• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Veracode
Logo of Veracode

Veracode

byVeracode
in
4.6
Market Presence: Application Security Testing, Software Supply Chain Security

Overview

Product Information on Veracode

Updated 13th October 2025

What is Veracode?

Veracode is a software focused on application security, offering tools for static analysis, dynamic analysis, software composition analysis, and manual penetration testing. The software scans code and binaries to identify vulnerabilities, helping organizations improve security throughout the software development lifecycle. It integrates with development environments and DevOps pipelines, enabling continuous security checks and remediation guidance for developers. Veracode addresses business challenges related to secure coding, regulatory compliance, and risk management by providing actionable insights, reporting, and governance features. The software supports a range of programming languages and frameworks, allowing teams to reduce security risks while maintaining development speed and agility.

Veracode Pricing

Veracode software offers pricing based on modules and usage, including application security testing solutions that are typically billed annually. Pricing can vary according to the number of applications or code scans required, with differing costs for features such as static analysis, dynamic analysis, and software composition analysis. Enterprise agreements and tailored pricing may be available for larger organizations or custom needs.

Overall experience with Veracode

IT OPS SPECIALIST
30B + USD, Banking
FAVORABLE

“Rich Explanations Provided, But False Positives and Speed Persist as Major Issues”

4.0
Oct 22, 2025
Veracode does a great job in finding the potential security flaws in code. Yet its limited intelligence on the overall project structure provides a lot of false positive findings. Also its support of the Python/JavaScript projects is quite limited
APPLICATION SECURITY SENIOR ENGINEER
50M - 250M USD, Services (non-Government)
CRITICAL

“Great product if your organization is ready for SAST.”

3.0
Jun 24, 2025
Overall the experience is good. There are some technical difficulties with using the Veracode solution (requirement of compiling the code) but other than that everything works great. Using the API is also sometimes flaky (from time to time it just stops working)

About Company

Company Description

Updated 25th July 2024

Veracode is a software security firm focused on identifying flaws and vulnerabilities across all stages of the software development lifecycle. The foundation of Veracode's approach lies in its Software Security Platform, which uses advanced AI algorithms trained on vast datasets of code. This allows for faster and more precise identification and rectification of security flaws. Veracode's mission is to evolve the concept of software security, ensuring it stays aligned with the dynamic needs of today's software development processes.

Company Details

Updated 26th February 2025
Company type
Private
Year Founded
2006
Head office location
Burlington, United States
Number of employees
501 - 1000
Website
https://veracode.com

Do You Manage Peer Insights at Veracode?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Veracode
Reviewer Insights for: Veracode
Performance of Veracode Across Market Features

Veracode Likes & Dislikes

Like

- it allows to perform multiple sandbox scans not affecting the overall compliance status of the project - Veracode has rich UI allowing to analyze and triage the findings - There are great explanations of the findings, including links to the source documents and training materials

Like

Having the environment (scanning platform) ready to use and always working.

Like

The dedication of the account team that supports the solution, combined with the fact that the various scanners Veracode offers are integrated in a single platform.

Dislike

- lot of false positive findings caused by not considering the overall structure of a project and dependencies; - slow assessment even of a quite small projects; - limited support of Python/JavaScript projects

Dislike

Ways that you can view and validate findings. Web portal is not usable and IDE plugins are not polished. Also some of the IDEs are not supported at all.

Dislike

Last year there have been many changes in the Veracode team supporting my organization. While this was inconvenient it did not affect the delivered service.

Top Veracode Alternatives

Logo of Checkmarx SAST
1. Checkmarx SAST
4.6
(398 Ratings)
Logo of Appknox
2. Appknox
4.8
(246 Ratings)
Logo of AppScan
3. AppScan
4.7
(213 Ratings)
View All Alternatives

Peer Discussions

Veracode Reviews and Ratings

Showing data for 401 ratings and reviews for Application Security Testing market. View all 422 ratings and reviews across markets for a complete picture.

4.6

(401 Ratings)

Rating Distribution

5 Star
69%
4 Star
26%
3 Star
4%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.6

Integration & Deployment

4.6

Service & Support

4.7

Product Capabilities

4.6

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • IT OPS SPECIALIST
    10B+ USD
    Banking
    Review Source

    Rich Explanations Provided, But False Positives and Speed Persist as Major Issues

    4.0
    Oct 22, 2025
    Veracode does a great job in finding the potential security flaws in code. Yet its limited intelligence on the overall project structure provides a lot of false positive findings. Also its support of the Python/JavaScript projects is quite limited
  • IT Security & Risk Management Associate
    50M-1B USD
    Banking
    Review Source

    Good scanning capabilities and frequent release of new features

    5.0
    Jul 1, 2025
    The SAST & SCA capabilities are easy to implement and deliver on the promises made by Veracode. Veracode is extremely committed with a good support desk and experts that are easy accessible. It does seem that the company mainly focuses at the US market and functionality in the EU comes with a slight delay. The performance of the solution is sometimes criticized - static scans delay the deployment pipelines and developers have to wait for the results.
  • CyberSecurity Consultant
    50M-1B USD
    Healthcare and Biotech
    Review Source

    Excellent tool with great support, but room for UX improvements.

    5.0
    Jul 1, 2025
    An excellent and comprehensive tool that has improved significantly over the past two years, with exceptional and prompt customer support.
  • IT Associate
    10B+ USD
    Banking
    Review Source

    Veracode Enables Rapid Code Analysis but May Cause False Positive Alerts

    4.0
    Jul 4, 2025
    I use Veracode every time my PRs synced via pipeline and it works well in analysing the code and performing security checks in a couple of minutes.
  • Manager, IT Security and Risk Management
    10B+ USD
    Banking
    Review Source

    Attentive Support Aids Transition Amid Unannounced Production Environment Adjustments

    4.0
    Jul 4, 2025
    Since the beginning of the migration , we have had constant support and assistance , always ready to help us at every step of the process
...
Showing Result 1-5 of 399

Recommended Gartner Research

  • Critical Capabilities for Application Security Testing
  • Magic Quadrant for Application Security Testing

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.