The primary use case is application security and application security testing, specifically static and dynamic analysis, and software composition analysis. It has performed excellently.
Senior Information Security Program Manager at a financial services firm with 10,001+ employees
Gives us every vulnerability that has been identified, so there is no human intervention
Pros and Cons
- "The ability on static scans to be able to do sandbox scans which do not generate metrics."
- "So, it is everything that we wanted from a security point of view, and it is easy to roll out."
- "I would love to be able to do a dynamic sandbox scan. I think that that would allow us to really get a lot more buy-in from the software development teams."
- "I would love to be able to do a dynamic sandbox scan."
What is our primary use case?
How has it helped my organization?
The benefits are the fact that it identifies our vulnerabilities, and it has improved us by allowing us to pull everything to the left in agreement with our SDLC and with our developers, and have them not only get buy-in because they can run sandbox scans that allow them not to generate metrics, but also run policy scans where we identify what the policy is and what is acceptable. So, it has helped us secure our company and our applications.
What is most valuable?
- The ability on static scans to be able to do sandbox scans which do not generate metrics.
- Gives us every vulnerability that has been identified, so there is no human intervention. Therefore, we can actually look and prioritize our own vulnerabilities as opposed to having someone else try to get in between.
What needs improvement?
I would love to be able to do a dynamic sandbox scan. I think that that would allow us to really get a lot more buy-in from the software development teams. We would be able to scan our applications, identify the vulnerabilities, not generate metrics, which would allow the teams to address the vulnerabilities earlier in the cycle, and then have cleaner scans later on.
Also, I would maybe like to see a better report engine.
Buyer's Guide
Veracode
April 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,221 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is extremely stable.
What do I think about the scalability of the solution?
So far, extremely scalable.
How are customer service and support?
We do have ongoing technical support. We use them more as a backstop. My team handles most of the calls and issues that any of the developers might have.
CA support has excellent time frames. They are knowledgeable and get back to you with an actual solution, which is always a plus.
How was the initial setup?
The initial setup was very straightforward.
- It is SaaS, so we did not have to install anything locally.
- We were able to give our privileged users better roles because it is role-based, and to do multi-factor authentication. All we have to do, once we set up our trust relationship, we have single sign-on and we white-listed everything. So, it is everything that we wanted from a security point of view, and it is easy to roll out.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
General Manager - Application Security at a tech consulting company with 51-200 employees
Needs to improve service levels and capabilities versus competitors. Provides a wide range of platforms and technology assessments.
Pros and Cons
- "Wide range of platforms and technology assessments."
- "Wide range of platforms and technology assessments."
- "It needs to reach the level of Checkmarx's and Fortify Software's capabilities and service levels, or may further loosen the market share."
- "It needs to reach the level of Checkmarx's and Fortify Software's capabilities and service levels, or may further loosen the market share."
How has it helped my organization?
PoC is in progress.
What is most valuable?
- Application testing
- False positives challenges
- Wide range of platforms and technology assessments
What needs improvement?
It needs to reach the level of Checkmarx's and Fortify Software's capabilities and service levels, or may further loosen the market share.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service:
A three out of 10.
Technical Support:
A two out of 10.
Which solution did I use previously and why did I switch?
Quality levels, service offerings, pricing, and mainly the features and abundance of technologies provided by others made us switch to a different solution.
What about the implementation team?
In-house.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty high.
Which other solutions did I evaluate?
Yes. Checkmarx, SonarQube and Fortify Software.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Veracode
April 2026
Learn what your peers think about Veracode. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,221 professionals have used our research since 2012.
Software Developer/Architect at a insurance company with 201-500 employees
Static, dynamic, and manual scan features were useful for us.
Pros and Cons
- "Static, dynamic, and manual scan features were all very useful for us and helped us fix many security flaws."
- "Although reports are well documented, it was difficult for us to understand them at first."
What is most valuable?
We used the application for the web. Static, dynamic, and manual scan features were all very useful for us. All of them helped us fix many security flaws.
How has it helped my organization?
It made us change our approach to coding. We tried to make sure our application stayed secure and safe.
What needs improvement?
The current features were enough for us. Although reports are well documented, it was difficult for us to understand them at first.
For how long have I used the solution?
We have been using the solution for about a year.
What do I think about the stability of the solution?
We did not encounter any issues with stability.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability.
How are customer service and technical support?
We didn't use the technical support, so I can't comment on this question.
Which solution did I use previously and why did I switch?
We did not use a previous solution. This was the first security application we used.
How was the initial setup?
It was very easy to setup. Everything on the website was clearly explained.
What's my experience with pricing, setup cost, and licensing?
I don't know about the prices.
Which other solutions did I evaluate?
We did not evaluate any alternative solutions.
What other advice do I have?
If it's the first time you are using a security application, be ready for some new tools which you will require you to revitalize the flaws reported.
Reports are very well documented. Once you understand what it means and you get used to it, you will see that it is detailed and clearly explained.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Consultant at a tech company with 501-1,000 employees
Allows developers to run their own scans. I would like to see the false positives corrected.
Pros and Cons
- "Reduced dependency on the security team to run scans."
- "I would like to see the following: Correction of the regularly received false positives, options to manage comments and mitigations, and better UI functionality."
What is most valuable?
Allows developers to run their own scans.
How has it helped my organization?
Reduced dependency on the security team to run scans. It helped the organizations to scan a large number of applications on a regular basis.
What needs improvement?
I would like to see the following:
- Correction of the regularly received false positives
- Options to manage comments and mitigations
- Better UI functionality
For how long have I used the solution?
We have used this solution for a year.
What do I think about the stability of the solution?
A few months ago, there were issues with the scanners and tickets were opened. However, they were resolved. This is a stable product.
What do I think about the scalability of the solution?
There have not been any scalability issues yet.
How is customer service and technical support?
I would give technical support a rating of 8/10. At times, we have not seen the best support in terms of issues faced during a scan.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Program Manager at a engineering company with 10,001+ employees
The coverage it provides of the last vulnerabilities reported and of the programming languages is valuable.
Pros and Cons
- "The coverage of the last vulnerabilities reported."
- "Veracode is one of very few options out there, and the very best."
- "To be able to upload source codes without being compiled. That’s one feature that drives us to see other sources."
- "To be able to upload source codes without being compiled, that’s one feature that drives us to see other sources."
How has it helped my organization?
We decided to begin a partnership with Veracode, so we can improve our services and provide the customers that trust us with a platform capable to report vulnerabilities and also delegate and keep tracking of the remediation until the applications score 100% on stability before they go to production.
What is most valuable?
- Customer and professional support
- Live sessions and training
- The coverage of the last vulnerabilities reported
- The coverage of the programming languages
What needs improvement?
- To be able to upload source codes without being compiled. That’s one feature that drives us to see other sources.
Compiled code means that the code written is stored in binaries for machine reading only. Veracode reads only those binaries (compiled code). The other way to have the code is “Source Code written only”, a process where you don’t compile and anyone is able to read line by line the code.
This example might seem weird, but maybe will clear things out:
Binary Code (Supported by Veracode):
11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010
11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 11110 010
1111000101000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 010 11110001011000 0111 0001 01 110 00010 0101
Source Code:
public class HelloWorld {
public static void main(String[] args) {
// Prints "Hello, World" to the terminal window.
System.out.println("Hello, World");
}
}
What do I think about the stability of the solution?
When tracking source code vulnerabilities, sometimes it’s possible that the tool loses the path of the issues when the source code has been modified significantly.
How are customer service and technical support?
Customer Service:
Customer and platform support is one of the best in the field. The experts are skilled and can have as many meetings and researches as needed.
Technical Support:
The Veracode support team excels with help of their experts capable to solve most of the situations, and taking advantage of the variety of their members to delegate issues and problems to solve.
Which solution did I use previously and why did I switch?
I use a portfolio of tools for security consulting, but Veracode is the main app I rely on because customers are happy to be able to track the status of each individual issue or vulnerability.
How was the initial setup?
Initial setup is very complex, requiring security knowledge, but it’s easy when experts guide you through all the process. Even after months of use, the Veracode experts are always there to help you on both the workflow and the dashboard tool.
What's my experience with pricing, setup cost, and licensing?
Veracode is a very complete tool; that drives you to invite customers, the apps team, developers and even the product and marketing team to navigate through the whole application. Its complexity makes it quite expensive, but it’s all worth it, with all the engineering in the background.
Which other solutions did I evaluate?
Before choosing this product, many tools were tested, such as HPE WebInspect, AppScan, Checkmarx, etc. Those tools are good, and do their jobs really well. Veracode has many pros that involve a human touch, which is something a consulting firm, customers and big companies want from the information technology field.
What other advice do I have?
I recommend exhausting all resources and gaining knowledge from different security tools, before making a decision. Veracode is not cheap, but it is a tool capable of giving dynamic, static and even manual scan results in one platform. Veracode is one of very few options out there, and the very best.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Consultant at a retailer with 1,001-5,000 employees
We were able to easily integrate static code testing into the SDLC process, moving from the waterfall to the agile methodology while still able to integrate Veracode testing within both.
Pros and Cons
- "We were able to easily integrate static code testing into the SDLC process."
- "It's been over a year since I used the product. But when I did, I found there were too many false positives."
Valuable Features
Static code analysis is a valuable feature.
Improvements to My Organization
We were able to easily integrate static code testing into the SDLC process. We moved from the waterfall to the agile methodology, and were still able to integrate Veracode testing within both methodologies.
Room for Improvement
It's been over a year since I used the product. But when I did, I found there were too many false positives.
Use of Solution
I used it for one year.
Deployment Issues
No issues encountered.
Stability Issues
No issues encountered.
Scalability Issues
No issues encountered.
Customer Service and Technical Support
Customer Service:
8/10
Technical Support:8/10
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Architect of solutions at IPComMx
Utilized for scanning containers and integrated within DevOps workflows
Pros and Cons
- "The coverage of backdoors attacks on security that's the most valuable for my clients."
- "There is room for improvement in documentation."
What is our primary use case?
We used Barracuda for scanning containers. And in all in DevOps workflow.
What is most valuable?
The coverage of backdoors attacks on security that's the most valuable for my clients.
What needs improvement?
There is room for improvement in documentation. Maybe the documentation about how to configure something. It is difficult to get the expected result.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
It's stable. It works very well in the parameter like an enterprise solution. We don't have any problems with that.
How are customer service and support?
We are very pleased with the support.
How would you rate customer service and support?
Positive
How was the initial setup?
I would rate my experience with the initial setup a six out of ten, where one is difficult and ten is easy to set up.
What about the implementation team?
We work on the deployment process. The solution is deployed both on-prem and in the cloud environment.
The solution doesn't require any maintenance.
What was our ROI?
It took two years to see ROI for our clients.
What's my experience with pricing, setup cost, and licensing?
Veracode is expensive. But the solution is worth it.
What other advice do I have?
Overall, I would rate the solution a nine out of ten. It is a good solution for security. In my personal opinion, there are not many products like Veracode in the market.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Container Security Software Composition Analysis (SCA) Static Code Analysis Dynamic Application Security Testing (DAST) Application Security Posture Management (ASPM)Popular Comparisons
SonarQube
Snyk
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Checkmarx One
GitLab
CrowdStrike Falcon Cloud Security
Orca Security
JFrog Xray
Coverity Static
Black Duck SCA
Acunetix
PortSwigger Burp Suite Professional
Mend.io
Buyer's Guide
Download our free Veracode Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Which gives you more for your money - SonarQube or Veracode?
- Checkmarx or Veracode. Which should we choose?
- Would you recommend Veracode? What are some of your use cases?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- What do I scan when changing code in Veracode?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?

















Thank you for taking the time to share your experience with Veracode. We appreciate your time and hope all is still going well. Please let me know if there's anything I can do to help, my role is new here and I'm fascinated with the customer feedback.