• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In

Overview

Product Information on Veracode

Updated 13th October 2025

What is Veracode?

Veracode is a software focused on application security, offering tools for static analysis, dynamic analysis, software composition analysis, and manual penetration testing. The software scans code and binaries to identify vulnerabilities, helping organizations improve security throughout the software development lifecycle. It integrates with development environments and DevOps pipelines, enabling continuous security checks and remediation guidance for developers. Veracode addresses business challenges related to secure coding, regulatory compliance, and risk management by providing actionable insights, reporting, and governance features. The software supports a range of programming languages and frameworks, allowing teams to reduce security risks while maintaining development speed and agility.

Veracode Pricing

Veracode software offers pricing based on modules and usage, including application security testing solutions that are typically billed annually. Pricing can vary according to the number of applications or code scans required, with differing costs for features such as static analysis, dynamic analysis, and software composition analysis. Enterprise agreements and tailored pricing may be available for larger organizations or custom needs.

Overall experience with Veracode

Software Developer
250M - 500M USD, IT Services
FAVORABLE

“CI/CD Integration Streamlines Automated Security Testing and Provides Transparency”

5.0
May 13, 2026
Our overall experience with Veracode has been very positive. The platform helps us strengthen application security across multiple stages of development by identifying vulnerabilities early in the SDLC. Integration with CI/CD pipelines makes security testing more efficient and reduces manual efforts for developers. The dashboard and reporting features provide good visibility into security posture and remediation progress. Overall, it has been a reliable and valuable solution for improving secure development practices.
Information Security Specialist
<50M USD, Transportation
CRITICAL

“Flexibility in Integration Noted, Yet Detection Gaps Remain in Veracode”

3.0
May 1, 2026
Veacode for secure code scanning worked as a basic tool that allowed to easily integrate code scanning on repositories and pipelines, lacking some in-depth detection.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Peer Discussions

Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

  1. Home
  2. /
  3. Veracode
Logo of Veracode

Veracode

byVeracode
in
4.6
Market Presence: Application Security Testing, Software Supply Chain Security

About Company

Company Description

Updated 25th July 2024

Veracode is a software security firm focused on identifying flaws and vulnerabilities across all stages of the software development lifecycle. The foundation of Veracode's approach lies in its Software Security Platform, which uses advanced AI algorithms trained on vast datasets of code. This allows for faster and more precise identification and rectification of security flaws. Veracode's mission is to evolve the concept of software security, ensuring it stays aligned with the dynamic needs of today's software development processes.

Company Details

Updated 26th February 2025
Company type
Private
Year Founded
2006
Head office location
Burlington, United States
Number of employees
501 - 1000
Website
https://veracode.com

Do You Manage Peer Insights at Veracode?

Access Vendor Portal to update and manage your profile.

User Sentiment About Veracode
Reviewer Insights for: Veracode
Performance of Veracode Across Market Features

Veracode Likes & Dislikes

Like

1. Strong static and dynamic application security testing capabilities that help identify vulnerabilities early in the development lifecycle. 2. Easy integration with CI/CD tools and developer workflows, making automated security testing more efficient. 3. Centralized dashboard that provides visibility into application risk, compliance and scan history

Like

It provides flexibility in integration with pipelines and reporting capabilities for the overall landscape of secure coding practices.

Like

1. Detailed reporting and remediation guidance that helps development teams understand and fix issues faster. 2. Reliable software composition analysis features for monitoring open source dependencies and related risks. 3. Strong static and dynamic application security testing capabilities that help identify risks early in the development lifecycle.

Dislike

1. Initial onboarding and policy configuration can be complex for teams that are new to application security tools. 2. Scan completion time for larger or complex application can sometimes be slower than expected. 3. False positives occasionally require additional manual validation from security

Dislike

Based on our secure life cycle we perform other testing with different tools and techniques; in multiple cases we found vulnerabilities that were supposed to be detected by veracode and they were not.

Dislike

1. Licensing and advanced features may feel expensive for smaller organizations with limited budgets. 2. Initial onboarding and policy configuration can be complex for teams that are new to application security tools. 3. Certain reports and dashboards can be more customizable for different stakeholder requirements.

Recommended Gartner Insights

  • Critical Capabilities for Application Security Testing
  • Magic Quadrant for Application Security Testing

Top Veracode Alternatives

Veracode Reviews and Ratings

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Software Developer
    50M-1B USD
    IT Services
    Review Source

    CI/CD Integration Streamlines Automated Security Testing and Provides Transparency

    5.0
    May 13, 2026
    Our overall experience with Veracode has been very positive. The platform helps us strengthen application security across multiple stages of development by identifying vulnerabilities early in the SDLC. Integration with CI/CD pipelines makes security testing more efficient and reduces manual efforts for developers. The dashboard and reporting features provide good visibility into security posture and remediation progress. Overall, it has been a reliable and valuable solution for improving secure development practices.
  • Engineer
    50M-1B USD
    IT Services
    Review Source

    Detailed Reporting and Remediation Guidance Accelerates Issue Resolution for Developers

    5.0
    May 13, 2026
    My overall experience with Veracode has been very positive. The platform helps us strengthen application security across multiple stages of development by identifying issues early in the SDLC. The integration pipeline made security testing more efficient and reduced manual efforts for developers. Overall, it has been a reliable and valuable solution for improving secure development practices.
  • Information Security Specialist
    <50M USD
    Transportation
    Review Source

    Flexibility in Integration Noted, Yet Detection Gaps Remain in Veracode

    3.0
    May 1, 2026
    Veacode for secure code scanning worked as a basic tool that allowed to easily integrate code scanning on repositories and pipelines, lacking some in-depth detection.
  • IT ASSOCIATE
    50M-1B USD
    IT Services
    Review Source

    Integrates Well With CI/CD But Slower Scans for Larger Applications Noted

    5.0
    May 6, 2026
    Our experience with Veracode has been very positive as it helps identify vulnerabilities early, integrates well with CI/CD pipelines and provides useful remediation guidance. Reporting and dashboards to improve visibility into application security and compliance tracking. While scan times can occasionally be slow for larger applications, the platform overall is very reliable and very effective for managing application security
  • Software Developer
    50M-1B USD
    Healthcare and Biotech
    Review Source

    Scanning Tool Identifies Specific Code Issues With Minimal False Positives Reported

    4.0
    Mar 3, 2026
    Overall experience is an outstanding scanning tool that provides great, very specific issues within the code, while minimizing the number of false positives.
...
Showing Result 1-5 of 405

Showing data for 407 ratings and reviews for Application Security Testing market. View all 429 ratings and reviews across markets for a complete picture.

4.6

(407 Ratings)

Rating Distribution

5 Star
69%
4 Star
26%
3 Star
4%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.6

Integration & Deployment

4.6

Service & Support

4.7

Product Capabilities

4.6

Logo of Checkmarx SAST
1. Checkmarx SAST
4.6
(401 Ratings)
Logo of Fluid Attacks Continuous Hacking
2. Fluid Attacks Continuous Hacking
4.8
(314 Ratings)
Logo of Appknox
3. Appknox
4.8
(257 Ratings)
View All Alternatives