

Veracode and CAST Highlight compete in the application security testing space. Veracode seems to have the upper hand due to its comprehensive scanning capabilities and extensive integration options, making it a strong choice for regulatory compliance and SDLC integration.
Features: Veracode provides comprehensive static, dynamic, and manual scanning capabilities, which are crucial for regulatory compliance and SDLC integration. It supports a broad range of programming languages and offers robust integration with IDEs and APIs. Veracode is valued for its ease of use, especially its ability to minimize false positives, along with features for sandbox scanning and vulnerability management. CAST Highlight offers fast, automated code scanning and portfolio assessments, providing a high-level overview rather than the in-depth analysis delivered by Veracode.
Room for Improvement: Veracode faces issues with false positives and complex integrations, leading to potential usability and reporting problems. Improvements in scanning speeds and language support are needed. CAST Highlight is criticized for its abstract reporting and lack of detailed analysis capabilities, with its pricing model viewed as inflexible, limiting deeper analyses without significant cost.
Ease of Deployment and Customer Service: Veracode can be deployed across various cloud environments—public, private, and hybrid—offering adaptability but with potential complexity in implementation. While its technical support receives mixed reviews, its quick response time is praised, despite some inconsistencies. CAST Highlight shares similar support complexities and the need for potential service improvements according to its users.
Pricing and ROI: Veracode's pricing is perceived as high but justified by its comprehensive features and robust security assurances, making it less accessible for small businesses but valuable for larger enterprises in risk management and operational efficiencies. CAST Highlight is considered more cost-effective than its sibling CAST AIP, but still requires careful cost-benefit analysis. Veracode is frequently cited for delivering more measurable benefits in reducing security vulnerabilities.
| Product | Mindshare (%) |
|---|---|
| Veracode | 5.9% |
| CAST Highlight | 1.3% |
| Other | 92.8% |

| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 5 |
| Company Size | Count |
|---|---|
| Small Business | 69 |
| Midsize Enterprise | 45 |
| Large Enterprise | 114 |
CAST Highlight is a comprehensive platform that integrates with Azure DevOps, offering remote functionalities without direct codebase access. It quickly identifies cloud migration blockers and supports most programming languages with an easy setup.
CAST Highlight stands out with its user-friendly interface and dashboard, enabling efficient scanning for environment quality. Its automation and speed are particularly valued, making it distinct in the software analysis domain. While users encounter challenges with language-specific insights and expensive licensing, they benefit from its capability to assess code base states during mergers, acquisitions, and cloud migration planning. Technical support poses issues, and some users face hurdles with configuration customization and issue reporting clarity. Despite these challenges, CAST Highlight demonstrates effectiveness in identifying application service quality and ensuring legal, security, and IP compliance.
What features define CAST Highlight?CAST Highlight is adopted across industries for tasks such as assessing code during mergers, managing application portfolios, and planning cloud migrations. It facilitates open source safety checks and replatforming architectures, serving roles in firewall and storage management. Users rely on it for service quality verification and distinguishing applications from competitors.
Veracode is a leading provider of application security solutions, offering tools to identify, mitigate, and prevent vulnerabilities across the software development lifecycle. Its cloud-based platform integrates security into DevOps workflows, helping organizations ensure that their code remains secure and compliant with industry standards.
Veracode supports multiple application security testing types, including static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), and manual penetration testing. These tools are designed to help developers detect vulnerabilities early in development while maintaining speed in deployment. Veracode also emphasizes scalability, offering features for enterprises that manage a large number of applications across different teams. Its robust reporting and analytics capabilities allow organizations to continuously monitor their security posture and track progress toward remediation.
What are the key features of Veracode?
What benefits should users consider in Veracode reviews?
Veracode is widely adopted in industries like finance, healthcare, and government, where compliance and security are critical. It helps these organizations maintain strict security standards while enabling rapid development through its integration with Agile and DevOps methodologies.
Veracode helps businesses secure their applications efficiently, ensuring they can deliver safe and compliant software at scale.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.