Skip to content
Veracode logo

Veracode

Veracode's Application Risk Management Platform identifies risks, automates flaw fixes, and simplifies governance and compliance.

Acquired
application securitySASTsoftware composition analysisDevSecOps
Share:

About

The Veracode Application Risk Management Platform is engineered for the AI-coding era. The vendor states it identifies risks across the software development lifecycle, automates flaw fixes, and simplifies governance and compliance. The platform aims to reduce risk and deliver secure software. Veracode states its platform has scanned 1.5M+ applications, analyzed 471T+ code lines, and fixed 148M+ software flaws, with a false-positive rate of less than 1.1%. The platform provides unified visibility for security teams across code, dependencies, containers, and runtime signals. Developers receive remediation guidance and AI-driven fixes within their existing tools. The platform also offers governance, reporting, and policy control for leaders to support compliance and demonstrate progress. Veracode states its platform helps safeguard AI-generated code, protect the software supply chain, secure the SDLC, and accelerate remediation.

Read from veracode.com on 2026-08-26. We describe what the vendor states; we do not audit it.

Enterprise Readiness

from cataloged data
57/100 · Established
Security & ComplianceNot disclosed

No compliance certifications listed

Deployment FlexibilityStrong

Flexible deployment: Cloud, Hybrid

Integration DepthStrong

8 documented integrations

Proven AdoptionPartial

6 documented use cases

Company MaturityPartial

Founded 2006

Composite of public compliance, deployment, integration, adoption, and company signals. “Not disclosed” reflects gaps in available data, not a vendor deficiency.

Independently sourced

Pulled directly from regulator filings and platform APIs. No vendor or editorial input.

Enterprise Use Cases

Static Application Security Testing (SAST)
Software Composition Analysis (SCA)
Dynamic Application Security Testing (DAST)
DevSecOps integration
Compliance reporting and audit readiness
Vulnerability management and remediation

Integrations

JenkinsGitHubGitLabAzure DevOpsJIRASlackServiceNowAtlassian

How Veracode compares

ToolReadinessPricingDeploymentComplianceIntegrations
Veracode57 · EstablishedEnterpriseCloud, Hybrid8
CheckmarxNot scoredEnterpriseCloud, On-Premise, Hybrid, Self-Hosted8
SnykNot scoredFreemiumCloud, On-Premise, Hybrid8
Snyk Code70 · StrongFreemiumCloud, On-Premise, Hybrid8

Peers from the same category, ranked by Enterprise Readiness. Readiness is a composite of cataloged compliance, deployment, integration, adoption, and company signals.

Frequently Asked Questions

What is Veracode used for?

Veracode is veracode's Application Risk Management Platform identifies risks, automates flaw fixes, and simplifies governance and compliance. It is commonly used for static application security testing (sast), software composition analysis (sca), dynamic application security testing (dast), and devsecops integration.

Is Veracode free, and how is it priced?

Veracode uses enterprise pricing, typically a custom quote based on seats, usage, and requirements. Contact the vendor for a quote.

How can Veracode be deployed?

Veracode supports Cloud and Hybrid deployment. It is delivered as a cloud-hosted service.

What does Veracode integrate with?

Veracode documents 8 integrations, including Jenkins, GitHub, GitLab, Azure DevOps, JIRA, and Slack.

When was Veracode founded?

Veracode was founded in 2006.

Is Veracode enterprise-ready?

Based on cataloged data, Veracode has an Enterprise Readiness score of 57/100 (Established tier), derived from its compliance, deployment, integration, adoption, and company-maturity signals.

Quick Facts

PricingEnterprise
DeploymentCloud, Hybrid
Founded2006

Procurement

Evaluating vendors like this one?

The Enterprise AI RFI/RFP asks the security, governance, and lock-in questions sales decks skip.

See the template — RFI $299 / RFP $699

Is this your product?

Claiming is free and lets you correct your listing's data. Upgrade to Enhanced ($199/yr) for a vendor-maintained mark, a richer profile, and lead routing.

·

Alternatives to Veracode

View all →

Comparable Code & Development tools, ranked by enterprise readiness.

Checkmarx logo

Checkmarx

checkmarx.com

Comprehensive static and interactive application security testing for enterprise-scale code security.

Funded$143MInsight PartnersSapphire Ventures
application securitystatic code analysisDevSecOpscompliance
Enterprise2.7k
OSSCloudOn-Prem
Snyk logo

Snyk

snyk.io

Developer-first security platform to secure code, dependencies, and infrastructure at scale

Funded$450M+AccelTiger Global
application securityvulnerability managementDevSecOpsopen source security
Freemium5.7k
CloudOn-Prem
Snyk Code logo

Snyk Code

snyk.io/product/snyk-code/

Snyk Code is a static application security testing (SAST) solution that helps developers find, prioritize, and auto-fix code issues.

Funded$450M+AccelTiger Global
static analysisapplication securitydeveloper-firstcompliance
Freemium5.7k
CloudOn-Prem
Endor Labs logo

Endor Labs

www.endorlabs.com/

AURI helps agents write secure code from the start and governs the actions they take.

Funded$7.3MVertex VenturesOurCrowd
automated code reviewCI/CD integrationsoftware qualitysecurity compliance
Enterprise
OSSCloudOn-Prem
Moderne AI logo

Moderne AI

moderne.io

Enterprise-grade AI-powered code review for scalable, secure software delivery.

Funded$15MAmplify PartnersSusa Ventures
AI-powered code reviewCI/CD integrationcode qualitysecurity compliance
EnterpriseDormant
OSSCloudOn-Prem
DeepCode logo

DeepCode

snyk.io/platform/deepcode-ai/

AI technology that powers application security testing tools in the Snyk platform

Funded$17MEarlybird Venture CapitalRedalpine Venture Partners
AI code reviewsecurity analysisCI/CD integrationscalable development
Freemium5.7k
CloudOn-Prem