No more typing reviews! Try our Samantha, our new voice AI agent.

Trend Micro Cloud App Security [EOL] vs Veracode comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 26, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Trend Micro Cloud App Secur...
Average Rating
8.2
Reviews Sentiment
6.2
Number of Reviews
9
Ranking in other categories
No ranking in other categories
Veracode
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (2nd)
 

Featured Reviews

Anuradha Buluwala - PeerSpot reviewer
Head of Technical at Connex Information Technologies Pvt Ltd
Useful for cloud data protection, particularly for email and file-sharing systems
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto. The solution should also expand integration from the public cloud to the private cloud and add Cloud DLP and CASB features.
reviewer2753535 - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
Integrates security into the development process and improves team collaboration
Veracode helps organizations develop software by reducing the risk of security vulnerabilities through developer enablement and applications focused on governance. You can utilize different levels of processes to achieve better performance or a more scalable service. Since I started working with it in 2022, I’ve found it to be cost-effective as well. Overall, Veracode is a user-friendly security tool. It includes features such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). During the development phase, we can identify vulnerabilities in the application. This process occurs in the staging environment during development. When we're ready to go to production, we conduct a final check. Essentially, this tool helps identify vulnerabilities during the code development stage, including both high-level vulnerabilities and those related to open-source software composition. We utilize specific methodologies for this purpose. Additionally, it offers a feature that allows us to set up policies based on client requirements. This means we can customize the tool to meet the specific needs of our clients, ensuring that they receive the appropriate level of security in their applications. Veracode is user-friendly as well. Compared to other tools, their scans take 15 minutes or under. If you have a large scale of libraries or data, it might take longer, but based on my personal experience, the scan usually runs within fifteen minutes. For my case study using the Veracode tool, I worked on an internal project following industry standards. We used Veracode to improve our security posture and speed up the time to market by streamlining the development process. This enhanced collaboration between developers, operations, and security teams. The automated scanning process helped identify and fix vulnerabilities earlier in the development process. We maintained compliance with regulatory requirements, avoided fines, and built customer trust by integrating security into the development process. When we conduct this scan, we receive data on a list of vulnerabilities. This information improved our communication and increased transparency, which leads to better reports about the efforts being put in. This results in a more effective and efficient collaboration process, making it user-friendly for all involved. When considering costs, if we resort to manual processes, it can be time-consuming. Therefore, we utilize automated scans to identify and fix security issues. This allows us to address vulnerabilities early in the development process, as we discussed previously. This applies both to our in-house code and third-party libraries, using Software Composition Analysis (SCA) agent-based scans. In the future, we will also implement SCA agent-based scans as a separate feature within Veracode, which can help organizations avoid the expensive and time-consuming consequences of security issues. Furthermore, we have seen an increase in compliance, helping to maintain adherence to regulatory requirements and industry standards, thereby avoiding fines and reputational damage associated with noncompliance. Additionally, by integrating security into the development process, we enhance customer trust in our organization and its products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Trend Micro Cloud App Security is its stability across all platforms."
"Our business emails are very important and Trend Micro Cloud App Security has provided a high level of protection. Additionally, there are updating the solution frequently."
"The solution is easy to integrate."
"Trend Micro Cloud App is easy to use and easy to install."
"I find Trend Micro Cloud App Security useful for scanning our email boxes. We can scan them one by one, which is a good feature. It's not just gateway-level protection - we integrate the email system with it. They have special protection and parameters for phishing emails."
"This is a very dependable solution and we are able to have a lot of Trend Micro security products integrated between each other."
"It has more intelligence features than other vendors."
"Dependable with ease of integration with other security products."
"We have such a wide variety of users for Veracode, including security champions, development leads, developers themselves, that the ease of use is really quite important, because we don't assume anything about what those people might already know, or need to know. It just makes it very useful for anyone who has to engage with it."
"Regarding Software Composition Analysis, an exceptional feature is that during a SAST scan, SCA is seamlessly conducted in the background."
"I like the way the flaws are reported in the system."
"The most important feature is the static scanning analysis, and the reason is that it can tell us vulnerability in that code, right before we go ahead and push something to production or provide something to a client... Dynamic scanning actually hits our Web applications, to try to detect any well known Web application vulnerabilities as well."
"It has also helped to increase our fix rate by almost 100 percent."
"This is a great tool for learning about potential vulnerabilities in code."
"The SAST and DAST modules are great."
"The most valuable feature is the SAST capability and its integration into the Veracode pipelines."
 

Cons

"Documentation could be improved; product cost is quite high."
"In the next release, I would like to see the cost go down."
"There is room for improvement in the DLP component of Trend Micro Cloud App Security."
"The solution's technical support services could be better."
"The price of the solution could improve by being lower."
"The cost of the license is on the high side."
"The pricing of this solution is quite high, about double what other similar solutions cost."
"The granulation of the policy setup needs to be better. Right now, it is too basic."
"To be able to upload source codes without being compiled. That’s one feature that drives us to see other sources."
"A high number of false positives are reported and this should be reduced."
"There were some additional manual steps or work involved that we should not have needed to do."
"Ideally, I would like better reporting that gives me a more concise and accurate description of what my pain points are, and how to get to them."
"Veracode's SAST, DAST, and SCA are pretty good with respect to industry standards, but with regard to container security, they are in either beta or alpha testing. They need to get that particular feature up and running so that they take care of the container security part."
"I noticed there is no integration with Bamboo."
"I wouldn't promote Veracode because it's not automated enough, and it has many configuration issues."
"Veracode's container scanning could be improved. We containerize all the platforms we use inside a Docker image. For example, we create a Microsoft Docker image that we build our application on top of. I would like Veracode to implement IT scans before we commit the code."
 

Pricing and Cost Advice

"The solution's price is mid-ranged."
"The product's pricing is reasonable compared to other vendors."
"The pricing of the solution could be better."
"The price of Trend Micro Cloud App Security is expensive for regular users. There are not any hidden fees. First-time users of the solution should purchase implementation packages or professional services."
"The cost of the license is on the high side. It's a yearly subscription."
"Licensing is pretty flexible. It's a little bit weird, it's by the size of the binary, which is a strange way to license a product. So far they've been pretty flexible about it."
"The pricing is really fair compared to a lot of other tools on the market."
"The price of Veracode Static Analysis could improve."
"Without getting too specific, I'd say the average yearly cost is around $50,000. The costs include licensing and maintenance support."
"Pricing-wise, I find it a bit expensive because it's based on the number of users requesting access to Veracode."
"Veracode provides value for the cost, with no additional charges apart from the standard licensing fee."
"The pricing is fair."
"It is pricey. There is a lot of value in the product, but it is a costly tool."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
13%
Comms Service Provider
9%
Construction Company
8%
Outsourcing Company
8%
Financial Services Firm
14%
Manufacturing Company
11%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise2
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What needs improvement with Trend Micro Cloud App Security?
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto. The solut...
What is your primary use case for Trend Micro Cloud App Security?
We use the solution for cloud data protection, particularly for email and file-sharing systems. It integrates with Microsoft Office 365 and Google Suite to scan mailboxes for spam, viruses, and phi...
What advice do you have for others considering Trend Micro Cloud App Security?
We chose the solution because they've been Gartner leaders for over 15 years, have a good customer base, and are a well-established company. I'd rate the product an eight out of ten.
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

No data available
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

MedImpact Healthcare Systems, ClubCorp USA, Copa Airlines, Aava, Azra Solutions, BSN INET Co, Ltd, Carhartt
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Application Security Tools. Updated: September 2026.
913,683 professionals have used our research since 2012.