I helped customers to build and start the journey of SecOps with Veracode.
Sales Engineer at a computer software company with 51-200 employees
Low false positive rate, good reports, and fair price
Pros and Cons
- "It is scalable and quick to deploy into the site and the pipelines. The reports and analytics are good, and the false positive rate is low. It gives true results."
- "There should be more APIs, especially in SCA, to get some results or automate some things."
What is our primary use case?
How has it helped my organization?
Veracode helps to know and prevent vulnerable code or applications from being deployed. We can scan, consume reports, and fix vulnerabilities before deploying an application.
It is very good for ensuring compliance with industry standards and regulations. We can have many dashboards and reports related to policy management.
Veracode provides visibility into application status at every phase of development. We can have many analytics dashboards and reports, and we can build a custom dashboard to have this visibility. This visibility is essential for DevSecOps processes. We need this visibility and information to have a strategic approach and mature our security.
Veracode has the lowest false positive rate in the market. Its results are accurate. In some cases, it is very difficult to see a false positive. We report it to the engineers, and they analyze it. If it is truly a false positive, the engineers will update the engine to provide better results at the next scan. The false positive rate of the static analysis has not affected the time we spend on tuning policies.
It has had a very good effect on our organization’s ability to fix flaws. We are developing a new feature, and Veracode will help to quickly fix any flaws.
It has helped our developers save time, but I do not have the metrics.
What is most valuable?
All features are valuable. I especially like SAST and ADO.
It is scalable and quick to deploy into the site and the pipelines. The reports and analytics are good, and the false positive rate is low. It gives true results.
What needs improvement?
There should be more APIs, especially in SCA, to get some results or automate some things.
Buyer's Guide
Veracode
March 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
886,426 professionals have used our research since 2012.
For how long have I used the solution?
I have been using this solution for almost three years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is very scalable. I help other companies to deploy. Some of them are small, and some of them are big.
How are customer service and support?
Their support is good. I would rate them a nine out of ten.
Which solution did I use previously and why did I switch?
I have not used any other solution previously. I have only worked with Veracode.
How was the initial setup?
It is a SaaS solution. Its initial setup is straightforward. I started with the most critical applications and automated the scanners inside the pipeline. After getting the results, I aligned the security policies. I prioritized the most critical vulnerabilities and assigned these reports to different groups and teams. I also integrated the other plugins into the IDE.
What about the implementation team?
I implemented it myself. I work with DevOps and security teams. In some cases, I also work with developers.
It does not require any maintenance. Because it is a SaaS solution, the maintenance is provided by them.
What was our ROI?
The ROI is in terms of time savings and mature security. When you deploy a solution like Veracode, you can have these quickly.
It reduces the cost of DevSecOps for the organization when you use it for more than one year.
What's my experience with pricing, setup cost, and licensing?
Its pricing is fair.
What other advice do I have?
It is essential and perfect for preventing vulnerable code from going into production. Nowadays, it is very important and sensible to have a solution like Veracode to know all the vulnerabilities and manage and prioritize the ones that are more critical and better for security posture.
I have not used the Software Bill of Materials (SBOM) feature much, but it is easy to create a report using the SBOM feature. It is important for the supply chain that your software uses.
I would rate Veracode a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Senior Manager Cyber Security at a tech services company with 201-500 employees
Identifies false positives, prevents vulnerable code from being introduced into production, and provides static scanning
Pros and Cons
- "Static Scanning is the most valuable feature of Veracode."
- "Veracode can be improved in terms of software composition analysis and related vulnerabilities."
What is our primary use case?
We scan various types of software codes, such as codes or applications built in languages like C, Java, Python, PHP, and Ruby, among others. We assess the code quality using Veracode.
How has it helped my organization?
Veracode prevents 90 percent of vulnerable code from being introduced into production.
Previously, in our organization, we did not have a dedicated workflow or a tool for capturing code vulnerabilities. After the code passed the testing phase, it was directly implemented in production. However, since implementing Veracode and launching it, we have been able to identify vulnerabilities beforehand. As a result, our code now goes into production without any vulnerabilities. Only after ensuring this, do we allow it to go live.
Veracode provides visibility into application status at every phase of development.
Based on our experience, Veracode quickly and effectively identifies false positives.
Our project teams understand the importance of conducting code scanning in addition to code development and Veracode testing. This ensures that any flow issues are addressed before proceeding to the next phase. It has become ingrained in their approach.
Veracode has helped our developers save time by assisting in fixing the vulnerabilities that could have had disastrous effects if they had gone into production.
Veracode has had a tremendous impact on our security posture, particularly in one region in Asia where Veracode is being used for security testing and vulnerability assessment. Now, other regions, including the US, have also recognized its value and started adopting Veracode.
What is most valuable?
Static Scanning is the most valuable feature of Veracode.
What needs improvement?
Veracode's policy reporting, which ensures compliance with industry standards and regulations, is valuable. It would also be helpful to have a specific example that we can relate to in order to better understand it. Currently, the information is scattered, so precision would greatly assist us.
Veracode can be improved in terms of software composition analysis and related vulnerabilities. For instance, when an application team provides us with their software code, we perform code scanning. During this process, we often encounter software composition analysis vulnerabilities that require the application team to upgrade their Java file from version X to version Y. We then communicate this to the application team, and they proceed with the upgrade. Once the upgrade is complete, we conduct a rescan. However, during the rescan, Veracode may identify compatibility issues with the upgraded version Y. This situation puts the application team in a difficult position, as they may be unable to accommodate this change within their project schedule. Therefore, this is an area where I believe Veracode could make improvements.
The technical consultation can be enhanced to effectively address the communication variations among different regions.
For how long have I used the solution?
I have been using Veracode for three years.
What do I think about the stability of the solution?
Veracode is 100 percent stable.
What do I think about the scalability of the solution?
Veracode can scale to meet our maximum requirements.
How are customer service and support?
There are cultural differences in the way we communicate with people from different countries. So, when a Japanese person is talking to an American, the rapid conversation provided by the American technical support person may not be easily understood by the Japanese individual. As a result, instead of having just one discussion or consultation with Veracode, we end up having three to four consultations.
How would you rate customer service and support?
Neutral
What other advice do I have?
I give Veracode a ten out of ten.
We are using Veracode in multiple locations and departments.
Veracode does not require any maintenance.
Veracode is an extremely user-friendly tool, operating through a web interface. Additionally, the support and guidance offered by the Veracode team are excellent. Considering all of these factors, I believe Veracode should be the choice for anyone.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Veracode
March 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
886,426 professionals have used our research since 2012.
Senior Director at a tech vendor with 10,001+ employees
The solution's static analysis has streamlined our DevSecOps process, which previously involved a lot of manual work
Pros and Cons
- "Veracode enables us to build a strong data security layer in our platforms. We can increase customer confidence in data security. Some PCI/HIPAA compliance issues were impossible to resolve without Veracode."
- "Veracode's ease of use could be improved. I would also like to see more online videos and tutorials that could help us understand the product better. It would also be helpful if Veracode created a certification program for DevSecOps staff to learn about their product and get certified. This kind of training would raise the company's profile within the industry."
What is our primary use case?
We use Veracode to scan our products for code security. Our company also uses Veracode's data security module.
How has it helped my organization?
Veracode enables us to build a strong data security layer in our platforms. We can increase customer confidence in data security. Some PCI/HIPAA compliance issues were impossible to resolve without Veracode. I rate Veracode's compliance features a nine out of ten because it provides detailed reports after each scan about potential regulatory violations.
The solution's static analysis streamlined our DevSecOps process, which previously involved a lot of manual work to trace code vulnerabilities. Veracode reduced our DevSecOps team's time on these tasks by around 20 to 30 percent while drastically improving code quality.
In the past, we also performed a scan using third-party vendor partners that took days to complete. Veracode conducts a quick dynamic scan each time a new iteration of code is built and deployed into the environment. It gives us an immediate result. We can deploy our products much faster, and there are no delays or surprises after the product is built. We aren't wasting time from development to deployment.
Our overall security posture improved, but we've only been using Veracode in production for less than two months. We expect a massive improvement in the next six to eight months.
The false positive rate is typically less than five percent. False positives can affect how developers use a solution. If we see too many false positives, we might start ignoring alerts. Sometimes the developers lose confidence and may take the work lightly. It isn't an issue currently because the rate is under five percent.
What is most valuable?
Dynamic scanning is the most useful feature.
What needs improvement?
Veracode's ease of use could be improved. I would also like to see more online videos and tutorials that could help us understand the product better. It would also be helpful if Veracode created a certification program for DevSecOps staff to learn about their product and get certified. This kind of training would raise the company's profile within the industry.
For how long have I used the solution?
We have used Veracode for about three months. We did a proof of concept for one month, and it has been in production for two.
What do I think about the stability of the solution?
I rate Veracode a ten out of ten for stability. We haven't had any issues.
What do I think about the scalability of the solution?
Veracode is scalable, but we haven't scaled it up. However, I expect it will work well when we do.
How are customer service and support?
I rate Veracode support a nine out of ten. Their support system is excellent and highly engaged.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We tried some Indian solutions and used third-party scans for static analysis, but Veracode is the first time we have fully integrated an enterprise code security solution.
How was the initial setup?
Veracode is a SaaS solution. Setting it up isn't simple, but it isn't too complex. We deployed Veracode with a three-person in-house team. Veracode requires a decent amount of maintenance. You must perform periodic validation checks on how the engine is performing.
What was our ROI?
You have to compare the price to the potential cost of data security threats, which could devastate your reputation and revenue overall. We do not doubt that the investment is worth it. It's too early to calculate an ROI, but we anticipate a reduction in overall DevSecOps costs.
What's my experience with pricing, setup cost, and licensing?
Veracode is priced competitively for our market.
Which other solutions did I evaluate?
We evaluated a few other vendor partners and decided to go with Veracode because of the various features they offered.
What other advice do I have?
I rate Veracode a nine out of ten. If you plan to implement Veracode, your DevSecOps should adopt modularized-based code segregation for better visibility into how this ecosystem works. It's crucial to be clear about the solutions you are procuring. There are multiple options, and not everything will work for you. Understanding your requirements, what your customer needs, and what will work best for your product is essential. Purchase the solution most suitable for your product and your company.
You should also maximize Veracode's benefit by working closely with the tech support team. We don't use many of the features we have procured. Setting up an ongoing review mechanism with Veracode technical support is critical to better understand the product and ensure you get the maximum return for your investment. These are some points that company leaders need to discuss with their DevSecOps and DevOps teams.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Engineer at a tech vendor with 10,001+ employees
Secures our apps with accurate vulnerability detection in a straightforward, efficient solution
Pros and Cons
- "I like the sandbox, the ability to upload compiled code, and how easy it is."
- "The sandbox could use some improvement; when creating a sandbox, it requires us to put the application name in twice, which seems unnecessary."
What is our primary use case?
Our primary use cases are uploading and assigning scans, uploading compiled codes into the sandboxes, and searching marks to determine whether scans have been completed.
We have multiple locations, teams, and endpoints; we're a worldwide telecommunications company with over 2000 internal and external apps. Some apps communicate from the outside to the inside, but every app goes through Veracode.
How has it helped my organization?
We have to scan about 2000 apps, and we're already at 366 scanned within the year's first two months. Additionally, the company has been using Veracode for years; both are testaments to the solution's efficiency.
The platform provides visibility into application status at every phase of the development- Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Testing throughout our SDLC. In terms of DevSecOps processes, the solution makes them quicker and smoother, with less confusion.
Veracode positively affects our organization's ability to fix flaws; we have a particular app at the moment that failed the scan twice due to its vulnerabilities. Without the solution, we likely wouldn't get that.
The solution has positively affected our organization's overall security posture and will continue to improve it.
What is most valuable?
I like the sandbox, the ability to upload compiled code, and how easy it is.
It's also straightforward to find scans we've uploaded.
The solution's ability to prevent vulnerable code from going into production is incredible. I have done several consultations and remediation calls with the app team, and Veracode catches almost everything. It picks up the same issues in everything we scan, and we've done a lot of retests that way; the tool is very proficient in this area.
Veracode helps our developers save time; it's a straightforward product that shows us the vulnerabilities and allows us to relay them back to the developers. This is faster and more efficient than staff going through the code manually. The solution is like having a proofreading app for our code rather than using a proofreader.
What needs improvement?
The sandbox could use some improvement; when creating a sandbox, it requires us to put the application name in twice, which seems unnecessary.
For how long have I used the solution?
We've been using the solution for a month and a half.
What do I think about the stability of the solution?
Veracode is very stable; unlike many programs and apps, I've never had a problem with it.
What do I think about the scalability of the solution?
The solution is scalable; we're a global telecom company, and we use it to scan every one of our over 2000 apps.
How are customer service and support?
The technical support is excellent.
How would you rate customer service and support?
Positive
What's my experience with pricing, setup cost, and licensing?
I'm unfamiliar with the solution's pricing, but it must be worth the cost from a company perspective, as we have been using it for years and have no plans to move away from it.
Which other solutions did I evaluate?
The product was in place long before I arrived at the company, so I don't know if they evaluated other options.
What other advice do I have?
I rate the solution 10 out of 10.
I recommend Veracode to any company looking for this type of platform. Though I need to become more familiar with competitor products, I like going into programs and clicking around. Even if I don't initially understand something within Veracode, I can keep going and make sense of it. I updated my resume to include my new experience with the solution.
Veracode reduced the cost of DevSecOps for our organization; we upload a scan, run the test, get the vulnerabilities, and set up a remediation meeting. This makes communication more manageable, and the information is more visible, as all our staff can access the scan results. In several instances, we've consulted with employees from the Veracode side, and they've been very helpful in walking our app team and testers through whatever vulnerabilities we've had issues with.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior software engineer at a tech services company with 1,001-5,000 employees
Provides visibility concerning security issues, is scalable, and no maintenance is required
Pros and Cons
- "The most valuable feature is the static scan that checks for security issues."
- "The zip file scanning has room for improvement."
What is our primary use case?
We use the solution to scan for and identify vulnerabilities or security issues.
We use a SaaS deployment.
How has it helped my organization?
Before releases, we must ensure that all the security issues identified by Veracode are addressed. Occasionally, some false positives may be encountered, but these can be safely ignored. We are usually satisfied with the accuracy of the report as all the important security issues are identified and addressed allowing us to focus on our release sooner.
All the applications that are going to production in our large company are required to pass through Veracode, which provides us with a uniform standard that everyone must adhere to. This standard allows us to ensure the quality of our products before they go to market.
Veracode may not seem to immediately save our developers time, and it may even seem tedious at times. Ultimately, however, it can be extremely useful in identifying issues and vulnerabilities before they become larger problems, making it a valuable resource.
Veracode helped our security posture by checking security gaps in the production environment.
What is most valuable?
The most valuable feature is the static scan that checks for security issues. We use Veracode for this purpose; we also use the solution for our UI, but for the backend, we only use the static scan. I'm not sure what it is called, but it is one of two scans, the other one being dynamic. We only use the static scan to identify any security issues.
Veracode assists in the prevention of vulnerable code from reaching production by providing a comprehensive review of security risks and comprehensive reports with thorough descriptions of the vulnerabilities. This allows us to address any security gaps in the release. Based on the severity, we should determine the standards for release. We should not have any security issues with a severity of medium or higher before releasing.
Veracode provides us with ultimate visibility concerning security issues. Additionally, we use OWASP, which checks our dependencies to identify any potential weaknesses, but Veracode is the only tool we use to check our source code. With Veracode, we have the capability to recognize any security issues in our source code.
What needs improvement?
The false positives have room for improvement. Sometimes, we will get false positives, which we mark as mitigated. However, it can be annoying when they come up again in the next release. Every time a new person is doing the work, they may not be aware of the history of the issue. They must then check the false positive again and mark it as mitigated, and it may come up again in the future. False positives can be an irritating and time-consuming issue for developers to deal with. Investigating them can be a waste of time, as they have already been looked into. This can be frustrating for those involved. False positives waste our time and resources.
The zip file scanning has room for improvement. Sometimes when we upload the zip files for scanning, it can take a long time to get the report. This can take up to a day. Unfortunately, even after waiting a day, sometimes we find that nothing happened and we have to start the process over. This is both time-consuming and frustrating, as we feel the system has crashed.
The reports have room for improvement. I believe the reports are thorough but can become overwhelming with unnecessary information that may not be pertinent to the developer. I'd prefer to have customizable reports that allow us to select which elements we'd like to include.
I believe the usability of the UI needs to be improved. For example, when we navigate away from a page, it should remember our last location and take us back there instead of sending us to the homepage. Additionally, it should be easier to navigate between pages without having to refresh the page each time.
Veracode should provide potential customers with better training materials and resources to help them make a more informed decision before purchasing the product. This could include tutorials, demonstrations, more about how the product works, the user interface, the quality of Veracode's reports, and more. It is unclear if these resources are already available, but they should be made more visible if so.
For how long have I used the solution?
I have been using the solution for over one year.
What do I think about the stability of the solution?
The report is usually ready without any problems, but occasionally there may be a crash or other issue occurring in the background that prevents it from being ready. This happens about 10% of the time. The solution is primarily stable.
What do I think about the scalability of the solution?
I haven't experienced any scalability issues so far. This is likely because the job is always the same and the files we upload remain the same. We haven't had to change any parameters in the input, so scalability hasn't been a concern.
Which solution did I use previously and why did I switch?
We used CodeSonar to analyze various aspects of our source code, and we already utilize OWASP to assess the security risks of our dependencies.
What other advice do I have?
I give the solution an eight out of ten.
One of the applications we supported through Veracode is designed for use by travelers of an airline. The application handles everything from searching for availability to obtaining tickets.
The solution does not require any maintenance. I am logging into my organization's portal, from which I have a direct link to access Veracode. I do not need to do anything else, such as create content or install anything.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VP of Product at a healthcare company with 51-200 employees
Useful scanning, highly scalable, and quick setup
Pros and Cons
- "The most valuable feature of Veracode Static Analysis is the scanning."
- "Veracode Static Analysis can improve the false positive. There are always improvements that can be done to the false positive rate. There are some things that get flagged that are not an issue. However, it is not a huge concern."
What is our primary use case?
We use Veracode Static Analysis in the IDE for our engineers to be able to catch security issues while they're coding. Additionally, we use it for the Veracode verified program to show that we're scanning and compliant, and we get the third-party seal of approval.
It's a scanning security, static analysis code scanning software.
How has it helped my organization?
Veracode Static Analysis has benefited our company because we are catching potential security issues earlier in the pipeline. Before anything goes to human code review, Veracode Static Analysis catches issues as the engineer is working in their IDE.
What is most valuable?
The most valuable feature of Veracode Static Analysis is the scanning.
What needs improvement?
Veracode Static Analysis can improve the false positive. There are always improvements that can be done to the false positive rate. There are some things that get flagged that are not an issue. However, it is not a huge concern.
For how long have I used the solution?
I have been using Veracode Static Analysis for approximately 18 months.
What do I think about the stability of the solution?
Veracode Static Analysis is stable.
What do I think about the scalability of the solution?
We have got 5 million lines of code and it hasn't choked at all but seems to run just fine.
We have approximately 40 users and most of those are frontline engineers. Additionally, we have security officers who use it to run reports and team leads that use it for training. We plan to increase our usage when we have new deployments.
I rate the scalability of Veracode Static Analysis a ten out of ten.
How are customer service and support?
I have not used the support from Veracode Static Analysis.
Which solution did I use previously and why did I switch?
We used HCL AppScan prior to Veracode Static Analysis.
How was the initial setup?
The deployment can be done in approximately 10 minutes. We use Bitbucket Pipelines and Veracode Static Analysis is integrated into our deployment pipelines.
I rate the initial setup of Veracode Static Analysis an eight out of ten.
What about the implementation team?
We did the deployment of the solution in-house. We typically can do the deployments with one person.
What was our ROI?
I cannot say we have had a return on investment because we haven't had any security incidents, but we didn't have any before using Veracode Static Analysis either.
What's my experience with pricing, setup cost, and licensing?
The price of Veracode Static Analysis is expensive. There is an annual fee to use the solution and the company is upfront with the pricing model and fees.
I rate the price of Veracode Static Analysis a three out of ten.
Which other solutions did I evaluate?
We evaluated Checkmarx and Synopsys before choosing Veracode Static Analysis.
What other advice do I have?
My advice to others is if they use Veracode Static Analysis they are using a very solid solution. You get what you pay for. It's an expensive solution, but it's very good. You're going to save a lot of time and a lot of headaches with fewer false positives, but you're going to pay for it. It's good if you want to automate something into your pipeline and it's going to run fast and give you good results. I would choose Veracode Static Analysis, but be cognizant of the cost.
I rate Veracode Static Analysis an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Software Engineer at a tech vendor with 11-50 employees
Integrates with our CI/CD pipeline and automatically scans our code when we do the build
Pros and Cons
- "I like Veracode's integration with our CI/CD. It automatically scans our code when we do the build. It can also detect any security flaws in our third-party libraries. Veracode is good at pinpointing the sections of code that have vulnerabilities."
- "We are testing Veracode's software composition analysis, but we're having trouble integrating it with SVN. It works out of the box when you use Git but doesn't work as well with other tools like SVN. It's more geared toward Git"
What is our primary use case?
We are a relatively young company that started about a decade ago. The company adopted Veracode about five years ago because it's a market leader in that segment.
Veracode checks for security flaws in our code. We provide software for companies in the financial sector, so it's critical that we use Veracode. There are some lesser-known competitors, but Veracode is the biggest player in security software. In a way, it's good marketing to use Veracode.
We are running it locally, but we plan to move to the cloud in the next few months. We're a small company with 20 employees. Our development team deals primarily with it, and some other support guys are involved occasionally.
How has it helped my organization?
We have been using Veracode for several years. It has become a crucial tool for preventing security flaws in our applications. The quality of our software has improved significantly since we started using Veracode. We have a software development shop and also provide solutions for other companies. It's critical to have our software checked by Veracode.
Our code must be free of security flaws, especially high-level ones. Our software must be above a minimum threshold. Veracode has enabled us to see the quality of our code security. We need at least an 80 percent score. We are sure that our code is high-quality and that our clients won't see security vulnerabilities in the code when we ship it to them.
Veracode covers every phase of development. We mainly use it for static analysis and recently started using it for software composition analysis.
The false positive rate is around 10 percent, which is expected in automated software. Veracode's competitors have false positives, but we're happy with Veracode's ability to mitigate the problem. We check every false positive and clear it. It does not affect our competence at all. We realize it will happen from time to time. The effect of false positives is negligible. We don't have a problem with that. We are experienced enough now to see what is or isn't.
What is most valuable?
I like Veracode's integration with our CI/CD. It automatically scans our code when we do the build. It can also detect any security flaws in our third-party libraries. Veracode is good at pinpointing the sections of code that have vulnerabilities.
What needs improvement?
We are testing Veracode's software composition analysis, but we're having trouble integrating it with SVN. It works out of the box when you use Git but doesn't work as well with other tools like SVN. It's more geared toward Git.
For how long have I used the solution?
I have been using Veracode for two years in my current role.
What do I think about the stability of the solution?
Veracode's stability is decent. That was only one instance where it identified a security flaw but didn't detect it afterward. Otherwise, it's mostly consistent.
What do I think about the scalability of the solution?
We use it on a couple of different projects, and we plan to move to the cloud. They have a cloud option that makes it scalable.
How are customer service and support?
I rate Veracode support nine out of 10 in its current state, but given our problems in the past, I might rate it seven overall. We had some problems when I joined. They put in a lot of effort, but it took them a couple of months to get it right. They did their best to resolve it, so I appreciate that, but we weren't happy it took so long.
How would you rate customer service and support?
Positive
What was our ROI?
We don't see a direct return from using Veracode, but it ensures we deliver a product without security faults. It has also reduced our development costs, but it's difficult to quantify that. By having the code tested before we ship it to clients, we ensure our clients don't have issues with the security of our software.
What's my experience with pricing, setup cost, and licensing?
The price is reasonable and affordable for a small company like ours. Veracode provides a lot of features. You can purchase some additional tools. For example, we are currently testing software composition analysis. We discussed adding that to our standard package.
What other advice do I have?
I rate Veracode eight out of 10. I recommend first testing it on your code to see if it's appropriate. You need to see how long it takes to scan the code.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Director, Quality Engineering at Everbridge
Easy issue tracking and high visibility
Pros and Cons
- "Veracode's technical support is great. They assigned us a TAM and once a week, we have a brief engagement with the TAM to verify that everything's going well. If we have any outstanding issues, they get serviced and addressed."
- "All of the Veracode applications operate as one platform, and with Veracode, you get a single pane of glass and reporting that you can combine with the different scan types to look at compliance."
- "I think if they could improve the operations around accepted vulnerabilities, we would see improvements in our productivity."
- "I think the biggest room for improvement is around known or accepted vulnerabilities that, when we re-scan, we want those things to be recognized as already accepted, as an exception."
What is our primary use case?
Our primary use case for Veracode is SAST and SCA in our SDLC pipelines. We also use it for DAST on a periodic basis and time-based scans on our staging system. We use the trading modules for certifying all our developers annually.
In addition, we use Veracode to scan within our build's pipeline. We do use Greenlight, which is their IDE solution for prevention of issues of vulnerabilities.
We are FedRAMP certified as a company, so we use this as part of our certification process for Veracode ISO 27001 and various other certifications we have.
How has it helped my organization?
There is a tight integration of Veracode with JIRA. We use JIRA for nearly all of our issue tracking.
This integration provides a way to link all of the vulnerabilities discovered to our backlogs and active scrum queues, so that there's high visibility within teams for any of the issues that are related to their teams.
What is most valuable?
I think the most valuable to us is the policy management, which enables us to create different kinds of policies for different kinds of applications. Veracode policy management also allows us to plan for, track against, and report on our compliance with those different policies.
What needs improvement?
I think the biggest room for improvement is around known or accepted vulnerabilities that, when we re-scan, we want those things to be recognized as already accepted, as an exception. Sometimes they show up as something new and we have to go back and re-accept that as an accepted exception in order to bring our numbers back into compliance. I think if they could improve the operations around accepted vulnerabilities, we would see improvements in our productivity.
I would also like to see more executive reporting. Having a good snapshot of how well we're tracking, where each of the teams that own the applications, how they're doing, and where their gaps are would be good. Currently, the reporting is geared towards tracking current vulnerabilities. Even though they have trending, the trending doesn't necessarily evaluate the teams and how well they're doing. I would also like to be more oriented towards teams.
Overall, I would give Veracode a nine out of 10.
For how long have I used the solution?
The company's been using Veracode for five years. I've been using it for four years.
What do I think about the stability of the solution?
Veracode is stable in my opinion. We've had very little interruption that was unplanned.
What do I think about the scalability of the solution?
We have not run into an issue with scalability yet. Veracode was built based on application counts and not users, which is what a lot of the competitors do.
We have some 300 people using Veracode. Some are executives while others are engineers actively working in Veracode.
How are customer service and support?
Veracode's technical support is great. They assigned us a TAM and once a week, we have a brief engagement with the TAM to verify that everything's going well. If we have any outstanding issues, they get serviced and addressed.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Veracode the entire time I have been with this organization. However, I know that they used Coverity and WhiteSource prior to switching to Veracode. The main reason my organization chose Veracode is its comprehensive dashboard.
How was the initial setup?
Our deployment took a while so I would say the initial setup was moderately complicated. We gradually moved into the pattern we are in today and displaced some other vendors along the way. So it was a slow ramp for us because of our business needs.
We were up and running and operational within a couple of months. And then, over time, we broadened our footprint with Veracode.
What about the implementation team?
We deployed Veracode in-house.
What was our ROI?
Our biggest return on investment is maintaining certifications that enable us to attract customers of larger scale and government-sensitive customers.
Going back to the cost structure, I think that the way Veracode is priced and their comparison to third parties, I still put them at four out of five.
What's my experience with pricing, setup cost, and licensing?
Veracode recently introduced some pricing based on microservices. This model gives us a lot of flexibility in being able to add and remove microservices and scale them that way.
The pricing is solid. I think with the current consolidated pricing that we have is pretty consistent every year.
What other advice do I have?
All of the Veracode applications operate as one platform. Most of the competitors out there separate their products from their reporting and configuration, so you don't get a single pane of glass. With Veracode, you get a single pane of glass and reporting that you can combine with the different scan types to look at compliance.
The advice I would give regarding this solution is this: Look at the policies, the dashboards, and integration with ALM applications like Veracode and JIRA. They have a tighter integration there that I see with most of the competitors.
I'm sure that the scan quality is consistent. Perhaps there's some applications that are a little better than others at detection. But we find that Veracode is very comparative to other things you solutions the quality of catching vulnerabilities.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Container Security Software Composition Analysis (SCA) Static Code Analysis Dynamic Application Security Testing (DAST) Application Security Posture Management (ASPM)Popular Comparisons
SonarQube
Snyk
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Checkmarx One
GitLab
CrowdStrike Falcon Cloud Security
Orca Security
JFrog Xray
Coverity Static
Black Duck SCA
Acunetix
Mend.io
GitHub Advanced Security
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Which gives you more for your money - SonarQube or Veracode?
- Checkmarx or Veracode. Which should we choose?
- Would you recommend Veracode? What are some of your use cases?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- What do I scan when changing code in Veracode?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?



















