Code Security Platform
Veracode
Enterprise AppSec platform spanning SAST, SCA, DAST, container/IaC scanning, AI auto-remediation, ASPM risk management, and developer training.
Deployment
Cloud · Self-Hosted (partial)
Languages
35+
Pricing model
Quote-based / Enterprise
Free tier
No
Workflow coverage
Where in the development lifecycle Veracode operates.
Greenlight gives instant in-IDE feedback as code is written, retiring 2026-12-31; Scan plugins run on demand.
Not offered in vendor documentation reviewed as of 2026-09-05.
Veracode CLI and Pipeline Scan JAR/Docker run locally; --allow-dirty re-verifies uncommitted changes
Pipeline Scan posts results to PRs; Fix GitHub Action adds PR comments and annotations
Veracode checks configurable as required status checks; --fail_on_severity/--fail_on_cwe break builds
Upload and Scan of packaged artifacts; repository scanning on push across all org repos
Policies enforce scan cadences - quarterly, semi-annual or annual - so repeat scans run on schedule.
DAST scans live apps/APIs; Quick scan safe in production; EASM discovers external assets
Analysis & detection
Every detection and code-analysis capability tracked for Veracode.
Upload and Scan plus Pipeline Scan on compiled/packaged artifacts, CWE-mapped, 0-5 severity scoring
Not offered in vendor documentation reviewed as of 2026-09-05.
Container/IaC scanning detects secrets via configurable RE2 secret-rules; 60+ named provider key types
Not offered in vendor documentation reviewed as of 2026-09-05.
Agent-based scan with quick, full and vulnerable-methods depths; direct vs transitive dependency graph
Vulnerable Methods scan (Level 3) checks whether first-party code calls vulnerable third-party methods
Veracode Package Firewall blocks malicious open-source packages at the registry level
License-risk ratings per component; policy rules block high-risk, non-OSS or unrecognized licenses
REST API and 'veracode sbom' CLI output CycloneDX 1.6, SPDX 2.3, Syft JSON; unbuilt Gradle limited
IaC misconfiguration scanning via repository integrations and CLI scan command with Rego custom policy
Container image/archive scanning across nine base OS families for vulns, misconfigurations, secrets
Veracode Risk Manager aggregates cloud infrastructure and security-tool findings; no native CSPM scanner documented
DAST covers web apps and REST/SOAP/OpenAPI/Postman APIs; Enterprise mode adds API spec management
SAST reports a 'Code Quality' CWE finding category covering non-security maintainability defects.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Security Quality Score, Veracode Levels VL1-VL5, open-flaw age and time-to-resolve dashboards; security debt only
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Buyers author custom regex secret rules plus Rego container and IaC policies.
Veracode Fix suggests up to five RAG-matched patches per flaw in CLI and IDE; Pipeline Scan findings only
Fix GitHub Action creates branch and PR; SCA auto-opens dependency-upgrade PRs on GitHub/GitLab
Vulnerable-methods reachability and VRM dedup/correlation cut noise; mitigation workflow is manual, not AI triage
Multi-module build uploads let you choose which modules to scan, adjacent to monorepo scanning; repo-scanning docs never use the term "monorepo" or describe per-directory project scoping.
AI capabilities
Veracode Fix uses ML plus RAG for remediation only; no AI reviewer that finds issues itself
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
Not offered in vendor documentation reviewed as of 2026-09-05.
A Veracode Fix whitepaper states customer code is never used to further train that model, but the commitment is scoped to Fix only; a platform-wide statement is gated behind Veracode's Trust Center.
Compliance & governance
User activity log and audit trails documented for enterprise governance
SSO/SAML documented, including a SAML gateway for standalone Security Labs accounts
Named roles including Security Lead, Reviewer, Security Labs admin/manager/user, Free Trial Admin
Pre-built analytics dashboards, PDF/JUnit/CSV DAST reports, SARIF export, REST API report retrieval
Certifications
Standards mapping
Integrations
CI/CD systems
IDEs
Issue trackers
Pricing & plans
Trial: Two documented 14-day trials only: DAST in the Veracode Platform (self-serve sign-up) and Security Labs (no Veracode account needed). A Free Trial Admin role allows up to nine extra users and four extra teams in a trial org.
Who it's for
Notable strengths
- Unusually broad legacy/mainframe language coverage: COBOL, RPG, PL/SQL, T-SQL, Classic ASP, ColdFusion, Perl CGI, Visual Basic 6, Apex
- Policy-governance layer with built-in and custom policies, Veracode Levels VL1-VL5, and named PCI compliance policy templates that gate application pass/fail
- Multiple testing types from one vendor: SAST, SCA, DAST, container/IaC/secrets, manual pen testing, EASM, Package Firewall, and VRM ASPM aggregation
- Baseline-file (results.json) incremental scanning isolates new findings from a legacy backlog in CI
- Bundled developer training: Security Labs interactive labs plus compliance-trackable eLearning curricula with recurring recertification periods
Notable limitations
- No published pricing, plan tiers, or free tier; licensing is per product/scan type and sales-negotiated, with only 14-day DAST and Security Labs trials
- Repository integrations exclude major providers: not supported on GitHub Enterprise Server, GitLab Self-Managed or GitLab Dedicated, and GitLab.com requires Premium or Ultimate
- Pipeline Scan is disconnected from the platform, so it supports no flaw mitigation or flaw matching, and is rate-limited to 6 scans per 60 seconds
- Veracode Fix only remediates Pipeline Scan findings, across a fixed CWE list for ten languages, and cannot auto-apply most suggestions in the pipeline
- U.S. Federal Region and FedRAMP environments explicitly lack the GitHub, GitLab and Azure DevOps workflow integrations plus other features
- Legacy Static-only IDE plugins and Greenlight reach end-of-life 2026-12-31, forcing migration to the Veracode Scan plugin line
Similar tools
Other Code Security Platform tools in the directory.
FAQ
When should you choose Veracode?
Veracode best fits Enterprise, Regulated industries. Unusually broad legacy/mainframe language coverage: COBOL, RPG, PL/SQL, T-SQL, Classic ASP, ColdFusion, Perl CGI, Visual Basic 6, Apex
What languages does Veracode support?
Veracode supports 35+ languages and frameworks, including Java (Java SE, Java EE, Jakarta), C#, VB.NET, ASP.NET, C++/CLI, JavaScript, TypeScript, PHP, Scala, Groovy, and 25 more.
What does Veracode integrate with?
Veracode integrates with GitHub, GitLab (partial), Bitbucket (partial), Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI, Azure Pipelines, Jenkins/Hudson, Atlassian Bamboo, and 11 more, and IDEs including Visual Studio Code, JetBrains IDEs, Eclipse, Visual Studio 2019, Visual Studio 2022, and 1 more.
What tools are similar to Veracode?
Similar Code Security Platform tools tracked here include Aikido, Checkmarx One, Corgea, GitHub Advanced Security.
What are Veracode's plans and pricing?
Veracode has paid plans starting around Quote-based pricing; enterprise pricing is quote-only.
Opens www.veracode.com in a new tab. Review Radar is not affiliated with Veracode.