We are Veracode partners/distributors in Quito, Ecuador.
At this moment, I am reviewing the solution.
We are Veracode partners/distributors in Quito, Ecuador.
At this moment, I am reviewing the solution.
It helps me to detect vulnerabilities.
I use the SAST feature the most.
All areas of the solution could use some improvement.
Scanning for code security vulnerabilities within our company's products.
Made our company aware of any potential code security vulnerabilities. Also, customers can use our products knowing they are verified by top organizations as safe.
Informing me of application security vulnerabilities. Bamboo build-automation with Veracode API calls are used.
No issues with stability.
No issues with scalability.
Great.
Somewhat straightforward. There was a little confusion about "missing modules" that are third-party files that we couldn't upload because we don't actually have them. That really confused us, but the technical support resolved the confusion.
I can't report on any cost savings relating to code fixes since implementing Veracode in our development process, but it makes us feel more confident about our code, which is awesome.
We are satisfied.
None. We might look into Checkmarx.
I am very likely to recommend Veracode to colleagues. Veracode is great.
Our primary use cases are for comprehensive security assessment using static analysis, dynamic analysis, source code composition, and manual penetration tests. We also use it for security training for developers.
Veracode is a valuable tool in our secure SDLC process.
Source code composition analysis for vulnerabilities and license compliance is the most valuable feature.
It needs better controls to include/exclude specific sections when creating a report that can be shared externally with customers and prospects.
I have been using Veracode for one year.
We also evaluated Synopsys.
I use Veracode to run scans on .NET applications, web applications and Windows/fat form applications. I also use it to make deployments in three-tier environments: the application server tier, web server tier and the database tier.
They should improve on the static scanning time.
PoC is in progress.
It needs to reach the level of Checkmarx's and Fortify Software's capabilities and service levels, or may further loosen the market share.
No.
No.
Customer Service:
A three out of 10.
Technical Support:
A two out of 10.
Quality levels, service offerings, pricing, and mainly the features and abundance of technologies provided by others made us switch to a different solution.
In-house.
The pricing is pretty high.
Yes. Checkmarx, SonarQube and Fortify Software.
We have heard the need for faster scan times and I see this was an area you wanted to see improvement. I wanted to give you an update regarding our Static scanning. We recently extended the Veracode Static Analysis product family to include three purpose-built scan types:
• IDE Scan, which provides fast, automated security feedback to developers in the IDE, in seconds
• Pipeline Scan, a new, first-of-its-kind offering, which runs on every build and provides security feedback on code at a team level, with a median scan time of 90 seconds
• Policy Scan, which returns a full security assessment of the code before release, in a median scan time of 8 minutes
If you would like more information on our static analysis improvements let me know!