Try our new research platform with insights from 80,000+ expert users
reviewer1345386 - PeerSpot reviewer
Senior Software Developer at a pharma/biotech company with 201-500 employees
Real User
Leaderboard
A robust and full-featured solution that provides a good analysis of the vulnerabilities
Pros and Cons
  • "The analysis of the vulnerabilities and the results are the most valuable features."
  • "It can have more APIs and capabilities to handle other things well. We were doing a trial for it. There were two things that I looked at: one was uploading some Java-related content and the other was uploading database SQL files and having the review done on the quarterback. The Java portion of it worked fine, and it was pretty seamless, but the database portion was not. We uploaded some files to use for vulnerabilities, and the tell-all portion of it was pretty easy. We uploaded a war file and Java files, and we got the reports back on these. They were pretty clear to understand. We did the same thing for the database portion for the most part. However, the content wasn't getting uploaded in a predictable fashion, and it was slow and hard to get done. We had to do it over and over. After it indicated that the content was uploaded, there were no results. There were zero search findings. It was possibly a user error, something that we didn't do correctly, but they had acknowledged that it was something they were currently enhancing. This is something that could be made easier if they haven't already done that. I don't know how many releases they've had in that timeframe. I haven't looked at it since then. It was a trial period."

What is our primary use case?

We used it for initial discovery and analysis and for reviewing the product. We were doing a trial. We had uploaded code on the Veracode server for analysis.

We used the cloud service or the cloud website where you could interact and identify the artifacts that you wanted to be reviewed, analyzed, and reported on. There was a plugin that we used with some of our IDs. It probably was Greenlight.

How has it helped my organization?

It pointed out some areas to be improved that we were not aware of. That was very helpful because if you don't know that there is a problem, you can't fix it.

What is most valuable?

The analysis of the vulnerabilities and the results are the most valuable features.

What needs improvement?

It can have more APIs and capabilities to handle other things well. We were doing a trial for it. There were two things that I looked at: one was uploading some Java-related content and the other was uploading database SQL files and having the review done on the quarterback. 

The Java portion of it worked fine, and it was pretty seamless, but the database portion was not. We uploaded some files to use for vulnerabilities, and the tell-all portion of it was pretty easy. We uploaded a war file and Java files, and we got the reports back on these. They were pretty clear to understand. We did the same thing for the database portion for the most part. However, the content wasn't getting uploaded in a predictable fashion, and it was slow and hard to get done. We had to do it over and over. After it indicated that the content was uploaded, there were no results. There were zero search findings. It was possibly a user error, something that we didn't do correctly, but they had acknowledged that it was something they were currently enhancing. This is something that could be made easier if they haven't already done that. I don't know how many releases they've had in that timeframe. I haven't looked at it since then. It was a trial period.

Buyer's Guide
Veracode
January 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,340 professionals have used our research since 2012.

What do I think about the stability of the solution?

It seemed fairly stable other than the database portion where the SQL files didn't seem to get uploaded.

What do I think about the scalability of the solution?

I didn't think there would be any concerns. We didn't exercise that. We didn't, in other words, try to upload gazillion artifacts and files. We just uploaded a few just to see how they handle it. It seemed fairly robust.

There were about ten Java and database developers who were using this solution. We were all collectively reviewing it and getting feedback on it.

How are customer service and support?

We didn't use their technical support.

Which solution did I use previously and why did I switch?

There was no other solution.

How was the initial setup?

I wasn't that involved in the setup. I was basically a reviewer after it was all done.

What about the implementation team?

I don't think there was any in-house work. I think it was just all on their server. We didn't have any equipment or any software per se other than just downloading a plugin or IDE, which essentially did the same sort of code analysis.

What's my experience with pricing, setup cost, and licensing?

Its cost for what we needed it for was too high. It wasn't too high for other companies and it was competitively priced, but for us, it just didn't fit. We did plan to use it and increase the usage. In the end, it may have been abandoned because of the cost, but I'm not a hundred percent sure. So, even though we had planned on using it more and more, because of the cost and the business conditions of things, we didn't have the opportunity to really use it more.

Which other solutions did I evaluate?

There were a few other solutions we had looked at, but they didn't seem to be as robust. They also didn't have good reviews. That's why we chose this solution.

What other advice do I have?

It is a robust software service for security analysis. It seemed to be pretty full-featured. We didn't exercise every single thing. Just a few of the features didn't seem to be up to snuff for our needs.

I would rate Veracode Manual Penetration Testing an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user673734 - PeerSpot reviewer
Chief Technology Officer at a tech vendor with 201-500 employees
Real User
Increases our confidence in the security of our sever-side and mobile apps
Pros and Cons
  • "It has an easy-to-use interface."
  • "We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time."

What is our primary use case?

We use it for security scanning of SaaS and mobile software that we develop: one server-side and two mobile applications. Most customers require SAST and DAST scanning in order to purchase.

How has it helped my organization?

It gives us more confidence in the application security of the products we scan. We use it as part of our AppSec best practices. 

What is most valuable?

It has an easy-to-use interface.

What needs improvement?

We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time.

What do I think about the stability of the solution?

We have never had any problems with the solution.

What do I think about the scalability of the solution?

It has always worked for us, we haven't found any issues. There have been no problems with scanning small and large objects.

How are customer service and technical support?

Technical support is excellent. It meets our needs.

Which solution did I use previously and why did I switch?

We had no previous solution. Our choice of Veracode was due to Veracode being a customer and requiring that we use their tool to scan our solution.

How was the initial setup?

The initial setup was straightforward. As it's a SaaS solution, it took no time to set up. But because I didn't take training, I spent a bit of time figuring out the product. No implementation (or strategy for implementation) was required, beyond some simple configuration settings.

What's my experience with pricing, setup cost, and licensing?

No issues, the pricing seems reasonable.

Which other solutions did I evaluate?

We evaluated no other products for SAST when we started using Veracode. 

What other advice do I have?

Be aware that the first run will find a lot of issues, many of which are not real issues; it will take time to understand that. Don't change object names as that will confuse it. Make sure you get development buy-in early.

We're looking to expand its use within the development organization and are looking into another license. Currently, we have four users of the solution, myself (security) and developers. The four of us also maintain it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Veracode
January 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,340 professionals have used our research since 2012.
it_user877104 - PeerSpot reviewer
VP Worldwide Delivery Acceleration at a financial services firm
Real User
Improved our security posture without the overhead of supporting infrastructure
Pros and Cons
  • "Because it is a SaaS offering, I do not have to support the infrastructure."
  • "Some important languages are not supported."
  • "We have encountered occasional issues with scalability."

What is our primary use case?

SAST vulnerability scanning. Veracode is embedded in our release pipeline.

How has it helped my organization?

It improved our security posture. In terms of cost savings relating to code fixes since implementing Veracode, I'm not sure there are any. How do you quantify reputational damage from a security breach? However, they have provided AppSec best practices and guidance to our security and development teams through our support agreement, weekly meetings, and annual review.

What is most valuable?

Because it is a SaaS offering, I do not have to support the infrastructure.

What needs improvement?

Some important languages are not supported.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

We have encountered occasional issues with scalability.

How is customer service and technical support?

Tech support is excellent.

How was the initial setup?

The initial setup was extremely straightforward.

What's my experience with pricing, setup cost, and licensing?

Negotiate for the best deal.

Which other solutions did I evaluate?

Fortify, App Scanner, Checkmarx.

What other advice do I have?

Make sure the supported  languages align with your developers.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user797976 - PeerSpot reviewer
Global Application Security at a pharma/biotech company with 10,001+ employees
Video Review
Real User
Its has the ability to scale and not produce a lot of false positives
Pros and Cons
  • "It has the ability to scale, and the fact that it doesn't produce a lot of false positives."
  • "It does nearly everything, but penetration testing."

How has it helped my organization?

Scalability and its optimization of security inspections. At the end of the day, I like the fact that it is all prim. It does not require a lot of support on our side. We get the benefit of security inspections and it scales with our community, which is global. 

What is most valuable?

It has the ability to scale, and the fact that it doesn't produce a lot of false positives.

What needs improvement?

Number one, I need analytics, analytics, and more analytics. It is all about risk based management and better decision support, that is why. 

What do I think about the stability of the solution?

It is rock solid, we have used it now for seven years.

How are customer service and technical support?

On a scale of one to 10, I would give it an eight. 

Which solution did I use previously and why did I switch?

We had no previous solution. We didn't know we needed to invest in Veracode. It worked out that way through our evaluation process that it was the right solution for us.

What other advice do I have?

I never give 10s. I would give it a nine. It does nearly everything, but penetration testing. It covers such a broad breadth of our portfolio. In our business, we have applications written in so many different languages. Finding something that can consistently scan and not generate false positives across the paradigm or the whole ecosystem of languages, that is impressive. It is speed of inspection, the accurateness of the inspection outcomes, and frankly, it has fairly good business analytics embedded on the platforms. So, it does a lot more for us than not.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1384917 - PeerSpot reviewer
reviewer1384917Director, Customer Advocacy at Veracode
Real User

Thank you for taking the time to share your experience with Veracode. We appreciate your time and hope all is still going well. Please let me know if there's anything I can do to help.

it_user779082 - PeerSpot reviewer
Senior Information Security Program Manager at a financial services firm with 10,001+ employees
Real User
Gives us every vulnerability that has been identified, so there is no human intervention
Pros and Cons
  • "The ability on static scans to be able to do sandbox scans which do not generate metrics."
  • "I would love to be able to do a dynamic sandbox scan. I think that that would allow us to really get a lot more buy-in from the software development teams."

What is our primary use case?

The primary use case is application security and application security testing, specifically static and dynamic analysis, and software composition analysis. It has performed excellently.

How has it helped my organization?

The benefits are the fact that it identifies our vulnerabilities, and it has improved us by allowing us to pull everything to the left in agreement with our SDLC and with our developers, and have them not only get buy-in because they can run sandbox scans that allow them not to generate metrics, but also run policy scans where we identify what the policy is and what is acceptable. So, it has helped us secure our company and our applications.

What is most valuable?

  1. The ability on static scans to be able to do sandbox scans which do not generate metrics.
  2. Gives us every vulnerability that has been identified, so there is no human intervention. Therefore, we can actually look and prioritize our own vulnerabilities as opposed to having someone else try to get in between.

What needs improvement?

I would love to be able to do a dynamic sandbox scan. I think that that would allow us to really get a lot more buy-in from the software development teams. We would be able to scan our applications, identify the vulnerabilities, not generate metrics, which would allow the teams to address the vulnerabilities earlier in the cycle, and then have cleaner scans later on.

Also, I would maybe like to see a better report engine.

What do I think about the stability of the solution?

It is extremely stable.

What do I think about the scalability of the solution?

So far, extremely scalable.

How are customer service and technical support?

We do have ongoing technical support. We use them more as a backstop. My team handles most of the calls and issues that any of the developers might have. 

CA support has excellent time frames. They are knowledgeable and get back to you with an actual solution, which is always a plus.

How was the initial setup?

The initial setup was very straightforward.

  1. It is SaaS, so we did not have to install anything locally.
  2. We were able to give our privileged users better roles because it is role-based, and to do multi-factor authentication. All we have to do, once we set up our trust relationship, we have single sign-on and we white-listed everything. So, it is everything that we wanted from a security point of view, and it is easy to roll out.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1384917 - PeerSpot reviewer
reviewer1384917Director, Customer Advocacy at Veracode
Real User

Thank you for taking the time to share your experience with Veracode. We appreciate your time and hope all is still going well. Please let me know if there's anything I can do to help, my role is new here and I'm fascinated with the customer feedback.

it_user335091 - PeerSpot reviewer
Senior Security Consultant at a retailer with 1,001-5,000 employees
Real User
We were able to easily integrate static code testing into the SDLC process, moving from the waterfall to the agile methodology while still able to integrate Veracode testing within both.

Valuable Features

Static code analysis is a valuable feature.

Improvements to My Organization

We were able to easily integrate static code testing into the SDLC process. We moved from the waterfall to the agile methodology, and were still able to integrate Veracode testing within both methodologies.

Room for Improvement

It's been over a year since I used the product. But when I did, I found there were too many false positives.

Use of Solution

I used it for one year.

Deployment Issues

No issues encountered.

Stability Issues

No issues encountered.

Scalability Issues

No issues encountered.

Customer Service and Technical Support

Customer Service:

8/10

Technical Support:

8/10

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Managing Director at Harrods
Real User
Provides the capability to track remediation and the handling of identified vulnerabilities. The application does not support API or Dynamic Application Security Testing
Pros and Cons
  • "Allows us to track the remediation and handling of identified vulnerabilities."
  • "Provides the capability to track remediation and the handling of identified vulnerabilities."
  • "The security team can track the remediation and risk acceptance statistics."
  • "The solution does not support Dynamic Application Security Testing."
  • "The current version of the application does not support testing for API."

What is our primary use case?

We are planning on introducing a static code analysis tool to support a DevOps effort in our environment. The objective of the solution is to allow the team to identify vulnerabilities in the source code and improve the hygiene of the developed code before deployment.

How has it helped my organization?

This is currently still under evaluation, and it is pending review and assessment against other static code analysis solutions.

What is most valuable?

The solution provides the capability for the application teams to track remediation and the handling of identified vulnerabilities. The system provides workflow capabilities for the application teams to send the completed scans to the security teams for their review. In addition, the security team can track the remediation and risk acceptance statistics.

What needs improvement?

The solution currently does not support Dynamic Application Security Testing which is an important facet of application security testing. In addition, the current version of the application does not support testing for API.

For how long have I used the solution?

Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
DevOps and Cloud Architect at a hospitality company with 1-10 employees
Real User
Great for automatic penetration testing and providing the ability to investigate problems
Pros and Cons
  • "Provides the ability to understand the black zones in our system."
  • "Security can always be improved."

What is our primary use case?

I'm the manager of DevOps and cloud architecture.

How has it helped my organization?

This product has given us the ability to investigate and understand the black zones in our system. 

What is most valuable?

Veracode can emulate the most sophisticated attack and create unique or specific use cases around automatic penetration testing. It gives us the ability to investigate any sensitivities to vulnerabilities that we may have.

What needs improvement?

Security can always be improved. I'd like to know how we can better prevent intrusions to our systems and create risk analysis use cases and understand them. What is the level of risk for what we want to do? How can we understand the process better? I'd like to have a better overview of what's going on. 

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

There are three layers of technical support and we have used all of them over time. We are happy with the service they provide. 

What other advice do I have?

It's important to understand your environment and know the specific use cases for your organization. Creating good orchestration application metrics is very important.

I rate this product eight out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.