimes it causes more work on our end.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

Not that I know of.

How is customer service and technical support?

I have not contacted tech support.

How was the initial setup?

It seemed straightforward. I didn't actually do the work, but from what I was told, it seemed like it was fairly easy to get going.

What was our ROI?

I cannot give numbers on any cost savings related to code fixes since implementing CA Veracode in our development process.

What's my experience with pricing, setup cost, and licensing?

It's worth the value.

Which other solutions did I evaluate?

We did evaluate other options, but I can't remember who we looked at.

What other advice do I have?

I would be highly likely to recommend working with CA Veracode to colleagues. 

I rate it an eight out of 10. It's a good product - I can't say that it's lighting my world on fire - but it does what it needs to do.

Just be prepared that it's going to take effort from all aspects of the business to be able to utilize and achieve the goal that you're looking to achieve with the product.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user802140 - PeerSpot reviewer
Product Manager at GMS
User
All areas of the solution could use some improvement. It helps me to detect vulnerabilities.
Pros and Cons
  • "It helps me to detect vulnerabilities."
  • "All areas of the solution could use some improvement."

What is our primary use case?

We are Veracode partners/distributors in Quito, Ecuador. 

At this moment, I am reviewing the solution. 

How has it helped my organization?

It helps me to detect vulnerabilities.

What is most valuable?

I use the SAST feature the most.

What needs improvement?

All areas of the solution could use some improvement.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are Veracode partners/distributors in Quito, Ecuador.
PeerSpot user
it_user854046 - PeerSpot reviewer
DevOps Release Engineer at a tech services company with 51-200 employees
Real User
Makes us aware of any potential code security vulnerabilities in our products
Pros and Cons
  • "Informs me of code security vulnerabilities. Bamboo build automation with Veracode API calls are used.​"
  • "The user interface could be more sleek. Some scanning requirements aren't flexible. Some features take some time for new users to understand (like what exactly "modules" are)."

What is our primary use case?

Scanning for code security vulnerabilities within our company's products.

How has it helped my organization?

Made our company aware of any potential code security vulnerabilities. Also, customers can use our products knowing they are verified by top organizations as safe.

What is most valuable?

Informing me of application security vulnerabilities. Bamboo build-automation with Veracode API calls are used.

What needs improvement?

  • The user interface could be more sleek.
  • Some scanning requirements aren't flexible.
  • Some features take some time for new users to understand (like what exactly "modules" are).

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

No issues with scalability.

How is customer service and technical support?

Great.

How was the initial setup?

Somewhat straightforward. There was a little confusion about "missing modules" that are third-party files that we couldn't upload because we don't actually have them. That really confused us, but the technical support resolved the confusion.

What was our ROI?

I can't report on any cost savings relating to code fixes since implementing Veracode in our development process, but it makes us feel more confident about our code, which is awesome.

What's my experience with pricing, setup cost, and licensing?

We are satisfied.

Which other solutions did I evaluate?

None. We might look into Checkmarx.

What other advice do I have?

I am very likely to recommend Veracode to colleagues. Veracode is great.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.