Try our new research platform with insights from 80,000+ expert users
it_user846645 - PeerSpot reviewer
VP Development
Real User
The scans have helped us make our code more secure, but mitigation can take a long time
Pros and Cons
  • "The coding standards in our development group have improved. From scanning our code we've learned the patterns and techniques to make our code more secure. An example would be SQL injection. We have mitigated all the SQL injection in our applications."

    What is our primary use case?

    To certify that we have valid code, and that the developers are working with valid structures and writing good code.

    How has it helped my organization?

    The coding standards in our development group have improved. When we scan our code - at the end of a build cycle we'll go through and scan our code - from those scans we've learned the patterns and techniques to make our code more secure. An example would be SQL injection. We have mitigated all the SQL injection in our applications.

    That is now part of our software development life cycle, to do a static scan before we release to our client base. We mitigate what we have to.

    I'm not aware of any cost savings relating to code fixes since implementing Veracode in our development process.

    In terms of Veracode providing application security best practices and guidance to our development teams, once we scan the software and we have to go through a mitigation process, we make sure we implement that in the base standards. Once we mitigate a problem, we implement it back into the base to make sure the developers who are still developing code are not going to have the same issues that we just mitigated.

    For our customers, they know that we go through another level of application security with our application, one our competitors don't use. They know our code meets a standard and that we implement the standard and the structures. That we have mitigated gives them a little bit of peace of mind that our code is valid, and that it's not going to hurt their infrastructure. 

    What is most valuable?

    We just use the static scan, it's all we got into as of now. We're happy with that, it seems to work very well for us.

    What needs improvement?

    Going through the mitigation is probably the hardest thing to do and that's still an ongoing process. If there is a code issue to mitigate, it sometimes takes a little bit longer than what you would think. It might not be anything that they're doing. It's just their engine is changing and our code is changing so we have two things moving. We get a good score one time, scan it again on a new release and the score drops because the engine is picking up more things. I don't know if they could do anything about that. It's just one of those things you might just have to live with.

    Buyer's Guide
    Veracode
    January 2025
    Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
    832,340 professionals have used our research since 2012.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    No issues with stability.

    What do I think about the scalability of the solution?

    No issues with scalability, we're good there.

    How are customer service and support?

    They're very good. Anything that we've brought up to them, they've responded to us very quickly.

    Which solution did I use previously and why did I switch?

    We used the built-in solution inside of Microsoft Visual Studio, and we switched because Veracode had more cohesive scanning abilities and found a lot more issues with our code, when we first scanned it.

    How was the initial setup?

    It was pretty straightforward.

    What's my experience with pricing, setup cost, and licensing?

    We get good value out of what we have right now.

    Which other solutions did I evaluate?

    We had a couple of products that we looked at, but went with Veracode.

    What other advice do I have?

    I am highly likely to recommend Veracode to colleagues.

    Make sure, once you scan and find issues with your code, that the developers know how to remediate those issues so they don't go through them again.

    It's going to take some time to get through your first set of scans and mitigations. To fix your code is not straightforward. But once you do that and implement it back through your whole development cycle, they identify the issues and it's very easy to fix them, once you know and have gone through it once.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    it_user833553 - PeerSpot reviewer
    CISSP, CISM at a tech services company with 1,001-5,000 employees
    Real User
    SAST, DAST, and Greenlight point out potentially insecure coding and how to fix it
    Pros and Cons
    • "For our rapid, secure DevOps cycle, we have integration of the Vericode API into our build tool, and Greenlight into our IDE."
    • "It would help if there were a training module that would explain how to more effectively integrate the SAST product into the build tool, Jenkins or Bamboo."
    • "It would help to have more training for developers to help them set it up."

    What is our primary use case?

    We use it for a lot of things and they're all primary: SAST, DAST, and Greenlight.

    How has it helped my organization?

    By using this product, we can point out not only any potentially insecure coding, but how to fix it. It's a requirement, a legal requirement. So we benefit by not breaking regulatory law.

    What is most valuable?

    SAST, DAST, and Greenlight are the most important features because today it's important for our regulatory compliance law to keep our product coding relatively secure.

    For our rapid, secure DevOps cycle, we have integration of the Vericode API into our build tool, and Greenlight into our IDE.

    What needs improvement?

    I think they are doing pretty well. It would help if there were a training module that would explain how to more effectively integrate the SAST product into the build tool, Jenkins or Bamboo. I think that's a real good idea.

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    No issues with stability.

    What do I think about the scalability of the solution?

    No issues with scalability, other than making sure that our people know how to use it.

    How are customer service and technical support?

    Excellent.

    Which solution did I use previously and why did I switch?

    Never. I've been using it for 20 years. I tried others, like HPE's and IBM's, when I was with Visa, but this is the best.

    How was the initial setup?

    I think it's simple, but sometimes it would help to have more training for developers to help them set it up.

    What was our ROI?

    I can't give you exact numbers, but it's a lot cheaper to do it sooner rather than later.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is worth the value. 

    Which other solutions did I evaluate?

    They didn't have products before this one. This one pre-dated them.

    What other advice do I have?

    I recommend CA Veracode all the time. I am a public speaker, frequently on the speaker circuit, and I recommend it all the time. There are really three solutions at the top of the industry ratings, and Veracode is the best, in my opinion.

    We are a good customer and we had been for a long time. I actually am a bit of an evangelist for them when I'm doing public speaking.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Buyer's Guide
    Veracode
    January 2025
    Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
    832,340 professionals have used our research since 2012.
    Chief Executive Officer at Cybrella
    Real User
    Deployment was easy, configurable, and simple to manage
    Pros and Cons
    • "The installation was straightforward."
    • "There needs to be better API integration to the development team's pipeline, which is something that is missing and needs to be improved."

    What needs improvement?

    There needs to be better API integration to the development team's pipeline, which is something that is missing and needs to be improved.

    For how long have I used the solution?

    We have been using the solution for approximately three months.

    How was the initial setup?

    The installation was straightforward.

    What other advice do I have?

    I rate Veracode Manual Penetration Testing a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user841116 - PeerSpot reviewer
    Information Security Lead Analyst at a consumer goods company with 10,001+ employees
    Real User
    We have learned from the recommended remediation strategies, making future code better
    Pros and Cons
    • "It has caught lots of flaws that could have been exploited, like SQL injection flaws. It has also improved developer engagement with information security."
    • "In terms of application security best practices and guidance to our teams, their engineering staff is really excellent. They provide our developers with suggestions and they take those to heart. They've learned from the recommended remediation strategies provided by the Veracode security engineers. That makes all of their future code better."
    • "The scanning is a little slow, but other than that it's fine. It's usually when the binaries get up into the multi-hundred megabyte size."

    What is our primary use case?

    Security scanning.

    How has it helped my organization?

    It has caught lots of flaws that could have been exploited, like SQL injection flaws. It has also improved developer engagement with information security.

    In terms of application security best practices and guidance to our teams, their engineering staff is really excellent. They provide our developers with suggestions and they take those to heart. They've learned from the recommended remediation strategies provided by the Veracode security engineers. That makes all of their future code better.

    As for our customers, it lowers the risk for people visiting our site.

    What is most valuable?

    Catching coding flaws before they go live.

    Regarding integrating Veracode into our software development lifecycle, we started out with it being used only as a web interface, and now developers are starting to use it right in their IDE on the desktop.

    What needs improvement?

    It's a pretty dynamic product. It's changing all the time and improving.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    The scanning is a little slow, but other than that it's fine. It's usually when the binaries get up into the multi-hundred-megabyte size.

    What do I think about the scalability of the solution?

    We haven't encountered any scalability issues with Veracode so far.

    How are customer service and technical support?

    They're awesome. Their timeliness is acceptable, but their expertise is phenomenal.

    Which solution did I use previously and why did I switch?

    Veracode is the first professional solution I've used. It was in place when I got to the company.

    How was the initial setup?

    We just use it as a cloud service for third-party developers.

    What was our ROI?

    In terms of cost savings relating to code fixes since implementing Veracode in our development process, I can't really give hard numbers.

    What's my experience with pricing, setup cost, and licensing?

    I'm not the pricing guy.

    Licensing is pretty flexible. It's a little bit weird, it's by the size of the binary, which is a strange way to license a product. So far they've been pretty flexible about it.

    What other advice do I have?

    I recommend it all the time.

    It's an important aspect of a complete security program. Not necessarily this product, but source code, fraud detection.

    I'd give it an eight out of 10 because it's pretty straightforward, but you still have to mostly wrap it with organizational policies that encourages its use. It's not a product - and I don't think it's really a product category - that sells itself to the end-user. They see benefits, but they do have to be convinced to use it.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    it_user835104 - PeerSpot reviewer
    Project Manager at a tech vendor with 501-1,000 employees
    Real User
    We use scan results for training to increase sensitivity to security issues during development
    Pros and Cons
      • "Calypso (our application) is large and the results take up to two months. Further, we also have to package Calypso in a special manner to meet size guidelines."
      • "Because our application is large, it takes a long time to upload and scan."

      What is our primary use case?

      Static code scan.

      How has it helped my organization?

      We have used the results of scans to train our people and make them more sensitive to security issues during development, although we haven't done any specific integration of Veracode into our software development cycle. Engineers are better trained, so we hope to see increased compliance with our security guidelines.

      We do incorporate the suggested course of action from the Veracode report (AppSec best practices and guidance) in our best practices.

      Also, our customers benefit from the fact that the application is more secure.

      What is most valuable?

      We use the results of the scan to identify vulnerabilities in the product.

      What needs improvement?

      Calypso (our application) is large and the results take up to two months. Further, we also have to package Calypso in a special manner to meet size guidelines.

      For how long have I used the solution?

      One to three years.

      What do I think about the stability of the solution?

      No issues with stability.

      What do I think about the scalability of the solution?

      Because our application is large, it takes a long time to upload and scan.

      How are customer service and technical support?

      Based on limited usage, we are satisfied.

      Which solution did I use previously and why did I switch?

      We did not have a previous solution. We picked this product because our partner (SAP) uses it.

      How was the initial setup?

      Straightforward.

      What was our ROI?

      There are no directly measurable cost savings. We see security improvement as a key part of our product development.

      What other advice do I have?

      When asked, we let our customers and partners know that we use Veracode and that we are happy with it.

      Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
      PeerSpot user
      it_user542859 - PeerSpot reviewer
      Security Consultant at a tech company with 501-1,000 employees
      Vendor
      Allows developers to run their own scans. I would like to see the false positives corrected.

      What is most valuable?

      Allows developers to run their own scans.

      How has it helped my organization?

      Reduced dependency on the security team to run scans. It helped the organizations to scan a large number of applications on a regular basis.

      What needs improvement?

      I would like to see the following:

      • Correction of the regularly received false positives
      • Options to manage comments and mitigations
      • Better UI functionality

      For how long have I used the solution?

      We have used this solution for a year.

      What do I think about the stability of the solution?

      A few months ago, there were issues with the scanners and tickets were opened. However, they were resolved. This is a stable product.

      What do I think about the scalability of the solution?

      There have not been any scalability issues yet.

      How is customer service and technical support?

      I would give technical support a rating of 8/10. At times, we have not seen the best support in terms of issues faced during a scan.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      reviewer1359297 - PeerSpot reviewer
      Software Engineer at a financial services firm with 501-1,000 employees
      Real User
      Source composition analysis component gives our developers comfort in using new libraries
      Pros and Cons
      • "The source composition analysis component is great because it gives our developers some comfort in using new libraries."
      • "I think for us the biggest improvement would be to have an indicator when there's something wrong with a scan."

      What is our primary use case?

      This was intended to scan all of our custom development efforts to ensure a certain level of (secure) code quality. Right now the scope of that effort is limited to web exposed systems but with maturity, we hope to increase that scope.

      How has it helped my organization?

      The Veracode platform probably hasn't improved our organization overall, although through no fault of theirs. Veracode is just one more tool that generates work for our developers.

      What is most valuable?

      The source composition analysis component is great because it gives our developers some comfort in using new libraries.

      What needs improvement?

      I think for us the biggest improvement would be to have an indicator when there's something wrong with a scan. For instance, we have CI scans that run automatically, and sometimes the files don't get upload and/or processed by Veracode. Now, there's a static scan that hasn't been completed, which blocks all future scans. The only way we know this is an issue is going into the Web UI, check each application, and look for stalled scans. This is time-consuming and frustrating.

      For how long have I used the solution?

      I have been using Veracode for three years.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      it_user697020 - PeerSpot reviewer
      Software Developer/Architect at a insurance company with 201-500 employees
      Vendor
      Static, dynamic, and manual scan features were useful for us.

      What is most valuable?

      We used the application for the web. Static, dynamic, and manual scan features were all very useful for us. All of them helped us fix many security flaws.

      How has it helped my organization?

      It made us change our approach to coding. We tried to make sure our application stayed secure and safe.

      What needs improvement?

      The current features were enough for us. Although reports are well documented, it was difficult for us to understand them at first.

      For how long have I used the solution?

      We have been using the solution for about a year.

      What do I think about the stability of the solution?

      We did not encounter any issues with stability.

      What do I think about the scalability of the solution?

      We did not encounter any issues with scalability.

      How are customer service and technical support?

      We didn't use the technical support, so I can't comment on this question.

      Which solution did I use previously and why did I switch?

      We did not use a previous solution. This was the first security application we used.

      How was the initial setup?

      It was very easy to setup. Everything on the website was clearly explained.

      What's my experience with pricing, setup cost, and licensing?

      I don't know about the prices.

      Which other solutions did I evaluate?

      We did not evaluate any alternative solutions.

      What other advice do I have?

      If it's the first time you are using a security application, be ready for some new tools which you will require you to revitalize the flaws reported.

      Reports are very well documented. Once you understand what it means and you get used to it, you will see that it is detailed and clearly explained.

      Disclosure: I am a real user, and this review is based on my own experience and opinions.
      PeerSpot user
      Buyer's Guide
      Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.
      Updated: January 2025
      Buyer's Guide
      Download our free Veracode Report and get advice and tips from experienced pros sharing their opinions.