Veracode

Enterprise AppSec platform spanning SAST, SCA, DAST, container/IaC scanning, AI auto-remediation, ASPM risk management, and developer training.

Quote-based pricingLast verified 2026-09-09

Deployment

Cloud · Self-Hosted (partial)

Languages

35+

Pricing model

Quote-based / Enterprise

Free tier

No

Workflow coverage

Where in the development lifecycle Veracode operates.

Real-Time IDE FeedbackYesadd-on

Greenlight gives instant in-IDE feedback as code is written, retiring 2026-12-31; Scan plugins run on demand.

AI Agent Guardrail (MCP)No

Not offered in vendor documentation reviewed as of 2026-09-05.

Local CLI / Pre-CommitYesadd-on

Veracode CLI and Pipeline Scan JAR/Docker run locally; --allow-dirty re-verifies uncommitted changes

PR Inline ReviewYesadd-on

Pipeline Scan posts results to PRs; Fix GitHub Action adds PR comments and annotations

Merge Gate BlockingYesadd-on

Veracode checks configurable as required status checks; --fail_on_severity/--fail_on_cwe break builds

Full Repo ScanYesadd-on

Upload and Scan of packaged artifacts; repository scanning on push across all org repos

Scheduled / Continuous RescanYesadd-on

Policies enforce scan cadences - quarterly, semi-annual or annual - so repeat scans run on schedule.

Runtime / Production MonitoringYesadd-on

DAST scans live apps/APIs; Quick scan safe in production; EASM discovers external assets

Analysis & detection

Every detection and code-analysis capability tracked for Veracode.

SASTYesadd-on

Upload and Scan plus Pipeline Scan on compiled/packaged artifacts, CWE-mapped, 0-5 severity scoring

Taint / Data-Flow AnalysisNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Secrets DetectionYesadd-on

Container/IaC scanning detects secrets via configurable RE2 secret-rules; 60+ named provider key types

Secrets ValidationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SCA (Dependencies)Yesadd-on

Agent-based scan with quick, full and vulnerable-methods depths; direct vs transitive dependency graph

Reachability AnalysisYesadd-on

Vulnerable Methods scan (Level 3) checks whether first-party code calls vulnerable third-party methods

Malicious Package DetectionYesadd-on

Veracode Package Firewall blocks malicious open-source packages at the registry level

License ComplianceYesadd-on

License-risk ratings per component; policy rules block high-risk, non-OSS or unrecognized licenses

SBOM GenerationYesadd-on

REST API and 'veracode sbom' CLI output CycloneDX 1.6, SPDX 2.3, Syft JSON; unbuilt Gradle limited

IaC ScanningYesadd-on

IaC misconfiguration scanning via repository integrations and CLI scan command with Rego custom policy

Container ScanningYesadd-on

Container image/archive scanning across nine base OS families for vulns, misconfigurations, secrets

Cloud Posture (CSPM)Partialadd-on

Veracode Risk Manager aggregates cloud infrastructure and security-tool findings; no native CSPM scanner documented

DAST / API ScanningYesadd-on

DAST covers web apps and REST/SOAP/OpenAPI/Postman APIs; Enterprise mode adds API spec management

Code Smells & MaintainabilityYesadd-on

SAST reports a 'Code Quality' CWE finding category covering non-security maintainability defects.

Complexity MetricsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Duplication DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Dead / Unused CodeNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Test Coverage TrackingNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Diff / New-Code CoverageNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Architecture GovernanceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Technical Debt QuantificationPartialadd-on

Security Quality Score, Veracode Levels VL1-VL5, open-flaw age and time-to-resolve dashboards; security debt only

Behavioral Delivery AnalyticsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

AI Logic Bug DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

PR Summaries & WalkthroughsNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Custom Rule AuthoringYesadd-on

Buyers author custom regex secret rules plus Rego container and IaC policies.

Autofix SuggestionsYesadd-on

Veracode Fix suggests up to five RAG-matched patches per flaw in CLI and IDE; Pipeline Scan findings only

Autofix via Agentic PRsYesadd-on

Fix GitHub Action creates branch and PR; SCA auto-opens dependency-upgrade PRs on GitHub/GitLab

AI Triage / False-Positive FilteringPartialadd-on

Vulnerable-methods reachability and VRM dedup/correlation cut noise; mitigation workflow is manual, not AI triage

Monorepo SupportPartial

Multi-module build uploads let you choose which modules to scan, adjacent to monorepo scanning; repo-scanning docs never use the term "monorepo" or describe per-directory project scoping.

AI capabilities

AI Review EnginePartialadd-on

Veracode Fix uses ML plus RAG for remediation only; no AI reviewer that finds issues itself

BYO Model / BYOKNo

Not offered in vendor documentation reviewed as of 2026-09-05.

MCP ServerNo

Not offered in vendor documentation reviewed as of 2026-09-05.

AI Usage GovernanceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Chat With ReviewerNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Learns From FeedbackNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Code Excluded From TrainingPartial

A Veracode Fix whitepaper states customer code is never used to further train that model, but the commitment is scoped to Fix only; a platform-wide statement is gated behind Veracode's Trust Center.

Compliance & governance

Audit LogsYesadd-on

User activity log and audit trails documented for enterprise governance

SSO / SAMLYesadd-on

SSO/SAML documented, including a SAML gateway for standalone Security Labs accounts

Role-Based Access ControlYesadd-on

Named roles including Security Lead, Reviewer, Security Labs admin/manager/user, Free Trial Admin

Compliance Reporting ExportsYesadd-on

Pre-built analytics dashboards, PDF/JUnit/CSV DAST reports, SARIF export, REST API report retrieval

Certifications

FedRAMP (distinct compliance environment with feature restrictions)

Standards mapping

OWASP Top 10 (including OWASP Top 10:2025)OWASP MobileOWASP API Security Top 10CWE Top 25CWE (full catalog, updated within 90 days of new versions)CERTPCI DSS (including PCI DSS 11.3 and PCI 3.2.1 policy)GDPR Article 32NIST (password/IAM guidance)

Integrations

GitHubYes
GitHub Enterprise ServerNo
GitLabPartial
GitLab Self-ManagedNo
BitbucketPartial
Bitbucket Data CenterNo
Azure DevOpsYes
REST APIYes
CLIYes
WebhooksYes

CI/CD systems

GitHub ActionsGitLab CIAzure PipelinesJenkins/HudsonAtlassian BambooJetBrains TeamCityCircleCICodeshipTravis CIApache AntApache MavenGradleAWS CodeStarTerraform CloudHygieiaBroadcom Automic

IDEs

Visual Studio CodeJetBrains IDEsEclipseVisual Studio 2019Visual Studio 2022Visual Studio 2017 (historical)

Issue trackers

Jira Server/Data CenterJira CloudAzure DevOpsBugzillaAsanaServiceNowDefectDojo

Pricing & plans

Trial: Two documented 14-day trials only: DAST in the Veracode Platform (self-serve sign-up) and Security Labs (no Veracode account needed). A Free Trial Admin role allows up to nine extra users and four extra teams in a trial org.

Who it's for

Notable strengths

  • Unusually broad legacy/mainframe language coverage: COBOL, RPG, PL/SQL, T-SQL, Classic ASP, ColdFusion, Perl CGI, Visual Basic 6, Apex
  • Policy-governance layer with built-in and custom policies, Veracode Levels VL1-VL5, and named PCI compliance policy templates that gate application pass/fail
  • Multiple testing types from one vendor: SAST, SCA, DAST, container/IaC/secrets, manual pen testing, EASM, Package Firewall, and VRM ASPM aggregation
  • Baseline-file (results.json) incremental scanning isolates new findings from a legacy backlog in CI
  • Bundled developer training: Security Labs interactive labs plus compliance-trackable eLearning curricula with recurring recertification periods

Notable limitations

  • No published pricing, plan tiers, or free tier; licensing is per product/scan type and sales-negotiated, with only 14-day DAST and Security Labs trials
  • Repository integrations exclude major providers: not supported on GitHub Enterprise Server, GitLab Self-Managed or GitLab Dedicated, and GitLab.com requires Premium or Ultimate
  • Pipeline Scan is disconnected from the platform, so it supports no flaw mitigation or flaw matching, and is rate-limited to 6 scans per 60 seconds
  • Veracode Fix only remediates Pipeline Scan findings, across a fixed CWE list for ten languages, and cannot auto-apply most suggestions in the pipeline
  • U.S. Federal Region and FedRAMP environments explicitly lack the GitHub, GitLab and Azure DevOps workflow integrations plus other features
  • Legacy Static-only IDE plugins and Greenlight reach end-of-life 2026-12-31, forcing migration to the Veracode Scan plugin line

Similar tools

Other Code Security Platform tools in the directory.

FAQ

When should you choose Veracode?

Veracode best fits Enterprise, Regulated industries. Unusually broad legacy/mainframe language coverage: COBOL, RPG, PL/SQL, T-SQL, Classic ASP, ColdFusion, Perl CGI, Visual Basic 6, Apex

What languages does Veracode support?

Veracode supports 35+ languages and frameworks, including Java (Java SE, Java EE, Jakarta), C#, VB.NET, ASP.NET, C++/CLI, JavaScript, TypeScript, PHP, Scala, Groovy, and 25 more.

What does Veracode integrate with?

Veracode integrates with GitHub, GitLab (partial), Bitbucket (partial), Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI, Azure Pipelines, Jenkins/Hudson, Atlassian Bamboo, and 11 more, and IDEs including Visual Studio Code, JetBrains IDEs, Eclipse, Visual Studio 2019, Visual Studio 2022, and 1 more.

What tools are similar to Veracode?

Similar Code Security Platform tools tracked here include Aikido, Checkmarx One, Corgea, GitHub Advanced Security.

What are Veracode's plans and pricing?

Veracode has paid plans starting around Quote-based pricing; enterprise pricing is quote-only.