We use Veracode to scan our products for code security. Our company also uses Veracode's data security module.
Senior Director at a tech vendor with 10,001+ employees
The solution's static analysis has streamlined our DevSecOps process, which previously involved a lot of manual work
Pros and Cons
- "Veracode enables us to build a strong data security layer in our platforms. We can increase customer confidence in data security. Some PCI/HIPAA compliance issues were impossible to resolve without Veracode."
- "Veracode's ease of use could be improved. I would also like to see more online videos and tutorials that could help us understand the product better. It would also be helpful if Veracode created a certification program for DevSecOps staff to learn about their product and get certified. This kind of training would raise the company's profile within the industry."
What is our primary use case?
How has it helped my organization?
Veracode enables us to build a strong data security layer in our platforms. We can increase customer confidence in data security. Some PCI/HIPAA compliance issues were impossible to resolve without Veracode. I rate Veracode's compliance features a nine out of ten because it provides detailed reports after each scan about potential regulatory violations.
The solution's static analysis streamlined our DevSecOps process, which previously involved a lot of manual work to trace code vulnerabilities. Veracode reduced our DevSecOps team's time on these tasks by around 20 to 30 percent while drastically improving code quality.
In the past, we also performed a scan using third-party vendor partners that took days to complete. Veracode conducts a quick dynamic scan each time a new iteration of code is built and deployed into the environment. It gives us an immediate result. We can deploy our products much faster, and there are no delays or surprises after the product is built. We aren't wasting time from development to deployment.
Our overall security posture improved, but we've only been using Veracode in production for less than two months. We expect a massive improvement in the next six to eight months.
The false positive rate is typically less than five percent. False positives can affect how developers use a solution. If we see too many false positives, we might start ignoring alerts. Sometimes the developers lose confidence and may take the work lightly. It isn't an issue currently because the rate is under five percent.
What is most valuable?
Dynamic scanning is the most useful feature.
What needs improvement?
Veracode's ease of use could be improved. I would also like to see more online videos and tutorials that could help us understand the product better. It would also be helpful if Veracode created a certification program for DevSecOps staff to learn about their product and get certified. This kind of training would raise the company's profile within the industry.
Buyer's Guide
Veracode
September 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
For how long have I used the solution?
We have used Veracode for about three months. We did a proof of concept for one month, and it has been in production for two.
What do I think about the stability of the solution?
I rate Veracode a ten out of ten for stability. We haven't had any issues.
What do I think about the scalability of the solution?
Veracode is scalable, but we haven't scaled it up. However, I expect it will work well when we do.
How are customer service and support?
I rate Veracode support a nine out of ten. Their support system is excellent and highly engaged.
Which solution did I use previously and why did I switch?
We tried some Indian solutions and used third-party scans for static analysis, but Veracode is the first time we have fully integrated an enterprise code security solution.
How was the initial setup?
Veracode is a SaaS solution. Setting it up isn't simple, but it isn't too complex. We deployed Veracode with a three-person in-house team. Veracode requires a decent amount of maintenance. You must perform periodic validation checks on how the engine is performing.
What was our ROI?
You have to compare the price to the potential cost of data security threats, which could devastate your reputation and revenue overall. We do not doubt that the investment is worth it. It's too early to calculate an ROI, but we anticipate a reduction in overall DevSecOps costs.
What's my experience with pricing, setup cost, and licensing?
Veracode is priced competitively for our market.
Which other solutions did I evaluate?
We evaluated a few other vendor partners and decided to go with Veracode because of the various features they offered.
What other advice do I have?
I rate Veracode a nine out of ten. If you plan to implement Veracode, your DevSecOps should adopt modularized-based code segregation for better visibility into how this ecosystem works. It's crucial to be clear about the solutions you are procuring. There are multiple options, and not everything will work for you. Understanding your requirements, what your customer needs, and what will work best for your product is essential. Purchase the solution most suitable for your product and your company.
You should also maximize Veracode's benefit by working closely with the tech support team. We don't use many of the features we have procured. Setting up an ongoing review mechanism with Veracode technical support is critical to better understand the product and ensure you get the maximum return for your investment. These are some points that company leaders need to discuss with their DevSecOps and DevOps teams.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Engineer at a tech vendor with 10,001+ employees
Secures our apps with accurate vulnerability detection in a straightforward, efficient solution
Pros and Cons
- "I like the sandbox, the ability to upload compiled code, and how easy it is."
- "The sandbox could use some improvement; when creating a sandbox, it requires us to put the application name in twice, which seems unnecessary."
What is our primary use case?
Our primary use cases are uploading and assigning scans, uploading compiled codes into the sandboxes, and searching marks to determine whether scans have been completed.
We have multiple locations, teams, and endpoints; we're a worldwide telecommunications company with over 2000 internal and external apps. Some apps communicate from the outside to the inside, but every app goes through Veracode.
How has it helped my organization?
We have to scan about 2000 apps, and we're already at 366 scanned within the year's first two months. Additionally, the company has been using Veracode for years; both are testaments to the solution's efficiency.
The platform provides visibility into application status at every phase of the development- Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Testing throughout our SDLC. In terms of DevSecOps processes, the solution makes them quicker and smoother, with less confusion.
Veracode positively affects our organization's ability to fix flaws; we have a particular app at the moment that failed the scan twice due to its vulnerabilities. Without the solution, we likely wouldn't get that.
The solution has positively affected our organization's overall security posture and will continue to improve it.
What is most valuable?
I like the sandbox, the ability to upload compiled code, and how easy it is.
It's also straightforward to find scans we've uploaded.
The solution's ability to prevent vulnerable code from going into production is incredible. I have done several consultations and remediation calls with the app team, and Veracode catches almost everything. It picks up the same issues in everything we scan, and we've done a lot of retests that way; the tool is very proficient in this area.
Veracode helps our developers save time; it's a straightforward product that shows us the vulnerabilities and allows us to relay them back to the developers. This is faster and more efficient than staff going through the code manually. The solution is like having a proofreading app for our code rather than using a proofreader.
What needs improvement?
The sandbox could use some improvement; when creating a sandbox, it requires us to put the application name in twice, which seems unnecessary.
For how long have I used the solution?
We've been using the solution for a month and a half.
What do I think about the stability of the solution?
Veracode is very stable; unlike many programs and apps, I've never had a problem with it.
What do I think about the scalability of the solution?
The solution is scalable; we're a global telecom company, and we use it to scan every one of our over 2000 apps.
How are customer service and support?
The technical support is excellent.
How would you rate customer service and support?
Positive
What's my experience with pricing, setup cost, and licensing?
I'm unfamiliar with the solution's pricing, but it must be worth the cost from a company perspective, as we have been using it for years and have no plans to move away from it.
Which other solutions did I evaluate?
The product was in place long before I arrived at the company, so I don't know if they evaluated other options.
What other advice do I have?
I rate the solution 10 out of 10.
I recommend Veracode to any company looking for this type of platform. Though I need to become more familiar with competitor products, I like going into programs and clicking around. Even if I don't initially understand something within Veracode, I can keep going and make sense of it. I updated my resume to include my new experience with the solution.
Veracode reduced the cost of DevSecOps for our organization; we upload a scan, run the test, get the vulnerabilities, and set up a remediation meeting. This makes communication more manageable, and the information is more visible, as all our staff can access the scan results. In several instances, we've consulted with employees from the Veracode side, and they've been very helpful in walking our app team and testers through whatever vulnerabilities we've had issues with.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Veracode
September 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
Senior software engineer at a tech services company with 1,001-5,000 employees
Provides visibility concerning security issues, is scalable, and no maintenance is required
Pros and Cons
- "The most valuable feature is the static scan that checks for security issues."
- "The zip file scanning has room for improvement."
What is our primary use case?
We use the solution to scan for and identify vulnerabilities or security issues.
We use a SaaS deployment.
How has it helped my organization?
Before releases, we must ensure that all the security issues identified by Veracode are addressed. Occasionally, some false positives may be encountered, but these can be safely ignored. We are usually satisfied with the accuracy of the report as all the important security issues are identified and addressed allowing us to focus on our release sooner.
All the applications that are going to production in our large company are required to pass through Veracode, which provides us with a uniform standard that everyone must adhere to. This standard allows us to ensure the quality of our products before they go to market.
Veracode may not seem to immediately save our developers time, and it may even seem tedious at times. Ultimately, however, it can be extremely useful in identifying issues and vulnerabilities before they become larger problems, making it a valuable resource.
Veracode helped our security posture by checking security gaps in the production environment.
What is most valuable?
The most valuable feature is the static scan that checks for security issues. We use Veracode for this purpose; we also use the solution for our UI, but for the backend, we only use the static scan. I'm not sure what it is called, but it is one of two scans, the other one being dynamic. We only use the static scan to identify any security issues.
Veracode assists in the prevention of vulnerable code from reaching production by providing a comprehensive review of security risks and comprehensive reports with thorough descriptions of the vulnerabilities. This allows us to address any security gaps in the release. Based on the severity, we should determine the standards for release. We should not have any security issues with a severity of medium or higher before releasing.
Veracode provides us with ultimate visibility concerning security issues. Additionally, we use OWASP, which checks our dependencies to identify any potential weaknesses, but Veracode is the only tool we use to check our source code. With Veracode, we have the capability to recognize any security issues in our source code.
What needs improvement?
The false positives have room for improvement. Sometimes, we will get false positives, which we mark as mitigated. However, it can be annoying when they come up again in the next release. Every time a new person is doing the work, they may not be aware of the history of the issue. They must then check the false positive again and mark it as mitigated, and it may come up again in the future. False positives can be an irritating and time-consuming issue for developers to deal with. Investigating them can be a waste of time, as they have already been looked into. This can be frustrating for those involved. False positives waste our time and resources.
The zip file scanning has room for improvement. Sometimes when we upload the zip files for scanning, it can take a long time to get the report. This can take up to a day. Unfortunately, even after waiting a day, sometimes we find that nothing happened and we have to start the process over. This is both time-consuming and frustrating, as we feel the system has crashed.
The reports have room for improvement. I believe the reports are thorough but can become overwhelming with unnecessary information that may not be pertinent to the developer. I'd prefer to have customizable reports that allow us to select which elements we'd like to include.
I believe the usability of the UI needs to be improved. For example, when we navigate away from a page, it should remember our last location and take us back there instead of sending us to the homepage. Additionally, it should be easier to navigate between pages without having to refresh the page each time.
Veracode should provide potential customers with better training materials and resources to help them make a more informed decision before purchasing the product. This could include tutorials, demonstrations, more about how the product works, the user interface, the quality of Veracode's reports, and more. It is unclear if these resources are already available, but they should be made more visible if so.
For how long have I used the solution?
I have been using the solution for over one year.
What do I think about the stability of the solution?
The report is usually ready without any problems, but occasionally there may be a crash or other issue occurring in the background that prevents it from being ready. This happens about 10% of the time. The solution is primarily stable.
What do I think about the scalability of the solution?
I haven't experienced any scalability issues so far. This is likely because the job is always the same and the files we upload remain the same. We haven't had to change any parameters in the input, so scalability hasn't been a concern.
Which solution did I use previously and why did I switch?
We used CodeSonar to analyze various aspects of our source code, and we already utilize OWASP to assess the security risks of our dependencies.
What other advice do I have?
I give the solution an eight out of ten.
One of the applications we supported through Veracode is designed for use by travelers of an airline. The application handles everything from searching for availability to obtaining tickets.
The solution does not require any maintenance. I am logging into my organization's portal, from which I have a direct link to access Veracode. I do not need to do anything else, such as create content or install anything.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VP of Product at a healthcare company with 51-200 employees
Useful scanning, highly scalable, and quick setup
Pros and Cons
- "The most valuable feature of Veracode Static Analysis is the scanning."
- "Veracode Static Analysis can improve the false positive. There are always improvements that can be done to the false positive rate. There are some things that get flagged that are not an issue. However, it is not a huge concern."
What is our primary use case?
We use Veracode Static Analysis in the IDE for our engineers to be able to catch security issues while they're coding. Additionally, we use it for the Veracode verified program to show that we're scanning and compliant, and we get the third-party seal of approval.
It's a scanning security, static analysis code scanning software.
How has it helped my organization?
Veracode Static Analysis has benefited our company because we are catching potential security issues earlier in the pipeline. Before anything goes to human code review, Veracode Static Analysis catches issues as the engineer is working in their IDE.
What is most valuable?
The most valuable feature of Veracode Static Analysis is the scanning.
What needs improvement?
Veracode Static Analysis can improve the false positive. There are always improvements that can be done to the false positive rate. There are some things that get flagged that are not an issue. However, it is not a huge concern.
For how long have I used the solution?
I have been using Veracode Static Analysis for approximately 18 months.
What do I think about the stability of the solution?
Veracode Static Analysis is stable.
What do I think about the scalability of the solution?
We have got 5 million lines of code and it hasn't choked at all but seems to run just fine.
We have approximately 40 users and most of those are frontline engineers. Additionally, we have security officers who use it to run reports and team leads that use it for training. We plan to increase our usage when we have new deployments.
I rate the scalability of Veracode Static Analysis a ten out of ten.
How are customer service and support?
I have not used the support from Veracode Static Analysis.
Which solution did I use previously and why did I switch?
We used HCL AppScan prior to Veracode Static Analysis.
How was the initial setup?
The deployment can be done in approximately 10 minutes. We use Bitbucket Pipelines and Veracode Static Analysis is integrated into our deployment pipelines.
I rate the initial setup of Veracode Static Analysis an eight out of ten.
What about the implementation team?
We did the deployment of the solution in-house. We typically can do the deployments with one person.
What was our ROI?
I cannot say we have had a return on investment because we haven't had any security incidents, but we didn't have any before using Veracode Static Analysis either.
What's my experience with pricing, setup cost, and licensing?
The price of Veracode Static Analysis is expensive. There is an annual fee to use the solution and the company is upfront with the pricing model and fees.
I rate the price of Veracode Static Analysis a three out of ten.
Which other solutions did I evaluate?
We evaluated Checkmarx and Synopsys before choosing Veracode Static Analysis.
What other advice do I have?
My advice to others is if they use Veracode Static Analysis they are using a very solid solution. You get what you pay for. It's an expensive solution, but it's very good. You're going to save a lot of time and a lot of headaches with fewer false positives, but you're going to pay for it. It's good if you want to automate something into your pipeline and it's going to run fast and give you good results. I would choose Veracode Static Analysis, but be cognizant of the cost.
I rate Veracode Static Analysis an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Software Engineer at a tech vendor with 11-50 employees
Integrates with our CI/CD pipeline and automatically scans our code when we do the build
Pros and Cons
- "I like Veracode's integration with our CI/CD. It automatically scans our code when we do the build. It can also detect any security flaws in our third-party libraries. Veracode is good at pinpointing the sections of code that have vulnerabilities."
- "We are testing Veracode's software composition analysis, but we're having trouble integrating it with SVN. It works out of the box when you use Git but doesn't work as well with other tools like SVN. It's more geared toward Git"
What is our primary use case?
We are a relatively young company that started about a decade ago. The company adopted Veracode about five years ago because it's a market leader in that segment.
Veracode checks for security flaws in our code. We provide software for companies in the financial sector, so it's critical that we use Veracode. There are some lesser-known competitors, but Veracode is the biggest player in security software. In a way, it's good marketing to use Veracode.
We are running it locally, but we plan to move to the cloud in the next few months. We're a small company with 20 employees. Our development team deals primarily with it, and some other support guys are involved occasionally.
How has it helped my organization?
We have been using Veracode for several years. It has become a crucial tool for preventing security flaws in our applications. The quality of our software has improved significantly since we started using Veracode. We have a software development shop and also provide solutions for other companies. It's critical to have our software checked by Veracode.
Our code must be free of security flaws, especially high-level ones. Our software must be above a minimum threshold. Veracode has enabled us to see the quality of our code security. We need at least an 80 percent score. We are sure that our code is high-quality and that our clients won't see security vulnerabilities in the code when we ship it to them.
Veracode covers every phase of development. We mainly use it for static analysis and recently started using it for software composition analysis.
The false positive rate is around 10 percent, which is expected in automated software. Veracode's competitors have false positives, but we're happy with Veracode's ability to mitigate the problem. We check every false positive and clear it. It does not affect our competence at all. We realize it will happen from time to time. The effect of false positives is negligible. We don't have a problem with that. We are experienced enough now to see what is or isn't.
What is most valuable?
I like Veracode's integration with our CI/CD. It automatically scans our code when we do the build. It can also detect any security flaws in our third-party libraries. Veracode is good at pinpointing the sections of code that have vulnerabilities.
What needs improvement?
We are testing Veracode's software composition analysis, but we're having trouble integrating it with SVN. It works out of the box when you use Git but doesn't work as well with other tools like SVN. It's more geared toward Git.
For how long have I used the solution?
I have been using Veracode for two years in my current role.
What do I think about the stability of the solution?
Veracode's stability is decent. That was only one instance where it identified a security flaw but didn't detect it afterward. Otherwise, it's mostly consistent.
What do I think about the scalability of the solution?
We use it on a couple of different projects, and we plan to move to the cloud. They have a cloud option that makes it scalable.
How are customer service and support?
I rate Veracode support nine out of 10 in its current state, but given our problems in the past, I might rate it seven overall. We had some problems when I joined. They put in a lot of effort, but it took them a couple of months to get it right. They did their best to resolve it, so I appreciate that, but we weren't happy it took so long.
How would you rate customer service and support?
Positive
What was our ROI?
We don't see a direct return from using Veracode, but it ensures we deliver a product without security faults. It has also reduced our development costs, but it's difficult to quantify that. By having the code tested before we ship it to clients, we ensure our clients don't have issues with the security of our software.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable and affordable for a small company like ours. Veracode provides a lot of features. You can purchase some additional tools. For example, we are currently testing software composition analysis. We discussed adding that to our standard package.
What other advice do I have?
I rate Veracode eight out of 10. I recommend first testing it on your code to see if it's appropriate. You need to see how long it takes to scan the code.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Lead Architect, Presales lead at Alerant Zrt.
Excels when it comes to binary scanning and has helped us significantly increase development speed
Pros and Cons
- "For use cases where our company buys a product with the source code, but only the final executables or the binaries, only Veracode is able to work on that type of tool."
- "It has also helped to increase our fix rate by almost 100 percent."
- "There is room for improvement in the speed of the system. Sometimes, the servers are very busy and slow... Also, the integration with SonarQube is very weak, so we had to implement a custom solution to extend it."
What is our primary use case?
We are using it for two purposes. The first is to analyze the final binaries in our normal development cycle and the second is for auditing old software.
It's a SaaS solution.
How has it helped my organization?
Veracode is able to analyze the final software products. We compile the applications and it's an advantage for us because there are a lot of areas where we don't have the source code. In some companies, only internal development is taking place and they have the source code and everything else for the software. With those companies, there are other tools that we can use. But for use cases where our company buys a product with the source code, but only the final executables or the binaries, only Veracode is able to work on that type of tool. We are working in the financial sector for big bank banks and insurance companies. A lot of times, these types of companies don't have the source code for the applications, only the final applications. This is the biggest advantage of Veracode, that it's able to analyze these types of applications.
We use the scanning process to help our security professionals and developers fix flaws in the code and that helps speed up the development cycle. It helps to "shift-left" all of the security control to the earliest phase of the development cycle. It has sped up the development cycle significantly. An unexpected vulnerability can stop the development pipeline, at least for a little while, and we are able to avoid that.
It has also helped to increase our fix rate by almost 100 percent. In the past, if it turned out that we had vulnerabilities, we had no time to correct them. We went into production with them. Now, we are able to fix everything, 100 percent, in the development cycle.
In terms of best practices, we have the results from Veracode and then we have a Knowledge Base of the types of vulnerabilities and how they should be corrected by our developers.
Another benefit is that it has helped us with certification and audits. We have a lot of automated reports based on the scans and we can show them to the auditors. That has saved us a lot of money and work.
And Veracode SCA has helped to reduce the risk of a security breach because it finds vulnerabilities as early as possible. It has increased our security and development teams’ productivity because, with the automated scanning, we are able to scan much more than previously. It saves us at least one week per development cycle, if not more.
The recommendations from Veracode have improved our efforts in fixing potential vulnerabilities, and not just finding them. That's important for us because fixing is a very expensive process. If you can save time on that, it is a big help. And SCA’s automated, peer, and expert advice have definitely reduced remediation times, saving us at least a week per development cycle.
Overall, SCA has significantly lowered the risk of vulnerabilities. If we didn't identify them before production, and it turned out that there were vulnerabilities, there would be a big risk. We would have to go into production with them or stop the development pipeline. So it lowers the security risk significantly by doing early scanning. It has reduced our risk by at least 60 percent. It definitely helps create secure software. That is 100 percent important because we are working for financial companies.
What is most valuable?
It's good that it's cloud-based because we don't have to operate a new IT system for security scanning.
It provides a centralized view across all testing types, including SaaS, DAST, SCA, and manual penetration testing. We now have a central place with overall visibility.
In addition, the mitigation recommendations provided by the scanning engine are good. They are not all perfect, but they are good and usable.
What needs improvement?
There is room for improvement in the speed of the system. Sometimes, the servers are very busy and slow. Also, because we are located in Europe, it would be a big help if they had a European or national service, because of the regulations, not only because of the speed.
Also, the integration with SonarQube is very weak, so we had to implement a custom solution to extend it.
For how long have I used the solution?
We have been using Veracode Software Composition Analysis for more than two years.
What do I think about the stability of the solution?
The stability is good. We haven't had any problems.
What do I think about the scalability of the solution?
The scalability issue is a good question because it's not too fast, but it's scalable because it's cloud-based.
We use it for 10 critical applications.
How are customer service and support?
Their technical support staff is skilled. We have been able to solve all of our problems with them. I wouldn't rate them a 10 because sometimes it's time-consuming to get the right guy to answer our questions. But we always get answers to our questions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used SonarQube because the developers liked it. We also used Checkmarx. We switched to Veracode SCA because of the binary scanning ability. Neither Checkmarx nor SonarQube is able to do that.
How was the initial setup?
The initial setup was very easy. Because it's a cloud-based service, we were able to do it without the help of Veracode. We just read the recommendations and followed them. We had three guys involved, two developers and one security guy.
It took three months to implement. Our implementation strategy was to do a pilot and then everybody in the organization copied the reference implementation.
What was our ROI?
Our return on investment is due to saving a lot of development hours.
What's my experience with pricing, setup cost, and licensing?
It's too expensive for the European market. That is why, in a big bank with 400 applications, we are able to use it for only 10 of them. But the other solutions are also expensive, so it wasn't a differentiator.
The static cost model is not that important. Veracode works on a subscription model, so we have to pay for it every year.
Which other solutions did I evaluate?
We chose Veracode's Software Composition Analysis after we evaluated more than 10 products. Among those we evaluated were Checkmarx, Fortify, and SonarQube. The primary differentiator was the binary scanning use case.
What other advice do I have?
Use Veracode for the special use case of binary scanning, because it is the best in this special use case.
Security Labs is very good as well. We are not using it day-to-day, but it's a good feature.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Drastically reduced post-deployment issues for us
Pros and Cons
- "Before Veracode, the application was deployed to the production server and there would be a lot of bugs and issues. Once we implemented the Veracode scan, the full deployment issues were drastically reduced."
- "One concern is that scans take a long time to run. We scan at the end of the day because we know it will take a lot of time. We leave it to run and the report will be generated by the next day when we arrive. The scanning time could be reduced."
What is our primary use case?
We use it to scan third-party libraries to check for vulnerabilities.
How has it helped my organization?
Our company relies on Veracode to prevent vulnerable code from going into production.
And it reduces post-deployment bug fixes. Before Veracode, the application was deployed to the production server and there would be a lot of bugs and issues. Once we implemented the Veracode scan, the full deployment issues were drastically reduced. In a month we do 10 releases and we used to get five or six post-deployment issues. Now, we barely get one or two.
Veracode has also significantly saved us time, around 30 to 40 percent, and we can concentrate on new features instead of fixing the old ones.
What is most valuable?
We use the full code analysis and the recommendations from the Veracode report.
What needs improvement?
One concern is that scans take a long time to run. We scan at the end of the day because we know it will take a lot of time. We leave it to run and the report will be generated by the next day when we arrive. The scanning time could be reduced.
For how long have I used the solution?
I have been using Veracode for the last three months.
What do I think about the stability of the solution?
It's very stable. I've never seen any downtime with Veracode.
What do I think about the scalability of the solution?
We use it on-prem, so I'm not sure whether it can be scaled. It's just one endpoint that multiple people access.
Which solution did I use previously and why did I switch?
We have two scanning stages. The first one uses SonarQube, which only does code analysis. It doesn't scan third-party libraries that we use in our code. Veracode is the second level of check. We work on a banking project. The bank trusts Veracode and they recommended Veracode to scan our products.
How was the initial setup?
The initial deployment was pretty straightforward. It's on-prem so there was no deployment strategy to follow. It took one to two days to deploy and check everything. A team of three to four people worked on the deployment. It depends on the project's complexity as well. As a DevOps engineer, I support a lot of projects within our organization, and the deployment varies from project to project.
In my department, we handle six to eight projects and each one needs a Veracode scan before deployment. As a company, we have multiple locations and departments but only the DevOps team of eight people has access.
The way we work with Veracode is that we have integrated it with Jenkins. We upload the artifacts to the server, trigger the Jenkins job, and the Veracode scan is generated. We have set everything from the Jenkins pipeline. The scan is automated using Jenkins, which means there is no need for maintenance. If there are new steps implemented in the pipeline, there might be some overhead, but it doesn't need any maintenance. We just set the port and everything works fine.
What other advice do I have?
Other than the scanning time, I would give it a solid eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Chief Software Architect at a tech services company with 51-200 employees
Has an automatic scanning feature and no issues with stability and scalability, but the time it takes to scan large projects could be faster
Pros and Cons
- "What we found most valuable in Veracode is the ability to do automatic scans of our software. We've incorporated the solution into our SDLC process, so we take our builds before they get released and put them through scans to ensure any new vulnerabilities haven't occurred."
- "An area for improvement in Veracode is the time that it takes to scan large projects, as that makes it difficult to fit into our CI/CD pipelines."
What is our primary use case?
We are a software company providing software to paper manufacturing organizations, and we have an extensive ERP product along with many add-on products.
With the need to increase security awareness and vulnerabilities, we decided that we needed to scan our software, so that was how we started using Veracode.
We found Veracode eye-opening because we had many third-party libraries in our application, and we found vulnerabilities and had to upgrade those libraries or seek alternatives.
Our use cases for Veracode were to make our software more secure and provide a better competitive advantage over our competitors by telling our clients that we have secure software.
What is most valuable?
What we found most valuable in Veracode is the ability to do automatic scans of our software. We've incorporated the solution into our SDLC process, so we take our builds before they get released and put them through scans to ensure any new vulnerabilities haven't occurred.
We found Veracode good at preventing vulnerable code from going into production.
We also use the Software Bill of Materials (SBOM) as we run many applications through Veracode. We use SBOM to discover all the different vulnerabilities and what that stack looks like.
We also found Veracode very good in helping us manage risks, such as supply chain, licensing, and security. The solution allows us to see where the risks are and if updates are available and identify how to remediate our software quickly.
Our company also found it moderately easy to use Veracode when creating a report via the Software Bill of Materials. There may be a bit of a learning curve, but once users have done it, they'll run the same report.
As for policy reporting in Veracode to ensure compliance with industry standards and regulations, we have not used the solution that way. Instead, we rely on the different statuses to achieve the levels we want to achieve and be able to use that on marketing material.
Veracode offers visibility into the application status at every development phase throughout the software development life cycle, but we have not implemented that. That feature is built into the development tool, so developers will get alerts as they code, but we plan to do that in the coming year.
We found a moderate false positive rate in Veracode. There were a few false positives. Veracode can identify vulnerabilities, which we found nice. We could flag false positives on Veracode so they don't continue to pop up and hunt them down, and the solution will ignore those in the future.
The false positive rate in Veracode doesn't affect developer confidence in the solution when fixing vulnerabilities because we realized that our application is huge. False positives will happen in large applications just because of the different ways of implementation and features. No toolset can handle all those different features and interactions, so we can't say they relate to vulnerability.
Veracode dramatically impacted our company's ability to have security awareness and achieve a level of confidence that we can put out to the marketplace.
We also saw how Veracode affected our company's overall security posture, explicitly being able to put the solution into automatic scanning mode, then through our SDLC cycles, and achieve a Veracode-verified status. We can use that as a marketing advantage and say that we've achieved Veracode-verified status with one of the leading vendors of security scanning software. We've reached a level of status with them, and we continually scan our software so our clients can be confident that our software has been scanned for security files before implementing a new software release.
What needs improvement?
An area for improvement in Veracode is the time that it takes to scan large projects, as that makes it difficult to fit into our CI/CD pipelines.
One of our app scans times out after two hours, which requires uploading and scanning that particular application manually. Still, there's no visibility into the CI system with the vulnerabilities found. My company cannot incorporate that into the automatic cycle and has to scan manually, so Veracode could improve on that.
For how long have I used the solution?
I've been using Veracode for about two years.
What do I think about the stability of the solution?
Veracode is very stable. I have no concerns with its stability.
What do I think about the scalability of the solution?
Veracode is very scalable from the perspective of ERP applications, though we aren't sure if other clients have applications larger than ours. For reference, we have five million lines of code in our application.
How are customer service and support?
I've contacted the Veracode technical support team and found the support responsive. The team also got back to me quickly. I didn't find any issues with Veracode support.
I would rate technical support as eight, just because you still need to do manual scans, as Veracode still has not addressed that issue.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used a product called Mend.io, formerly WhiteSource, before Veracode to look at vulnerabilities.
How was the initial setup?
I was part of the initial deployment of Veracode, and it was straightforward because Veracode had excellent training programs and onboarding procedures. The Veracode team also helped along the way and was very supportive in answering questions and keeping my team plugged into any new offerings.
What about the implementation team?
We implemented Veracode in-house with only three people involved.
What's my experience with pricing, setup cost, and licensing?
I found Veracode very expensive, though I'm not the person paying for it. I was surprised to find out how much the subscription costs and that the executive board approved it, but it was a no-brainer because now my company has better security scans.
What I can tell others looking into Veracode but concerned about its price is that the price or cost is justified. After all, you can tell potential clients that your software is better than competitor software because you're scanning it and Veracode-verified.
The verification levels of Veracode are essential because you can use Veracode to start climbing up the ladder to say that your software's even more secure than anybody else because it achieved this level of verification.
In terms of Veracode reducing the cost of DevSecOps in our company, we find that tough to determine because we never had a real concentration on DevSecOps before Veracode. It was forced on us by the fact that the industry was becoming more vulnerable, so now we are experiencing an increase in price in DevSecOps because we're paying attention to it now. We used to skate by and weren't affected by vulnerabilities. Still, because the industry had more vulnerabilities, our customers asked if we were scanning our software, so we had to find a solution and add DevSecOps to address industry needs.
Which other solutions did I evaluate?
I did a Gartner search on the top three solutions and looked at their reviews, and Veracode came out to be the leader, so I just went with the leader from a partner perspective.
What other advice do I have?
My company has a hybrid Veracode deployment. It's a cloud-based solution, so it's tied to the company's automatic build cycles, where you can access and do scans through the cloud.
Veracode doesn't require maintenance. The only maintenance my company performs is fixing vulnerabilities found by Veracode.
Overall, my rating for Veracode is seven out of ten.
I advise others looking to evaluate Veracode to utilize the presales marketing side first. For example, my company was able to utilize Veracode in a presales environment and do the scans to find out how vulnerable my company's software is and compare Veracode with the previous tool, WhiteSource. My company found additional vulnerabilities and was able to do that before signing the contract. It may be best to do a test run of Veracode to find out what the tool is all about and how it looks to your company.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
DevSecOps Engineer at Tata Consultancy
Can perform software composition analysis along with static and dynamic scans
Pros and Cons
- "The best feature of Veracode is that we can do static and dynamic scans."
- "Veracode should include the feature to run multiple scales at a time."
How has it helped my organization?
I have manually worked in CI/CD pipelines without Veracode. We could get automatic reports after integrating Veracode plugins into the build tool. The pipeline has become much more automatic by integrating the solution.
What is most valuable?
The best feature of Veracode is that we can do static and dynamic scans. Veracode performs software composition analysis, and we can use the solution to download different reports like the summarized report. Veracode’s interface is good.
What needs improvement?
Veracode should include the feature to run multiple scales at a time.
For how long have I used the solution?
I have been using Veracode for one year.
What do I think about the stability of the solution?
Veracode is a stable solution, except on one occasion when I faced some issues. I rate Veracode a nine out of ten for stability.
What do I think about the scalability of the solution?
Veracode has good scalability. In our organization, Veracode is used only by our team, which consists of seven members.
Which solution did I use previously and why did I switch?
We have used the JFrog XRAY tool for SCA (software composition analysis).
How was the initial setup?
Veracode’s initial setup was easy and straightforward.
What about the implementation team?
Implementing Veracode doesn't take much time. It takes only a few hours to implement the solution. Veracode was deployed by a team consisting of two to three members.
What other advice do I have?
I am into DevOps, and we have integrated Veracode into our DevOps pipeline.
I would recommend Veracode to other users.
Overall, I rate Veracode a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Devops Engineer at Accenture
Good scanning, manages security risks, and prevents vulnerable code from going into production
Pros and Cons
- "The deployment mode is very useful."
- "The pricing is worth it."
- "It's taking too much time to do a quality scan."
What is our primary use case?
We have data deployments for B2B and B2C with the product. Before we used a deployment center like Jenkins. We use it for backend content.
What is most valuable?
We've only used the solution for a year; it hasn't been that long.
The deployment mode is very useful.
We like that it can prevent vulnerable code from going into production.
We use the low-level elements and do greenlight deployment through Veracode.
It helps us manage our licensing and security risks. However, we are in the implementation process right now. So far, it's okay and working fine.
It's good that we can do a full code scan, front to back, or vice versa.
We mostly use the policy scan and vulnerability scan mostly.
The security is okay.
What needs improvement?
The reporting can be difficult. It's not very easy.
It's taking too much time to do a quality scan. It hasn't saved us much time. Deployment was three or four months ago. We did a policy scan using a greenlight deployment. When we do the deployment in Jenkins, we can do it faster. In Veracode, it can take four hours or even eight hours.
We don't like how long it takes to do a deployment. It should deploy more quickly.
For how long have I used the solution?
I've used the solution for a year.
What do I think about the stability of the solution?
While there is no lagging or crashing, it takes too much time to deploy.
What do I think about the scalability of the solution?
We haven't had any issues with scalability. That said, currently we are not scaling. Previously it was fine. Currently, we're not scaling.
How are customer service and support?
Currently, we do not use support. We don't communicate with them.
Which solution did I use previously and why did I switch?
We have used SAP and Jenkins in the past.
How was the initial setup?
The deployment takes too long.
I was not directly involved in the deployment of Veracode. I generally use Jenkins only.
Two people are typically involved in the deployment.
Every week, on Friday, we put the servers down, and every Monday, we put them back up, to save on costs.
What about the implementation team?
The deployment is automated using Jenkins. We just need some parameters to deploy the code to the environment.
What's my experience with pricing, setup cost, and licensing?
The pricing is worth it. However, users need to go through the documentation first to get a handle on the implementation. Users might need the help of a support platform.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this solution.
What other advice do I have?
I'm not sure how much visibility we are getting using the solution.
The false positive rate we haven't really looked into. We need to learn more about it.
We are just end users, not partners.
I'd rate the solution eight out of ten.
It's a good idea to look at the documentation. Be very cautious when implementing servers.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Container Security Software Composition Analysis (SCA) Static Code Analysis Dynamic Application Security Testing (DAST) Application Security Posture Management (ASPM)Popular Comparisons
SonarQube
Snyk
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Checkmarx One
Prisma Cloud by Palo Alto Networks
Check Point Cloud Firewall (formerly CloudGuard Network Security)
GitLab
Qualys Exposure Management
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
FortiCNAPP
PortSwigger Burp Suite Professional
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Which gives you more for your money - SonarQube or Veracode?
- Checkmarx or Veracode. Which should we choose?
- Would you recommend Veracode? What are some of your use cases?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- What do I scan when changing code in Veracode?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?






















