Veracode
Veracode is a private application security company founded in 2006 that sells a cloud-based Application Risk Management Platform combining SAST, DAST, SCA, container security, ASPM, AI-powered remediation, and supply chain protection to enterprise and mid-market customers across regulated industries and government.
- Company typePrivate
- Founded2006
- HeadquartersBurlington, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingSoftware
What Veracode does
Veracode, Inc. is a privately held application security company founded in 2006 and headquartered in Burlington, Massachusetts, that sells a cloud-based Application Risk Management Platform to enterprise and mid-market organizations. The platform unifies multiple testing modalities — Static Analysis (SAST), Dynamic Analysis (DAST), Software Composition Analysis (SCA), Container Security, and External Attack Surface Management — alongside proprietary modules: Veracode Risk Manager (an ASPM solution built from the April 2024 Longbow Security acquisition), Veracode Fix (an AI-powered code remediation tool patented in April 2025), and Veracode Package Firewall (which identifies 40–50 indicators of compromise to block malicious open-source packages across NPM, PyPI, Maven, Nexus, Artifactory, and Azure Artifacts). The platform is built on a proprietary vulnerability database accumulated over two decades of scanning, currently covering 1.5M+ applications, 135M+ flaws fixed, and 448T+ lines of code, supporting a sub-1.1% false-positive rate. The product integrates deeply into developer and security workflows via IDE plugins (Eclipse, IntelliJ, VS Code, Visual Studio), CI/CD (Jenkins, Azure DevOps), SCM (GitHub, GitLab), ticketing (Jira, Bugzilla), ITSM/GRC (ServiceNow, RSA Archer), and WAF tools (Imperva, ModSecurity), and participates in the Wiz Integration Network for cloud security correlation.
Veracode generates revenue primarily through annual subscription contracts with quote-based pricing for enterprise and mid-market customers, distributed via a sales-led motion that combines direct field sales for large enterprises, inside sales for mid-market, and the Velocity Partner Program for channel distribution (with regional distributors such as AmiViz for MEA and Centrico/Sella for Italian banking). The company serves a diverse customer base spanning financial services, government/public sector, healthcare, retail/e-commerce, energy, and developers/DevSecOps teams, with named enterprise customers including HDI Global SE, Manhattan Associates, Cox Automotive, Azalea Health, and Tecnimont Services (MAIRE). The firm holds FedRAMP and StateRAMP authorizations that unlock U.S. federal, state, and local government contracts, and operates engineering offices in Prague (opened 2023 with Accion Labs) in addition to its Burlington headquarters and London EMEA office. It is backed by TA Associates following a March 2022 growth investment, has completed three acquisitions in roughly two years (Crashtest Security, Longbow Security, Phylum), and is led by CEO Brian Roche, appointed in April 2024, alongside a refreshed executive team including a new CFO, Chief Strategy Officer, and General Counsel added during 2025.
Veracode firmographics
Firmographics- Name
- Veracode
- Legal name
- Veracode, Inc.
- Website
- https://veracode.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- Veracode is a private application security company founded in 2006 that sells a cloud-based Application Risk Management Platform combining SAST, DAST, SCA, container security, ASPM, AI-powered remediation, and supply chain protection to enterprise and mid-market customers across regulated industries and government.
- Ownership category
- akta.pro rank
Veracode industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where Veracode is headquartered
LocationHeadquarters
- HQ city
- Burlington
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Veracode business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Application Security Platform Subscription: Veracode generates revenue primarily through subscription-based licensing of its Application Risk Management Platform. Customers pay for access to security scanning tools including SAST, DAST, SCA, and AI-powered remediation capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise and mid-market subscription tiers with quote-based pricing |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels7 records
Veracode product offering
Product offeringCore offering
Veracode provides a cloud-based Application Risk Management Platform that identifies security risks across the software development lifecycle, automates flaw fixes, and simplifies governance and compliance. The platform combines SAST, DAST, SCA, container security, a package firewall, ASPM (Risk Manager), and AI-powered remediation (Veracode Fix), sold primarily as annual subscriptions to enterprise and mid-market organizations.
Product overview
Veracode offers a unified Application Risk Management platform designed for the AI-coding era. The portfolio centers on the Veracode Platform providing AI-driven prioritization and integrated tools to detect, understand, and remediate application vulnerabilities across the SDLC. Core testing products include SAST (Static Analysis) for source code scanning, DAST (Dynamic Analysis) for runtime web app testing, SCA (Software Composition Analysis) for open-source vulnerabilities, and Container Security for container technologies. The platform is enhanced by Veracode Fix (AI-powered code remediation that automates vulnerability fixes through pull requests), Veracode Package Firewall (supply chain protection blocking malicious packages from NPM, PyPI, Maven, Azure Artifacts, Nexus, and Artifactory), and Veracode Risk Manager (ASPM providing unified visibility and risk correlation). Additional modules include eLearning and Security Labs for developer training, PTaaS for penetration testing services, Application Security Consulting, Pipeline Scan for CI/CD integration, and External Attack Surface Management for discovering internet-exposed assets. The platform integrates with IDEs (Eclipse, IntelliJ, Visual Studio, VS Code), CI/CD tools (Jenkins, Azure DevOps), SCM systems (GitHub, GitLab), ticketing platforms (Jira, Bugzilla), and security/WAF tools (Imperva, ModSecurity). Veracode has grown through acquisitions including Longbow Security (now Risk Manager), Phylum (malicious package detection), and Crashtest Security (DAST capability).
Differentiator
Problem solved
Functional benefit
Brands
- Veracode Risk Manager: An Application Security Posture Management (ASPM) platform that provides unified visibility and remediation of application risk. Originally developed from the Longbow Security acquisition.
- Veracode Fix
- Veracode Package Firewall
Products and services
- Veracode Platform Unified Application Risk Management platform combining SAST, DAST, SCA, container security, package firewall, AI remediation, and ASPM for enterprise application security programs.
- SAST (Static Application Security Testing) Static Application Security Testing product that scans source and binary code to find vulnerabilities during development for enterprise development teams.
- DAST (Dynamic Application Security Testing) Dynamic Application Security Testing product that finds and fixes runtime vulnerabilities in running web applications, including AI-assisted authentication and EASM capabilities.
- SCA (Software Composition Analysis) Software Composition Analysis product that identifies vulnerable and malicious open-source components and license compliance issues for development and security teams.
- Veracode Package Firewall Software supply chain firewall that detects malicious open-source packages in real time and blocks downloads of compromised code from supported repositories.
- Veracode Risk Manager (ASPM) Application Security Posture Management platform that correlates and contextualizes application security risks across tools and traces them back to root cause for enterprise security teams.
- Veracode Fix AI-powered code remediation tool that automatically generates vulnerability fixes and refactors first-party code through pull requests to prevent breaking changes, for development and security teams.
- Container Security Container and Kubernetes security product that scans container images and configurations to prevent vulnerabilities from reaching production environments.
- Penetration Testing as a Service (PTaaS) Managed penetration testing service combining human expertise with automation to deliver comprehensive security testing for enterprise customers.
- Veracode eLearning On-demand secure coding training product for developers to build security skills aligned with their organization's coding standards.
- Security Labs Hands-on, interactive security training labs that let developers practice exploiting vulnerabilities in a safe environment.
- External Attack Surface Management (EASM) External Attack Surface Management product that automatically discovers internet-exposed assets and unmanaged applications to identify shadow IT risk.
Quantifiable outcome
- 184% ROI for Veracode Application Risk Management Platform customers (Total Economic Impact Study)
- +5 more outcomes
Companies that use Veracode
Customer profileNamed customers5 records
Segments7 records
Ideal customer profiles5 records
Veracode technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration23 records
AI capability12 records
Feature6 records
Veracode partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered strategic, core and regional.
- AmiVizstrategicAmiViz, a Middle East-based cybersecurity and AI value-added distributor, partnered with Veracode to distribute its AI-powered application security platform across the Middle East, East Africa, and Libya. The partnership enables Veracode to expand into new geographic markets while providing AmiViz customers with tools to embed security into AI-driven software development workflows.
- Wiz (WIN Partnership)coreVeracode joined the Wiz Integration Network (WIN) to eliminate application-to-cloud security blind spots. The partnership provides unified security visibility from code to cloud.
- PhylumcoreVeracode acquired Phylum, a malicious package analysis firm, to bolster its software supply chain security. The integration aims to improve detection and blocking of malicious code in open-source libraries.
- Longbow SecuritycoreVeracode acquired Longbow Security, a provider of security risk management for cloud-native environments. The acquisition (now rebranded as Veracode Risk Manager) brought Application Security Posture Management (ASPM) capabilities into Veracode's suite, transforming it from code testing to comprehensive unified risk management from code to cloud.
- Centrico Spa (Sella Group)regionalCentrico Spa, part of Sella Group, collaborated with Veracode to help secure the application development lifecycle for Italian banking and financial customers.
- Accion LabsregionalPartnership with Accion Labs to open Veracode's Prague engineering office in March 2023, expanding Veracode's global engineering capabilities.
Scale indicators7 records
Recent moves7 records
Expansion highlights6 records
Veracode competitors and assessment
Company assessmentEmerging players
- ArmorCode: ASPM and vulnerability management platform that competes with Veracode Risk Manager by aggregating findings across multiple scanning tools into a unified risk view.
- Apiiro: Application Security Posture Management (ASPM) emerging player focused on risk prioritization across the SDLC. Competitor to Veracode Risk Manager (formerly Longbow) in the ASPM category.
- Contrast Security: Runtime application security via interactive application security testing (IAST) and runtime vulnerability analysis. Adjacent to Veracode's DAST and SAST offerings with an alternative instrumentation-based approach.
Direct peers
- Snyk: Developer-first application security platform offering SAST, SCA, container, and IaC security. Snyk directly competes with Veracode across most product lines and is explicitly named on Veracode's own competitive comparison pages.
- Checkmarx: Enterprise application security testing vendor offering SAST, SCA, DAST, and IaC scanning. One of the closest direct competitors to Veracode, also named in Veracode's competitive comparisons and consistently positioned alongside it in the Gartner AST Magic Quadrant.
- Synopsys (Black Duck / Coverity): Synopsys' Black Duck (SCA) and Coverity (SAST) products overlap directly with Veracode's core offerings. Synopsys is named on Veracode's competitive pages and competes in the same Gartner AST and Forrester Wave evaluations.
- GitHub Advanced Security: Microsoft-owned native application security offering embedded in GitHub Enterprise, covering SAST, SCA, and secrets scanning. Named by Veracode as a primary competitor and the leading developer-native challenger leveraging Microsoft's distribution and bundling power.
- OpenText (Fortify): OpenText Fortify offers SAST, DAST, and runtime application security. Directly competes with Veracode in the Gartner AST Magic Quadrant and is named in Veracode's competitive comparison set.
- Mend (formerly WhiteSource): SCA-focused application security vendor that also extends into SAST and container security. Directly competes with Veracode's SCA and supply-chain security capabilities including Package Firewall.
Broad incumbents
- CrowdStrike: Endpoint and cloud security leader that has expanded into application security and ASPM-adjacent capabilities via acquisition. While not a specialist in Veracode's core SAST/DAST/SCA category, it competes at the platform-security-buyer level for enterprise security budgets.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
Veracode social profiles
Digital presenceVeracode compliance and trust
Trust signalCompliance11 records
Veracode financial estimates
Financial estimateRevenue estimate
Valuation estimate
Veracode leadership team
Management profileNumber of profiles
Profiles11 records
Veracode subsidiaries and ownership
Company hierarchySubsidiaries3 records
Veracode funding detail
Funding detailFunding overview
Funding rounds7 records
Investors14 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Veracode M&A and investment
M&A and investmentM&A4 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Veracode
What does Veracode do?
Veracode provides a cloud-based Application Risk Management Platform that identifies security risks across the software development lifecycle, automates flaw fixes, and simplifies governance and compliance. The platform combines SAST, DAST, SCA, container security, a package firewall, ASPM (Risk Manager), and AI-powered remediation (Veracode Fix), sold primarily as annual subscriptions to enterprise and mid-market organizations.
Is Veracode a public or private company?
Veracode is a private company. It is classified as private equity controlled and is currently operating.
When was Veracode founded?
Veracode was founded in 2006. It employs 501 to 1,000 people.
Where is Veracode based?
Veracode is headquartered in Burlington, United States, in the North America region.
How does Veracode make money?
One revenue line is on record: application Security Platform Subscription.
Who are Veracode's main competitors?
Emerging players on record are ArmorCode, Apiiro and Contrast Security. Direct peers are Snyk, Checkmarx, Synopsys (Black Duck / Coverity), GitHub Advanced Security, OpenText (Fortify) and Mend (formerly WhiteSource). CrowdStrike is listed as a broad incumbent.
Does Veracode have an API?
Yes. Veracode provides REST APIs and XML APIs that allow programmatic interaction with the Veracode Platform. The APIs enable developers to create application profiles, package and upload applications, submit applications for scanning directly from IDEs, SCM tools, and CI/CD environments, import security findings into issue tracking systems, and generate compliance reports. The platform requires access to specific region domains depending on the account region, with communication on port 443 to REST API domains. Veracode also provides API wrappers (CLI programs) for XML API communication. Developer documentation is at docs.veracode.com/r/Veracode_APIs.
What industry is Veracode in?
Veracode's product category is Application Security Testing. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 5132 and its SIC code is 7372.