Try our new research platform with insights from 80,000+ expert users
it_user873345 - PeerSpot reviewer
Cyber Security Engineer at a consumer goods company with 1,001-5,000 employees
Video Review
Real User
Provides an all-in-one metrics location, I can see where everything is across my full portfolio
Pros and Cons
  • "What's important for me, from Veracode, is the all-in-one metrics location. I can see where everything is across the entire portfolio of applications I have in this program, and I can report out on it."
  • "When we scan binary, when we perform binary analysis, it could go faster. That has a lot to do with the essence of scanning binary code, it takes a little bit longer. Certain aspects, depending on what type of code it is, take a little long, especially legacy code."

How has it helped my organization?

It has given us visibility into the applications we have that are participating in the application security program.

What is most valuable?

For me, at the program manager level, I'm not a developer. What I do is run applications through a security program. What's important for me, from Veracode, is the all-in-one metrics location. I can see where everything is across the entire portfolio of applications I have in this program, and I can report out on it. That is one of the more important pieces for me, at the compliance level.

What needs improvement?

Speed. When we scan binary, when we perform binary analysis, it could go faster. That has a lot to do with the essence of scanning binary code, it takes a little bit longer. Certain aspects, depending on what type of code it is, take a little long, especially legacy code. In our case, we have quite a bit of older code. It takes some time to get through.

For how long have I used the solution?

More than five years.
Buyer's Guide
Veracode
January 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,340 professionals have used our research since 2012.

What do I think about the stability of the solution?

As a SaaS product, you have certain expectations for it to be stable. It is a very mature platform so we haven't had any issues with its performance.

What do I think about the scalability of the solution?

It absolutely scales out. Our program is pretty small, but the eventual goal is complete application portfolio coverage. I have no expectation that we are going to have any issues with scaling.

How are customer service and support?

Technical support is great. The folks that I have interacted with, from services all the way through to the pen-testers have been great. They are on par with anybody else out there. In some cases, specifically for applications, they are probably a lot better than most.

Which solution did I use previously and why did I switch?

I have done a lot of product comparisons in my time, in information security. A lot of them are modules of a product, there is no single pane of glass. When I talk about metrics, I want to see everything in a single pane of glass, I want to see all of my results in one location. A lot of the other application security products out there can't do that yet. They are getting there but Veracode has already been able to do that for years. Veracode can run multiple types of tests and you can see all the results in one area.

When selecting a vendor the most important criteria are 

  • scalability
  • reliability of results - we want to see results-oriented success.

How was the initial setup?

Setup is very straightforward. Since everything is SaaS, everything is uploaded to the cloud. It's very simple to do. There is no setup on the back-end, initially. Once we start getting a little more sophisticated with integrations we are going to be just fine. Currently, we are early in the program so everything is done manually. So there is no setup. Everything is just done in the cloud.

What other advice do I have?

I give Veracode a solid nine out of 10 because it is a full-featured product. It is not just something that they are selling to you and then leaving you to figure out how to use it. They actually help you every single step of the way and they want to show you how to do it. 

Their testers, their application security consultants, really help you and help educate the developers. They walk you through every step of the way.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1825527 - PeerSpot reviewer
Product Security Engineer at a tech services company with 5,001-10,000 employees
Real User
Good pipeline scanner, requires minimal maintenance, and helps easily reveal design flaws
Pros and Cons
  • "With the pipeline scanner, it's easier for developers to scan their products, as they don't have to export anything from their computers. They can do everything with the command line on their computer."
  • "Maybe the pipeline scanning doesn't support enough languages. It might only support Java and Python only, so that could be improved."

What is our primary use case?

I'm working on security reviews for our in-house products. We are trying to solve problems. The use case for Veracode is to discover flaws in design before our application reaches end customers. We are using Veracode as one of the tools to ensure that our products are following secure design guidelines.

How has it helped my organization?

We have some applications where Veracode found a potential XSS due improper input controls. Based on Veracode recommendations, I work with dev team and remediate the flaw. That's something that I would probably missed if I did only the manual code review.

What is most valuable?

We recently started working with pipeline scanner, which is quite useful. In Veracode, you need to import zip files for the source code. With the pipeline scanner, it's easier for developers to scan their products, as they can do everything via command line. When a scanner detects a flaw, it also generates a good explanation about that flaw and good references for mitigation. That's also very useful for us.

What needs improvement?

In terms of improvement, I don't have any valuable input. The application works fine and I don't have any negative feedback. Maybe pipeline scanner can be improved to support some additional language packages.

For how long have I used the solution?

I've used the solution for two years now. It hasn't been that long. 

What do I think about the stability of the solution?

The solution is stable. I haven't experienced any hiccups in my work in any way. 

How are customer service and support?

I haven't worked with Vercode's support and therefore cannot comment on how helpful or responsive they are. 

Which solution did I use previously and why did I switch?

I don't have experience with other SAST products.

How was the initial setup?

This solution was already deployed when I was hired. I can't speak to what the deployment process was like. 

The maintenance is minimal. I just need to create accounts for people who want to scan by themselves and that's it. It's easily maintainable.

What's my experience with pricing, setup cost, and licensing?

I don't have any insights on pricing. I don't handle any aspects of the licensing process so I can't speak to the overall costs or terms.

What other advice do I have?

We are accessing via a web browser to Veracode. I'm guessing it's some type of cloud deployment, hosted by Veracode.

We have a lot of applications that are scanned with Veracode. We did scans for some of our core products, as well as on-demand products, and web applications. I'm mostly working with web applications for now. 

Based on my experience, new users should check as many features as they can, and also read the reports carefully. That way, they can get a full picture of how this product works.

I'd rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Veracode
January 2025
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,340 professionals have used our research since 2012.
it_user873348 - PeerSpot reviewer
VP at a non-tech company with 11-50 employees
Video Review
Real User
Enables us to provide secure code training packages to our customers

How has it helped my organization?

It has helped us be more secure, and it has helped us put a package together for our customers that will take into consideration training, all the way down to the coding level.

What is most valuable?

For us, it's the partnership. We have always been very strong partners with Veracode. They provide excellent training to our sales team, so we are able to work with our customers to show them the value of secure code training.

What needs improvement?

More integration into the specific application; an open API would be good. Aside from that, I think they do a really good job in terms of the features they have. 

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

Veracode has always been a very stable product for us, a very stable product for our customers, and it has been a very stable relationship as well.

What do I think about the scalability of the solution?

We have customers of every size from several hundred to several hundred thousand. The product works well, regardless of the size of the company we are working with.

How is customer service and technical support?

We have had customers - and it has been our own experience as well - tell us that the support is second to none. They are very quick to respond, very quick to answer questions in a really knowledgeable way.

How was the initial setup?

We've had no comments from our customers other than that it is an easy setup.

Which other solutions did I evaluate?

When it comes to secure coding, Veracode is the only one we really considered.

What other advice do I have?

For us, whenever we are selecting a partner, vendors to work with who are going to be working with our customers, we have to make sure that they align regarding customer support philosophy, and that is the reason we selected to work with Veracode.

I would definitely rate Veracode a 10 out of 10, based on our customer feedback. Whenever we know the relationship is going well between Veracode and our customers, it reflects very well on us.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
PeerSpot user
Software Security Consultant at DXC Technology
Real User
Code scanning is fast with current, updated algorithms
Pros and Cons
  • "Provides consistent evaluation and results without huge fluctuations in false positives or negatives."
  • "The solution is a specialist in SAST that you can rely on. Code scanning is fast with current, updated algorithms​."
  • "It should include more informational, low level, vulnerability summaries and groupings. Large related groups of low level vulnerabilities may amount to a design flaw or another avenue for attack."

What is our primary use case?

Provides static code analysis of the customers' applications from all industries. It includes any type of code and scripts, but mostly Java, .Net, C++, and C# environments.

How has it helped my organization?

The solution is a specialist in SAST that you can rely on. Code scanning is fast with current, updated algorithms.

What is most valuable?

Provides consistent evaluation and results without huge fluctuations in false positives or negatives. 

What needs improvement?

It should include more informational, low level, vulnerability summaries and groupings. Large related groups of low level vulnerabilities may amount to a design flaw or another avenue for attack.

For how long have I used the solution?

More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Raj Nachiappan - PeerSpot reviewer
Director of Solutions Architecture at VetsEZ
Real User
Easy to set up and it helps ensure that our code is secure
Pros and Cons
  • "The most valuable feature is the dynamic application security testing."
  • "In the future, I would like to see the RASP capability built-in."

What is our primary use case?

We use Veracode to ensure that the software we are building is secure.

What is most valuable?

The most valuable feature is the dynamic application security testing.

What needs improvement?

It takes a while to get a response to the software composition analysis. It is within an acceptable range but it could still be improved.

In the future, I would like to see the RASP capability built-in.

For how long have I used the solution?

We have been using Veracode SCA for three months.

What do I think about the stability of the solution?

SCA is pretty stable.

What do I think about the scalability of the solution?

Scalability doesn't really apply to a software composition analysis tool.

How are customer service and technical support?

The technical support is pretty good. When I requested help they contacted me within an hour. I don't have any issues with them.

How was the initial setup?

The initial setup is pretty straightforward.

What other advice do I have?

In summary, I think that this is a good tool and I recommend it for helping with security in software development.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Enterprise Architect at a computer software company with 1-10 employees
Real User
Excellent article scanning, good data support and great analysis
Pros and Cons
  • "The article scanning is excellent."
  • "The documentation is poor and the technical support isn't helpful."

What is our primary use case?

We primarily use the solution for article scanning.

What is most valuable?

The article scanning is excellent. 

The composition analysis and common CBEs attached to it are quite good.

The solution offers a lot of really great analysis. There's lots of good data support.

What needs improvement?

The licensing model could be improved. 

If they can provide an automatic upload model, that would be really good. Right now we have to upload the NK bucket hosting to get through the analysis. That is kind of cumbersome.

The documentation is poor and the technical support isn't helpful.

For how long have I used the solution?

We've been using the solution for three or four years.

What do I think about the scalability of the solution?

We don't plan on increasing usage. We are a product company. We have three products that are built. All of them go through this solution. We are not a services company. 

We have about 80 people on the solution currently. They are all developers.

How are customer service and technical support?

We did previously reach out to technical support. When we had to set up all of the automation, we contacted them for assistance. Their documentation is awful and their response time wasn't ideal.

How was the initial setup?

The initial setup was not complex. It was pretty straightforward. However, the integration and automation of the CI cloud was a nightmare. 

Deployment varies. sometimes it takes three months. Sometimes it only takes one hour. The average is one hour, but we have experienced much, much longer deployment times.

What's my experience with pricing, setup cost, and licensing?

I have no idea what the licensing costs on the solution are. Our IT team handles the details.

What other advice do I have?

We were part of the initiation when the company started. They introduced it and we began using the solution. We're just a customer.

For those companies hoping to automate the solution, I would not recommend it. It's too difficult for those heavily dependant on automation. However, for those companies who want to manually use it, I can recommend the solution. In those cases, it's easy to use even if you won't build it as a part of your automation test tools or on any internet server.

I'd rate them eight out of ten. I'd rate them higher, but they have bad automation and terrible documentation. Other than that, they are very good.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Global Presales Head - Security Assurance at Wipro Technologies
Real User
Provides faster scans but with a higher number of false positives
Pros and Cons
  • "Veracode provides faster scans compared to other static analysis security testing tools."
  • "Veracode scans provide a higher number of false positives."
  • "The overall reporting structure is complicated, and it's difficult to understand the report."

What is our primary use case?

Static application security testing, which is the primary use case. 

There were different web applications which were scanned using this tool.

How has it helped my organization?

Veracode scans provide a higher number of false positives. Also, the overall reporting structure is complicated, and it's difficult to understand the report.

What is most valuable?

Veracode provides faster scans compared to other static analysis security testing tools.

What needs improvement?

Veracode should provide support to more software languages, like ABAP.

For how long have I used the solution?

Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1384917 - PeerSpot reviewer
reviewer1384917Director, Customer Advocacy at Veracode
Real User

Thank you for taking the time to share your experience with Veracode. We appreciate your time and hope all is going well. Please let me know if there's anything I can do to help.  My role is new here and I'm working to check in with customers who have taken effort to comment on their Veracode solutions.

it_user854052 - PeerSpot reviewer
Head of Technology. at a tech services company with 11-50 employees
Real User
Allows us to prove our security levels to vendors, helps with our HIPAA security policies
Pros and Cons
  • "It allows us to prove our security levels to vendors, and additionally helps us with our HIPAA security policies."
  • "Mitigation review isn't always super easy."
  • "Straightforward to set up, but the configuration of the rules engine is difficult and complicated."

What is our primary use case?

Certifying the application security of my SAS-based application code base.

How has it helped my organization?

It allows us to prove our security levels to vendors, and additionally helps us with our HIPAA security policies. Also, CA Veracode has provided AppSec best practices and guidance to our teams. Finally, it makes the IT Governance process of the sales cycle easier.

What is most valuable?

Static and dynamic scans of the code. It is part of our release cycle.

What needs improvement?

Mitigation review isn't always super easy.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

No issues with scalability.

How is customer service and technical support?

It is excellent.

How was the initial setup?

Straightforward to set up, but the configuration of the rules engine is difficult and complicated.

What was our ROI?

It helps us get over the line for security when contracting with customers, and any help reducing security vulnerabilities is a big help to us.

What's my experience with pricing, setup cost, and licensing?

Pricing/licensing is complicated.

What other advice do I have?

Do your research, make sure you implement the tools you need.

I am very likely to recommend Veracode to a colleague.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.