Veracode offers SAST, DAST, SCA, and ASPM tools to secure applications. Learn about Veracode pricing, features, history, and alternatives.
Veracode is an application security testing company that helps engineering and security teams identify and fix vulnerabilities in custom code, open-source dependencies, and running applications. It was founded in 2006 by Chris Wysopal and Christien Rioux, two former members of the L0pht hacker think tank, and built its early reputation on cloud-delivered static analysis.
The company has been owned by several different parents over its history, moving through CA Technologies, Broadcom, and Thoma Bravo before TA Associates acquired a majority stake in 2022 at a roughly 2.5 billion dollar valuation, and it now operates as an independent application security vendor headquartered in Burlington, Massachusetts.
Veracode serves more than 2,400 customers and reports scanning over 315 trillion lines of code, positioning itself for organizations that need to secure software across the full development lifecycle, from code written in-house to open-source components and running production applications.
Veracode's core testing capabilities include Static Application Security Testing for finding flaws in source code, Dynamic Application Security Testing for scanning running web applications, and Software Composition Analysis for identifying known vulnerabilities in open-source dependencies.
Beyond core scanning, Veracode offers Risk Manager for Application Security Posture Management, AI-assisted remediation through its Fix capability, container security scanning, a Package Firewall that proactively blocks malicious open-source packages, and Penetration Testing as a Service.
The platform also includes developer-focused eLearning and security labs, aimed at reducing vulnerabilities at the source by training developers directly.
Veracode does not publish standard pricing tiers. Costs are quote-based and typically scale with the number of applications, lines of code, or scan types an organization needs, which is common for enterprise application security platforms.
Prospective customers request a demo or quote directly from Veracode's sales team, and pricing can vary significantly depending on which modules, such as SAST, DAST, SCA, or PTaaS, are included in a contract.
Veracode provides application security testing, including static, dynamic, and software composition analysis, to find and fix vulnerabilities.
Chris Wysopal and Christien Rioux founded Veracode in 2006.
TA Associates acquired a majority stake in Veracode in March 2022 at a roughly 2.5 billion dollar valuation.
Veracode uses custom, quote-based pricing that is not published publicly.
No, Veracode scans application code for security flaws, while Vanta automates compliance and audit workflows; they are different companies.
Yes, through its Software Composition Analysis capability.
Veracode is used across regulated industries like finance, healthcare, and government, as well as general enterprise software teams.
Yes, Veracode offers IDE plugins and CI/CD integrations for automated scanning.